Safety built around action
dots take ongoing responsibility, so OpenAI documents safeguards beyond ordinary chat: model refusals on GPT-6 Astra, sandboxing in each dot’s cloud environment, secure sign-in flows that keep passwords out of the model context, monitoring for harmful behavior, and a separate Auto-review check before consequential actions. This page is a community summary. Read How we build safety, security, and privacy into dots for the full official text.
A protected workspace for each dot
Each dot works on its own cloud computer. Your personal computer stays separate unless you choose to connect it. Sandboxing restricts what code and tools that workspace can reach. Environments are isolated between users. Dots cannot use workspace access to disable required safety checks.
Clear rules, Custom Rules, and approvals
Built-in action rules decide when a dot may proceed, must ask, or must hand a step back to you (for example password changes or certain money transfers). Custom Rules let you tighten or shape preferences inside those guardrails — such as never sending email — but cannot remove mandatory confirmations or core safety requirements. Purchases with saved cards require your approval.
Auto-review
Before actions like sending email or changing files, Auto-review checks the planned step against your instructions, Custom Rules, and safety requirements. If it blocks a step, the dot is told why and may ask you, try a permitted alternative, hand the step back, or stop. Your approval cannot override core safety requirements.
Local computer defaults to off
Help Center: access to your local computer is optional and starts turned off. Enable it only from the ChatGPT desktop app when you need local files or tools. Proactive research in the background uses read-only tools on connected apps — it cannot send messages, change app content, or control your browser or computer by itself.
Official sources
- Safety, security, and privacy into dots
- Introducing dots — control and safeguards sections
- Getting started with your dot — local computer, plugins, reset
- Capabilities — features beside these controls
Chinese edition: OpenAI dots 安全.
Frequently asked questions
What is Auto-review for dots?
A separate safety check before consequential actions (such as sending mail or changing files) against your instructions, Custom Rules, and safety requirements. Your approval cannot override core safety requirements.
Is my local computer connected by default?
No. Each dot works on its own cloud computer. Local computer access is optional and starts turned off; enable it only from the ChatGPT desktop app if you need it.
What are Custom Rules?
Preferences you set for when a dot may act, must ask, or must stop — within built-in guardrails. Dots can help draft rules but need your approval to change them.