Updated: October 6, 2026 · Source-first reference130 documented agents & platforms · No paid rankings

AgentenCode Knowledge

ChatGPT dots: how an always-on agent changes the model

An always-on agent can watch for changes, resume work and run recurring checks without waiting for a new chat message, which makes permissions and governance especially important.

Direct answer

ChatGPT dots is an always-on agent concept built around persistent work, scheduled tasks, cloud execution, connections and rules. Its significance is the combination of continuity and action, not just conversational memory.

More than a chat with memory

A persistent agent is different from a normal conversation because it can continue to operate over time. The value comes from durable task state, scheduled execution and the ability to use connected services repeatedly.

That makes the system useful for monitoring and recurring work, but it also means mistakes or overly broad instructions can have longer-lived effects.

A cloud computer changes execution

One of the important ideas in the dots model is a dedicated cloud execution environment. Work can continue independently of a personal device and can maintain a more persistent operational context.

Cloud execution changes the security boundary. Organizations need to understand what files, credentials, network destinations and connected services are available inside that environment.

Connections and scheduled tasks

Dots can make use of connected ChatGPT services and recurring schedules. A persistent agent can therefore monitor for useful changes before a user explicitly asks again.

Recurring execution should be treated like automation: triggers, frequency, permissions, error handling and approval conditions need to be deliberate rather than assumed.

What the agent remembers

Persistent agents may combine conversation context, task state and longer-lived memory. The operational question is not simply whether memory exists, but which information is retained, how it can be corrected and how long it persists.

Workspace and personal contexts may have different governance expectations, especially where business data and shared policies are involved.

Custom rules and control

Rules can constrain how a persistent agent behaves, but rules are not a substitute for technical permissions. The safest architecture combines instructions with bounded tools, least-privilege access, approvals and logging.

Always-on operation should have clear stop conditions and ownership so a human can understand and interrupt recurring behavior.

Prompt injection remains relevant

An agent that reads webpages, documents or messages can encounter malicious instructions. Persistent operation can make this more consequential if untrusted content affects future tasks or stored state.

External content should therefore remain data, not policy. High-impact tool calls deserve independent authorization and review.

Workspace governance

Enterprise administrators may need separate controls for persistent agents and their execution environments. Product availability, data handling, connectors and policy can vary by workspace and plan.

AgentenCode keeps these dimensions separate rather than using the existence of a dot as evidence for every possible enterprise control.

Use cases and limits

Always-on agents are useful for recurring monitoring, follow-up, personal workflows and long-running research. They are less suitable where the objective is poorly defined or where every action requires high-confidence human judgment.

“Always on” should never be read as “unlimited autonomy.” The actual action surface is determined by tools, permissions, rules and approvals.

Sources and further reading

Frequently asked questions

Is a dot just ChatGPT memory?

No. The concept combines persistence, execution, scheduled work and connected capabilities, not only remembered conversation context.

Can a persistent agent keep working when my device is off?

Cloud execution is designed for work that is not tied to a powered-on personal device, subject to the product’s current documented behavior.

Does always-on mean the agent can do anything?

No. Tools, permissions, rules, workspace policy and approvals define what the agent may actually do.