OpenAI Dots for Business: A Human-Approved AI Agent Pilot Checklist
Learn how a small business can pilot OpenAI Dots for recurring operations work with a permission checklist, practical costs, measurement ideas and safeguards.
UniqueTechCamp Editorial
UniqueTechCamp Editorial Desk • UniqueTechCamp Engineering Unit
An always-on AI agent sounds useful when a team repeatedly checks updates, prepares drafts or follows a process across several apps. The operational risk is equally clear: an agent may see the wrong information, misunderstand an instruction or act before a person has checked the result. A good business pilot starts with one limited responsibility and makes permission and approval rules part of the design.
OpenAI introduced Dots at DevDay on 29 September 2026. OpenAI describes Dots as always-on agents powered by GPT-6 Astra, with their own cloud computer and connections to more than 4,000 apps through its plugin ecosystem. The announcement says users can follow work in ChatGPT and communicate through Slack or Teams. Rollout is limited to eligible markets and plans; OpenAI’s DevDay recap lists Pro and Business Premium availability and says Enterprise, Edu and Healthcare workspaces can try a beta when an administrator enables it. Confirm availability and current plan terms in your account before making a client commitment. OpenAI’s Dots announcement · DevDay 2026 availability notes
A product launch is not proof that an agent is suitable for every task. TechCrunch’s independent coverage also notes that much of the underlying agent capability existed in other tools; Dots packages it as an always-on assistant. TechCrunch’s launch report
A low-risk pilot: supplier and product-change monitoring
A distributor could ask an agent to monitor a small list of public supplier pages and prepare a weekly internal note about confirmed changes to product specifications, manuals or published availability. It should link to each source, mark the date checked, distinguish fact from interpretation and draft questions for a staff member. It should not change stock records, update a catalogue or email a supplier without approval.
A technology consultancy could turn that into a client offer: a short workflow-mapping session, a permission and approval plan, a configured agent, a test pack, a runbook and a review at the end of the pilot. Ongoing support could cover new sources, prompt changes and quality reporting. The client is paying for a bounded, governed process and human support, not a guaranteed number of discoveries or a promise that the agent will operate without error.
The checklist for a two-week pilot
1. Choose one recurring, low-impact task. Write down the trigger, sources, expected output, owner and what the agent must never do. Prefer public or non-sensitive information at the start.
2. Record the current process. Measure how staff do the task now, including checking and correction time. This is the comparison point for later measurement; it is not a claimed saving.
3. Map access before connecting apps. List each account, what the agent can read, what it can change and who owns the connection. Use the least access needed. OpenAI says Dots’ proactive research uses read-only tools, while follow-up actions remain subject to action rules and checks. Read the OpenAI safety and privacy explanation and configure the actual permissions available to your workspace.
4. Define approval gates in plain language. For example: “You may prepare an internal weekly draft from these public pages. Do not send messages, edit the catalogue, place orders or make payments. Stop and ask if a source is inaccessible or contradictory.” Keep the rule narrow enough to test.
5. Test known cases and hostile inputs. Use a set of past supplier updates and expected findings. Include a changed page, a dead link, conflicting information and an irrelevant instruction embedded in a source. Check whether the agent flags uncertainty and stays within the assigned task.
6. Run in shadow mode. For two weeks, have a staff member review every output before anyone acts on it. Keep a record of useful findings, false alarms, omissions, source errors, failed runs and time spent reviewing.
7. Make a go/no-go decision. Continue only if the team’s agreed quality threshold is met, the review burden is manageable and the cost is acceptable. Expand access or actions one step at a time, with a named owner and a rollback plan.
Costs and measurements to put in the proposal
OpenAI says the first Dot is included at no extra cost with eligible Pro and Business Premium plans. Enterprise users, including Edu and Healthcare, can try the beta when an administrator enables it. Rollout is limited by market, so confirm the client’s actual access and current plan price before quoting. “No extra cost” for the first Dot does not mean the service is free: the client still needs an eligible plan, and the workflow may require setup, testing, staff approval, monitoring and connected-app fees. OpenAI also says tasks started through Codex or ChatGPT Work count towards the usual usage limits.
