Mingyu's Library主页
AI 深度学习文档AI Deep-Dive
今日精选主题深度学习 Today's Featured Deep Dive

OpenAI Dots:当 agent 变成"常驻在线",权限怎么设计

OpenAI Dots: When Agents Go Always-On, How Do You Design Permissions?

2026 年 9 月 29 日的 DevDay 上,OpenAI 发布了 Dots——运行在各自云端电脑里、无需逐条提示就能持续工作的 ChatGPT 智能体。这不只是一个新功能,而是 agent 产品形态从"被调用"走向"持续在线"的标志。本文拆解它的组成、三级权限与自动复核机制、配套 API 和成本结构,并给出适用场景与常见坑(发布仅数日,信息主要来自官方回顾与媒体报道)。

At DevDay on September 29, 2026, OpenAI announced Dots — ChatGPT agents that run in their own cloud computers and keep working without per-step prompts. This is more than a feature: it marks agents moving from "invoked" to "continuously on". This piece breaks down their components, the three-tier permission and auto-review mechanisms, the companion APIs and cost structure, then gives fit scenarios and pitfalls (it shipped only days ago; information comes mainly from OpenAI's recap and press coverage).

发布日期:2026-10-05Published: 2026-10-05 阅读时长:约 12 分钟Reading time: ~12 min 领域:Agent 工程 · 产品形态Topics: Agent Engineering · Product Shape

01是什么:常驻智能体与 DotsWhat Are Always-On Agents and Dots

Dots 是 OpenAI 在 2026-09-29 的 DevDay 上发布的 ChatGPT 常驻智能体(always-on agents)。官方描述是:用户给一个 dot 设定目标、连接需要的应用、定义它的自主程度,它就在自己的云端电脑和浏览器里持续工作,在两次对话之间也不停,并把结果交回给你审阅。据报道,每个 dot 由 GPT-6 Astra 驱动,可连接 4000+ 应用及 Slack/Teams。

Dots are ChatGPT's always-on agents, announced by OpenAI at DevDay on 2026-09-29. As OpenAI describes it, you give a dot a goal, connect the apps it needs and define how autonomous it may be; it then keeps working in its own cloud computer and browser, including between conversations, and returns results for your review. According to reports, each dot is powered by GPT-6 Astra and connects to 4,000+ apps plus Slack/Teams.

和传统的"你问一句、它答一句"的聊天助手相比,关键差别是触发方式:dot 可以在没有用户提示的情况下继续任务。报道中给出的例子包括:监控客户反馈、实现修复并提交 pull request、在产品范围变化时更新材料、用新数据重跑分析、修订提案、搭建概念验证集成,以及把访谈转录稿转成短视频片段和社交帖子。早期测试者的一个例子是一个 dot "与客服谈判,每年省下约 500 美元费用"(Latent Space 转述)。

Compared with a classic "you ask, it answers" assistant, the key difference is the trigger: a dot can continue a task without a user prompt. Examples in the coverage include monitoring customer feedback, implementing fixes and submitting pull requests, updating materials when product scope changes, rerunning analyses with new data, revising proposals, building proof-of-concept integrations, and turning interview transcripts into clips and social posts. One early tester reported a dot "negotiating with customer service to cut ~$500/yr in charges" (as relayed by Latent Space).

一句话定义Dots = 目标 + 连接的应用 + 一套预先写好的权限规则 + 一台属于它自己的云端电脑,让 agent 从"被调用"变成"持续在线"。
In one sentenceDots = a goal + connected apps + pre-written permission rules + a cloud computer of their own — turning an agent from "invoked" into "continuously on".

02DevDay 2026 全景:Dots 不是孤立发布DevDay 2026 in Context: Dots Did Not Ship Alone

Dots 是一整套发布的一部分。下表按 OpenAI 官方回顾与 Latent Space 的整理,列出与"常驻智能体"最相关的部分(价格与基准为发布时厂商/媒体口径,未经独立复现)。

Dots shipped as part of a larger bundle. The table below, based on OpenAI's recap and Latent Space's write-up, lists the pieces most relevant to always-on agents (prices and benchmarks are vendor/press figures at launch and have not been independently reproduced).

