Skip to content
redactsure
Book a demo

Explore.

Comparison · By Chris Sowa · Published
Last updated

Do OpenAI Dots' Custom Rules Control What the Agent Sees?

Custom Rules govern what a dot may do. They do not, by themselves, establish which fields reach its model. Review the actual model input before connecting regulated records.

A browser record passes through a privacy screen beside a separate approval gate, illustrating AI agent input and action controls.

Custom Rules govern what a dot may do. They do not, by themselves, establish which fields reach its model. Review the actual model input before connecting regulated records. OpenAI describes permissions, isolated workspaces, secure credential handling and a separate Auto-review system. Those controls matter, but an action rule does not demonstrate that patient names or account numbers were removed from a permitted page. This comparison separates documented safeguards from the field-level exposure policy a buyer still needs to verify. RedactSure, an AI agent controls, governance and data protection company, applies Least Exposure and render-layer tokenization to this problem.

Key findings

What do Dots actually do, in OpenAI's words?

A dot is an always-on agent assigned work by chatting through text, Slack or Microsoft Teams, with its own cloud computer and browser and plugin connections to more than 4,000 apps; Enterprise, Edu and Healthcare workspaces can enable beta versions through administrator controls (The Next Web).

The controls, from OpenAI's document: Custom Rules set what a dot may do on its own, what requires approval and what is forbidden. Password changes stay with the user. When the user is away, a dot does "proactive research" in read-only mode. Auto-review checks planned actions against instructions, Custom Rules and safety requirements before execution; "If Auto-review blocks a step, it prevents the action from running and tells the dot why." Custom Rules cannot override mandatory confirmations. Secure sign-in "sends your credentials directly to the browser environment and submits them without exposing them to the model's context." An Activity View lets the user follow, redirect or stop work.

Every one of those sentences is about what the dot does. The one sentence about what it sees says the model receives webpage text and document content within connected apps: the page, in full.

What is the difference between a permission and an exposure?

A permission answers "may the agent do this?" An exposure answers "what does the agent receive while it works?" An organization can have a complete set of one and none of the other.

Custom Rules, mandatory confirmations and Auto-review are permissions. They sit between the model's plan and the action, not between the application and the model. When a dot opens a customer record to prepare a refund, the rule "ask before issuing a refund" stops the refund. It does not stop the model from reading the name, address, card number and order history. Reading is not an action the rule can see (Does Least Privilege Cover What the AI Sees?).

Exposure runs where the screen is rendered, before any model reads it, and is set per task: the fields a refund needs, with CARD_001 and ACCT_001 in place of the identifiers it does not need. That is render-layer tokenization. OpenAI's documentation describes no such layer, and read-only mode is a permission (the dot may not act), not an exposure (the dot still reads).

What does a dot receive when it reads a connected app?

The page. A dot connected to a CRM receives the contact record; to a finance system, the vendor master with bank details; to an EHR or a student information system, the chart or the student record. What the model receives is decided by what the application shows, not by the task.

The other agents in the market draw the line in the same place: Meta's Muse vaults credentials and reads page content within its permitted access. The password is the one value every vendor keeps from the model, and the vault does not extend to the record (Can a Credential Vault Protect What an AI Agent Reads?).

Who is the judge of a dot's actions?

Auto-review is a model reviewing the agent's planned actions before they execute. The agent runs on GPT-6 Astra; the reviewer is OpenAI's; both run on OpenAI's infrastructure. The organization that owns the record supplies the Custom Rules and receives the Activity View. It does not own the environment, hold the keys, or receive a record of what the dot saw for its own SIEM.

Separation of model and control names the alternative: the environment deciding what an agent sees and who approves what it does is owned by the customer and independent of whichever model performs the work. Latent Space cites METR research finding coding agents self-approving flagged actions; a review model from the same vendor is one layer against that, and a named person holding the record is another. Activity View covers actions, not what the model received screen by screen, which is what an AI Control Record holds.

What does a successful prompt injection collect from a dot?

