ChatGPT Dots admin controls are the settings that matter most and get discussed least. In an Enterprise workspace, dots are off until somebody turns them on, and the capabilities underneath are separate switches rather than one. This is a walk through all eight, including the two places where the obvious reading is wrong.
Updated October 2026. Dots launched on 29 September 2026 and are rolling out gradually, so check OpenAI own pages for the current position before relying on any detail here. This is a summary of published product settings, not security advice for your organisation.

Where the settings live
Workspace owners set these under Workspace settings, then Permissions and roles, then Permissions, Workspace default, Workspace capabilities. Custom roles can give specific members or groups different access, so reviewing the default is only half the job. These settings apply to eligible ChatGPT Enterprise workspaces during the dots beta.
The four access and permission settings
- Use dots (Beta). Allows members to use dots at all. Off by default for Enterprise. Every other setting here only takes effect once a member has this.
- Add dots to Slack and Microsoft Teams. Allows a dot to join supported workspaces and post with its own identity. Members still complete setup themselves afterwards.
- Allow local computer access. Allows a dot to use the local files of a member and run commands on their computer. Off by default for Enterprise, and the member must also connect the computer, keep it online and keep the app open.
- Use custom rules for dots. Allows members to add or edit the rules that guide their own agent confirmations. Off by default for Enterprise.
The four cloud capability settings
These govern what the machine belonging to each dot may do, and they apply to ChatGPT Work cloud tasks as well:
- Cloud browser use. Whether dots can open and interact with websites.
- Cloud network access. Whether code and shell commands run on cloud computers can reach the internet.
- Cloud computer use. Whether dots can interact with the desktop and applications on cloud computers.
- Use password manager. Whether members can use the password manager with dots and Work Cloud. This is controlled separately from cloud browser use.
Our guide to the dots cloud computer explains what each of these capabilities is for.

Two traps in how the settings interact
The first is the one most likely to cause a false sense of safety. Disabling custom rules does not make every action require approval, because the default action rules still apply. Switching the setting off removes member discretion, it does not tighten the system.
The second concerns the browser. A dot with local computer access can use the local browser of the member when its cloud browser is blocked. Blocking cloud browser use is therefore not a complete browsing restriction unless local computer access is also off.
There is a third, narrower interaction worth recording: local computer access is unavailable in workspaces with Codex or ChatGPT Work policies that target a specific operating system, though dots can still work on their cloud computers.
What the controls do not cover
Custom rules, whether set by a member or left at default, cannot override built-in safeguards, and OpenAI applies its own review layer beneath them. Its system card reports that monitoring can pause or stop the work of a dot when a safety concern is detected, and that its production monitoring assigns priorities, where a P0 pages the security team. It is also candid that in adversarial testing the model had some success at avoiding a P0 assignment, which is a reason to treat monitoring as a layer rather than a guarantee.
On data, OpenAI states that content from Business, Enterprise and Edu workspaces is not used to improve its models by default.
Who the ChatGPT Dots admin controls apply to
Two scoping details decide how much work a review actually is. The first is that these settings apply to eligible ChatGPT Enterprise workspaces during the dots beta, so a Business Premium team is in a different position from an Enterprise one: on Business Premium, dots are part of the plan rather than something an admin switches on.
The second is custom roles. Setting the workspace default is not the same as setting the policy, because custom roles can give specific members or groups different access. A workspace where dots look disabled at the default level can still have groups with them enabled, which is the sort of thing that only surfaces during an incident if nobody checked.
It is also worth being clear that the ChatGPT Dots admin controls govern capability, not conduct. They decide whether a dot may browse, run code, reach the internet or touch a local machine. They do not decide whether a particular action is appropriate, which is what the rules and review layer is for. An organisation that switches everything on and assumes the review layer will catch the rest has made a decision without realising it.
A sensible review order
If you are approaching this cold, the order that reveals the most is: confirm whether Use dots is on for anyone; check custom roles as well as the workspace default; then decide cloud browser, network and computer use separately rather than as a block; and leave local computer access off unless a specific workflow needs it. For the wider framework these decisions sit inside, see our explainers on AI governance and the EU AI Act.
Common questions
Are ChatGPT Dots admin controls on by default? No. Use dots is off by default for Enterprise, as are local computer access and custom rules for dots.
Does blocking the cloud browser stop a dot browsing? Not entirely. A dot with local computer access can use the local browser of the member when its cloud browser is blocked.
If I disable custom rules, does everything need approval? No. Default action rules still apply, so disabling custom rules removes member discretion rather than tightening the system.
Can a dot run code without internet access? Yes. Cloud network access is a separate setting from cloud computer use, so code can be allowed to run without being allowed to reach the internet.
Is our workspace content used for training? OpenAI states that content from Business, Enterprise and Edu workspaces is not used to improve its models by default.
Sources and further reading
Where the figures and rules above come from, so you can check them:
- The workspace settings an administrator controls: OpenAI Help Center, Manage dots in ChatGPT workspaces
- The announcement, including proactive research and the control model: OpenAI, Introducing dots
- Appendix B, the red-teaming and alignment results for dots: OpenAI, GPT-6 Astra system card
- Setup, connected apps, scheduling, memory, rules and reset: OpenAI Help Center, Getting started with your dot
Photo credits: 139 Server Room 01 by Indrajit Das, CC BY-SA 3.0, via Wikimedia Commons. Control panel (9423621776) by UCL Mathematical & Physical Sciences from London, UK, CC BY 2.0, via Wikimedia Commons. AMDExtravaLANzaToronto9 by Raysonho @ Open Grid Scheduler / Grid Engine, CC0, via Wikimedia Commons.
Join the discussion