A simple quote can separate a fixed-scope setup from monthly support. For example, charge for the hours needed to map the process, configure permissions, write the test cases and train the owner, then estimate ongoing review time from the pilot. Add direct subscription and integration costs transparently. Those are cost categories, not earnings promises; record the actual hours before offering a fixed recurring price.
Track source accuracy, missed changes, false alarms, the proportion of outputs accepted without correction, review minutes per run, failed connections and any attempted action that the rule correctly blocked. Also note the time from a source change to a reviewed internal update. A dashboard should show both useful work and exceptions, not only activity volume.
Privacy and accountability are part of the product
Kenya’s Data Protection Act requires lawful, fair and transparent processing for a defined purpose, with data limited to what is necessary. It also regulates transfers of personal information outside Kenya. If the agent reads staff or customer data through connected services, document the purpose, access, retention and any cross-border processing, and check whether a data-protection impact assessment or other safeguards are required for the proposed use. Kenya Data Protection Act, 2019 · ODPC cross-border transfer guidance
Do not begin with payroll, health records, payment approvals, legal decisions or customer-facing promises. Use separate test accounts where possible, restrict sensitive sources, tell affected staff how the system works and keep a named person accountable for decisions. An agent can make mistakes even when it has strong safeguards; preserve an audit trail and a way to pause or disconnect it.
Turn the pilot brief into an operating control
A pilot brief is useful only when somebody can use it to decide what happens next. Add an owner for the business outcome, an approver for consequential actions and a technical contact who can disconnect an account. Name a deputy for absences. Record the approved task, permitted data, blocked actions, escalation route and review date in one place. Give the document a version number; a changed prompt, connected app or source list should create a new version rather than silently changing the experiment.
Keep an evidence register beside the brief. For each run, retain the source URL, retrieval date, relevant passage, agent output, reviewer decision and correction. If a page changes, preserve the earlier capture or a lawful internal reference to it. This makes a disputed summary reviewable without treating the agent’s wording as proof. A register also helps separate a bad source from a bad interpretation and gives the owner evidence for a go/no-go decision.
Design tests around failure, not just fluent answers
A convincing demonstration is not a safety test. Build a small, labelled test pack before the first live run. Include an unchanged page, a genuine change, a page with an ambiguous date, a temporary error, a redirect, duplicated content, a conflicting supplier statement and a source containing instructions aimed at the agent. The expected result should say whether to report, wait, cite both sources or ask a person. Test an empty result too: “no confirmed change found” is different from “all sources checked and unchanged”.
Include a stop test. When a connected page contains a request to reveal credentials, ignore the request and record the attempted injection. When a source is unavailable, the expected behaviour is to say so, not to fill the gap from memory. OpenAI describes prompt injection as malicious instructions in webpages, emails or documents, and says it combines model safeguards with tool restrictions, action checks and monitoring. Read the official Dots safety, security and privacy explanation , then test the exact sources and permissions used by this pilot rather than assuming a general safeguard covers every workflow.
Make human approval meaningful
Approval should be proportional to impact. A reviewer might approve an internal summary containing links, while a change to a customer record, a purchase, a payment, a contractual message or a publication requires a separate, explicit decision. Use two people for actions where an error could create a material financial, legal, safety or reputational consequence. If the product cannot express that distinction clearly, keep the workflow in draft-only mode.
Set an expiry on approvals. A permission granted for one weekly report should not automatically authorise a new source, a new recipient or a new type of action. Ask again when the scope, data, destination or consequence changes. Keep emergency stopping practical: document who can pause the dot, revoke the connection, quarantine an output and notify affected colleagues. Run that exercise once during the pilot so the rollback plan is more than a sentence in a proposal.
