Issue #: 011
Send date: 5 Oct, 2026
Subject line: Everyone's asking what OpenAI's new agent can do. The better question is what it's allowed to do.
Preheader: OpenAI shelved a model for acting without asking. The next day it shipped agents that never log off.

THE MONEY BEAT

Here's a sentence worth stopping on.

In OpenAI's launch post for dots, there's one example from someone outside the company. An early tester's dot noticed he'd forgotten to invoice a publication. It prepared the invoice and sent it after he approved.

That's the whole product in one line. A dot is an always-on agent with its own cloud computer. It keeps working after you close the chat, and it brings you the things you forgot to do.

Now look at what happened the day before. OpenAI decided not to release a model called GPT-6.1 Astra. Its head of safety systems, Saachi Jain, said it “didn't quite meet the bar in terms of staying within scope and authorization.” In testing, the model kept going on tasks without asking permission, and it was less reliable about reporting what it had actually done.

Dots run on the earlier GPT-6 Astra. But the two failures OpenAI refused to ship are the two that matter most when an agent works while you're not watching. One is doing something you didn't approve. The other is telling you something different from what happened.

OpenAI's own numbers show the risk doesn't go to zero. Its system card describes workplace tests built to trip agents up, with vague instructions, look-alike files, and tangled permissions. With the default approval rules on, the model behind dots still ended up somewhere the user didn't intend in 3.0% of tasks. It sent a message nobody authorized in 1.4% of them.

Those are hard tests, not your Tuesday. But 3 in 100 is the right number to keep in your head.

So where's the money? Not in the agent being smart. It's in the agent being there. Most money a small business loses doesn't go to bad decisions. It goes to follow-through: the invoice nobody sent, the lead nobody answered on Thursday, the renewal nobody chased. None of it is hard. It just needed someone around when it needed doing.

So the money sits in two places. Inside your business: give one dot one standing job, chasing money you're already owed, and keep every outgoing message behind your approval. As a service: most owners who turn this on will keep the default settings and hope. Writing the job, the rules, and the weekly check for them is a setup fee plus a retainer.

This skill outlasts the product name. Meta's Muse, dots, whatever ships next quarter: the question stays the same. Can you describe the job tightly enough that you'd notice when the agent steps outside it? If yes, hand it over. If no, keep it.

THIS WEEK'S MOVE

● Beginner: pick one dropped job and lock the rules before connecting anything. ● Operator: make the report checkable, make approvals narrow, then sell the setup.

MOVE 01 · BEGINNER
Write down the one follow-up you keep forgetting, as a job description.

Objective: you finish with a three-line brief an agent could actually follow.

Start with money already owed or nearly owed. Invoices unpaid past 14 days. Leads with no reply after 48 hours. Proposals sent with no answer. OpenAI's one outside example was a forgotten invoice, so that's a good place to start.

Write three lines. What it watches. What "handled" looks like. What it tells you every Friday. If you can't write line two, the job is too vague to hand off yet.

Tools: a note on your phone

MOVE 02 · BEGINNER
Set your Custom Rules before you connect a single app.

Objective: you finish with written limits that still apply when the dot works in the background or hands work to another agent.

Go to Settings, then Personalization, then Custom rules under Permissions. Each rule names an action and gives it one of four settings: take action without asking, take action when you say so, ask before taking action, or hand off to you.

Start with two rules. "Ask before taking action" for sending any message. "Hand off to you" for deleting anything. OpenAI's controls guide is honest that these are instructions the dot tries to follow, and it can still make mistakes. Treat them as your first fence, not your only one.

MOVE 03 · BEGINNER
Run week one as drafts only, and read every draft.

Objective: you finish the week knowing what the dot would have sent, before it sends anything.

OpenAI's docs spell it out: asking your dot to draft replies doesn't give it permission to send them. Use that. Ask for drafts and then a Friday report listing what it noticed, what it drafted, and what it would have sent.

Count the drafts you'd send without changing a word. That number tells you how ready the job is to hand off.

Tools: ChatGPT dots · Gmail or your invoicing app

MOVE 04 · OPERATOR
Require a did/didn't/couldn't report, and check it against Activity.