The page. OpenAI's stated defense is "model safeguards with tool restrictions, checks before actions, and monitoring to help prevent that content from turning into an unwanted action." Every element acts on the action. If an injected instruction persuades the dot to send what it has read somewhere, the gate may catch the send; it has not changed what the dot read. OWASP's LLM01 lists prompt injection first because the model cannot reliably tell instruction from data. The narrower answer, tokens, exists only when the model never held the real values (Prompt Injection When the Agent Sees Only Tokens).

How do Dots compare with what regulated work requires?

Control OpenAI Dots (from documentation) Controls to evaluate for the workflow RedactSure
Environment Cloud computer per dot, OpenAI infrastructure Owned by the customer Secure VM on hardware-encrypted enclaves, in the customer's cloud
Credentials Secure sign-in; password outside model context Same Same; a tethered agent
What the model receives The page, in full The task's fields, identifiers as tokens Render-layer tokenization
Who decides what it sees The application A named workflow owner, per task The Planner; a named person confirms
Action gate Custom Rules, mandatory confirmations A named person, every consequential action Supervised Delegation
Reviewer Auto-review, OpenAI's model Independent of the model The environment and the named person
Record Activity View, OpenAI's app Screens as tokens, approvals by name, in the customer's SIEM The AI Control Record
Keys Not disclosed The customer Customer-held; RedactSure holds ciphertext it cannot decrypt
Model GPT-6 Astra Any, swappable Claude, GPT, Gemini, open-weights
Injection collects The page Tokens and remaining task context Tokens

Where does RedactSure sit?

RedactSure supplies the row the documentation leaves empty: what the model receives. AI co-workers do real work across an organization's applications inside a governed environment, with no per-application integration and no change to user permissions. Every identifier chosen by policy is replaced by a consistent token at the render layer before any model reads the screen. The model is handed the task's fields rather than a picture of the page. The customer, patient or claimant on that screen never enters the model's memory; the model works with CARD_001 and ACCT_001. The Planner sets which values are tokenized and what the agent may do on each screen. A named person confirms that policy and approves every payment, submission and record change.

Every screen as tokens, every action and every approval lands in the AI Control Record and exports to the customer's SIEM. Keys stay with the customer. The model is swappable, so a GPT model can do the work under the same controls. Deployments are in pilot. The child pages on patient records, student records, cardholder and bank data, Privacy Act records and claim files apply each regulator's test.

Methodology and limitations

The page rests on OpenAI's "How we build safety, security and privacy into dots" (September 29, 2026), cited with their dates. Meta AI Research's "How We Built Safety Into Muse" (September 2026) is read the same way. The Next Web, Axios and Latent Space coverage of September 29, 2026 and a 2026 Tech Insider comparison supply the reporting. OWASP's LLM01:2025 entry is cited from its text. Where the vendor documentation is silent, the page says so rather than inferring. Independent analysis is cited as that analyst's view. All sources were read as of September 30, 2026.

No hands-on testing of Dots or Muse was performed; what a dot receives, checks or blocks is OpenAI's own description. OpenAI refers to a system card that was not available for this reading. That document could disclose the key holder for the cloud computer, certifications, training defaults or an activity export that the launch material does not. The METR finding on coding agents comes through Latent Space and is treated as that analyst's summary. Tech Insider's statement that the approval model is untested at scale is an analyst's view. Vendor features change; the page carries its date and is revised when the documentation changes. The refund, CRM and EHR examples describe record types, not any organization; no customer or prospect is described.

Whether any control meets an organization's requirements belongs to its counsel, assessor, privacy officer or compliance officer, not to this page.

We did not run the vendor products or capture their model requests. Workflow examples are analysis, and RedactSure behavior is described from its current design.

What the record shows

Custom Rules govern what a dot may do. They do not, by themselves, establish which fields reach its model. Review the actual model input before connecting regulated records. For one permitted task, ask for the model request and the action approval record. Evaluate those as separate controls.

Frequently asked questions

Does Auto-review inspect the data or the action?

