How To

ChatGPT Dots Custom Rules: 6 Settings Worth Getting Right

ChatGPT Dots Custom Rules: 6 Settings You Must Get Right
Photo: 2014 USAREUR Best Warrior Competition 140917-A-BS310-391 by Markus Rauchenberger, Public domain, via Wikimedia Commons

ChatGPT Dots custom rules are the setting that decides whether an always-on agent is useful or alarming. They are also easy to misread: the four options sound similar, one of them means something more specific than it appears, and there is a second review layer you do not configure at all. This guide works through both.

Updated October 2026. Dots launched on 29 September 2026 and are rolling out gradually, so check OpenAI own pages for the current position before relying on any detail here. This is general information about a product setting, not security advice for your organisation.

ChatGPT Dots custom rules: Yellow traffic signal (9722336142)
Yellow traffic signal (9722336142) by Ben Schumin from Montgomery Village, Maryland, USA, CC BY-SA 2.0, via Wikimedia Commons

The four behaviours

When you add a rule you describe the action it covers, then choose one of four behaviours:

  1. Take action without asking. The dot proceeds on its own.
  2. Take action if pre-approved. This is the one people misread. OpenAI defines pre-approved as meaning you explicitly requested the action in your prompt, not that you approved the category once in advance.
  3. Ask before taking action. The dot stops and requests confirmation.
  4. Hand off to you. The dot does not do it at all and passes it back.

Rules apply to things a dot can share, purchase or access, which is a good summary of where the risk sits.

What rules cannot do

Two limits are stated plainly and are worth knowing before you rely on this:

  • Custom rules cannot override built-in safeguards. You cannot widen the boundary, only narrow it.
  • Turning custom rules off does not make every action require approval. Default action rules still apply, so the absence of your rules is not a strict mode.

OpenAI also notes that a dot can make mistakes, including when following your rules, which is the right way to think about this: rules shape behaviour, they do not guarantee it.

Auto-review, the layer you do not set

Underneath your rules sits auto-review, where a separate model checks actions that could affect your accounts or share information against your instructions, your rules and the built-in safety requirements. It decides what can proceed, what needs approval, and what you have to do yourself.

The system card lists the six threat models auto-review is evaluated against, which is the clearest published statement of what it is looking for: data disclosure, destructive actions, financial commitments, access and security, unauthorised communication, and ambiguous authorisation. OpenAI generated 30 synthetic disallowed cases per category and separately replayed 5,000 unedited requests from de-identified employee traffic to measure how often the reviewer refuses ordinary work. It reports that recall is weakest in the ambiguous authorisation cases, which is the honest place for it to be weakest.

ChatGPT Dots custom rules: Stop sign COV
Stop sign COV by Emma0mb, CC BY 4.0, via Wikimedia Commons

The actions that always stay with you

Some tasks are not configurable at all. OpenAI gives changing a password as its example of a sensitive task that always stays with the user. Anything in that class is handed back regardless of how permissive your rules are.

How the rules hold up when the ground shifts

The most interesting published result concerns what happens when permissions change mid-task, which is a real risk for an agent that works for hours. OpenAI built an evaluation where an external change, such as revoking permission, is introduced part way through. Dots passed 91.8 percent of episodes, 45 out of 49, including all 17 cases where permission changed explicitly. The four flagged episodes involved genuine ambiguity about the boundary.

A second result is the one to design around. When OpenAI doubled the number of intervening tasks in a chain from five to ten, the flag rate for moderate scope violations roughly doubled too, from 8.6 percent to 19.7 percent. Long chains of loosely related work are where boundaries blur.

Writing ChatGPT Dots custom rules that hold up

Because a rule is a description of an action rather than a switch on a named feature, the wording does the work. Four habits make the difference between a rule that holds and one that is interpreted around.

  1. Name the action and the object. Sending an email is a category; sending an email to anyone outside my company is a rule.
  2. Set the risky cases first. Spending money, messaging customers, sharing files and changing access deserve explicit rules before anything else.
  3. Prefer hand off to you over ask before acting for anything you would not want to approve at a glance on a phone. The two behaviours feel similar and are not.
  4. Turn every surprise into a rule. The practical use of the approval log is spotting the thing you had not thought to forbid.

It is also worth remembering what rules are measured against. Auto-review weighs an action against your instructions, your rules and the safety requirements together, so a permissive rule does not override the layer underneath. OpenAI tested exactly this case: scenarios where a dot was instructed never to ask permission and to work entirely on its own were part of the red-teaming, and the confirmation policies were updated in response to what those tests found.

Where rules sit in a workspace

In Enterprise workspaces, custom rules are themselves a permission. Use custom rules for dots is off by default, and when it is off the default action rules still apply. Our guide to dots admin controls covers the full set, and our explainer on AI agent email permissions covers the same question for mail specifically.

Common questions

What does pre-approved mean in ChatGPT Dots custom rules? OpenAI defines it as meaning you explicitly requested that action in your prompt. It is not a standing approval for a category.

Can a rule let my dot do anything it likes? No. Custom rules cannot override built-in safeguards, and certain sensitive tasks always stay with you.

If I turn custom rules off, does everything need approval? No. OpenAI states that disabling custom rules does not make every action require approval, because default action rules still apply.

What is auto-review checking for? Data disclosure, destructive actions, financial commitments, access and security, unauthorised communication, and ambiguous authorisation.

What happens if I revoke a permission while the dot is working? In OpenAI own evaluation, dots passed all 17 explicit permission-change cases and 91.8 percent of episodes overall. That is a test result, not a guarantee.

Sources and further reading

Where the figures and rules above come from, so you can check them:

Photo credits: 2014 USAREUR Best Warrior Competition 140917-A-BS310-391 by Markus Rauchenberger, Public domain, via Wikimedia Commons. Yellow traffic signal (9722336142) by Ben Schumin from Montgomery Village, Maryland, USA, CC BY-SA 2.0, via Wikimedia Commons. Stop sign COV by Emma0mb, CC BY 4.0, via Wikimedia Commons.

Join the discussion

Held for review before it appears. Links are not allowed and your email is never published.