表 1:DevDay 2026 与常驻智能体相关的发布
发布要点
Dots自己的云端电脑;4000+ 应用;三级权限规则;Pro / Business Premium / Enterprise(beta)
GPT-6.1 Sol$2 / $10 每百万 token;缓存输入 $0.10;上下文 1,050,000;DeepSWE v1.1 75.2%、OSWorld 2.0 71.4%(Vellum 整理)
Ultrafast 速度档Codex 中最高 8× 生成速度(300 tok/s)、API 中 6×;价格约为标准价 6 倍
Decisions API基于 GPT-6 Luna 的近即时多选分类与路由,支持文本与图像
Agents API(含 computer use)多 agent 与软件交互能力;另有与 AWS 合作的 Bedrock Managed Agents
Codex Cloud / CLI云端环境在合上笔记本后仍可运行;CLI 增加 worktrees 与 /agents 视图
套餐与生态新增 Pro 500 档;Sign in with ChatGPT;OpenAI Marketplace;ChatGPT 周活 12 亿
Table 1: DevDay 2026 releases relevant to always-on agents
ReleaseKey points
DotsOwn cloud computer; 4,000+ apps; three-tier permission rules; Pro / Business Premium / Enterprise (beta)
GPT-6.1 Sol$2 / $10 per million tokens; cached input $0.10; 1,050,000 context; DeepSWE v1.1 75.2%, OSWorld 2.0 71.4% (per Vellum)
Ultrafast tierUp to 8× generation speed (300 tok/s) in Codex, 6× in the API; priced ~6× standard
Decisions APINear-instant multiple-choice classification and routing on GPT-6 Luna, text and image input
Agents API (with computer use)Multi-agent and software-interaction capabilities; plus Bedrock Managed Agents with AWS
Codex Cloud / CLICloud environments keep running with the laptop closed; CLI adds worktrees and an /agents view
Plans & ecosystemNew Pro 500 tier; Sign in with ChatGPT; OpenAI Marketplace; 1.2 billion weekly ChatGPT users
注意口径表中数字来自 OpenAI 官方回顾、Latent Space 与 Vellum 等二手整理,发布初期可能随文档更新而变化;做采购或架构决策前请回到官方文档核对。
Caveat about figuresNumbers in the table come from OpenAI's recap and secondary sources such as Latent Space and Vellum, and may change as documentation is updated; verify against official docs before purchasing or architecture decisions.

03架构拆解:一个 dot 里有什么Architecture: What Is Inside a Dot

把公开信息拼起来,一个 dot 可以看成五个部件:模型(GPT-6 Astra)、云端电脑与浏览器(执行环境)、应用连接层(4000+ 应用,经 OpenAI 的插件生态接入,另可从桌面/网页/移动端 ChatGPT、Slack、Teams 交互,SMS 即将支持)、它写给自己的笔记(并据反馈随时间改进),以及规则闸门。连接用户自己的机器是可选项。

Piecing together the public information, a dot has five parts: the model (GPT-6 Astra), a cloud computer and browser (the execution environment), an app connection layer (4,000+ apps through OpenAI's plugin ecosystem; users can also interact from desktop/web/mobile ChatGPT, Slack and Teams, with SMS coming), notes the dot writes to itself (it also "learns from feedback over time"), and a rules gate. Connecting your own machine is optional.

