# Dots for workspace admins: enable, restrict and audit

Workspace owners turn dots on under Permissions & roles in Workspace settings. See what each of the eight switches allows and how to remove a member's access.

*From How to Use Dots, an independent guide (not affiliated with OpenAI). Web version: https://howtousedots.com/admin Last verified: 2026-10-06.*

In a ChatGPT Enterprise workspace, dots are off until a workspace owner turns them on. The switch is in **Workspace settings**, under **Permissions & roles**, and seven more switches decide what each member's dot is allowed to do.

**In short**

- **Dots start off** in Enterprise, Edu and Healthcare workspaces. An owner turns them on for everyone, or for one group through a custom role.
- **Eight switches matter:** four dots permissions, three cloud computer controls and the password manager.
- **Turning dots on connects nothing.** Apps, Slack and a member's own computer each need their own setup.
- **One role that grants dots is enough.** To remove access, clear it from the workspace default and from every role the member holds.

## Can your workspace turn dots on?

Start here, because three kinds of Enterprise workspace can't use dots at all, and two common requirements aren't met even when dots are on.

| Your workspace has | Dots | What to know |
|---|---|---|
| FedRAMP | No | Dots are unavailable |
| Enterprise Key Management (EKM) | No | Dots are unavailable |
| Inference residency set to the UAE | No | Dots are unavailable |
| HIPAA | Yes | If the workspace meets the other requirements. Confirm coverage under your agreement before a dot touches health data |
| Data residency, or inference residency elsewhere | Yes | Dots don't support either. Turning dots on doesn't make their data or processing residency-compliant |
| A zero data retention requirement | Yes | Dots keep data. Don't enable them for work that must leave nothing behind |

## Turn dots on

If your workspace qualifies, turning dots on takes four steps. You need to be a workspace owner.

**Walkthrough: Turn dots on for your workspace**

### Step 1: Open Permissions & roles

Open **Workspace settings** and click **Permissions & roles** in the list on the left.

![The workspace settings of a ChatGPT workspace. The menu on the left lists General, Members, Groups, Permissions and roles, Billing, Usage limits, GPTs, Models, Plugins, Apps, Skills, Workspace analytics and Sites. The main area shows the Workspace default role with a list of switches](https://howtousedots.com/assets/shots/admin-permissions-and-roles.jpg)

Image: OpenAI (https://learn.chatgpt.com/docs/enterprise/roles-and-workspace-permissions)

### Step 2: Choose who gets a dot

The **Workspace** role, tagged **Default**, covers every member who has no custom role. Turn dots on here to give everyone a dot. To give dots to one group only, leave the default off and turn them on in a custom role assigned to that group.

![The same screen. The heading reads Workspace, with a Default tag. Under it: This page controls the permissions for members who don't have a custom role assigned. Changes can take around 5 minutes to take effect after an admin updates these settings.](https://howtousedots.com/assets/shots/admin-permissions-and-roles.jpg)

1. **Default** marks the role everyone falls back to.
2. A change takes about five minutes to reach members.
3. **Back to roles** lists your custom roles.

Image: OpenAI (https://learn.chatgpt.com/docs/enterprise/roles-and-workspace-permissions)

### Step 3: Turn on the dots switch

Under **Workspace capabilities**, turn on **Use dots (Beta)**. A Business workspace lists the same switch in a **dots** group as **Allow members to use dots**, as in this picture.

![The Permissions and roles page of a Business workspace: Configure baseline permissions for your workspace and tailor access with custom roles. A Workspace tab, a box reading Search 32 permissions, and a group headed dots with one switch, Allow members to use dots, in the off position](https://howtousedots.com/assets/shots/admin-allow-members-switch.jpg)

Image: u/sorryredditggg on Reddit (https://www.reddit.com/r/codex/comments/1wtpnl3/has_anyone_tried_dots_yet_my_organisation_seems/)

### Step 4: Save, then test with one member

Save, wait five minutes, and ask one member who should have a dot to open ChatGPT on a computer. They should see **Your dot** in the sidebar, right under **New chat**.

![The top of the ChatGPT sidebar: New chat, then Your dot, then Projects](https://howtousedots.com/assets/shots/setup-sidebar-your-dot.jpg)

Image: Pat Simmons (https://www.youtube.com/watch?v=-fzbEP_sOjk)

## Decide the other switches

With dots on, seven more switches set what a member's dot can do. Try your plan here before you touch the real settings: flip a switch and watch the list beside it.

