OpenAI's Dots beta is off in ChatGPT Enterprise until a workspace owner turns it on. That owner should decide three things first: who gets the "Use dots" permission, whether the workspace is even eligible, and what will serve as the audit trail when an always-on agent acts in the cloud. The answers are already in OpenAI's own admin documentation. During the beta, dots support neither data residency nor inference residency. Workspaces with EKM or FedRAMP can't use them at all. And the cloud orchestration events never reach your OpenTelemetry collector.
Dots are always-on agents powered by GPT-6 Astra, each running on its own cloud computer and browser. OpenAI launched them at DevDay on September 29, 2026. Our DevDay coverage of GPT-6.1 Sol dealt with the model's price and benchmarks. This piece covers the agent product, because it's the one your users will ask you to switch on.
What OpenAI Shipped at DevDay
A dot is a persistent agent that keeps working on goals you assign while your own laptop is closed. OpenAI's overview page says each dot tracks progress between conversations, reaches out when a decision needs a person, and can be reached through ChatGPT, Slack or Teams. Its cloud computer keeps "its own files, software, and browser sessions", and website sessions stay live until the user signs out or the session expires.
The reach is wide. The Next Web reports that a dot can connect to more than 4,000 apps through plugins and that Pro and Business Premium plans include one at no extra cost. TechCrunch describes dots as agents that pursue goals "continuously in the background with minimal oversight", and reports that OpenAI is wiring them into Microsoft's Agent 365 security controls. Dots can also schedule themselves: according to the tasks and memory docs, a dot can "decide when to pause and wake up to continue," and it can split work across background agents running in parallel.
Enterprise, Edu and Healthcare workspaces get a beta, and MediaNama reports that it "is off by default" until an administrator enables it. So the first decision belongs to you, before any employee makes it.
Which Workspaces Cannot Turn Dots On
Some of the most regulated tenants are excluded outright. OpenAI's local access guide for Work Cloud and dots states that "Dots are unavailable for FedRAMP workspaces, workspaces with EKM, and workspaces with inference residency set to AE (UAE)." The same page adds that "During the Enterprise beta, dots do not support data residency or inference residency," and that eligible workspaces can opt in only after acknowledging those limits. HIPAA workspaces can take part if they meet the other requirements.
Read that list against your own tenant configuration. If you paid for in-region processing because a regulator or a customer contract required it, turning dots on means accepting a product whose agent work sits outside that commitment. The admin guide also notes that if any cloud policy has enforce_residency enabled, local computer access is unavailable for dots. The residency control and the agent fight each other, and OpenAI resolves the conflict by switching a feature off.
If residency is the reason you bought ChatGPT Enterprise in the first place, our guide to which LLM providers actually keep data in region is the comparison to reread before you sign the acknowledgment.
Where the Audit Trail Breaks
Your existing observability pipeline will see only half of what a dot does. The local access guide says the local executor "can still export supported execution events," and also that "Cloud orchestration events do not reach your existing OpenTelemetry collector." It closes off the obvious workaround as well: "Changing the collector endpoint does not restore cloud orchestration events."
OpenAI points you to the Compliance API for "supported cloud records." The admin guide frames that API as the way "to investigate user messages and dots' replies." Neither page lists which orchestration events count as supported. That's a reasonable gap in a beta, but your security team should know it exists before an incident forces the question.
This matters more for an agent than for a chatbot. An agent that wakes itself up, opens a browser session and acts through a plugin creates a chain of decisions nobody typed. The FTC chair's theory of agent liability, which we covered when the probe of OpenAI and Anthropic surfaced, assigns responsibility to whoever gave the instruction. If you can't reconstruct the chain from your own logs, you can't show who that was. Our earlier piece on agent monitoring explains why OpenTelemetry became the default collection layer; dots route around it for their cloud half.
What Survives When You Revoke a Dot
Turning a dot off doesn't erase what it learned. The admin guide is direct: "A dot can create saved memories, including information from connected apps. Disconnecting an app does not delete information already obtained." It also warns that "removing dots access does not replace disconnecting an app or signing out of a website," and tells admins to review saved memories and reset options when handling sensitive data or offboarding.
The user-facing docs add one more layer. A dot's notes "are separate from ChatGPT's saved memory", and changing a ChatGPT saved-memory setting "doesn't necessarily change the notes your dot has already made." An employee who clears their ChatGPT memory has not cleared their dot's memory.
That makes offboarding a four-step process: revoke the permission, disconnect each app, sign out of each website session on the cloud computer, and reset the dot's memory. We saw the same pattern with Copilot memory that survived a password reset. Update the leaver checklist before the first dot is created.
