send.message.worldsend a message to anyone · no undo | “You can connect your personal email account so your dot can use it for your tasks. At launch, you cannot give your dot its own standalone email address.” A message is sent as you. “To send a message or share a file, they are taught to seek authorization that covers the information and the type of recipient.” “Approving one message does not give your dot ongoing permission to contact people on your behalf.” In Slack and Teams, where a workspace allows it, a dot can “post with its own identity”.Getting started; Safety post; FAQs; Manage dots in workspaces | ◉ a Custom Rule, “such as telling your dot never to send emails”: prose to the model, yours. ○ Auto-review: “before your dot sends an email, Auto-review checks the recipient and message”, a separate reviewer kept “outside the environments dots can change”, the vendor’s. The vendor adds that it “can still make mistakes” and, in its own documentation, that it “is not a deterministic security guarantee”. ◐ the app’s permission option (Always ask … Allow all actions), yours. See section 04 on a boundary that is a judgement. |
delete.file.hostdelete anywhere it reaches · no undo | “Some actions require your confirmation each time, including permanently deleting data, installing or running software from an unrecognized source, or granting new security-sensitive access.” Custom Rules “cannot remove mandatory confirmations”.Safety post; FAQs | ○ a confirmation the vendor requires each time and neither you nor the dot can switch off. The vendor’s; you answer it. |
write.budget.tenantspend against an account · no undo | “Your dot can also make purchases using a card you’ve saved on a merchant’s website. These purchases require your approval, which may be given in advance when it specifically covers the purchase.” Transfers are out of reach: “transferring money between financial accounts, dots can help with the surrounding task but must hand those sensitive steps back to you.”FAQs; Safety post | ○ an approval the vendor requires, which you may give in advance for one purchase. The transfer itself is a hand-off, not a capability. |
send.endpoint.worldreach any host · no undo | “Cloud browser use: Allows dots and Work Cloud tasks to open and interact with websites using a browser.” “Cloud network access: Allows code and shell commands run by dots and Work Cloud tasks on cloud computers to access the internet.” “A dot’s cloud computer does not automatically inherit a member’s local VPN, browser sign-ins, or device policies.”Manage dots in workspaces | ● on a Pro account: nothing on the pages read. ◐ in an Enterprise workspace: two switches under Cloud computer capabilities, the administrator’s. |
read.message.tenantread mail or chat it is connected to · no undo | “Connected apps give your dot access to information it can use for your tasks. Your dot can also review that information proactively and form memories from it, even when you haven’t asked a specific question about it.” Proactive research “can read information from permitted connected sources and save private notes”.Getting started; FAQs | ◐ the app’s permission option and the connection itself (Settings › Plugins), yours; or the administrator’s where a workspace disables the app. Whether Always ask applies to a read the dot makes before you asked anything is not on the pages read (section 05). |
read.file.hostread any file the account can reach · no undo | Connected storage, through the same permissions. And your own machine, if you connect it: “When you connect a computer and confirm Allow access, your dot can access files and work on that computer from any of its messaging channels. Confirm Revoke access to stop your dot from accessing files or working on that computer.”Getting started | ◐ for your computer, the connection: “optional and starts turned off”, yours. ○ for a workspace member whose administrator left Allow local computer access off, which is the default for Enterprise. ◐ for connected storage, the app permission, yours. |
authenticate-as.credential.tenantact in accounts with the credentials it holds · no undo | “For signing into supported websites, dots can use saved passwords without exposing them to the model.” “For supported sign-ins, your dot pauses while you enter your credentials in a secure login form.” The workspace switch: “Use password manager: Allows members to use the password manager with dots and Work Cloud.”Introducing dots; FAQs; Manage dots in workspaces | ◐ you type the password, once; after that the signed-in session is the dot’s. ● with a saved password, nothing per site. ◐ in a workspace, the password-manager switch, the administrator’s. The credential service keeps the password from the model; it does not keep the account from the dot. |
read.credential.hostread credentials stored where it runs · no undo | “Your dot’s context does not retain credentials, images, or screenshots.” But: “These protections apply to supported sign-in flows. They don’t cover passwords you share separately in a chat or document, or through a plugin.” And: “a secret placed separately in a readable message or document may still be visible to the model.”FAQs; Safety post | ● for any secret that lives in mail, a document or a chat the dot can read, which for most inboxes is where the one-time codes and the reset links are. Nobody holds a barrier here; the pages say so. |
execute.process.hostrun programs as the account · undo with effort | “Each dot has its own cloud computer, where it can browse, analyze information, create files, and run tools.” “Within each dot’s protected workspace, sandboxing restricts what code and tools that dot can access.” On your machine, once connected: “your dot can create Work or Codex tasks, use local skills, and use your local browser when its cloud browser is blocked.”Safety post; Getting started | ● on its own cloud computer, for a Pro account. ◐ in a workspace, Cloud computer use, the administrator’s. ◐ on your machine, the connection, yours; ○ for a member whose administrator left it off. The vendor’s sandbox bounds what the dot can do to the vendor’s systems, not what it can do with yours. |
write.file.hostchange any file the account can reach · undo with effort | Connected apps can “take supported actions, such as creating or updating information”. “Before dots take actions such as sending emails or changing files, a separate safety system called Auto-review checks the planned steps.” If a mistake is made, “your dot may be able to reverse unintended edits to a document”.Connected apps; Safety post; FAQs | ◐ the app’s permission option, yours. ○ Auto-review, the vendor’s, with the same caveat as the first row. |
create.schedule.tenantcreate something that outlives the session · undo | “Your dot can research in the background and suggest ways to help. It can also review connected information proactively and form memories from it, even when you haven’t asked a new question. It can run reminders or recurring tasks you’ve scheduled.” The system card adds that dots work “often delegating work to subagents”.Getting started; GPT-6 Astra system card, appendix 12.1 | ◐ Pause, and the Scheduled list, yours. Proactive research runs without a schedule you wrote; pausing the dot is the switch. Its tools are read-only by a limit the vendor says it enforces in code: ○ for what that research can change, none for what it can read. |
grant.credential.selfchange its own permission settings · undo | “Dots can help you write Custom Rules, but they need your approval to change them.” Granting “new security-sensitive access” is among the actions that “require your confirmation each time”.Safety post | ○ a confirmation the vendor requires; the dot cannot widen its own rules or its access without you. Whether it can ask you to, as often as it likes, is not restricted on the pages read. |