OpenAI's September 29 launch of dots extends its assistant into ongoing work across connected apps. For people deciding whether to connect work accounts, the useful distinction is between background research and carrying out a requested task. OpenAI says proactive research uses read-only tools; separately authorized work can involve actions governed by instructions, permissions and review.
The Verge's October 2 report brought attention to the agent's range. The controls described here come from OpenAI's launch announcement and current documentation, rather than our own hands-on test.
Background access still exposes information
Each dot has a cloud computer. OpenAI describes proactive research as background use of connected apps that cannot send messages, edit app content or operate a browser or computer. That restriction addresses changes to an account, but reading its contents remains a consequential permission.
A useful first decision is therefore which information the task needs. An agent asked to monitor project updates may need a particular workspace; that does not make every personal account relevant. Limiting the initial connection gives the user a clearer way to assess whether the resulting suggestions actually help.
Local computer access is optional and starts disabled, according to the Help Center. This is a separate decision from providing an app connection. Our coverage of macOS Full Disk Access consent explains why a broad device permission deserves its own review.
A requested task has an authorization boundary
OpenAI says Custom Rules can permit an action, require approval or block it, while built-in safety requirements continue to apply. Its action-review system evaluates consequential operations against those rules and the user's instructions. The company also cautions that dots can make mistakes.
The practical choice is to define a reviewable output before enabling repeated work. Asking an agent to prepare a weekly account summary is different from authorizing it to send that summary to customers. Specify the recipients and approval step if sending is part of the job; inspect the first completed result before making it routine. This is editorial guidance, not a finding that a particular workflow has passed independent testing.
Disconnecting an app is different from clearing memory
The Help Center says removing a connection does not delete information a dot already obtained. Resetting the dot deletes its conversations, saved memories and scheduled tasks. Those are different controls for future access and retained context; readers should review what they need to preserve before a reset. Our Muse memory analysis examines the related question of what an assistant retains about other people.
Availability also needs checking. OpenAI documents a gradual rollout, regional restrictions for Pro, and an administrator-enabled beta for Enterprise. Specialist dots with their own organizational identity begin in focused pilots. The launch establishes a service and its proposed controls; it does not establish that every account can use it or that continuous operation delivers reliable results without review.