The action. OpenAI describes Auto-review as checking planned actions against instructions, Custom Rules and safety requirements before execution, and blocking a step by preventing it from running. Nothing in the description removes values from what the model receives; the data is already in context when a planned action reaches review. RedactSure replaces identifiers before the model reads the screen, so review and exposure are separate controls.

What does a successful prompt injection collect from a dot?

Whatever the dot has read: the page, the document and the record in the connected app, less the password, which secure sign-in keeps out of context. An agent working on tokens gives an injection SSN_001 and CARD_001, and the consequential action still stops for a named person.

Who holds the keys to a dot's cloud computer?

OpenAI's safety document does not say. It refers to a system card and names no compliance certification; Axios reports that dots run on OpenAI infrastructure. The organization should ask in the security review and record the answer (What Should an AI Agent Security Review Cover?). A RedactSure environment runs in the customer's cloud with keys the customer holds.

Can a dot be enabled on a Healthcare or Edu workspace, and what does it see there?

Yes, in beta, through administrator controls, per the launch coverage. It sees what the application shows: the chart in an EHR, the student record in a student information system. The regulatory tests are on the child pages for patient records and student records.

Is a dot's read-only mode an exposure control?

No. Read-only mode, OpenAI's "proactive research" while the user is away, limits what the dot may do. The dot still reads what it opens. An exposure control limits what the model receives and is enforced before the model reads the screen, not after. RedactSure applies that control at the render layer, in read and write modes alike.

Sources

Vendor documentation

  1. OpenAI, "How we build safety, security and privacy into dots" (September 29, 2026). https://openai.com/index/how-we-build-safety-security-and-privacy-into-dots/
  2. Meta AI Research, "How We Built Safety Into Muse" (September 2026). https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse

Standards

  1. OWASP, LLM01:2025 Prompt Injection. https://genai.owasp.org/llmrisk/llm01-prompt-injection/

Independent analysis and press

  1. The Next Web, "OpenAI launches dots, always-on AI agents with their own cloud computers" (September 29, 2026). https://thenextweb.com/news/openai-dots-always-on-ai-agents-cloud-computers-devday
  2. Axios, "Meet OpenAI's dots" (September 29, 2026). https://www.axios.com/2026/09/29/openai-dots-ai-assistant-devday
  3. Latent Space, "AINews: OpenAI DevDay 2026" (September 29, 2026). https://www.latent.space/p/ainews-openai-devday-2026-dots-61
  4. Tech Insider, "OpenAI Dots vs Meta Muse: 4,000-App Enterprise Agent" (2026). https://tech-insider.org/openai-dots-meta-muse-enterprise-agent-2026/

RedactSure documents

  1. RedactSure, "The Two Gaps AI Agents Opened in Your Security Stack" (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
  2. RedactSure, "Accountable AI and Workflow Governance" (2026). https://redactsure.com/blog/accountable-ai-and-workflow-governance/
  3. RedactSure, "Secure AI That Crosses Every Silo" (2026). https://redactsure.com/blog/secure-ai-that-crosses-every-silo/
  4. RedactSure Research, "Should the AI Agent's Secure Environment Belong to the Model Vendor?" (2026). https://redactsure.com/research/should-ai-agent-environment-belong-to-model-vendor
  5. RedactSure Research, "What Is Least Exposure?" (2026). https://redactsure.com/research/what-is-least-exposure
  6. RedactSure Research, "What Is Render-Layer Tokenization?" (2026). https://redactsure.com/research/what-is-render-layer-tokenization
  7. RedactSure Research, "What Is Supervised Delegation?" (2026). https://redactsure.com/research/what-is-supervised-delegation
  8. RedactSure Research, "What Is an AI Control Record?" (2026). https://redactsure.com/research/what-is-an-ai-control-record
  9. Product behavior described on this page reflects RedactSure's current design. OpenAI, ChatGPT and Dots are trademarks of OpenAI; Meta and Muse are trademarks of Meta Platforms, Inc.; named to identify the products.

See it on your workflow.

Bring one billing, collections, claims or patient-account workflow and your questions.

Book a demo

Book a demo

Having trouble? Open the booking page or email us.