**Interactive: Dots rollout checklist for workspace admins**

Open it: https://howtousedots.com/widgets/admin-rollout-checklist.html

What it does: A tick-off checklist of the eight workspace settings an admin reviews before enabling dots: the four dots permissions (Use dots (Beta), Add dots to Slack and Microsoft Teams, Allow local computer access, Use custom rules for dots) and the four shared cloud controls (Cloud browser use, Cloud network access, Cloud computer use, Use password manager), each with its default for ChatGPT Enterprise as of 5 October 2026 and what to check first. It counts progress and copies the list as text.

Its content as text:

### Flip the switches, see what a member's dot can do

Set the eight switches the way you plan to. The list beside them shows what a member's dot is then allowed to do, and what still stops it. Copy the result into your rollout notes.

A member's dot can do 0 of 9 things

#### Your settings

Workspace settings, Permissions & roles. Everything starts off here.

Dots permissions

- [ ] Use dots (Beta)
  Members can create and use a dot. The three switches below do nothing for a member who doesn't have this one.
  Enterprise default: off
- [ ] Add dots to Slack
  A member's dot can join Slack and post under its own name.
  Also listed as "Add dots to Slack and Microsoft Teams"
- [ ] Allow local computer access
  A dot can use files and run commands on the member's own computer.
  Enterprise default: off
- [ ] Use custom rules for dots
  Members can add and edit rules for what their dot does without asking.
  Enterprise default: off

Cloud computer and passwords

- [ ] Cloud browser use
  Dots and Work Cloud tasks can open websites and click around in them.
  Keeps the setting you already have for Work Cloud
- [ ] Cloud network access
  Code and shell commands on a cloud computer can reach the internet.
  Keeps the setting you already have for Work Cloud
- [ ] Cloud computer use
  Dots and Work Cloud tasks can use the desktop and the applications on a cloud computer.
- [ ] Use password manager
  Members can use the password manager with dots and Work Cloud. Set apart from browser use.

#### What a member's dot can do

- **Exist at all**: The member can create a dot, message it and call it. · Off. No member has a dot until **Use dots (Beta)** is on, in the workspace default or in a role they hold.
- **Use the member's connected apps**: Yes, within your Plugin controls and each app's permission. Turning dots on connects nothing new. · Needs Use dots (Beta).
- **Open websites in its cloud browser**: Yes. The cloud browser has none of the member's sign-ins or VPN, so a site may ask the member to sign in there. · Needs Use dots (Beta) and Cloud browser use.
- **Run code that reaches the internet**: Yes, from its cloud computer. · Needs Use dots (Beta) and Cloud network access. Browser use doesn't cover this.
- **Use desktop apps on its cloud computer**: Yes. · Needs Use dots (Beta) and Cloud computer use.
- **Sign in with a login the member saved**: Yes. The member saves the login in the password manager. · Needs Use dots (Beta) and Use password manager.
- **Join Slack**: Allowed. Two more people still have to act: a Slack owner installs or approves the ChatGPT app, and the member connects the dot from its profile. · Needs Use dots (Beta) and Add dots to Slack.
- **Work on the member's own computer**: Allowed. The member still has to allow it from the dot's profile, keep the computer online and keep the ChatGPT app open. · Needs Use dots (Beta) and Allow local computer access.
- **Follow rules the member wrote**: Yes. Members add and edit custom rules. Built-in safety requirements still win. · No. Saved rules don't apply and members can't add any. The default rules still decide when a dot acts, asks or hands a step back, so off doesn't mean "ask every time".

Apps have their own controls. Which apps a dot can use, and what it can do in them, is set in your Plugin controls and each app's permission. [Apps and permissions](https://howtousedots.com/apps)

## Get dots into Slack

Slack is the one setting your switch can't finish alone. Three people have to act, in this order.

Diagram: Three people in a row. The ChatGPT workspace owner turns on the permissions. The Slack owner installs or approves the ChatGPT app. Then each member connects their own dot from its profile.
1. You turn on the dots switch and Add dots to Slack for the members who should have it.
2. A Slack owner or app manager makes sure the ChatGPT app is installed, and approves the request if your Slack needs approval.
   - ChatGPT owner → Slack owner: then
3. Each member connects their own dot from the dot's profile.
   - Slack owner → Each member: then

Once a dot is in Slack, only its owner can direct it. A message or mention from anyone else starts nothing, and everyone in a conversation can see what the dot posts there. [What members see in Slack](https://howtousedots.com/slack)

## Take a dot away from a member

Removing access works the other way round from granting it: one remaining grant keeps the dot.

