OpenAI Dots is worth piloting for a small business only when one trusted operator has a recurring, reviewable workflow that crosses several apps. A dot is not simply another ChatGPT conversation: it is an always-on agent with its own cloud computer and browser, persistent context, scheduled work, proactive read-only research, and the ability to continue between conversations. That broader responsibility is also the risk. At launch, access is gradual, only one primary dot is included, work allowances are not quantified publicly, and future pricing for extra dots or more capacity is unknown.
The practical buying decision is therefore not “Can it do things?” It is whether the business can give it narrow permissions, define mandatory handoffs, tolerate approval friction, and measure useful completed work without exposing customer, financial, or employee data unnecessarily.

Dots promises persistent work across business systems, but the owner still needs to define the boundaries and review consequential actions.
OpenAI Dots pricing and availability as of October 1, 2026
The first dot has no separate add-on price for eligible plans, but that does not make Dots a free product. You must buy an eligible ChatGPT plan, and OpenAI has not published the normal post-launch allowance, overage model, price of additional dots, or price of faster/higher-capacity output.
| Eligible plan | Current US plan price | Dot-specific price | Launch availability | What is still unknown |
|---|---|---|---|---|
| ChatGPT Pro 100 | $100/month | First primary dot included at $0 extra | Gradual rollout; outside the EEA, Switzerland, and UK | Exact dot allowance after launch, top-ups, extra dots, speed/capacity pricing |
| ChatGPT Pro 200 | $200/month | First primary dot included at $0 extra | Same Pro market restriction and gradual access | Same unknowns; a larger Pro allowance is not a published dot-work quota |
| ChatGPT Pro 500 | $500/month | First primary dot included at $0 extra | Same Pro market restriction and gradual access | Same unknowns; Pro 500’s broader plan capacity should not be converted into a dot quota without documentation |
| ChatGPT Business Premium | $125/user/month, or $100/user/month billed annually | First primary dot included at $0 extra for an eligible Premium user | Supported ChatGPT regions; gradual access | Normal dot allowance, workspace credit treatment, extra dots and capacity pricing |
| Enterprise, Edu, Healthcare | Contract pricing | Beta; no public dot-specific price | Admin must enable the beta; it starts off by default | Commercial terms, allowance, rollout timing, and organization-specific controls |
OpenAI says eligible plans receive an allowance for “deeper work,” with extended limits for the first month after launch. The live documentation does not publish a task count, token amount, credit conversion, rollover rule, or post-launch price. Treat the first month as an evaluation window, not evidence that ongoing work will remain unmetered.
Conversations with a dot do not count toward normal ChatGPT usage limits. However, tasks the dot starts or manages in Codex or ChatGPT Work count against those products’ usual allowances. That distinction matters: conversation can be included while the delegated work still consumes scarce capacity.
Access may take several days to reach an otherwise eligible account. Pro availability excludes the European Economic Area, Switzerland, and the UK at launch. Business Premium is available across supported ChatGPT regions, while Enterprise-family access depends on an admin-controlled beta.
What is a dot, and how is it different from normal ChatGPT?
A normal ChatGPT conversation responds inside a session; a dot can accept ongoing responsibility and keep working between sessions. It has a dedicated cloud computer, a browser, connected plugins, its own retained context, an activity view, scheduled work, and proactive research.
The launch model is personal and singular: one primary dot that you name and work with across ChatGPT, Slack, and Microsoft Teams. OpenAI describes future teams of dots and specialist dots, but small businesses should buy for the one-dot product that exists now, not the multi-agent roadmap.