目标 / 触发用户设定·无需逐条提示一个 dotGPT-6 Astra自己的云端电脑 + 浏览器自己的笔记 / 反馈学习4000+ 应用 · Slack / Teams规则闸门自主/审批/禁止外部应用动作邮件·工单·客服等派生 Codex 任务这部分才计入套餐用量用户审批并可随时暂停
图 1:一个 dot 的组成与动作流向(依据公开资料整理的示意图)
Goal / triggerset once, no per-step promptOne dotGPT-6 AstraOwn cloud computer + browserOwn notes / feedback learning4,000+ apps · Slack / TeamsRules gateauto / approve / neverActions in appsemail, tickets, support…Spawned Codex tasksthese count against plan usageUser approvalcan pause any time
Figure 1: Components of a dot and how actions flow (schematic compiled from public information)
关于用量计量据 Latent Space,主 dot 自己的直接工作不消耗套餐用量,只有它派生的 Codex 任务才计入。这意味着"一直在线"的成本结构和按调用计费的 API 很不一样。
On usage meteringAccording to Latent Space, the primary dot's direct work does not consume plan usage; only the Codex tasks it spawns do. That makes the cost structure of "always on" quite different from per-call API billing.

04权限与安全:三级规则 + 自动复核Permissions and Safety: Three-Tier Rules Plus Auto-Review

常驻意味着没人盯着,所以权限设计是 Dots 最值得学的部分。官方说明是:用户设置自定义规则(Custom Rules),把动作分成三类——可以自行执行的、需要先审批的、禁止执行的。此外:改密码这类操作始终由用户自己完成;系统内置自动复核(auto-review),对照用户指令与安全要求检查动作;内置安全监控用于防御恶意指令,并可以暂停运行。OpenAI 也明确写道 dots "可能犯错"。

Always-on means nobody is watching, so permission design is the most instructive part of Dots. OpenAI's description: users set Custom Rules that sort actions into three buckets — what the dot may do on its own, what needs approval first, and what is prohibited. In addition, sensitive actions such as password changes always stay with the user; a built-in auto-review checks actions against the user's instructions and safety requirements; and built-in security monitoring defends against malicious instructions and can pause operation. OpenAI also states plainly that dots "can still make mistakes."

dot 拟执行的动作发邮件/改代码/付款…Custom Rules用户事先定义自主执行低风险·可回滚需审批推送给用户确认禁止如改密码:始终用户亲自做自动复核对照指令与安全要求
图 2:动作经过规则闸门后的三种去向(示意)
Action a dot planssend email / edit code / pay…Custom Rulesdefined by the user up frontAutonomouslow risk · reversibleNeeds approvalpushed to the userProhibitede.g. password change: user onlyAuto-reviewchecks vs. instructions & safety
Figure 2: The three destinations of an action after the rules gate (schematic)

隐私与训练数据

Privacy and Training Data

值得对照自己的 agent三级规则本质是把"动作风险"显式化:低风险自动做、中风险问人、高风险不碰。如果你自己的 agent 只有"全部允许/全部询问"两档,Dots 的分级是一个可直接借鉴的最小模型。(这是分析性结论,非 OpenAI 原话。)
Worth comparing with your own agentThe three tiers make action risk explicit: low-risk auto, medium-risk ask, high-risk never. If your agent only has "allow all / ask all", Dots' tiers are a minimal model to borrow. (This is analysis, not OpenAI's wording.)

05配套件:Decisions API、Codex Cloud 与 Sol 的成本曲线Companion Pieces: Decisions API, Codex Cloud and Sol's Cost Curve

常驻智能体的经济性取决于"每一步用多贵的脑子"。DevDay 同时给出了分层的积木:Decisions API(GPT-6 Luna,近即时的多选分类与路由,不做深度推理)适合做"这封邮件要不要升级、该派给谁"这类分流;GPT-6.1 Sol($2/$10,缓存输入 $0.10)被官方描述为"近 Astra 智能、五分之一价格";Codex Cloud 让代码类任务在你合上笔记本后继续跑。

The economics of an always-on agent depend on how expensive a "brain" each step uses. DevDay shipped layered building blocks: the Decisions API (GPT-6 Luna; near-instant multiple-choice classification and routing without deep reasoning) suits triage such as "escalate this email, and to whom"; GPT-6.1 Sol ($2/$10, cached input $0.10) is described as "near-Astra intelligence for a fifth of the price"; Codex Cloud lets coding tasks keep running after you close your laptop.

