OpenAI’s dots turn an ongoing responsibility into something you can delegate to an agent with its own computer. The useful first step is to choose a small responsibility with an observable result. Before connecting valuable accounts, decide what the dot may read, what it may change and which decisions must return to you.
Editorial note: Prepared October 1 as a September 29, 2026 dispatch, using the dated announcements cited below. Later product developments are outside this article’s scope.
- 01Access is stagedCheck your plan, market and workspace settings before planning a rollout.
- 02Reading and acting differProactive research is read-only; delegated work needs its own action boundaries.
- 03Included does not mean unlimitedTasks started in Work or Codex use their usual plan allowances.
01 — The evidenceWhat OpenAI announced
In its September 29 introduction, OpenAI describes GPT-6 Astra agents with their own cloud computer and browser, connections to more than 4,000 apps, and access through ChatGPT, Slack and Teams. Text messaging is planned. Pro and Business Premium access is rolling out in eligible markets; Enterprise, Edu and Healthcare workspaces must enable the beta. Specialist dots begin with enterprise pilots, while Microsoft Agent 365 integration remains in development.
Those are product capabilities and announced stages, not a promise that an agent can finish any job correctly. A persistent agent changes how work arrives and continues, but the person delegating still needs to define success. A weekly research brief, for example, can have a fixed source list, a delivery format and a reviewer. “Help grow the business” leaves both the actions and the acceptance standard undefined.
Our DevDay preparation guide covers the planning background. Dots add a continuing relationship to that picture: instructions need to remain understandable after the conversation that created them is no longer fresh.
02 — Practical implicationsWrite the responsibility as a short contract
Give the first assignment an input, output, cadence and stopping condition. An example is: review these public release pages each weekday, save a short brief with source links, and flag changes that affect our current product. Sending the brief to a client should be a separate decision. This makes the difference between preparing information and representing the business explicit.
| Part | Example boundary |
|---|---|
| Inputs | Only the named public pages and an approved internal product brief. |
| Output | A dated draft with source links and an uncertainty section. |
| Actions | Save the draft; request approval before external communication. |
| Stop | Pause if a source requires new access or the task exceeds its budget. |
Describe exceptions in plain language. If a source is unavailable, the agent should record that fact instead of substituting an unrelated source. If two sources disagree, it should show the conflict. If a task requires a login or a broader permission, it should return to the owner. The value of these instructions is that a reviewer can check them against actual work.
03 — Practical implicationsSeparate background reading from authorized action
OpenAI says proactive research uses read-only tools. Custom Rules can allow, require approval for or block actions, and Activity View exposes progress. Auto-review checks consequential actions against instructions and safety requirements; some sensitive tasks stay with the user. These mechanisms reduce the amount of supervision needed, but they do not remove the need to review consequential outputs.
Collect a bounded evidence set
Use approved sources and inspect the resulting brief for omissions or unsupported claims.
Create a reviewable draft
Let the agent prepare a message, patch or document while you decide whether it is ready.
Change a business system
Authorize a narrow class of actions only after the preparation workflow behaves reliably.
Test a rule with an innocuous example before relying on it. Ask the dot to prepare an external message, then inspect whether it waits at the intended boundary. Check the activity record for the attempted action and the approval request. A rule that sounds precise can still leave ambiguity about recipients, attachments or which account is being used.
Our guide to permission defaults explains why narrow access matters independently of the quality of the instructions. Connecting an app creates a capability; the task contract explains when that capability should be used.
04 — Practical implicationsBudget the work, including follow-on tasks
OpenAI includes the first dot with Pro or Business Premium. Dot conversations do not consume ChatGPT limits, but tasks it starts or manages in Codex or Work count normally. The launch post does not publish additional-dot prices. Do not translate “included” into an unlimited monthly production budget.
For the pilot, record the number of requested tasks, accepted outputs, follow-on jobs and minutes of human correction. Those observations are more useful than counting messages. An agent can exchange many short messages while doing little billable work, or start a substantial task from one sentence. Put an owner on the allowance and define what should happen when it is nearly exhausted.
Review access and data settings for the specific workspace. Keep the first assignment away from unnecessary personal or customer information. A useful public-source brief can establish the workflow before the organization makes a separate decision about private material. Our runtime boundary comparison provides a broader checklist for computer access.
05 — Practical implicationsExpand after reviewing complete outcomes
Review several finished assignments, including one where information was missing and one where an approval was required. Look for useful evidence, correct routing of exceptions and a clear record of what happened. An impressive first answer is less informative than consistent behavior across these ordinary difficulties.
If the pilot succeeds, expand one dimension at a time: more sources, a longer task or a new action permission. This makes a regression easier to explain and reverse. Our AI transformation service helps teams define these task-level evaluations and operating boundaries.
Start with a responsibility you can inspect
Give the dot a useful but limited job, make the approval boundary explicit and review the whole result. Persistent access becomes easier to justify when the work record shows that the agent handles both the normal path and the exceptions correctly.