| Product or approach | Best understood as | Persistent/always-on? | Main small-business use | Key limitation compared with a dot |
|---|---|---|---|---|
| Normal ChatGPT conversation | Interactive chat and tool session | Usually conversation-led | Questions, drafting, analysis, one-off help | Does not itself own an ongoing operating responsibility |
| ChatGPT Work | Agentic work environment for multi-step tasks and deliverables | Tasks can continue and be scheduled | Build reports, documents, spreadsheets, browser or desktop work | A task/work surface, not the same personal always-on identity and cross-channel context |
| Workspace agents | Organization-configured agents for shared or defined roles | Depends on configuration | Repeatable team workflows under workspace governance | More role- or workspace-oriented; a primary dot works for one user at launch |
| Scheduled tasks | Time- or event-triggered runs | Recurs on schedule | Daily checks, reminders, periodic reports | A trigger mechanism, not an agent identity with broad context and ongoing judgment |
| Codex | Coding agent and software-delivery environment | Cloud tasks can continue | Code changes, tests, reviews, environments | Specialized for software work; a dot can delegate to Codex but is not a replacement for its engineering controls |
| Self-hosted agent system | Infrastructure you operate and customize | Potentially | Maximum control, custom models, internal tools, data boundaries | Higher setup, security, observability, maintenance, and incident-response burden |
The closest practical comparison is not “Dots versus ChatGPT.” It is Dots versus the combination of chat, scheduled automations, agent tasks, connectors, and a human operations coordinator. Dots bundles those surfaces behind one persistent relationship. That can reduce context switching, but it can also concentrate permissions and memory in one place.
For broader context, see ChatGPT Work for small business and what AI agents are useful for—and where the hype breaks.
Which small businesses are a good fit for Dots?
Dots fits an owner-led or operations-led company with repeat work, scattered context, and a person who can supervise the pilot. The best workflows are frequent enough to learn from, valuable enough to measure, and reversible when the agent gets something wrong.
Good-fit buyers
- A 5–50 person service business where one operator already coordinates inboxes, documents, projects, calendars, and reporting.
- A founder or operations manager with three or more recurring information-gathering and preparation tasks each week.
- A Business workspace that can separate Premium seats for high-use operators from Standard seats for occasional users.
- A team willing to clean up plugin permissions and define review rules before connecting customer or financial systems.
- A business that values prepared drafts, exception lists, and decision support more than unsupervised execution.
Poor-fit buyers
- A company expecting a guaranteed number of monthly jobs at a known cost; OpenAI has not published that model.
- A regulated or high-consequence workflow without mature identity, retention, approval, and audit practices.
- A business that cannot name one accountable owner for the dot.
- A team hoping the agent will repair bad source data, unclear processes, or overshared folders automatically.
- A buyer that needs multiple independent agents today; launch access centers on one primary dot.
Verdict by buyer type: a solo operator on Pro should test Dots only if a $100–$500 monthly plan already makes sense beyond the agent. A small team should prefer one Business Premium pilot seat, provided the workspace controls and data posture matter. Enterprise-family buyers should treat the beta as a governed experiment. Buyers who need predictable unit economics or full infrastructure control should keep scheduled automation or self-hosted systems on the shortlist.
Five practical Dots workflows for a small business
The strongest launch workflows prepare work and surface exceptions; they do not silently commit the business. These examples are based on documented capabilities and vendor scenarios, not hands-on testing by 5Min Systems.
1. Inbox triage
Let the dot read a narrowly scoped mailbox or label, group messages by urgency, identify missing information, and draft suggested replies. Require approval before every external send during the pilot. Measure how many messages were categorized correctly and how much editing the drafts needed.
2. Customer-feedback monitoring
Connect support, survey, review, or community sources with read-only permissions. Ask the dot to cluster complaints, identify repeated requests, and prepare a weekly evidence-backed brief. Do not let it promise fixes, contact customers, or change product priorities automatically.
3. Recurring reporting
Schedule a morning or weekly collection from approved dashboards and spreadsheets. Have the dot produce a draft report, flag missing or contradictory data, and link back to sources. The owner should approve distribution until the report has passed several error-free cycles.
4. Project follow-up
Allow the dot to review project boards, meeting notes, and calendars, then prepare a list of overdue items, unanswered decisions, and suggested follow-ups. Keep status changes and messages behind approval. A useful follow-up system reduces forgotten commitments; a bad one becomes an automated nag with excellent uptime.