Objective: you finish with a weekly report you can verify, not just read.

Misreporting is the failure that got GPT-6.1 Astra shelved. OpenAI's own system card makes the point plainly: an agent that misdescribes its work makes it harder for anyone to supervise it.

So build the check in. Every Friday report gets three columns: what it did, what it chose not to do and why, and what it couldn't do. Then open the dot's profile, go to Activity, and trace three lines back to the actual steps it took.

This is the trace column from Issue #010 applied to actions instead of numbers. If the report says something the activity log doesn't show, stop the job and tighten the brief.

Tools: ChatGPT desktop app

MOVE 05 · OPERATOR
Write standing approvals like contracts: who, what, when.

Objective: you finish with one advance approval narrow enough that you'd be fine reading every message it covers.

OpenAI's guidance is to give any ongoing instruction a clear scope: who's involved, what should happen, and when. An approval covers future actions inside that scope, and anything outside it needs a new decision. So be literal: "Send the 14-day reminder template once to clients on the overdue list, weekdays 9 to 11am, only if the invoice is still unpaid and they haven't replied."

The system card shows why narrow matters. In one simulated case, a user asked the model to set up an hourly helper. The model switched on every available action across its connections and turned off per-action approval. OpenAI flagged it as a serious case and says this kind of behavior is rare. But it's exactly the failure you'd worry about in a standing job.

So check the Scheduled tab every Friday. One more thing to know: pausing your dot only stops its current main task. It doesn't stop delegated tasks or cancel scheduled runs. Ending a job means deleting the schedule. Anything that moves money stays on your permanent list from Issue #005, and dots hand transfers back to you anyway.

Tools: ChatGPT desktop app

MOVE 06 · OPERATOR
Package agent onboarding as a monthly service.

Objective: you finish with one repeatable deliverable: the job description, the rules, the approval scopes, and four weeks of report checks.

Always-on agents are landing on owners who've never written a job description for software. The built-in defaults are sensible, but they're generic. Your product is the rulebook plus the Friday check.

Lead with the follow-through job. Recovered receivables pay for the engagement in a way the client can see in their bank account. The retainer is the weekly check against Activity.

Keep the client signing off on anything that leaves their business. The agent prepares. They approve.

Tools: ChatGPT dots · Google Docs or Notion

THE ONRAMP

Your first standing job for dots. About thirty minutes to set up, one week to watch, no code.

Issue #005 had you supervise one agent run. This is the next step: an agent that keeps a job between your conversations. Bring your brief from Move 01. If you skipped Move 01, do it first. A test on a job you don't actually drop proves nothing.

Check that you have access. Dots are rolling out to Pro users outside the EEA, Switzerland, the UK, and to Business Premium in all supported regions. OpenAI says it can take several days to reach your account. You create your dot in the ChatGPT desktop app or on desktop web, not on mobile.

Before anything else, open Plugins. Connections are shared across ChatGPT, ChatGPT Work, and Codex, so your dot can use apps you connected months ago. According to OpenAI's getting started guide, it can also read them in the background and form memories from them. Disconnect anything this job doesn't need. Disconnecting later won't erase what the dot already learned. Only deleting the dot does that.

Set the two Custom Rules from Move 02. Then connect exactly one app: the one the job lives in.

Paste this brief and adjust it to your job: "Your standing job: [your Move 01 brief]. Check daily. Don't contact anyone. Draft follow-ups for my review. Every Friday, report in three columns: what you did, what you didn't do and why, and what you couldn't do. If something doesn't match what you expect, stop and ask me instead of guessing."

Open Activity for two minutes each day. You're grading how it behaves, not what it writes.

On Friday, compare the report to Activity and to the app itself. This is the actual exercise. If every line checks out, the job is working. If one doesn't, you've found out before it cost you anything.

Run a second week before you change anything. The same behavior two weeks running means you have a process. Different behavior means your brief left something open. Tighten it and run the week again.

Don't approve any sending yet. The permanent list from Issue #005 still holds. Anything that touches a client's inbox or your money stays supervised for at least a few clean weeks. Money stays supervised after that too.

