← Latest reporting

An always-on agent needs a delegation register before it needs more memory

OpenAI’s Dots can operate persistently with identities, tools and enterprise access. Organisations should inventory each delegated authority, approval boundary and human handoff before expanding autonomy.

Skills Systems and HR TechWork and Role Change
A full-scale conceptual operations room shows a central delegation desk connecting five distinct work stations, each with a visible key tether, approval gate and return path.
Conceptual AI-generated illustration of persistent work being controlled through explicit delegation and handoff points; it does not depict an OpenAI office or the Dots interface.

What happened

OpenAI introduced Dots on 29 September as persistent specialist agents with their own identity, credentials, access, responsibilities and tools, with review and approval controls and enterprise integrations.

Why it matters

Persistence changes the control problem from a single prompt to continuing delegated authority. Memory and access can compound across time unless owners can see, narrow and revoke every grant.

OpenAI says Dots are persistent specialist agents that work on a person’s behalf. A dot can have an identity, credentials, access, responsibilities and tools, and the product includes review and approval controls. The company describes integrations with enterprise systems and a rollout to paid individual plans with an enterprise beta. Reuters and TechCrunch reported the launch and its position in a growing enterprise-agent market.

The announcement does not establish error rates, reliability over long runs or effectiveness of controls in a buyer’s environment. It does establish a more important design boundary: an always-on agent is not just a better chat session. It is a continuing delegation of authority whose state, permissions and unfinished work can persist after the person stops looking.

Record the delegation before activation

Create one register entry for every agent instance. Name the business purpose, accountable owner, sponsor, authorised users, credentials, connected systems, data classes, allowed actions, forbidden actions, approval points, maximum spend or consequence, retention, expiry and emergency revocation path. Link each entry to the agent version and every material configuration change.

Do not infer authority from a broad role label such as “researcher” or “sales assistant.” Break work into explicit verbs: read, summarise, draft, send, modify, purchase, invite, export or delete. The same data access may be tolerable for drafting and unacceptable for external transmission. Approvals should bind to a specific action and object, not become a reusable blanket consent.

Design the human handoff

Persistence makes queues and ownership visible control surfaces. Every task should have a state, evidence trail, next review time and human recipient when confidence is low or a boundary is reached. The agent should not silently retry a rejected action with a new route. A handoff record should show what it attempted, what changed, what remains uncertain and which permissions it used.

Make that state visible to the affected worker, not only to administrators.

Memory deserves the same discipline. Separate transient task context, reusable preferences and authoritative organisational facts. Let users inspect and correct durable memory, record its source and expiry, and prevent low-confidence inferences from becoming shared facts. Revoking a credential should also stop queued work that depends on it; otherwise the register describes access but not effective authority.

Name the fallback mode when a service, approver or data source is unavailable. The agent should fail closed for consequential actions, surface incomplete work and preserve a resumable checkpoint. Test whether a restored connection causes stale queued actions to execute unexpectedly. Continuity is useful only when the organisation can distinguish intended persistence from unattended accumulation.

The counterargument is that detailed registers slow adoption and duplicate identity-governance systems. The answer is integration, not omission. Import identities and entitlements from existing systems, then add the agent-specific purpose, action boundary, approval rule and task state those systems usually lack. Start with consequential systems and automate evidence capture from runtime logs.

Test revocation in practice. Disable an owner, rotate a credential, withdraw an approval and change a data classification. Verify that active and queued work stops, downstream copies are identified and the human owner receives a comprehensible alert. Measure orphaned agents, stale credentials, approval bypasses, retry loops, unresolved handoffs and corrections to durable memory.

Use the Skills Intelligence Role Dictionary to map the work outcomes an agent supports, not to grant it every permission associated with a job title. When work crosses functions, record the receiving human or system and its accountability.

The immediate decision is to make persistent agents conditional on a live delegation register. More memory and autonomy should follow evidence that owners can inspect, narrow and revoke authority across the complete work path.