按 Vellum 的整理,Sol 在 DeepSWE v1.1 达 75.2%(与 GPT-6 Astra 持平,单任务成本约低 80%),OSWorld 2.0 为 71.4%(Astra 73.5%,成本约七分之一);同一来源中 Claude Sonnet 5.5 为 71.0%。Google 官方称 Gemini 4 Argon 为 77.9%。三者口径来自各自发布方,不宜直接当作同台对比。

Per Vellum, Sol reaches 75.2% on DeepSWE v1.1 (matching GPT-6 Astra at roughly 80% lower per-task cost) and 71.4% on OSWorld 2.0 (Astra: 73.5%, at about one-seventh the cost); in the same source Claude Sonnet 5.5 scores 71.0%. Google says Gemini 4 Argon scores 77.9%. These figures come from different publishers and should not be treated as a like-for-like comparison.

06怎么用:把 Dots 的思路搬到自己的 agent 工程How To Use It: Carrying the Dots Ideas Into Your Own Agent Engineering

如果你手头有 Pro、Business Premium 或已开启 beta 的 Enterprise 工作区,第一个 dot 是包含在套餐里的(Pro 先在符合条件的市场推出,不含 EEA、瑞士、英国)。无论是否使用 Dots,下面这套做法都适用于任何"无人值守 agent"(以下为基于公开信息的分析建议):

If you have Pro, Business Premium or an Enterprise workspace with the beta enabled, your first dot is included in the plan (Pro is rolling out first in eligible markets, excluding the EEA, Switzerland and the UK). With or without Dots, the following applies to any unattended agent (the points below are analysis based on public information):

  1. 先写规则,再给目标:列出这个 agent 会碰到的 10 个最常见动作,分到"自主 / 审批 / 禁止"三栏,再开始使用。
  2. 从只读任务起步:先让它监控、汇总、起草;把"发送、付款、合并"留在审批栏。
  3. 给高风险动作设人工专属区:参考"改密码始终由用户完成"的做法,明确哪些动作永远不交给 agent。
  4. 分层选模型:路由/分类走轻量接口,难推理才上大模型;并留意缓存价对长上下文的影响。
  5. 留暂停键与审计记录:任何时候都能一键暂停,并能回看它做过什么、为何这样做。
  1. Write the rules before the goal: list the ten most common actions the agent will meet and sort them into auto / approve / prohibited before you start.
  2. Start with read-only work: let it monitor, summarize and draft first; keep send, pay and merge in the approval bucket.
  3. Reserve a human-only zone: following "password changes always stay with the user", decide which actions are never delegated.
  4. Tier your models: use a lightweight interface for routing/classification and a large model only for hard reasoning; mind how cached-input pricing affects long contexts.
  5. Keep a pause button and an audit trail: be able to pause any time and review what it did and why.

07什么场景该用When To Use It

表 2:场景适配(分析性建议)
场景适配度原因
持续监控 + 定期汇总(客户反馈、竞品、指标)高触发靠"持续在线",产出可审阅,出错代价低
起草并提交可回滚的变更(PR、文档更新)中高结果落在可审查的载体上,配合审批规则可控
对外沟通、谈判、付款中低不可逆或影响真实关系,应放审批栏或禁止栏
涉及账户安全(改密码等)不适用官方设定始终由用户亲自完成
Table 2: Scenario fit (analytical guidance)
ScenarioFitWhy
Continuous monitoring + periodic summaries (feedback, competitors, metrics)HighValue comes from being always on; outputs are reviewable and errors are cheap
Drafting and submitting reversible changes (PRs, doc updates)Medium–highResults land in reviewable artifacts; approval rules keep it controlled
Outbound communication, negotiation, paymentsMedium–lowIrreversible or touches real relationships; belongs in approve or prohibited
Account security (password changes etc.)N/ABy design always done by the user

08常见坑与局限Pitfalls and Limitations

本文的边界Dots 发布仅数日,公开信息主要来自官方回顾与媒体报道,尚缺乏独立实测与长期运行数据;表中"分析性建议"为作者推断。
Scope of this documentDots shipped only days ago; public information comes mainly from OpenAI's recap and press coverage, with no independent testing or long-run data yet. "Analytical guidance" items are the author's inference.

