Published September 30, 2026
OpenAI Dots Permissions, Approvals and Safety Controls
How users choose apps, set allow/approve/block rules and what read-only proactive mode is allowed to do.
OpenAI stresses that users stay in control of what a Dot may do.
Plugin and app selection
Only connected plugins the user enables are in scope. Permissions can align with other ChatGPT plugin settings.
Action rules
Users can define actions the Dot may take alone, actions that require approval and actions that are blocked. Defaults plus custom rules form the policy layer.
Inspection
The Dot's cloud computer can be opened so the user can review work in progress.
Proactive mode boundary
Background help while idle is limited to read-only tools on connected apps. OpenAI states that mode cannot send messages, change app content or control browser or computer.
Age
Dots were not available to users under 18 at launch.
These controls do not remove operational risk when a Dot is granted access to sensitive systems. They are the published mechanisms for limiting scope.
Related: Privacy and Security, How Dots Work, homepage.