Home  ›  Insights  ›  OpenAI dots for enterprise admins
Field Note

OpenAI dots for enterprise admins: the call

OpenAI’s always-on agents are in ChatGPT, off by default for Enterprise, and one toggle away from your users’ connected apps. Here is what the launch film left out, and what to do before someone asks you to switch them on.

The call

WATCH: keep dots off in your Enterprise workspace for now. Real product, not ready for enterprise data: no residency, no cloud events in your own collector, no price beyond the first dot. The ChatGPT workspace owner and the CISO should hold the toggle, with the Salesforce platform owner in the room.

OpenAI launched dots at DevDay on 29 September: always-on agents, powered by GPT-6 Astra, each with its own cloud computer and browser, that keep working between conversations (TechRadar). On 2 October OpenAI updated its Enterprise admin guide for the beta (OpenAI Help Center). That guide is the document your team will be asked about this month.

What it is. What it is not.

It is a persistent agent that holds context, runs scheduled and delegated work, and acts through connected apps, a cloud browser, and optionally the user’s own computer. In Enterprise, eight permissions govern it, including cloud browser use, cloud network access, cloud computer use, and password manager use. “Use dots (Beta)”, local computer access, and custom rules are all off by default (vendor, OpenAI Help Center). Each dot has four action modes, from “Take action without asking” to “Hand off to you” (independent, Beri).

It is not governed by your existing ChatGPT controls. OpenAI’s own guide says Enterprise model controls and default model settings do not apply to dots, and that a dot’s cloud computer does not inherit the member’s VPN, browser sign-ins, or device policies (vendor, same source). Your laptop controls stop at the laptop. Pausing a dot stops its main task, not its delegated tasks or schedules (independent, General Analysis). And disconnecting an app does not delete what the dot already learned from it (independent, Beri).

The number nobody is quoting

The launch coverage quotes the safety wins: 99.79% of internal prompt-injection attempts defended. The figure that matters to an admin sits in the same system card appendix: how often a dot strays outside its brief as its task chain grows. Always-on means long chains.

FigureValueLabel
Chains flagged for boundary problems, 5 tasks8.6%vendor, via The New Stack
Chains flagged for boundary problems, 10 tasks19.7%vendor, via The New Stack
Rise when the chain doubles19.7 ÷ 8.6 = 2.3xour maths
Internal injection attempts not defended100% − 99.79% = 0.21%our maths on vendor figure
External red-team (Gray Swan) attack success, 1,810 attacks8.5%, about 154 attacks (1,810 × 0.085)vendor-reported; count is our maths
Example: 200 users, one 10-task chain each per working day200 × 19.7% = about 39 flagged chains a day, about 827 a month at 21 working daysour maths; the 200 users and one chain a day are our assumptions

The internal and external injection tests use different attack sets, so do not divide one by the other. The point stands: the headline number is the easy test. OpenAI reports no high-severity breaches in these tests and has not said what the flagged problems were (vendor, via The New Stack). Thirty-nine a day is not thirty-nine incidents. It is thirty-nine things someone has to review. Who?

Missing:

  • A price for any dot beyond the first, and the limits after the launch month’s extended allowance (Beri).
  • Data residency and inference residency. Neither is supported in the Enterprise beta, and dots are unavailable in FedRAMP and External Key Management workspaces (independent, Beri).
  • Cloud orchestration events in your own OpenTelemetry collector. They do not reach it, and changing the endpoint does not fix that; the Compliance API is the stated route (independent, General Analysis and Beri).
  • A way to delete what a dot remembers from an app you have since disconnected (CIO Insights).
  • How a dot’s action appears in a connected system’s own audit log: as the dot, or as the human. We found nothing that says.
  • An SLA, and any independent measure of multi-day reliability or cost per accepted task (Kingy AI).

Who owns what

Running the agent is OpenAI’s job. What it may touch in your systems is ours.

Where that sits in a Salesforce stack:

  • Identity. A dot working through a user’s sign-in or app grant leaves that user’s name on the log line. Until OpenAI shows otherwise, a Salesforce audit trail cannot separate the person from the agent.
  • Access. Review Connected App and External Client App OAuth grants for anything issued to OpenAI or ChatGPT. Revoke what nobody approved.
  • Scope. If a dot ever gets into the org, it gets its own integration user, a read-only permission set, and Named Credentials. No shared logins, no password manager handover.
  • Evidence. Event Monitoring retention long enough to cover a vendor’s notification lag. Our audit-trail Field Note has the drill.

Monday morning

  • Step 1. Confirm “Use dots (Beta)”, local computer access, and custom rules are off, and that no custom role grants them. Owner: ChatGPT Enterprise workspace owner.
  • Step 2. Find Pro and Business Premium subscriptions bought outside the Enterprise workspace. Those plans had dots at launch. Owner: IT asset management with finance.
  • Step 3. Pull OAuth Usage for Connected Apps in Salesforce and flag any grant to OpenAI or ChatGPT. Owner: Salesforce platform owner.
  • Step 4. Write the enablement bar: residency, cloud events in your collector, memory deletion, a price, and a named reviewer for flagged chains. Owner: CISO, with procurement.
  • Step 5. Brief the business sponsors who saw the launch film. Off is a decision, not a delay. Owner: CIO.

What would change our call: we move this to PILOT, read-only and outside Salesforce, when OpenAI sends cloud orchestration events to customer collectors and publishes the price of a second dot.

Frequently asked questions

Are OpenAI dots switched on in ChatGPT Enterprise?

No. OpenAI’s admin guide says Use dots (Beta), local computer access, and custom rules are all off by default for Enterprise. A workspace owner has to grant them through roles. Pro and Business Premium plans got dots at launch on 29 September.

Do dots meet data residency requirements?

Not yet. Independent coverage of the Enterprise beta documentation says dots do not support data residency or inference residency during the beta, and are unavailable in FedRAMP workspaces and workspaces using External Key Management.

Should a Salesforce team let a dot into its org?

Not during the beta. Keep Salesforce out of scope until a dot’s actions can be told apart from the human user’s in your logs, cloud orchestration events reach your own collector, and OpenAI documents how to delete what a dot remembers.

Living page. Last updated 3 Oct 2026. What would change our call: cloud orchestration events reaching customer collectors and a published price for additional dots.