How to Use Dots
Cheat sheetGet the cheat sheet

Reference

Dots for workspace admins: enable, restrict and audit

Workspace owners turn dots on under Permissions & roles in Workspace settings. See what each of the eight switches allows and how to remove a member's access.

Last verified

On this page

In a ChatGPT Enterprise workspace, dots are off until a workspace owner turns them on. The switch is in Workspace settings, under Permissions & roles, and seven more switches decide what each member's dot is allowed to do.

#Can your workspace turn dots on?

Start here, because three kinds of Enterprise workspace can't use dots at all, and two common requirements aren't met even when dots are on.

Your workspace has Dots What to know
FedRAMP No Dots are unavailable
Enterprise Key Management (EKM) No Dots are unavailable
Inference residency set to the UAE No Dots are unavailable
HIPAA Yes If the workspace meets the other requirements. Confirm coverage under your agreement before a dot touches health data
Data residency, or inference residency elsewhere Yes Dots don't support either. Turning dots on doesn't make their data or processing residency-compliant
A zero data retention requirement Yes Dots keep data. Don't enable them for work that must leave nothing behind

#Turn dots on

If your workspace qualifies, turning dots on takes four steps. You need to be a workspace owner.

Walkthrough

Turn dots on for your workspace

  1. The workspace settings of a ChatGPT workspace. The menu on the left lists General, Members, Groups, Permissions and roles, Billing, Usage limits, GPTs, Models, Plugins, Apps, Skills, Workspace analytics and Sites. The main area shows the Workspace default role with a list of switches
    Image: OpenAI

    1Open Permissions & roles

    Open Workspace settings and click Permissions & roles in the list on the left.

    1. Default marks the role everyone falls back to.
    2. A change takes about five minutes to reach members.
    3. Back to roles lists your custom roles.
    Image: OpenAI

    2Choose who gets a dot

    The Workspace role, tagged Default, covers every member who has no custom role. Turn dots on here to give everyone a dot. To give dots to one group only, leave the default off and turn them on in a custom role assigned to that group.

  2. 3Turn on the dots switch

    Under Workspace capabilities, turn on Use dots (Beta). A Business workspace lists the same switch in a dots group as Allow members to use dots, as in this picture.

  3. The top of the ChatGPT sidebar: New chat, then Your dot, then Projects
    Image: Pat Simmons

    4Save, then test with one member

    Save, wait five minutes, and ask one member who should have a dot to open ChatGPT on a computer. They should see Your dot in the sidebar, right under New chat.

#Decide the other switches

With dots on, seven more switches set what a member's dot can do. Try your plan here before you touch the real settings: flip a switch and watch the list beside it.

Flip the switches, see what a member's dot can do

Set the eight switches the way you plan to. The list beside them shows what a member's dot is then allowed to do, and what still stops it. Copy the result into your rollout notes.

A member's dot can do 0 of 9 things

Your settings

Workspace settings, Permissions & roles. Everything starts off here.

Dots permissions

  • Members can create and use a dot. The three switches below do nothing for a member who doesn't have this one.

    Enterprise default: off

  • A member's dot can join Slack and post under its own name.

    Also listed as "Add dots to Slack and Microsoft Teams"

  • A dot can use files and run commands on the member's own computer.

    Enterprise default: off

  • Members can add and edit rules for what their dot does without asking.

    Enterprise default: off

Cloud computer and passwords

  • Dots and Work Cloud tasks can open websites and click around in them.

    Keeps the setting you already have for Work Cloud

  • Code and shell commands on a cloud computer can reach the internet.

    Keeps the setting you already have for Work Cloud

  • Dots and Work Cloud tasks can use the desktop and the applications on a cloud computer.

  • Members can use the password manager with dots and Work Cloud. Set apart from browser use.

What a member's dot can do

  • Exist at allThe member can create a dot, message it and call it.Off. No member has a dot until Use dots (Beta) is on, in the workspace default or in a role they hold.
  • Use the member's connected appsYes, within your Plugin controls and each app's permission. Turning dots on connects nothing new.Needs Use dots (Beta).
  • Open websites in its cloud browserYes. The cloud browser has none of the member's sign-ins or VPN, so a site may ask the member to sign in there.Needs Use dots (Beta) and Cloud browser use.
  • Run code that reaches the internetYes, from its cloud computer.Needs Use dots (Beta) and Cloud network access. Browser use doesn't cover this.
  • Use desktop apps on its cloud computerYes.Needs Use dots (Beta) and Cloud computer use.
  • Sign in with a login the member savedYes. The member saves the login in the password manager.Needs Use dots (Beta) and Use password manager.
  • Join SlackAllowed. Two more people still have to act: a Slack owner installs or approves the ChatGPT app, and the member connects the dot from its profile.Needs Use dots (Beta) and Add dots to Slack.
  • Work on the member's own computerAllowed. The member still has to allow it from the dot's profile, keep the computer online and keep the ChatGPT app open.Needs Use dots (Beta) and Allow local computer access.
  • Follow rules the member wroteYes. Members add and edit custom rules. Built-in safety requirements still win.No. Saved rules don't apply and members can't add any. The default rules still decide when a dot acts, asks or hands a step back, so off doesn't mean "ask every time".
Turn on everything except Use dots (Beta), and count what's allowed. Open on its own page