1. Turn the dots switch off in the workspace default, if it's on there.
2. Open every custom role the member holds, directly or through a group, and turn it off in each.
3. Disconnect the member's apps and sign their dot out of websites separately. Removing dots access does neither.

## See what a dot did

When you need to look into a dot's work afterwards, there are four places to look, and each shows something different.

| Look in | You get |
|---|---|
| Compliance API | Members' messages to their dots and the dots' replies. Confirm which records it covers before you rely on it for an audit |
| Analytics API | Adoption and usage totals. No record of single actions |
| OpenTelemetry | Events from work on a member's own computer. Work in the cloud doesn't reach your collector |
| Managed hooks | Your admin-managed hooks run on dots' cloud work, when managed policy and remote hooks are enabled |

Members follow their own dot's work in **Recent activity**, in the dot's profile.

## Check you've got it

**Predict: You turn the dots switch off in the workspace default. Sam is in a group whose custom role has it on. Can Sam still use a dot?**

- Yes
- No, the default wins
- Only until Sam signs out

Answer: Yes

A role that grants dots keeps granting them, whatever the default says. Clear every role Sam holds, including the ones that come through groups.

**Next:** [Privacy and security](https://howtousedots.com/privacy-security)

Your dot reads what you connect and keeps it until you delete your dot. See what each connection opens, when OpenAI trains on it and what stops a hostile email.

### The dots switch is greyed out. Why?

On Business, dots reach workspaces gradually, and the switch stays grey until your workspace has them. That can take several days after you add a Premium seat. On Enterprise, check the table at the top of this page. [Dots not showing up](https://howtousedots.com/not-showing-up)

### What does a member need for local computer access?

Your **Allow local computer access** switch, ChatGPT desktop app version 26.929 or higher, and their own OK in the dot's profile. Local access is unavailable when a cloud policy has `enforce_residency` enabled, or when a Codex or Work policy targets one operating system. After you switch it off, a local task that was already approved can still finish.

### Do our workspace model settings apply to dots?

No. Enterprise model controls and default model settings don't apply to dots.

### Does OpenAI train on what a dot reads in our workspace?

Not by default. OpenAI doesn't use content from Business, Enterprise or Edu workspaces to train its models by default. [Privacy and security](https://howtousedots.com/privacy-security)

### Can members text their dot from a work account?

No. Phone messaging through iMessage, RCS or WhatsApp isn't available in Enterprise workspaces.

- 2026-10-06: Rebuilt with the real admin screens and a planner for the eight switches.
- 2026-10-05: First published.

## Sources

- [OpenAI Help Center: Manage dots in ChatGPT workspaces](https://help.openai.com/en/articles/20001554-manage-dots-in-chatgpt-workspaces)
- [OpenAI docs: Manage dots permissions and capabilities (admin guide)](https://learn.chatgpt.com/docs/enterprise/dots-admin-guide)
- [OpenAI docs: Local computer access for Work Cloud and dots](https://learn.chatgpt.com/docs/enterprise/cloud-local-access)
- [OpenAI Help Center: Managing feature access with role-based access control](https://help.openai.com/en/articles/11750701-managing-feature-access-with-role-based-access-control-in-chatgpt)
- [OpenAI Help Center: HIPAA eligible products and functionality](https://help.openai.com/en/articles/20001069-hipaa-eligible-products-and-functionality)
- [OpenAI docs: ChatGPT Work admin FAQ](https://learn.chatgpt.com/docs/enterprise/work-admin-faq)
- [OpenAI docs: Analytics API](https://learn.chatgpt.com/docs/enterprise/analytics-api)
- [ChatGPT Business product page (dots on Premium seats)](https://chatgpt.com/business)
- [OpenAI Help Center: Getting started with your dot](https://help.openai.com/en/articles/20001530-getting-started-with-your-dot)
- [OpenAI Help Center: Dots privacy, security, and safety FAQs](https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs)
- [OpenAI Developer Community: Unable to enable dots on Business Premium (with OpenAI Support reply)](https://community.openai.com/t/unable-to-enable-dots-despite-being-on-business-premium-plan/1402580)
- [OpenAI docs: Roles and workspace permissions (screenshot of Permissions & roles)](https://learn.chatgpt.com/docs/enterprise/roles-and-workspace-permissions)
- [Pat Simmons on YouTube: screenshot of the sidebar](https://www.youtube.com/watch?v=-fzbEP_sOjk)
- [Reddit r/codex: screenshot of the Allow members to use dots switch](https://www.reddit.com/r/codex/comments/1wtpnl3/has_anyone_tried_dots_yet_my_organisation_seems/)