This is consistent with the risk-management logic in the NIST AI Risk Management Framework . NIST presents the framework as voluntary guidance for incorporating trustworthiness into the design, development, use and evaluation of AI systems. For this pilot, translate that idea into four practical questions: have we mapped the context and harms; can we measure the result; can we manage a detected problem; and can we govern ownership and decisions?
For a Kenyan SME planning a controlled agent trial, UniqueTechCamp can help define the task, approval gates and outcome measures before expansion.
Protect information throughout the trial
Start with a data inventory, not an app list. Identify personal data, confidential business information, credentials, commercially sensitive prices and information about children or health. For each category, record why it is needed, who can view it, where it is processed, how long it is retained and how it will be deleted or disconnected. Redact or sample data where the task can be tested without the original records. Do not paste secrets into instructions or source documents; secure sign-in is not a reason to relax ordinary credential hygiene.
Where personal information is involved, ask the organisation’s privacy lead to confirm the lawful basis, notices, processor terms, retention schedule and transfer safeguards. The UK Information Commissioner’s AI guidance hub links to detailed guidance on applying data-protection principles to AI and to a risk toolkit for assessing effects on people’s rights and freedoms. It is UK guidance, not a substitute for Kenyan advice, but its questions about accountability, risk and affected people are useful prompts for a cross-border review.
Measure value without turning activity into success
Define a primary outcome before looking at the dashboard. For supplier monitoring, it might be a reviewed internal note that correctly identifies a material change and cites the relevant passage. Secondary measures can cover review minutes, missed changes, false alarms, failed runs and time to escalation. Report denominators and exceptions: “12 findings” says little without the number of sources checked, the number supported after review and the number still awaiting a decision.
If the work could affect people in the European Union, check whether the use falls within the European Commission’s AI Act framework and obtain current legal advice. The Commission describes a risk-based framework and highlights logging, documentation, human oversight, robustness and monitoring for high-risk uses, while transparency obligations can apply when people interact with AI. A low-risk supplier note is not automatically a high-risk system, but payroll, recruitment, credit, essential services and other consequential uses need a different assessment.
Decision record: expand, hold or stop
At the review meeting, attach the test results, evidence register, privacy review, cost record, incidents and the owner’s recommendation. Expand only one variable at a time: more sources, more data, more users or a new action. Hold the scope when quality is acceptable but review effort or uncertainty is not. Stop and disconnect when the agent repeatedly exceeds its scope, sources cannot be verified, an incident cannot be investigated or the organisation cannot keep a human accountable.
The most useful outcome may be a documented decision not to automate. A bounded pilot still succeeds when it shows that the task needs better source ownership, clearer procedures or a different tool. If the decision is to continue, set the next review date, name the approval owner and repeat the tests after material changes. OpenAI’s own guidance says Dots can still make mistakes and consequential work should be reviewed; treat that as an operating requirement, not a footnote.
The next step
Before adopting Dots, write a one-page pilot brief: task, allowed sources, prohibited actions, approver, cost ceiling and success measures. If access is available, test it on non-sensitive data in shadow mode. UniqueTechCamp can help a business map the process, set up a controlled pilot and decide from measured results whether an always-on agent belongs in its operations.
Deploy An Autonomous AI Lead Gen System Today
We engineer high-converting web applications with integrated 24/7 WhatsApp qualification bots and multi-channel follow-up drips.
Related Strategy Articles
Google Workspace Skills: A Practical Guide for SMEs
Google Workspace Skills let teams reuse custom instructions across supported Workspace apps. This practical guide explains the rollout, eligibility checks, a safe pilot workflow and what to measure before expanding.
Cloudflare Clef: A Practical AI Triage Guide for SMEs
Cloudflare Clef turns support messages into bounded decisions rather than free-form answers. Here is a practical way for SMEs to test it, measure value and keep a human in control.
Microsoft Copilot Code for SMEs: A Practical Workflow-to-App Offer
Microsoft Copilot Code is still rolling out. Learn a practical workflow-to-app service for Kenyan SMEs, with verified pricing, usage limits and a safe pilot plan.
UniqueTechCamp Desk
Online • Reply < 5 mins