ChatGPT Dots for Small Business: Rules to Write First
OpenAI's always-on dots run on their own computer, around the clock. Here is what Business Premium owners should lock down before turning one on.

OpenAI just launched an assistant that keeps working after you close the laptop. It has its own computer, whatever apps you connect, and a list of rules you wrote in one sitting. That is ChatGPT dots for small business in one sentence. It i
OpenAI just launched an assistant that keeps working after you close the laptop. It has its own computer, whatever apps you connect, and a list of rules you wrote in one sitting.
That is ChatGPT dots for small business in one sentence. It is useful, and the usefulness lives in the rules you set on day one.
A dot is an employee that works from your login
OpenAI announced dots on September 29, 2026. They are always-on agents powered by GPT-6 Astra, each with its own cloud computer and its own browser.
Through plugins, a dot can reach more than 4,000 apps. You talk to it in ChatGPT, Slack, or Teams, and it can message you back with progress, questions, and decisions.
The part that matters for an owner is the word always. A dot picks up a project, runs it while it works on several others, and goes looking for more to do when you are not around.
OpenAI's own small-business-shaped example is the invoice. An early tester's dot noticed he had forgotten to bill a publication, prepared the invoice, and sent it after his approval.
That story has a gate in it. The rest of this post is about where the gates are, and where they are not.
Business Premium is the plan that gets one in Europe
Dots are rolling out gradually. According to OpenAI's help article, Pro users get them in markets that exclude the European Economic Area, Switzerland, and the UK.
Business Premium users get them across all supported ChatGPT regions. Enterprise can try a beta, but it starts switched off until a workspace admin enables it.
That is the $125-per-seat tier we priced out in our Business Premium versus Standard breakdown. The first dot is included, so the upgrade question just changed shape.
Before, you were buying a higher usage ceiling. Now you are also buying access to a different kind of tool.
OpenAI says additional dots, and more speed or monthly capacity per dot, will come later at prices it has not shared. Conversations with your dot do not count toward ChatGPT usage limits, but work it hands to Codex or ChatGPT Work does.
Custom Rules are where your business policy lives
Every dot ships with built-in rules for when to act alone and when to ask. On top of those, you write Custom Rules in plain language, and each one gets one of four behaviors: take action without asking, take action if pre-approved, ask before taking action, or hand off to you.
"Pre-approved" has a precise meaning in the help article. It means you explicitly requested the action in your prompt.
My read: a rule set to "if pre-approved" only fires when the task you typed named that action. A recurring job you scheduled in March leans on a sentence you wrote once and have not looked at since.
OpenAI's safety post gives a feel for the sharing rules. Health data always needs a named recipient. Less sensitive details, like an email address or phone number, need a class of recipient by default, such as "any airline company". You can broaden that with a Custom Rule, for example "share with any online form."
That last example is the one to read twice. A rule that sounds like a convenience is a standing permission.
OpenAI checks for harm and your policy is a separate question
Before a dot sends an email or changes a file, a separate system called Auto-review checks the planned step against your instructions, your Custom Rules, and OpenAI's safety requirements. For an email it checks the recipient and the message, to catch a wrong address or information you did not intend to share.
OpenAI also keeps some things off the table. Dots must confirm permanently deleting data, running software from an unrecognized source, and granting new security-sensitive access. Changing a password and transferring money between financial accounts are handed back to you.
Purchases on a card saved with a merchant need your approval too. That is a good floor.
It is a floor for harm. It is not your pricing policy, your refund rules, or your promise to a client that nothing goes to their competitor's inbox.
Auto-review compares an action to what you told the dot. If you told it something loose, the check passes something loose. That is not a flaw in the design. It is the reason the rules are your job.
— OpenAI, introducing dots, September 29, 2026Dots can still make mistakes, so always review consequential work.
The launch pages leave four things open
I read the launch post, the help article, and the safety post. These are the gaps a business owner should know about before connecting anything.
Your dot is you. At launch you cannot give it its own email address. You connect your personal email so it can use it for your tasks. Everything it sends comes from the identity your customers already trust.
