OpenAI switched on Dots at DevDay on September 29, and the pitch fits in one sentence: hand an agent a goal and it works on it around the clock, on its own cloud computer, wired into more than 4,000 apps. I’ve had one running since launch day, mostly on inbox triage and a morning brief that assembles itself from my calendar and the news. The always-on part delivers. What’s bothering me two days in is everything the Dot remembers and I can’t see.
Each Dot runs on GPT-6 Astra with a dedicated browser and cloud environment, learning your preferences as it goes and surfacing results for your review. One ships free with ChatGPT Pro at $100 a month, and with Business Premium. Sensitive actions like password changes and permanent deletes still need explicit sign-off, and a rules screen defines what the agent does alone, when it asks, and what it never touches.
The real product is a primary Dot
Here’s the shift most of the launch noise skimmed past. People aren’t treating Dots as a feature, they’re treating one Dot as the front door to ChatGPT. Instead of opening a fresh chat for every question, you hand standing work to a single persistent agent and check in on it. Overnight briefs, competitor monitoring with scheduled pings, leads qualified straight into a CRM, meetings converted into action items. The chat thread stops being the product.
That logic extends to teams. ChatGPT Space, launched the same day, gives humans and multiple Dots a shared workspace where agents collaborate on documents with context that carries across Slack and Teams. For engineers the framing gets more interesting still, because Dots can act as orchestrators that spin up custom cloud dev environments with your dependencies, drive a local desktop through computer use, and delegate sub-tasks before reviewing the output. That’s a control plane, not a chatbot.

The fine print that decides whether you trust one
Now the friction. Memory is all or nothing right now. You can wipe a Dot’s learned preferences with a full reset, but there’s no way to inspect individual memories, edit them, or delete one thing it picked up. Disconnecting an app stops future access without erasing what the agent already learned. For anyone in a regulated industry, or anyone who simply wants to know why their Dot keeps formatting reports a certain way, that opacity is a genuine blocker.
Persistence has cracks too. Cloud environments can reset and lose installed tooling and saved credentials, a strange experience for an agent sold on continuity. I watched mine lose a workspace setup mid-week and rebuild it from scratch. Access is gated hard as well. The Pro rollout excludes the EEA, Switzerland, and the UK at launch, setup is desktop-only for now, and texting sits in a limited US beta.
The pricing tells you where this goes. OpenAI launched a higher Pro 500 tier alongside Dots and flagged future paid scaling for extra Dots, faster output, and higher volume. Tasks already draw down plan allowances, and the generous first-month limits won’t last. That’s a payroll model for digital employees, and it sits on top of the compute buildout OpenAI has been financing all year.
On trust, I keep coming back to what we wrote about rogue agent kill switches earlier this year. The rules screen is the right instinct, and requiring consent for destructive actions matters. But auditability is what turns delegation into trust, and a memory system you can’t read is the opposite of auditable.
My verdict after two days: the always-on paradigm is real and the primary Dot habit forms faster than I expected, but the persistence layer is half-built and memory controls lag well behind the ambition. Watch whether OpenAI ships granular memory inspection before enterprise admins make that call for them. I like where this is headed, and I still won’t hand a Dot my inbox until I can see exactly what it remembers about me.






