Short answer
- Custom rules let you choose, per action, whether your dot should act without asking, act if pre-approved, ask first or hand off to you.
- “Pre-approved” means you explicitly asked for that action in your prompt. Approving one message is not ongoing permission.
- No rule can override the built-in guardrails: password changes and money transfers always come back to you.
Custom rules are the part of dots that decides how much you actually have to supervise. Set them too loose and your dot acts on things you would rather see first. Set them too tight and every task stalls on a confirmation. This page covers what OpenAI documents about each setting, and then gives a starting rule set you can adapt.
What custom rules cover
In other words, a rule is a pair: an action you describe (for example “sending email to people outside my company”) and one of four behaviors for that action. OpenAI’s announcement sums up the range as letting you “allow specific actions, require approval, or block them.”
The four behaviors
When you add a rule, you pick one of these four options. The names below are OpenAI’s exact wording.
| Behavior | What your dot does | Where it fits (our reading) |
|---|---|---|
| Take action without asking | Goes ahead with the action and does not stop to confirm. | Low-stakes, easy-to-undo actions you would never want to be asked about. |
| Take action if pre-approved | Acts only when you explicitly requested that action in your prompt. | Actions you are happy to trigger yourself, but never want your dot to start on its own. |
| Ask before taking action | Pauses and asks you to confirm before it acts. | Anything that leaves your account or reaches another person. |
| Hand off to you | Stops and hands the step back for you to complete yourself. | Steps you want to do personally, even if your dot has done all the prep. |
What “pre-approved” actually means
OpenAI defines it narrowly: “‘Pre-approved’ means you explicitly requested the action in your prompt.” The privacy and safety FAQ adds two limits that matter in practice:
- Approval does not carry over. “Approving one message does not give your dot ongoing permission to contact people on your behalf.” Any advance approval stays limited to what you authorized.
- Be specific. For a future message, OpenAI suggests including who it should go to, what it should say, and when or under what conditions it should be sent.
Some actions can be approved in advance. OpenAI’s example is sending recurring messages. Purchases made with a card saved on a merchant’s website also need approval, which “may be given in advance when it specifically covers the purchase.”
What no rule can change
Custom rules sit on top of safeguards you can’t edit. According to OpenAI:
- The most sensitive actions always come back to you. Changing a password or transferring money requires you to take over and finish the step yourself.
- Some actions may need approval every time. OpenAI lists permanently deleting data and installing software as examples.
- Auto-review still runs. Before certain actions, such as sending an email, Auto-review checks them against your instructions, your custom rules and safety requirements. Rules cannot change or disable it.
- Proactive research stays read-only. When your dot researches in the background, its tools cannot send messages to other people, change content through plugins, or control a browser or computer. Rules cannot lift that restriction.
How to add a rule
OpenAI’s help center documents these steps in the ChatGPT mobile app:
- Open your dot’s profile and go to Customize → Custom rules.
- Review the default rules, or choose to add a rule.
- Describe the action the rule covers, in plain language.
- Choose one of the four behaviors.
- Save the rule with the checkmark, then check it in the Custom rules list.
The safety FAQ also says you can view your custom rules “by accessing your settings.” OpenAI hasn’t yet published separate desktop steps, so we will add them after our own setup walkthrough.
A starting rule set (cheat sheet)
| If your dot wants to… | Start with | Why |
|---|---|---|
| Read your calendar or inbox to prepare a summary | Take action without asking | Reading only, and it’s the whole point of a daily briefing. |
| Send a recurring update you defined (same recipient, same format) | Take action if pre-approved | You name it once in the task; OpenAI lists recurring messages as approvable in advance. |
| Email someone new, or reply outside your company | Ask before taking action | Anything that reaches another person deserves a look. Auto-review checks recipients too, but you know the context. |
| Share a file or link outside your workspace | Ask before taking action | Sharing is hard to take back once someone has opened it. |
| Buy something with a saved card | Ask before taking action | OpenAI already requires approval for purchases. Keep it per purchase until you trust the pattern. |
| Delete data or install software | Hand off to you | OpenAI may ask for approval each time anyway. Doing it yourself keeps the undo in your hands. |
| Change a password or move money | Hand off to you | OpenAI always hands these back. The rule just makes your intent explicit. |
Writing rules that hold up
- Describe the action, not the app. “Sending messages to anyone outside my team” covers email, Slack and texting. A rule scoped to one tool can leave gaps.
- Loosen one rule at a time. Start strict and move one action from Ask to Pre-approved after you have seen it done well a few times.
- Put approvals in the task itself. Because pre-approval has to be explicit, write scheduled tasks as full instructions: who, what, when. See scheduled tasks.
- Check your connected apps first. Rules decide how your dot acts. Plugin permissions decide what it can reach in the first place, and they’re shared across ChatGPT, ChatGPT Work and Codex.
Official sources
Every product fact on this page was checked against the pages below. Last verified . Spot something out of date? Tell us.
- OpenAI Getting started with your dot — Controls and approvals Accessed Sep 30, 2026
- OpenAI Dots privacy, security, and safety FAQs Accessed Sep 30, 2026
- OpenAI Introducing dots — You're always in control Accessed Sep 30, 2026
Questions people ask
Where do I find custom rules for my dot?
OpenAI's help center documents the mobile path: open your dot's profile, then Customize → Custom rules. From there you can review the default rules or add a new one.
What does “Take action if pre-approved” mean?
Your dot may take the action only if you explicitly asked for it in your prompt. A general go-ahead earlier in the conversation, or approval of a different message, does not count.
Can a custom rule let my dot change passwords or send money on its own?
No. OpenAI says the most sensitive actions, such as changing a password or transferring money, always require you to take over. Custom rules cannot turn off these core safety requirements or the Auto-review system.
Do custom rules stop my dot from making mistakes?
No. OpenAI notes that a dot can make mistakes, including when following your rules. Treat rules as a boundary, and still review consequential work before relying on it.