Apps have their own controls. Which apps a dot can use, and what it can do in them, is set in your Plugin controls and each app's permission. Apps and permissions

#Get dots into Slack

Slack is the one setting your switch can't finish alone. Three people have to act, in this order.

thenthenChatGPT ownerSlack ownerEach memberthenthenChatGPT ownerSlack ownerEach member
  1. You turn on the dots switch and Add dots to Slack for the members who should have it.
  2. A Slack owner or app manager makes sure the ChatGPT app is installed, and approves the request if your Slack needs approval.
  3. Each member connects their own dot from the dot's profile.

Once a dot is in Slack, only its owner can direct it. A message or mention from anyone else starts nothing, and everyone in a conversation can see what the dot posts there. What members see in Slack

#Take a dot away from a member

Removing access works the other way round from granting it: one remaining grant keeps the dot.

  1. Turn the dots switch off in the workspace default, if it's on there.
  2. Open every custom role the member holds, directly or through a group, and turn it off in each.
  3. Disconnect the member's apps and sign their dot out of websites separately. Removing dots access does neither.

#See what a dot did

When you need to look into a dot's work afterwards, there are four places to look, and each shows something different.

Look in You get
Compliance API Members' messages to their dots and the dots' replies. Confirm which records it covers before you rely on it for an audit
Analytics API Adoption and usage totals. No record of single actions
OpenTelemetry Events from work on a member's own computer. Work in the cloud doesn't reach your collector
Managed hooks Your admin-managed hooks run on dots' cloud work, when managed policy and remote hooks are enabled

Members follow their own dot's work in Recent activity, in the dot's profile.

#Check you've got it

Predict

You turn the dots switch off in the workspace default. Sam is in a group whose custom role has it on. Can Sam still use a dot?

  • Yes
  • No, the default wins
  • Only until Sam signs out
Show the answer

Yes

A role that grants dots keeps granting them, whatever the default says. Clear every role Sam holds, including the ones that come through groups.

A role that grants dots keeps granting them, whatever the default says. Clear every role Sam holds, including the ones that come through groups.

The dots switch is greyed out. Why?

On Business, dots reach workspaces gradually, and the switch stays grey until your workspace has them. That can take several days after you add a Premium seat. On Enterprise, check the table at the top of this page. Dots not showing up

What does a member need for local computer access?

Your Allow local computer access switch, ChatGPT desktop app version 26.929 or higher, and their own OK in the dot's profile. Local access is unavailable when a cloud policy has enforce_residency enabled, or when a Codex or Work policy targets one operating system. After you switch it off, a local task that was already approved can still finish.

Do our workspace model settings apply to dots?

No. Enterprise model controls and default model settings don't apply to dots.

Does OpenAI train on what a dot reads in our workspace?

Not by default. OpenAI doesn't use content from Business, Enterprise or Edu workspaces to train its models by default. Privacy and security

Can members text their dot from a work account?

No. Phone messaging through iMessage, RCS or WhatsApp isn't available in Enterprise workspaces.

  1. Rebuilt with the real admin screens and a planner for the eight switches.
  2. First published.

Sources

14
  1. OpenAI Help Center: Manage dots in ChatGPT workspaces help.openai.com
  2. OpenAI docs: Manage dots permissions and capabilities (admin guide) learn.chatgpt.com
  3. OpenAI docs: Local computer access for Work Cloud and dots learn.chatgpt.com
  4. OpenAI Help Center: Managing feature access with role-based access control help.openai.com
  5. OpenAI Help Center: HIPAA eligible products and functionality help.openai.com
  6. OpenAI docs: ChatGPT Work admin FAQ learn.chatgpt.com
  7. OpenAI docs: Analytics API learn.chatgpt.com
  8. ChatGPT Business product page (dots on Premium seats) chatgpt.com
  9. OpenAI Help Center: Getting started with your dot help.openai.com
  10. OpenAI Help Center: Dots privacy, security, and safety FAQs help.openai.com
  11. OpenAI Developer Community: Unable to enable dots on Business Premium (with OpenAI Support reply) community.openai.com
  12. OpenAI docs: Roles and workspace permissions (screenshot of Permissions & roles) learn.chatgpt.com
  13. Pat Simmons on YouTube: screenshot of the sidebar youtube.com
  14. Reddit r/codex: screenshot of the Allow members to use dots switch reddit.com