The bubbly avatar is not the product.
On September 29, 2026, at DevDay, OpenAI launched Dots: always-on agents powered by GPT-6 Astra, each with their own cloud computer, a plugin path into more than 4,000 apps, and reach into ChatGPT, Slack, and Teams. You can name one, dress it up, call it on voice, and watch it work in the background. TechCrunch called the branding a bubbly, cartoonish persona “similar to Meta’s recently released Muse agent.” The Verge framed the launch as OpenAI’s Muse competitor with cute, customizable avatars (OpenAI, September 29, 2026; TechCrunch, September 29, 2026; The Verge, September 29, 2026).
That is the press photo. It is not the operator ticket.
The ticket is identity. Specialist Dots get their own identity, credentials, and tools. Slack and Teams can let a Dot post under that identity. Enterprise workspaces keep “Use dots” and several related permissions off by default. Microsoft Agent 365 is the planned governance surface. Conversations with a Dot do not count toward ChatGPT usage limits, while Codex and ChatGPT Work tasks still do. Marketing and ops teams who brief this as a sticker on the chat window will miss which roles get a Dot identity, which channels that identity can speak in, and which admin toggles have to flip before any of that is real.
What OpenAI actually shipped
Keep the claim exact.
Dots are always-on agents built to handle ongoing work, not a single prompt. They run on GPT-6 Astra. Each has its own cloud computer and browser. They connect through ChatGPT’s plugin ecosystem to more than 4,000 apps. You can message or call them in ChatGPT on desktop, web, and mobile, and message them in Slack and Teams, with texting described as coming soon. Context carries across channels. Today you start with a primary Dot. Over time OpenAI envisions teams of Dots. Your first Dot is included in eligible Pro or Business Premium plans at no extra cost, with an allowance for deeper work and extended limits for the first month after launch (OpenAI, September 29, 2026).
OpenAI’s launch post is careful on plan language. Dots are rolling out across Pro, Business Premium, and Enterprise plans in eligible markets. Enterprise users (including Edu and Healthcare) can try the beta when a workspace admin enables it. TechCrunch’s same-day report named Pro and Business Premium for Tuesday availability. The Verge named Pro, Business Premium, and Enterprise. Independent operator writeups that sat with the livestream and Help Center add geography: Pro outside the EEA, Switzerland, and the UK; Business Premium across supported ChatGPT regions; Enterprise beta off until an admin turns it on (TechCrunch, September 29, 2026; The Verge, September 29, 2026; ZipLyne, September 29, 2026; Flavio Copes, September 30, 2026).
Attribute the discrepancy. Do not invent a single roster. If your seat is Enterprise, the avatar means nothing until “Use dots (Beta)” is on. If your seat is Pro in a blocked region, the livestream demo is not your product.
Safeguards sit next to the soft branding. Cloud computers stay separate from your laptop unless you connect it. Saved passwords can sign into supported sites without exposing credentials to the model. Background “proactive research” runs on connected apps with read-only tools. Custom Rules let you allow, require approval, or block actions. Auto-review checks account-affecting or information-sharing actions against instructions, Custom Rules, and safety requirements. Sensitive steps such as changing a password stay with you. OpenAI’s own line: Dots can still make mistakes, so always review consequential work (OpenAI, September 29, 2026).
That is still not the identity story. The identity story is specialist Dots, channel posting, and the Enterprise permission matrix.

Specialist Dots are IAM, not costume
Your personal Dot works on your behalf. Specialist Dots take on dedicated responsibilities inside the organization.
OpenAI says the company sets up each specialist Dot with its own identity, credentials, and access to the systems it needs. Early internal testing covered procurement, invoice processing, email marketing, customer support, and commercial contracting. Launch is framed as focused enterprise pilots, with OpenAI engineering teams working directly with organizations to define responsibilities, tools, and review. On the livestream, specialist Dots were described as virtual teammates for intensive work such as accounting, marketing, and legal. Feedback on their work is meant to be shared across the company. OpenAI is also working with Microsoft so specialist Dots can sit under Agent 365 enterprise governance and security controls (OpenAI, September 29, 2026; ZipLyne, September 29, 2026; Flavio Copes, September 30, 2026).
That language is familiar to anyone who has provisioned a service account, a bot user, or a shared mailbox. It is not familiar to anyone who has only spun a chat avatar. A marketing Dot with CRM write access is a different risk object from a personal Dot that drafts social posts for approval. A legal Dot with contract systems is a different risk object from a content Dot clipping transcripts. The operator question is not “do we like the mascot.” It is which roles get a Dot identity, which credentials that identity holds, which systems of record it can touch, and who reviews what it produces before it leaves the building.
ChatGPT Space sits next to this as the collaboration surface. The Verge notes that colleagues can work with a Dot in ChatGPT Space, a new collaborative workspace. ZipLyne’s livestream notes add that Space is where people, teammates, and agents share pages, tag Dots the way you tag people, and keep live charts and standing instructions. Treat Space as a channel-and-artifact layer, not as proof that specialist IAM is already live for your org (The Verge, September 29, 2026; ZipLyne, September 29, 2026).
Slack and Teams: posting under a Dot’s own identity
The Help Center article for Enterprise workspaces is the load-bearing doc for channel ownership.