09对比:Dots 与相邻形态Comparison With Adjacent Forms

表 3:常驻智能体与相邻形态(分析性对比)
形态触发方式执行环境典型风险控制
聊天助手用户每次提问对话内,通常无独立电脑用户逐条看到结果
Dots(常驻智能体)目标 + 持续运行,可无提示继续自己的云端电脑与浏览器三级规则 + 自动复核 + 可暂停
Codex Cloud用户发起任务,可在合上笔记本后继续云端环境环境隔离 + 代码评审
定时任务 / cron 式 agent时间表视实现而定通常需自行设计权限与告警
Table 3: Always-on agents vs. adjacent forms (analytical comparison)
FormTriggerExecution environmentTypical risk control
Chat assistantUser asks each timeIn-conversation, usually no own computerUser sees each result
Dots (always-on agents)Goal + continuous operation, may proceed without promptsOwn cloud computer and browserThree-tier rules + auto-review + pausable
Codex CloudUser starts a task; can continue with laptop closedCloud environmentEnvironment isolation + code review
Scheduled / cron-style agentsA scheduleDepends on implementationPermissions and alerts usually self-designed

10术语表Glossary

Always-on agent(常驻智能体)
不依赖用户逐条提示、可持续运行的 agent。
Dot
OpenAI 对 ChatGPT 常驻智能体的称呼,拥有自己的云端电脑与浏览器。
Custom Rules(自定义规则)
用户定义的权限规则:自主执行 / 需审批 / 禁止。
Auto-review(自动复核)
对照用户指令与安全要求检查 agent 动作的机制。
Decisions API
基于 GPT-6 Luna 的近即时多选分类与路由接口。
Prompt injection(提示注入)
通过网页或文档里的恶意文字诱导 agent 偏离用户意图的攻击。
Always-on agent
An agent that runs continuously without per-step user prompts.
Dot
OpenAI's name for a ChatGPT always-on agent that has its own cloud computer and browser.
Custom Rules
User-defined permission rules: autonomous / needs approval / prohibited.
Auto-review
A mechanism that checks agent actions against the user's instructions and safety requirements.
Decisions API
Near-instant multiple-choice classification and routing interface built on GPT-6 Luna.
Prompt injection
An attack in which malicious text in a web page or document steers an agent away from the user's intent.

11参考来源Sources

  1. OpenAI DevDay 2026 Recap · 2026-09-29
  2. [AINews] OpenAI DevDay 2026 — Latent Space · 2026-09
  3. OpenAI launches dots… — MediaNama · 2026-10
  4. OpenAI launches dots, always-on ChatGPT agents with their own computers — BetaNews · 2026-09
  5. GPT-6.1 Sol Benchmarks Explained — Vellum · 2026-09/10
  6. Gemini 4 Argon — Google blog · 2026-09-30
  7. ArXiv AI Research Weekly Digest 2026-10-05 (agents-radar) · 2026-10-05
  1. OpenAI DevDay 2026 Recap · 2026-09-29
  2. [AINews] OpenAI DevDay 2026 — Latent Space · 2026-09
  3. OpenAI launches dots… — MediaNama · 2026-10
  4. OpenAI launches dots, always-on ChatGPT agents with their own computers — BetaNews · 2026-09
  5. GPT-6.1 Sol Benchmarks Explained — Vellum · 2026-09/10
  6. Gemini 4 Argon — Google blog · 2026-09-30
  7. ArXiv AI Research Weekly Digest 2026-10-05 (agents-radar) · 2026-10-05