OpenAI Dots for RIAs
OpenAI's dots can sign into your apps and work around the clock. Here is where they help an RIA, and what to check before they touch client work.
OpenAI's dots are a capable always-on assistant for a person's own work at an RIA: research, inbox and calendar, follow-ups, and one-off tasks the person checks. For repeated client work like account opening, CRM updates, and service requests, they plan each run fresh and keep records per user, so most RIAs will want a verifiable agent for that work and keep dots for the rest.
This fall, three AI companies shipped the same idea within weeks: an agent with its own computer that works for you around the clock. xAI launched Grok Bot in August, Meta launched Muse in September, and OpenAI answered with dots at the end of the month. Operations teams at RIAs are already asking whether one of them can take work off their plate.
This guide is for that question. It covers what OpenAI's dots are, where they fit at an RIA, and the five things the firm has to answer before an always-on agent touches repeated client work. Every product fact comes from OpenAI's own pages as of October 1, 2026, and these products are changing fast.
What is OpenAI Dots?
dots are OpenAI's always-on agents, announced at DevDay on September 29, 2026. Each dot runs on GPT-6 Astra with its own cloud computer and browser, connects to over 4,000 apps through ChatGPT, and works toward your goals in the background. You can reach your dot in ChatGPT, Slack, and Microsoft Teams.
dots learn from feedback over time, can delegate to other agents, and OpenAI says it envisions teams of dots. Specialist dots with their own identity are in an enterprise pilot.
dots are good at the open-ended work of a busy professional: following up on threads, researching ahead of a meeting, drafting an update, and keeping track of loose ends across thousands of apps.
- Plans. Your first dot is included with ChatGPT Pro (from $100 a month, not yet in the EEA, Switzerland, or the UK) and Business Premium. Enterprise, Edu, and Healthcare get a beta an admin has to turn on.
- Model. GPT-6 Astra.
- Custom Rules. Each rule is set to take action without asking, take action if pre-approved, ask before acting, or hand off to you.
- Auto-review. A separate system checks planned actions, like emails and file changes, against your instructions and rules before they run.
- Hard stops. Deleting data and granting security-sensitive access always need confirmation. Password changes and transfers between financial accounts are handed back to you.
- Records. Activity View shows tasks in progress, scheduled, and completed. Business, Enterprise, and Edu content is not used for training by default.
Product details as of October 1, 2026, from the vendor's own announcement, help, and security pages.
Where RIAs want to use dots
Nobody at an RIA needs an agent to do the professional judgment. They want back the hours their teams spend on repeated, system-to-system work:
- Account opening. Turning a new household's details into completed custodian forms and sending them for signature in DocuSign.
- CRM updates. Getting meeting notes, tasks, and life events into Wealthbox, Redtail, Salesforce, or Practifi.
- Service requests. Handling address changes, distributions, and beneficiary updates from the shared inbox.
- Billing and reconciliation. Checking fee schedules and balances across Orion, Black Diamond, or Tamarac and the CRM.
- Review prep. Assembling the packet for each client review from the portfolio system and the CRM.
Picture an operations lead using a dot to handle service requests: read the shared inbox, draft the reply, update the CRM, and prepare the paperwork. Custom Rules can require approval before anything goes to a client, and OpenAI's hard stops hand transfers between financial accounts back to a person by design.
Those guardrails fit a fiduciary's instincts. The open question is procedure and record: each request is planned fresh by the model, OpenAI notes a dot can make mistakes even when following your rules, and the activity record is per user, not a firm archive. For work an examiner may ask about, an RIA needs both a fixed procedure and a record it can produce.
Five questions before dots touch client work
None of these are reasons to avoid dots. They are the questions any RIA has to answer for any agent that acts on a client's behalf.
Will dots do the work the same way every time?
You give a dot a goal and define what it can do on its own; it works out what needs to happen next. Scheduled tasks and Custom Rules shape that, but OpenAI does not describe a saved, step-by-step workflow, and its help center notes that a dot "can make mistakes, including when following your rules."
For account opening, CRM updates, and service requests, that matters. You cannot test a procedure on last month's cases and rely on the result if the next run is planned again from scratch.
Who supervises dots at an RIA?
OpenAI's controls are layered: Custom Rules per action type, an Auto-review system that sits outside the dot's environment, hard stops for destructive and security-sensitive actions, and stricter recipient checks as data gets more sensitive. Those are real safeguards. Like the others, they decide which individual actions need a person, not whether the overall procedure is right.
Under the SEC's compliance rule, Rule 206(4)-7, an adviser needs written policies and procedures reasonably designed to prevent violations, and for dual registrants FINRA Regulatory Notice 24-09 reminds firms that Rule 3110 requires a reasonably designed supervisory system when they use generative AI. A procedure that is re-planned on every run is hard to write a policy around.
Can the firm show what dots did?
Activity View shows each user what their dot is doing, has scheduled, and has finished. OpenAI's dots materials do not describe an exportable audit log or an admin-level log of dot activity.
SEC Rule 204-2 requires advisers to keep books and records, including copies of written communications on listed topics, generally for five years. An agent that emails clients or updates account records from a user's login is creating those records, and a per-user activity feed is not a books-and-records archive.
What happens to client data?