Workspace owners control who can use Dots and which capabilities are available. Dots access is off by default for Enterprise. Under Permissions and roles, owners find “Use dots (Beta)” and related toggles. Separately, “Add dots to Slack and Microsoft Teams” allows a Dot to join supported Slack or Teams workspaces and post with its own identity, where available. Members must complete setup after the permission is enabled. For Slack, both “Use dots (Beta)” and the Slack/Teams permission must be on. If the Slack workspace requires app approval, a Slack owner or app manager must approve the install. Only a Dot’s owner can direct it. Other people’s DMs or mentions do not start work for that Dot. When a Dot posts in a channel, other channel members can see its messages. Phone messaging through iMessage, RCS, or WhatsApp is unavailable for Enterprise at launch (OpenAI Help Center, accessed September 30, 2026).
Read that again as a marketing ops problem. A Dot that posts in a launch channel is a named presence on the record. Clients, agencies, and partners who sit in those channels will treat it as a speaker, not as a private sidekick. Brand voice, disclosure, approval queues, and audit trails all move. This is closer to provisioning a branded bot user than to enabling a cute reply suggestion.
Local computer access is another off-by-default Enterprise control: the Dot can use a member’s local files and run commands only if the permission is on, the member connects the computer, keeps it online, and keeps the ChatGPT app open. Custom rules for Dots are also off by default for Enterprise. Cloud browser use, cloud network access, cloud computer use, and password manager controls sit under cloud computer capabilities and apply to Dots even when Work or Work Cloud is disabled. A Dot’s cloud computer does not inherit a member’s VPN, browser sign-ins, or device policies. Enterprise model controls and default model settings do not apply to Dots (OpenAI Help Center, accessed September 30, 2026).
That last sentence matters for teams that thought model allowlists were their safety net. Dots are gated by Dots permissions, not by the model picker your security team already argued about.

Usage limits are a second identity boundary
OpenAI draws a bright line on metering.
Conversations with your Dot do not count toward ChatGPT usage limits. When you ask your Dot to start or manage tasks in Codex or ChatGPT Work, those tasks count toward usage limits as usual. The first Dot is included at no extra cost on eligible Pro or Business Premium plans, with deeper-work allowance and extended first-month limits. Future pricing for more Dots, more speed, or more monthly capacity is promised without a published rate card (OpenAI, September 29, 2026; ZipLyne, September 29, 2026).
For marketing finance, that split is the difference between “unlimited chat with the mascot” and “agent labor that still burns Work and Codex budgets.” Briefs that treat Dots as free always-on headcount will understate cost the moment the Dot starts shipping PRs, browser work, or Work Cloud jobs. Briefs that treat every Dot conversation as ChatGPT burn will overstate cost and scare teams off the wrong line item.
Verge and TechCrunch both restated the always-on, multi-app framing without inventing new plan math. Use them as independent confirmation of the product shape, then return to OpenAI and the Help Center for the permission and metering fences (The Verge, September 29, 2026; TechCrunch, September 29, 2026).
What operators will get wrong this week
Five failure modes show up immediately.
First, Muse cosplay. Meta’s Muse is a useful consumer comparison for the avatar and the chat-like interface. It is a bad comparison for Enterprise IAM, Slack identity posting, and Agent 365. If your deck leads with cuteness, rewrite it around roles and credentials.
Second, assuming Enterprise is on. It is not. “Use dots (Beta)” is off by default. Slack/Teams identity posting, local computer access, and custom rules are separate switches. An excited VP demo does not equal a provisioned workspace.
Third, collapsing primary Dot and specialist Dot. A named personal Dot that drafts your launch copy is not the same object as a company-provisioned marketing Dot with systems-of-record access. Pilot language for specialists is not general availability.
Fourth, ignoring channel ownership. A Dot that can post in Slack under its own identity changes who speaks for the brand in that channel. Decide disclosure, approval, and who owns the Dot before you invite it into client rooms.
Fifth, misreading the usage fence. Dot conversation is metered differently from Work and Codex task burn. Your FinOps sheet needs both lines, or you will fight the wrong budget battle.
What to do this week
Run an identity review, not an avatar review.
Inventory seats and regions. Map Pro, Business Premium, and Enterprise eligibility against what each named source actually says, including Pro geo limits reported by independent guides. Ask workspace owners whether “Use dots (Beta)” is on, and whether Slack/Teams, local computer, and custom rules are on for any role.
Name the first three responsibilities you would ever give a Dot, then decide whether each is personal Dot work or specialist Dot work. Email marketing, invoice follow-up, and support triage appeared in OpenAI’s own early-test list. Those are credentialed roles, not sticker jobs.
Before any Dot joins a Slack or Teams channel that clients see, write the posting policy: who owns the Dot, what it may say without approval, how it is labeled, and how you revoke it. Treat the Slack app approval step as part of brand ops, not as IT trivia.
Clean connected apps before onboarding. A Dot inherits plugin reach. Independent deep dives stress that disconnecting an app does not erase what a Dot already learned, and that resetting memories can mean deleting the Dot (Flavio Copes, September 30, 2026; ZipLyne, September 29, 2026). Give a new hire access on day one only to what you would actually give a new hire.
Split the budget narrative. Dot conversation outside ChatGPT limits is one story. Work and Codex tasks started by a Dot are another. Publish both to marketing finance before someone books “unlimited agent labor.”
Finally, put Agent 365 on the governance calendar if you already live in Microsoft’s admin stack. The integration is a stated direction, not a finished control plane. Ask what is pilot, what is preview, and what your tenant can actually manage today.
The avatar will keep getting screenshots. The identity decisions will decide whether Dots become a useful operator surface or a permission incident with a cute face. Brief the second story.




