Short answer
- Custom rules let you choose, per action, whether your dot should act without asking, act if pre-approved, ask first or hand off to you.
- “Pre-approved” means you explicitly asked for that action in your prompt. Approving one message is not ongoing permission.
- No rule can override the built-in guardrails: password changes and money transfers always come back to you.
Custom rules are the part of dots that decides how much you actually have to supervise. Set them too loose and your dot acts on things you would rather see first. Set them too tight and every task stalls on a confirmation. This page covers what OpenAI documents about each setting, and then gives a starting rule set you can adapt.
What custom rules cover
In other words, a rule is a pair: an action you describe (for example “sending email to people outside my company”) and one of four behaviors for that action. OpenAI’s announcement sums up the range as letting you “allow specific actions, require approval, or block them.”
The four behaviors
When you add a rule, you pick one of these four options. The names below are OpenAI’s exact wording. One of them has two names: the help center calls it “Take action if pre-approved,” while OpenAI’s learn docs call it “Take action when you say so.” Both describe the same behavior, so look for either label in the app.
| Behavior | What your dot does | Where it fits (our reading) |
|---|---|---|
| Take action without asking | Goes ahead with the action and does not stop to confirm. | Low-stakes, easy-to-undo actions you would never want to be asked about. |
| Take action if pre-approved (also shown as “Take action when you say so”) | Acts when you explicitly requested that action; otherwise asks right before acting. | Actions you are happy to trigger yourself, but never want your dot to start on its own. |
| Ask before taking action | Pauses and asks you to confirm before it acts. | Anything that leaves your account or reaches another person. |
| Hand off to you | Stops and hands the step back for you to complete yourself. | Steps you want to do personally, even if your dot has done all the prep. |
What “pre-approved” actually means
OpenAI defines it narrowly: “‘Pre-approved’ means you explicitly requested the action in your prompt.” The privacy and safety FAQ adds two limits that matter in practice:
- Approval does not carry over. “Approving one message does not give your dot ongoing permission to contact people on your behalf.” Any advance approval stays limited to what you authorized.
- Be specific. For a future message, OpenAI suggests including who it should go to, what it should say, and when or under what conditions it should be sent.
Some actions can be approved in advance. OpenAI’s example is sending recurring messages. Purchases made with a card saved on a merchant’s website also need approval, which “may be given in advance when it specifically covers the purchase.”
What no rule can change
Custom rules sit on top of safeguards you can’t edit. According to OpenAI:
- The most sensitive actions always come back to you. Changing a password or transferring money requires you to take over and finish the step yourself.
- Some actions may need approval every time. OpenAI lists permanently deleting data and installing software as examples.
- Auto-review still runs. Before certain actions, such as sending an email, Auto-review checks them against your instructions, your custom rules and safety requirements. Rules cannot change or disable it.
- Proactive research stays read-only. When your dot researches in the background, its tools cannot send messages to other people, change content through plugins, or control a browser or computer. Rules cannot lift that restriction.
How to add a rule
OpenAI documents two paths. On desktop, per the learn docs:
- After setting up your dot, open Settings > Personalization and select Custom rules under Permissions.
- Select Add and describe the action, in plain language.
- Choose how your dot should handle it (one of the four behaviors).
- Select Add rule. Use a rule’s menu later to edit or delete it.
In the ChatGPT mobile app, the help center describes opening your dot’s profile and going to Customize → Custom rules, where you can review the default rules, add a rule, and save it with the checkmark.
OpenAI gives two examples of its own: Ask before taking action for sending messages to customers, and Hand off to you for deleting shared project files.
You don’t need a rule for every approval. OpenAI suggests starting with clear instructions in the conversation, such as asking your dot to show you drafts before sending them, and saving rules for specific, ongoing boundaries.
A starting rule set (cheat sheet)
| If your dot wants to… | Start with | Why |
|---|---|---|
| Read your calendar or inbox to prepare a summary | Take action without asking | Reading only, and it’s the whole point of a daily briefing. |
| Send a recurring update you defined (same recipient, same format) | Take action if pre-approved | You name it once in the task; OpenAI lists recurring messages as approvable in advance. |
| Email someone new, reply outside your company, or message a customer | Ask before taking action | Anything that reaches another person deserves a look. Auto-review checks recipients too, but you know the context. |
| Share a file or link outside your workspace | Ask before taking action | Sharing is hard to take back once someone has opened it. |
| Buy something with a saved card | Ask before taking action | OpenAI already requires approval for purchases. Keep it per purchase until you trust the pattern. |
| Delete data or install software | Hand off to you | OpenAI may ask for approval each time anyway. Doing it yourself keeps the undo in your hands. |
| Change a password or move money | Hand off to you | OpenAI always hands these back. The rule just makes your intent explicit. |
Writing rules that hold up
- Describe the action, not the app. “Sending messages to anyone outside my team” covers email, Slack and texting. A rule scoped to one tool can leave gaps.
- Loosen one rule at a time. Start strict and move one action from Ask to Pre-approved after you have seen it done well a few times.
- Put approvals in the task itself. Because pre-approval has to be explicit, write scheduled tasks as full instructions: who, what, when. See scheduled tasks.
- Check your connected apps first. Rules decide how your dot acts. Plugin permissions decide what it can reach in the first place, and they’re shared across ChatGPT, ChatGPT Work and Codex.
Official sources
Every product fact on this page was checked against the pages below. Last verified . Spot something out of date? Tell us.
- OpenAI Control your dot — ChatGPT Learn Accessed Sep 30, 2026
- OpenAI Getting started with your dot — Controls and approvals Accessed Sep 30, 2026
- OpenAI Dots privacy, security, and safety FAQs Accessed Sep 30, 2026
- OpenAI Introducing dots — You're always in control Accessed Sep 30, 2026
Questions people ask
Where do I find custom rules for my dot?
On desktop, OpenAI's learn docs say to open Settings > Personalization and select Custom rules under Permissions. In the mobile app, the help center describes your dot's profile, then Customize → Custom rules.
What does “Take action if pre-approved” mean?
Your dot may take the action only if you explicitly asked for it in your prompt. A general go-ahead earlier in the conversation, or approval of a different message, does not count.
Can a custom rule let my dot change passwords or send money on its own?
No. OpenAI says the most sensitive actions, such as changing a password or transferring money, always require you to take over. Custom rules cannot turn off these core safety requirements or the Auto-review system.
Do custom rules stop my dot from making mistakes?
No. OpenAI notes that a dot can make mistakes, including when following your rules. Treat rules as a boundary, and still review consequential work before relying on it.