What It Costs After the First Dot
Nobody can tell you yet, OpenAI included. The overview says each plan comes with one dot at no extra charge, that conversations with a dot don't count toward ChatGPT usage limits, and that plans include "extended limits for the first month after launch." Work a dot starts in Codex or ChatGPT Work still draws on those products' allowances.
Beam's analysis of the launch terms lists what remains unpublished: the permanent per-plan dots allowance, the price of additional dots, the cost of speed and workload upgrades, and any per-task charge for background work. MediaNama reports that users "will later be able to add more dots and scale each by speed or monthly workload". That describes a meter, and its rates haven't been published.
The practical consequence: whatever pilot you run in October runs on launch-month allowances. Usage numbers from that window will understate what the same behavior costs once OpenAI publishes ongoing terms. Record task counts and hours of background work during the pilot, so you can price them when the rate card appears.
The Strongest Case for Turning It On
There is a real argument for enabling the beta now, for a small group. OpenAI ships meaningful guardrails from day one. The controls page describes custom rules with four settings ("Take action without asking," "Take action when you say so," "Ask before taking action," "Hand off to you"), an automatic review before actions that could affect accounts or share information, and a hard rule that "you must change a password yourself." Admins can separately control cloud browser use, cloud network access, cloud computer use, password manager use and adding dots to Slack, and granting dots access does not grant access to any app. If your employees are going to use always-on agents anyway, a governed beta inside the corporate tenant beats a personal Pro account you can't see. Our report on agents that leaked images from users who never opted out shows what the unmanaged version looks like.
The counterweight is OpenAI's own caution. The controls page says custom rules are "instructions your dot tries to follow, and it can make mistakes." And the same week, OpenAI held back its next model. NBC News reports that GPT-6.1 Astra was withheld because, in the words of safety systems head Saachi Jain, it "didn't quite meet the bar in terms of staying within scope and authorization". Dots run on the current GPT-6 Astra, which shipped. But staying inside scope and authorization is exactly what an always-on agent with saved logins has to do, and OpenAI has told you it's still working on it. The kill switch that failed for 2.5 hours after a DNS escape is the recent precedent for what happens when that bar is missed.
What to Do Before Users Ask
Make the decision deliberately, in writing, before the help desk gets the first request.
This Week:
- Check eligibility. Pull your ChatGPT Enterprise workspace settings and confirm whether EKM, FedRAMP, data residency or inference residency is enabled. If any is, write down that dots are unavailable or out of residency scope, and tell the business owners who will ask.
- Leave "Use dots" off in workspace defaults. Grant it only through a custom role for a named pilot group of 10 to 20 people whose work doesn't touch regulated data.
- Leave "Allow local computer access" and "Add dots to Slack" off for the pilot. Start with the cloud computer only, and decide on the desktop and Slack surfaces after you've read the activity.
This Month:
- Ask your OpenAI account team in writing which dots orchestration events the Compliance API returns, at what latency, and for how long. Have your security lead pull a test export from the pilot and confirm a dot's cloud action can be traced to the user who instructed it.
- Add the four-step dots offboarding (revoke, disconnect apps, sign out of web sessions, reset memory) to the leaver runbook. Test it on one pilot account.
- Set plugin controls so the pilot's dots reach only the apps you'd let a new contractor touch. Map each dot's connected accounts the same way you would map agent identities in your IdP.
Before the Launch-Month Allowance Ends:
- Record pilot task volume and background run hours so you can price them against whatever per-dot or workload pricing OpenAI publishes.
- Decide the broader rollout only after both the ongoing usage terms and the Compliance API coverage are on paper.
The Bottom Line
Dots follow a familiar enterprise pattern: a consumer-grade agent arrives with enterprise controls that cover access well and evidence poorly. The permission model is granular, and the default is off. Residency, EKM and the cloud half of the audit trail remain beta gaps. Treat it that way: a small named group, a written note of what the logs cannot see, and a second decision once OpenAI publishes its terms.
Set "Use dots" to off in workspace defaults today, and grant it by role when you're ready.
Continue Reading
- GPT-6.1 Sol's $5.47 Task Scores 11 Points Below Astra's $23.80
- FTC Chair's Rogue-Agent Theory Blames Whoever Gave the Order
- OpenAI's Agent Kill Switch Failed for 2.5 Hours After a DNS Escape
- Copilot Memory Survives Your Password Reset. Go Purge It.
- LLM Data Residency: Which Providers Actually Keep Data In Region
- Best AI Agent Monitoring: Langfuse, Then a Real Kill Switch
