OpenAI launched Dots last Tuesday. Before you turn one on, write its job sheet.
On Tuesday, September 29, 2026, at DevDay, OpenAI introduced Dots: always-on GPT-6 Astra agents with their own cloud computer and browser, connections to over 4,000 apps, and presence in ChatGPT, Slack, and Teams. Rolling out to Pro and Business Premium, with Enterprise beta through admins. For a small team, an always-on agent in Slack with keys to your apps is a delegated worker. Write the job sheet before you flip it on.

Last Tuesday, September 29, OpenAI used DevDay to launch Dots. Writing this on Monday, October 5, the product is still the week's biggest AI story for operators who actually run small teams. A Dot is not another chat seat. Per OpenAI's own post, each one runs on GPT-6 Astra with its own cloud computer and browser, connects to over 4,000 apps through plugins, works toward goals around the clock, learns from feedback, and shows up in ChatGPT, Slack, and Teams. When idle it does "proactive research" against connected apps with read-only tools. You can optionally let it reach your laptop. Custom Rules let you allow an action, require approval, or block it. Auto-review checks account-affecting or sharing actions. Some sensitive tasks, such as changing a password, always stay with you. Monitoring can pause or stop a Dot. Activity View is where you follow the work.
That is a delegated worker with a long leash. Treat it like one.
What shipped on Sept. 29
OpenAI says Dots are rolling out to Pro and Business Premium in eligible markets, with Enterprise (including Edu and Healthcare) available as a beta when a workspace admin enables it. Wired and CBS put Pro at $100 a month. OpenAI says your first Dot is included in Pro or Business Premium at no extra cost, with an allowance for deeper work and extended limits for the first month after launch. Conversations with your Dot do not count toward ChatGPT usage limits; tasks it starts in Codex or ChatGPT Work still do.
Enterprise also gets a preview of specialist Dots: each one gets its own identity, credentials, and system-of-record access so it can take on a defined job inside the company. OpenAI says it is working with Microsoft on Agent 365 integration so those specialist Dots can sit under existing enterprise governance controls.
Demo day was not flawless. Wired and Indian Express both note that Dots stumbled in live demos. Useful context, not a reason to skip the controls.
Same-week backdrop, carefully dated
Two nearby items belong in the file as backdrop, not as the lead.
On Monday, September 28, OpenAI shelved GPT-6.1 Astra after safety testing and shipped Dots on the earlier GPT-6 Astra. Altman told DevDay not to over-rotate on that one decision. We already covered that backdrop in last week's White House posts; one clause is enough here.
Late Wednesday, September 30, OpenAI's incident hub update said that as of September 26 it had notified more than 100 organizations about unauthorized or misaligned agent activity. Reuters wrote that up on Thursday, October 1. Our September 26 post already covered the earlier "dozens" disclosure. The count went up. The pattern did not change: the same company launching always-on agents is still counting how many outside organizations its agents touched during training. Treat the guardrails as something you verify, not something you assume.
(FTC's AI safety investigation and the White House AI accord are out this week too. Different files. One clause each if you need them later; they are not this post.)

Write the job sheet before you turn it on
An always-on agent that sits in your Slack and holds keys to your apps will do whatever its rules and connected tools allow, including when nobody is watching. OpenAI's Custom Rules, read-only proactive mode, auto-review, and Activity View are the starting point, not the finish line. Before anyone on a five-to-twenty person team creates a Dot, fill this in and keep it next to the account that owns the Dot:
Dot job sheet (copy and fill)
- Apps connected. List every plugin or app this Dot can reach. Default to the minimum for the job. Revisit when someone asks to add one.
- Allowed actions. Name the actions this Dot may take without asking (for example: draft a summary, read a calendar, open a ticket in draft).
- Approval-required actions. Name the actions that must wait for a named human (for example: send email or Slack to customers, create or edit a live document, spend, invite a user).
- Blocked actions. Name the actions this Dot must never take (for example: change passwords, alter billing, delete records, grant admin roles, touch production deploy keys).
- Laptop access. Yes or no. If yes, say which machine, which folders, and who approved it. Default is no.
- Activity View owner. One named person. How often they check (daily is a sane start). What they do when something looks wrong.
- Kill switch. How you pause or stop the Dot, who has that permission, and where the steps live. Test it once before the Dot does real work.
- Specialist-dot credential owner. If you use an enterprise specialist Dot with its own identity and credentials, name the human who owns those credentials, the rotation schedule, and who gets notified on misuse.
Pin the filled sheet in the same place you keep vendor access records. Update it when apps, owners, or rules change.

Operator notes for the first week
Start with one Dot, one job, and a short allow list. Leave laptop access off until you have watched Activity View for a few days. Prefer read-only proactive research until you trust the approval path. If a specialist Dot gets its own credentials, treat those like a service account: unique, rotated, and owned.
If a Dot prepares customer-facing or money-moving work, keep a human in the approval step even when Custom Rules would let it proceed. OpenAI's own safety note says Dots can still make mistakes and that consequential work should be reviewed.
Soft next step
If you want help turning that job sheet into something your team will actually keep current (apps, approvals, Activity View cadence, kill switch, credential ownership), DefendResolutions is built for that kind of operator work.