Admin control on Business Premium is unclear. Enterprise dots start off until an admin enables them. I did not find a matching statement for Business Premium seats, so ask before assuming the owner can switch dots off for a team.
Disconnecting does not delete. The help article says disconnecting an app does not delete information the dot has already obtained. Deleting it means resetting the dot, which also wipes its conversations, memories, and scheduled tasks. Plan for the day someone leaves.
Background notes can feed training on personal plans. Dots do proactive research on read-only tools, and those tools cannot send messages, change content, or control a browser. OpenAI says it does not train directly on those notes, but a note pulled into a later task may be used depending on your settings. OpenAI does not use ChatGPT Business content for training by default, so this matters most if your team uses personal accounts.
That is the same slow leak as staff pasting client data into personal accounts, only now an agent does the pasting.
Two more details. Access to your own computer is optional and starts off. And at launch a dot cannot call you or start phone calls.
The rules we would write on day one
OpenAI is candid that this is a system to supervise. We run a similar supervision problem ourselves. In our OpenClaw Factory field report, 33 production agents showed a 4.1% reversal rate over six months: how often a human had to undo something an agent did. We would shut things off above 10%.
You will not measure a dot that precisely on day one. You can still set the same posture.
Start read-only. Connect calendar and analytics first and ask for summaries. Drafting and analysis are where agents earn their keep with the least downside.
Split the inbox from the money. The account that reads messages from strangers should not sit next to the one that sees QuickBooks or Stripe. A poisoned email is only dangerous when something valuable is within reach. OpenAI's own safety post names prompt injection, malicious instructions hidden in a webpage, email, or document, as the threat that makes this split matter.
Set outbound email to ask first. Not "if pre-approved." Ask. The tap is the safety system.
Name recipients in rules for anything customer-facing. "Send to any client" is a standing permission. "Send the weekly update to these four contacts" is a rule.
Check Activity View weekly for the first month. If you would not have approved something in the log, tighten before you widen.
If you tried the earlier ChatGPT agent, our take is in ChatGPT Work for small business. It waited for you to open it and hand it a job. A dot does not wait, and that changes the rules you need.
Meta announced the same shape of agent on the very same day. Our Muse for Small Business permissions guide shows how its approval grants differ, and the checklist above transfers almost one to one.
A specialist dot is what most owners actually want
The dot in ChatGPT is a personal agent. It acts as you.
What a business usually needs is narrower. An agent that handles invoice follow-ups, or supplier orders, or first-pass support triage, with its own identity, its own limited access, and a person who reviews the output.
OpenAI has described exactly that and calls it a specialist dot. Your company sets up each one with its own identity, credentials, and system access. OpenAI says it is starting with focused enterprise pilots, where its engineers work directly with an organization to define each dot's responsibilities, tools, and how people review and approve its work. It lists procurement, invoice processing, email marketing, customer support, and commercial contracting as early areas.
Read that as a statement about difficulty. The vendor's own plan for role-specific agents is a hands-on engineering engagement, and for now it is aimed at enterprises.
A small business can use the personal dot for thinking, research, and drafts, and it should. The moment the work touches money, customers, and a schedule, you want the version where the scope is designed.
That is the workflow automation we build. The invoice reminder or the lead follow-up runs on rails, a person approves before anything goes out, and every action leaves a log you can read. We disclose the obvious: we are a vendor, and for one person with a light stack, a dot may be all you need.
Three more from the log.

Muse for Small Business: What to Connect, What to Skip
Meta's Muse for Small Business plugs into QuickBooks, Stripe, Shopify and Slack. Its own security post explains why you should scope it first.
Sep 30, 2026 · 6 min
Connecticut AI Law: What Starts Oct 1 for Small Business
Headlines say Connecticut's AI law hits chatbots on October 1. The text says January 2027. Here's what actually starts, and what your business owes.
Sep 21, 2026 · 7 min
Does TRAIGA (Texas's AI Law) Cover Your Business?
Texas's AG just switched on the AI complaint portal. Here's what TRAIGA requires from a small business, and the two places most coverage gets it wrong.
Sep 16, 2026 · 6 min