5. Invoice preparation
Use approved project records, timesheets, contracts, and expense documents to prepare an invoice draft and an exception checklist. Require a human to verify customer identity, scope, tax, currency, amount, and payment details. Sending the invoice—and especially moving money—should remain a mandatory handoff.
OpenAI cites an early tester whose dot noticed a missed invoice, prepared it, and sent it after approval. That is a vendor-selected example, not an independent success rate. Use it as workflow inspiration, not ROI evidence.
Plugins, Slack, Teams, and computer access need separate decisions
A dot’s reach is determined by the permissions already connected to ChatGPT and by any computer access you add. OpenAI claims its plugin ecosystem can connect to more than 4,000 apps. That is a vendor ecosystem count, not proof that every integration supports the action, region, account type, or reliability your workflow requires.
Plugin permissions are shared across dots, ChatGPT, ChatGPT Work, and Codex. This is convenient, but it creates a hidden governance problem: a connection approved for an occasional interactive task may become available to an always-on agent. Review every existing plugin before setup instead of assuming the new dot starts with an empty permission set.
Slack and Microsoft Teams can act as messaging channels. A user can continue a project across ChatGPT and those channels while the dot carries context. Enterprise admins separately control whether dots can join supported Slack or Teams workspaces and post with their own identity. At launch, a personal email account can be connected, but the primary dot cannot be given its own standalone email address.
Every dot has a cloud computer and browser. Local-computer access is optional and starts off. If enabled, the dot can access files, create Work or Codex tasks, use local skills, and use the local browser when the cloud browser is blocked. Enterprise local access also requires admin permission, the machine to remain online, and the ChatGPT desktop app to remain open. Local access should be a later pilot stage, not an onboarding default.
Permissions, prompt injection, and shared access are the real risk
The main risk is not that the dot writes a bad paragraph; it is that a bad instruction reaches a connected system with too much authority. A webpage, email, document, or plugin response can contain prompt injection designed to redirect the agent or expose private information. OpenAI says model safeguards, tool restrictions, Auto-review, approvals, and monitoring reduce this risk—but explicitly says they do not eliminate it.

Shared plugins can turn one old connection into broad agent reach. Re-authorize from first principles and keep write access narrow.
Use these controls together:
- Least-privilege plugins: grant only the sources and actions required for the pilot workflow.
- Separate identities where supported: use a distinct Slack identity or tightly scoped account instead of an owner’s broad personal access.
- Custom Rules: explicitly allow, require approval for, or block supported actions. Rules cannot remove core safeguards.
- Mandatory handoffs: password changes and financial transfers must stay with the human; use the same approach for tax filing, payroll, customer refunds, contract acceptance, and final invoice sends.
- Auto-review: let the separate review system check consequential actions, but do not treat an allowed action as proof that the underlying facts are correct.
- Activity review: inspect delegated and background work, especially after permission, prompt, or source changes.
Proactive research has stricter controls. Its tools are read-only: they cannot directly send messages, change plugin content, or control a browser or computer. Any follow-up action returns to the normal action and approval rules. That makes proactive research appropriate for monitoring and preparation, not autonomous back-office execution.
Memory and deletion controls are weaker than many buyers expect
Dots gains continuity by retaining context, but individual dot memories cannot currently be viewed, edited, or deleted one at a time. A dot can receive memories and recent conversation context from ChatGPT, create its own memories, and retain information from connected apps.
Turning off ChatGPT Memory stops future sharing; it does not delete information already received. Disconnecting a plugin stops new access; it does not remove information already incorporated into the dot’s context. Deleting the dot removes its own context, conversations, saved memories, and scheduled tasks, but does not automatically delete files, Codex threads, ChatGPT conversations, or ChatGPT memories stored elsewhere.
