OpenAI Dots Permissions: Apps, Memory and Control
Understand OpenAI Dots permissions, connected apps, custom rules and memory. Learn how to review ongoing work and stop tasks without guessing the scope.
OpenAI dots permissions have several parts: which apps it can access, what your request authorises, and which boundaries you set for actions. Memory and recurring work need their own attention. OpenAI’s control documentation describes built-in checks and optional custom rules, and says rules can still be followed incorrectly. Read the result of important work rather than assuming a saved rule makes mistakes impossible.
This guide explains the distinctions using a supplier email example. It is based on public OpenAI documentation checked on 30 September 2026, not a security audit or a hands-on test. For access to the product itself, see what OpenAI dots is. For a first draft task, use how to use OpenAI dots.
Start with the action you actually want
“Help with suppliers” is a topic, not permission to do every supplier-related action. Decide whether the agent should read a quote, draft a reply, send it, update a shared document or commit to a purchase. Each step has a different consequence. Describe the steps you want and the point at which you need to review them.
For a first request, ask for a comparison and a draft. That leaves a visible output you can check. Once you have read the draft, you can make a separate decision about sending it. The distinction is useful because a confident draft can contain an accidental promise. If you are not ready to make that promise, the message is not ready to send.
The same division appears in using AI as an executive assistant: preparation and judgement belong in different parts of the workflow. An agent can help you see a decision more clearly without being given authority to settle it.
App access and task authority are different
OpenAI’s privacy and permissions FAQ says plugin permissions are shared across dots, ChatGPT, ChatGPT Work and Codex. Review existing connections as well as new ones. Creating a dot is not necessarily starting from a blank set of app permissions.
Suppose an email connection supports both reading and sending. You might still authorise only a draft for this task. Conversely, asking the agent to send something does not establish a connection that your account has never approved. The task needs both the relevant access and a clear instruction within that access.
Before connecting work email, establish which account is selected. A personal inbox, a shared mailbox and a company account are different sources with different audiences. Do not put an ambiguous “my email” in the brief when more than one connected account could match it.
Write down the account, folder or thread the task should use. Name the output and recipient. If the task only concerns one quote, say so. A tightly scoped request also makes later corrections easier: you can see whether the agent used the wrong thread, found an outdated attachment or addressed the wrong person.
Your computer is another connection
OpenAI’s computer and app guide treats local-computer access separately from app and messaging connections. The cloud browser has its own sessions. A website login on your laptop does not automatically sign the dot into that website.
That matters when a task stops for a login. Establish which browser and account the task is using before adding more access. Do not solve a missing website session by assuming that the dot needs every file on your laptop. A local connection may be useful for a local workbook, but it should follow from the task’s actual requirement.
For a supplier quote exercise, list what the task needs: the quote, the previous terms and perhaps a specific email thread. Then check where those sources are stored. If you can supply approved copies for a draft, the task may not need a broader computer connection at all.
Make the boundary readable
Here is a proposed brief for the example. It is deliberately specific about the permitted sources and the action that must wait.
Use the two supplier quotes I attached to compare the renewal terms. Draft a reply to the named supplier contact asking about the unresolved delivery date. Keep the reply in this conversation for my review. Do not send messages, accept terms, edit shared files or forward attachments. If the contact address or date is missing, ask me. Use these quotes only; do not search unrelated email threads.
This is an exercise in clear delegation, not a claim that the prompt enforces a technical barrier. Read the draft and confirm what happened. If the result says an action was taken, check the relevant app rather than assuming the status line is enough.
Compare it with “sort out the renewal”. The shorter version leaves price, timing, recipient and authority unstated. Being concise is useful, but omitting the decision that matters is not. Writing a prompt that works first try gives you a reusable structure for making a request precise without making it long.
When to use a custom rule
A custom rule is useful for a boundary that should apply repeatedly. For example, you may want customer messages to require review even when you have an ongoing customer-support task. Keep preferences such as tone in the task brief; use action rules for when something may happen.
Check the saved wording and the behaviour selected. “Ask before sending messages to customers” is different from “ask before every message”. If you only mean customers, say that. If you mean a particular account or audience, include it. Avoid a rule so broad that ordinary draft work constantly stops, or so vague that you cannot tell whether an action falls inside it.
OpenAI’s control guide says custom rules do not grant app access or override built-in safeguards. That distinction should shape your expectations. A rule is not a way to make an unavailable app work, and it is not proof that every future decision will match your intention.
After changing a rule, inspect the next relevant task. The practical test is whether you understand the request for approval and the action it refers to. A button labelled approve only helps if the draft, audience and effect are clear enough to review.
Read the approval as a decision
Before approving the supplier reply, check the recipient and the exact promise in the text. A request for a delivery date should not accidentally accept a price increase. Check whether an attachment includes other suppliers’ information. Read the amount, date and scope against the quote rather than relying on the summary.
- Is this the account and recipient you intended?
- Does the message make a commitment you have not decided on?
- Are attachments limited to what the recipient should receive?
- Is the action a draft, an edit or an external message?
- Can you inspect the actual output before confirming?
For factual claims, use the habits in checking an AI answer. For broader weaknesses, what AI is actually bad at is a useful reminder that fluent wording and good judgement do not always arrive together.
Memory is not the same as a connected account
OpenAI’s tasks and memory documentation separates ChatGPT memory from the dot’s saved notes. Changing a ChatGPT memory setting does not necessarily change notes the dot already made. Treat a preference correction and a data-control change as different tasks.
If you previously said a supplier was approved and that decision changes, state the correction clearly. “We are no longer treating this supplier as approved; keep the renewal draft on hold” is more useful than deleting a file and hoping the absence tells the agent what changed. Check that the next draft reflects the new decision.
Do not assume disconnection erases previously obtained information. OpenAI’s getting-started FAQ says disconnecting an app does not delete information already obtained, and describes resetting the dot as deletion of its conversations, saved memories and schedules. Read the current confirmation before using a destructive control, and save deliverables you need.
Stop the right part of the work
An active task and a recurring schedule are different things. If you want the supplier renewal stopped, identify whether there is a draft task running, a weekly check saved, or both. Inspect the relevant Activity and Scheduled entries. Confirm that the work you meant to stop has stopped.
OpenAI’s safety explanation acknowledges that agent mistakes can affect files and information sharing. Stopping future work does not recall a message or restore a file already changed. If something went wrong, establish the actual action and affected account before deciding how to correct it.
Keep a small record for your own review: the brief, connected source, approved action and final deliverable. You do not need a complicated audit process for an exercise. You need enough evidence to understand what you asked for and what happened.
A useful starting boundary
Begin with a task that produces a draft from sources you can share. Check the result, correct it and inspect the next version. Add a connection or recurring responsibility only when it solves a specific need. More access should follow a reason you can explain.
Coursium teaches practical AI skills on your phone. Clear requests, source checks and deliberate review matter just as much when an agent can take actions as when an assistant only writes answers. The first useful control is knowing exactly what you want it to do.