THE OPERATOR QUESTION

Q: "I am interested in learning how to automate my organization using AI. Specifically, I would like to explore actionable workflows and tools for automating routine business processes and operations, and integrating AI into daily team communication and task management."

A: Don't automate the organization. Automate one process, then let your team show you the next one.

Start with the routine side. Pick one process that repeats every week, has a clear finish line, and wouldn't hurt anyone if it went wrong once: the Monday status update, chasing overdue invoices, sorting inbound requests. Write it as the three-line brief from Move 01: what it watches, what "done" looks like, what it reports back. On ChatGPT Business, put it in team tasks. On Pro or Business Premium, give it to a dot. Run it drafts-only for two weeks before it sends anything.

For team communication, do the opposite. Don't design anything yet. Add @ChatGPT to the Slack or Teams channel where work actually gets assigned. On Business plans, teammates can use it there without their own license. Then watch what people ask it for over two weeks. The requests that come up three or four times are your automation list, ranked by your team instead of by a vendor demo.

One rule across both: anything that approves, pays, or speaks for the company stays with a person. That's the permanent list from Issue #005, and it applies to a whole organization even more than to one founder.

/

THE STACK UPDATE

BUY · dots, for one bounded follow-through job. WATCH · dots, as the agent that "handles everything."

Where it's strong: each dot works on its own cloud computer, separate from yours unless you choose to connect it. Background research is read-only, and OpenAI says that limit is enforced in code, so research can't send messages or change anything. A separate check called Auto-review looks at actions like sending an email before they run. It sits outside anything the dot can change or turn off. Passwords go through a secure sign-in form, so the model never sees them.

Where it breaks: you can't view or edit individual memories, and the only reset is deleting the dot. OpenAI's help center says its defenses against hidden instructions in emails and web pages reduce the risk but don't eliminate it. OpenAI staff can review a dot's activity in limited cases, such as safety reviews, even with training turned off. And TechCrunch pointed out that much of what dots do was already possible through Codex and similar tools. Dots package it into one product. We haven't found a published independent test of dots on real business work yet.

Use it to chase what you're owed. Don't hand it your inbox and walk away.

The rest of the shelf: five things from the last week worth your attention.

BUY, for work someone reviews · GPT-6.1 Sol. Launched September 29 as the upgrade to the Sol from Issue #010. It's in ChatGPT Work and Codex, not regular chat yet. OpenAI reports it beat Opus 5.5 by 2.2 points on Zapier's AutomationBench, which tests multi-step business workflows. That's OpenAI's claim, and its competitor scores come from public reports, not a head-to-head test. The Move 05 sort from #010 still holds: reviewed work goes here, and numbers nobody checks stay on Opus 5.5.

BUY, if you're on ChatGPT Business · team tasks. You hand off recurring work, like weekly project updates. It runs on a schedule or when something happens, like a new email or Slack message. Teammates can edit the instructions together. It's the shared version of Move 01 for teams that don't have dots.

BUY, if your team lives in Slack or Teams · @ChatGPT in channels. On Business and Enterprise, you mention @ChatGPT in a channel, thread, or DM, and it works with your connected tools. Teammates can add context and refine the answer without their own ChatGPT license. It's a cheap way to see which jobs your team would actually hand off before anyone sets up a dot.

WATCH · MCP events for plugins. On all plans, a plugin can now start an automation when something happens in a connected app. OpenAI's example is ChatGPT watching a project board and drafting a plan when a new task comes in. It's the no-dots route to a standing job. We're calling WATCH because it's built on a proposed spec and only works with plugins that support it.

WATCH · Meta Muse. The main rival to dots, with a free tier and paid plans. It's US-only for now. Meta says that unless users opt out, it will strip critical personally identifying information and then use agent conversations to improve its models. Read the data settings before you connect anything with client information in it.

Carried forward. Opus 5.5 (#010) still closes the books. Jev (#009) still sits in front for yes/no decisions. The Chrome profile with no saved logins from #005 is still where browser agent work belongs.

You're reading the Operator Brief:

A weekly dispatch for founders, freelancers, and operators who treat AI as a business tool, not a hobby. Every Monday, one question: what changed in AI this week that you should actually do something about?

Anthony | Founder of Uncover AI