For Business, Enterprise, and Edu workspaces, OpenAI says customer content is not used to train models by default. On personal Pro plans, the “Improve the model for everyone” setting controls whether eligible dot conversations and work can be used. OpenAI says proactive research threads and private notes are not trained on directly, but information brought from those notes into an eligible conversation or task may be used depending on the setting.
This is why the pilot should avoid customer secrets, payroll, health records, payment credentials, legal strategy, and unrestricted storage drives. Deletion is not one big red button; it is a scavenger hunt across context, conversations, files, delegated tasks, and connected systems.
Custom Rules, Auto-review, and approval fatigue
Good controls reduce harm, but too many prompts can make staff approve reflexively. Custom Rules support four practical behaviors: take action without asking, take action if pre-approved, ask before acting, or hand off to the user. Core safety checks, proactive-research restrictions, and mandatory handoffs cannot be overridden.
Approval fatigue appears when the workflow generates frequent, low-information confirmation requests. The cure is not broad blanket approval. Redesign the workflow:
- Keep information gathering read-only.
- Batch related drafts into one review packet.
- Separate fact approval from action approval.
- Define narrow pre-approval conditions with named recipients, data classes, thresholds, and time windows.
- Hand off rare, irreversible, or high-value actions.
- Stop a workflow that routinely requests approvals outside its normal pattern.

The useful operating model is broad assistance with narrow authority: research and prepare automatically, then pause at consequential actions.
OpenAI’s launch safeguards are meaningful, but independent reporting offers a useful reality check. PYMNTS reported that voice commands failed during the DevDay demo and that several announced capabilities were still rolling out. TechCrunch noted that much of the underlying functionality already existed across Codex and other agent systems, with Dots packaging it around continuous responsibility and a persistent identity. Those are not reasons to dismiss Dots; they are reasons to pilot it as a new product rather than treat the launch presentation as operational proof.
A least-privilege 14-day Dots pilot
Pilot one workflow, one owner, one dot, and the minimum possible data. Do not connect the whole company and call that a test.
Days 1–2: define the boundary
- Choose one workflow: inbox triage, feedback brief, recurring report, project follow-up, or invoice preparation.
- Name the owner, reviewer, source systems, expected output, schedule, and stop conditions.
- Record a manual baseline: time spent, items processed, errors, rework, and missed deadlines.
- Set all external sends, writes, purchases, deletions, account changes, and financial steps to approval or handoff.
Days 3–5: run read-only
- Connect only the minimum plugin scopes.
- Keep proactive research and source gathering read-only.
- Compare the dot’s findings with the source data daily.
- Track false positives, missed items, unsupported claims, and sensitive-data exposure.
Days 6–10: allow drafting, not commitment
- Let the dot prepare replies, reports, follow-ups, or invoice drafts.
- Batch review rather than approving one tiny action at a time.
- Reject any output without linked evidence or clear source provenance.
- Do not add local-computer access unless cloud-only work has a documented blocker.
Days 11–14: test one narrow approved action
- Allow one reversible action under a precise Custom Rule, such as updating a noncritical internal project field.
- Keep customer sends, payments, deletions, security changes, and final financial documents behind mandatory review.
- Review Activity View and exported evidence with the owner.
- Remove unused plugins and reset the dot if the pilot exposed data it should not retain.
Stop/go criteria for a small business
Continue only if the workflow produces measurable net value without permission drift. Use thresholds agreed before the pilot.
| Measure | Go threshold | Stop or redesign trigger |
|---|---|---|
| Task usefulness | At least 80% of outputs usable after normal review | Fewer than 60% usable or repeated misunderstanding of the objective |
| Accuracy | Zero consequential factual errors; minor error rate below 5% | Any wrong recipient, amount, customer, deadline, or irreversible action |
| Review burden | At least 25% net time reduction after review and correction | Review consumes most of the time saved |
| Approval quality | Fewer than 3 unnecessary prompts per run | Staff begins rubber-stamping or prompts lack useful context |
| Permission discipline | No unused write scopes; all access mapped to the workflow | Permission expansion without owner approval or unexplained cross-app access |
| Reliability | At least 90% scheduled-run completion during the pilot | Repeated missed runs, blocked sessions, or untraceable failures |
| Cost visibility | Owner can identify plan, allowance signals, and any credits used | Usage cannot be attributed or the post-launch cost case depends on guesswork |
These thresholds are an editorial pilot rubric, not OpenAI guarantees. For invoice work, customer messages, financial records, or other consequential processes, use stricter standards.