Business, Enterprise, and Edu content is not used for training by default; on personal plans it depends on the Improve the model setting, which can include actions your dot takes. Disconnecting an app does not delete what your dot already pulled from it; removing that data means resetting the dot.
Regulation S-P requires advisers to safeguard customer information and, since the 2024 amendments, to run an incident response program. An agent holding an adviser's email and CRM access is part of that program.
OpenAI says plainly: "Dots can still make mistakes, so always review consequential work."
Do dots reach the systems RIAs run on?
Over 4,000 apps through the ChatGPT ecosystem, plus Slack and Teams as places to talk to your dot. OpenAI's dots materials do not single out specific practice-management, document-management, or CRM connectors.
RIA operations run through the CRM (Wealthbox, Redtail, Salesforce, Practifi), the portfolio system (Orion, Black Diamond, Tamarac, Addepar), DocuSign, and a stack of custodian forms. Reaching a system is only half of it; the other half is doing the same thing in it every time.
| OpenAI Dots | Caddi | |
|---|---|---|
| How the work is defined | A goal plus Custom Rules | Tested code you can read and change |
| Same input, same path? | Not claimed by the vendor | Yes, for the coded steps |
| Role of AI in a run | Plans and performs each step | Named judgment steps, scoped and logged |
| Human control | Custom Rules, Auto-review, and hard stops | Review the procedure; exceptions go to a named person |
| Record of each run | Per-user Activity View; no stated audit export | Every run logged, tied to its source documents |
| Built for | A person's own varied work | RIAs' repeated back-office workflows |
What a verifiable agent does differently
The fix is not a better prompt or a stricter approval setting. It is moving the procedure out of the model. A hybrid agent runs the workflow as code, which can be read, tested, and versioned, and calls AI only for the steps that need judgment, each one scoped and logged.
For account opening, that means the code pulls the household from the CRM, fills the custodian's forms, and sends the DocuSign envelope the same way every time, while AI handles the judgment inside it: reading a scanned trust document, matching a beneficiary to the right record, spotting a missing signature. Anything unclear goes to the operations team, logged.
That split is what makes an agent verifiable: a reviewer can read the procedure before it runs, every judgment call is on the record, and changes are made on purpose.
More on the idea in what are verifiable AI agents and what are hybrid agents.

Connect Wealthbox to Caddi
Allow1Sign in to your tools
One click each for Wealthbox, Docusign and Microsoft Outlook. No API keys.
Automate account opening.
ScreenshareType it2Show or tell it
Screenshare the job, or type it in chat. Change it any time.
- Running



14 done1 for review
3Watch it run
Caddi does the work and flags anything unsure for review.
How RIAs can use both
OpenAI's dots and a verifiable agent are not competing for the same job. Let people use dots for the work around them, where every task is different and the person who asked checks the result.
Put the repeated client work, account opening, CRM updates, and service requests, on an agent the firm can verify. That is what Caddi builds: an ops person shows Caddi the workflow on a screen share or describes it in chat, Caddi runs it as code across the firm's tools with the judgment steps logged, and the team changes it in plain English as the work changes. Across Caddi customers, 99% of agent runs complete successfully.
Keep reading
- What are verifiable AI agents?
- Grok Bot vs. Muse vs. Dots for professional services firms
- Grok Bot for RIAs
- Meta Muse for RIAs
- OpenAI Dots for law firms
- OpenAI Dots for professional services
- Caddi for RIAs and wealth managers
- Client onboarding automation
- RIA compliance automation
- Caddi + Wealthbox
- The Wealth Advisory COO's Guide to AI
- What are hybrid agents?
Caddi
See how Caddi AI Agents can run your RIA's back office the same way every time and log every run for compliance
Frequently asked questions
Is OpenAI Dots safe for RIAs?
OpenAI's dots have real safeguards: custom Rules, Auto-review, and hard stops. For a person's own work, those are sensible. For repeated client work, an RIA also has to answer for supervision, records, and confidentiality, and dots plan each run fresh with records kept per user. Most firms will keep it for personal work and use a verifiable agent for client workflows.
Can OpenAI Dots run account opening, CRM updates, and service requests unattended?
They can attempt it: dots work in the background and can reach many apps. But each dot decides how to handle each case on that run, and the vendor does not claim repeatable runs, so the firm cannot test the procedure once and rely on it. For unattended client work, a verifiable agent that runs the steps as code is the safer fit.
Does OpenAI Dots keep an audit trail?
Activity View shows each user what their dot is doing, has scheduled, and has finished. OpenAI's dots materials do not describe an exportable audit log or an admin-level log of dot activity. For RIAs, check whether that record can be exported, retained, and reviewed at the firm level before relying on it.
Does OpenAI Dots train on our data?
Business, Enterprise, and Edu content is not used for training by default; on personal plans it depends on the Improve the model setting, which can include actions your dot takes. Disconnecting an app does not delete what your dot already pulled from it; removing that data means resetting the dot.
What should an RIA use for repeated client work?
A verifiable agent: one whose procedure you can read, whose judgment steps are logged, and whose every run leaves a record. Caddi builds these for RIAs. Your team shows the workflow on a screen share or describes it in chat, and Caddi runs it as code across your tools, with exceptions routed to a named person.