The small-business verdict
OpenAI Dots is a promising operations layer, not a finished substitute for an employee, automation platform, or governed agent stack. Its appeal is the combination of persistent context, a cloud computer and browser, cross-channel messaging, connected plugins, scheduling, and proactive research. Its weakness is the same combination: one always-on agent can accumulate broad context, shared permissions, and ongoing influence before the business has learned how to supervise it.
Buy or pilot Dots when the eligible ChatGPT plan already fits, one operator owns the rollout, and the first workflow is mostly read, analyze, prepare, and escalate. Wait when you need predictable dot-level pricing, multiple independent agents, individual-memory controls, regional access that has not launched, or unsupervised high-consequence execution.
The safest operating principle is simple: give the dot broad visibility only where necessary, narrow authority everywhere, and no permission that the business cannot audit and revoke.
Methodology and sources
This guide is a mixed-verified editorial synthesis, not a hands-on test. Product behavior, rollout, plan eligibility, plan prices, permissions, memory, data-use rules, and launch allowances were checked against live OpenAI product and Help Center pages on October 1, 2026. OpenAI capability and ecosystem claims are treated as interested-party evidence. Independent launch reporting was used for skepticism and early-use signals. No Google Search Console or GA4 evidence was available, and no first-party performance claims were invented.
- OpenAI: Introducing dots
- OpenAI Help: Getting started with your dot
- OpenAI Help: Dots privacy, security, and safety FAQs
- OpenAI Help: Manage dots in ChatGPT workspaces
- OpenAI: Safety, security, and privacy in dots
- OpenAI Help: ChatGPT Pro tiers
- OpenAI: ChatGPT Business Premium seats
- TechCrunch: OpenAI launches Dots
- PYMNTS: OpenAI’s Muse rival arrives half-baked
FAQ
Is OpenAI Dots a separate subscription?
No. The first primary dot is included at no extra charge with eligible Pro or Business Premium plans. Enterprise-family access is a controlled beta. The underlying plan still costs money, and future extra-dot or capacity pricing is unpublished.
How much does an OpenAI dot cost after the first month?
OpenAI has not published a standalone price or the normal allowance for the included dot. It says the first month has extended limits and that future buyers will be able to add dots or increase speed and monthly work. Do not present those future prices as known.
Can a dot send email or change business data?
It can take supported actions through connected systems when permissions and action rules allow them. Proactive research itself is read-only. Consequential actions should remain subject to approval, Auto-review, Custom Rules, and mandatory handoffs.
Does a dot use the same plugins as ChatGPT and Codex?
Yes. Plugin permissions are shared across dots, ChatGPT, ChatGPT Work, and Codex. Review existing connections before enabling the dot because an old broad permission may now be available to an always-on agent.
Can I delete one thing my dot remembers?
Not currently. Individual dot memories cannot be viewed, edited, or deleted one by one. Deleting the dot clears its own context, conversations, memories, and schedules, but separately stored files, tasks, conversations, and ChatGPT memories require their own controls.
Can a dot work when my laptop is off?
Yes, on its dedicated cloud computer for supported cloud work. Local-computer tasks require the connected machine to be online and the ChatGPT desktop app to remain open.
Should a small business connect its accounting system on day one?
No. Start with read-only source access or exported reports, then allow invoice preparation without sending or payment authority. Move-money actions require human takeover, and final financial outputs should remain under qualified review.