Back to all posts

cat posts/openai-dots-audit-log-whose-action-was-that.md --category "AI & Cloud Infrastructure" --views 11

OpenAI Dots and the audit log: whose action was that?

A standard OpenAI dot acts on its owner's account, so downstream logs name the employee and cannot separate attended from unattended action, while Microsoft's Entra agent labels never see it. Specialist dots with their own identity are in pilots with an undated Agent 365 integration, so today's controls are plugin scope, the four rule levels, role permissions and a usage policy written for agents.

  • --author By Falak Mahmood
  • --date October 4, 2026
  • --read 12 min read
  • --views 11 views

A standard OpenAI dot works on its owner's account. When it sends an email at 03:10 while the owner is asleep, the mailbox records that the owner sent it. The German consultancy innFactory compressed the consequence into one sentence the day after launch: an agent working with an employee's credentials "is indistinguishable from that employee in an audit". This is part three of our Dots series. Part one described the product and part two compared it with Meta Muse. Here the subject is narrower and more practical: what your logs can and cannot tell you once dots are switched on, what Microsoft's agent identity model would change, and which controls exist today for a company that does not want to wait.

Two kinds of dot, two kinds of log entry

OpenAI describes two classes of dot. The standard dot is the one included with Pro and Business Premium plans and available as an admin-enabled beta in Enterprise workspaces. It reaches other systems through the ChatGPT plugins its owner already connected and, for supported websites, through the owner's saved passwords. The specialist dot is in enterprise pilots. In the wording The Next Web took from the launch, specialist dots "get their own identity, credentials and access to company systems to take on set roles". OpenAI says it tested them internally in procurement, invoice processing and customer support, among other functions.

For an auditor, that split decides everything that follows.

Question Standard dot Specialist dot
Whose identity acts?The employee'sIts own
Whose permissions?Whatever the employee granted to ChatGPT plugins, plus saved loginsAssigned to the dot by the company
Actor in downstream logsThe employeeThe dot
OffboardingTied to the employee's accountIts own lifecycle
Availability on 4 October 2026ShippingEnterprise pilots only

The dot a Swedish company can enable this month is the one in the middle column.

What the downstream log actually records

"Indistinguishable" deserves a closer look, because the picture differs by access path.

Plugin access. A ChatGPT plugin to a mailbox or a file store is a delegated OAuth grant. In Microsoft 365, delegated access is logged with the user as the actor and the client application's ID alongside. So an investigator can usually see that an action arrived through the ChatGPT integration and did not come from Outlook on the employee's laptop. That is useful, and it is also where the trail stops. Plugin permissions are shared across dots, ChatGPT, ChatGPT Work and Codex. The same application ID appears whether the employee typed a request into a chat window and watched the result, or a dot decided at 03:10 to act on a rule written two weeks earlier.

Browser sign-in. When a dot signs in to a website with a saved password, the target system sees a login by that user from a cloud address. No application ID marks it as an agent.

Local computer access. This is off by default and must be confirmed in the desktop app. Once on, actions happen on the employee's machine in the employee's session.

OpenAI has not published a description of the fields a dot leaves in third-party logs, and we have not run a dot against a test tenant, so treat the above as how delegated access behaves in general. The point that survives any testing is the missing distinction between attended and unattended action. Your SIEM can answer "did this come through ChatGPT?" It cannot answer "was a person in the loop?"

What OpenAI's own side records

The other place to look is OpenAI's records. Three things are known.

First, the owner can open the dot's cloud computer and check its work at any time. That is a review tool for one user. It does not give a security team a queryable trail.

Second, OpenAI runs a Compliance Platform that feeds workspace logs to eDiscovery, DLP and SIEM tools. Its help article addresses Enterprise and Edu customers and states that the logs platform retains data for 30 days, after which the customer's own archive is the only copy. We found no statement that Business Premium workspaces get it, and Business Premium is the plan through which most Swedish companies would reach dots. On coverage, the Creuto analysis of OpenAI's dots admin guide, published 2 October, reports the instruction to confirm record coverage before relying on the Compliance API for an audit. For local computer access it reports that the available sources "do not establish a complete record of every local command, file operation, screenshot, approval, or external action". The same analysis quotes a line every Enterprise admin should read twice: "Enterprise model controls and defaults do not apply to dots."

Third, memory. OpenAI's help text says the memories of an individual dot cannot currently be viewed or edited. A dot's memory can be paused, and deleting the dot deletes its context. Creuto adds two limits on what deletion achieves: disconnecting an app "does not delete information already obtained", and deleting a dot does not recall messages already delivered. For an investigation this means the reasoning behind an action may sit in a store nobody in the company can read. Tomorrow's part four takes up what that does to a GDPR access request.

What Entra Agent ID changes in the log

Microsoft's answer to this class of problem is to make the agent a principal in the directory. Entra Agent ID gives an agent its own object, and the Entra logs were extended so that agent activity is labelled. The audit log schema now carries an agentType property on the initiator, the performer and the target of an event. The documented values are worth knowing by name:

  • notAgentic: a normal user, application or service principal.
  • agenticApp: an agent identity blueprint, the template for an agent.
  • agenticAppInstance: an agent identity, one running instance.
  • agentIDuser: an agent's user account, which lets the agent act with user-delegated permissions under its own name.

Sign-in logs gained an agentSignIn event type and two filters in the Entra admin center, "Agent type" and "Is Agent". Microsoft's documentation gives the Graph request for agent sign-ins, which is on the beta endpoint today:

GET https://graph.microsoft.com/beta/auditLogs/signIns
  ?$filter=signInEventTypes/any(t: t eq 'servicePrincipal')
  and agent/agentType eq 'AgentIdentity'

Put a standard dot next to that schema. Its plugin actions are delegated to a human user through an ordinary application, so every one of them is notAgentic. The "Is Agent" filter returns nothing. The tenant has an always-on agent with mailbox access, and the directory built to label agents does not know it exists.

A specialist dot with an Entra agent identity would be the opposite case. It would appear as agenticAppInstance or agentIDuser, it could be scoped with its own access policies, and it could be disabled without touching any employee's account.

Agent 365: what is promised and what is live

Agent 365 is Microsoft's control plane on top of those identities. It has been generally available since 1 May 2026, licensed per user, with Microsoft E5 named as the recommended prerequisite. It adds a registry of agents in the Microsoft 365 admin center, observability, and policy through Entra, Purview and Defender. Partner platforms that integrate get, in Microsoft's words, "a governed Microsoft Entra Agent ID" for every agent they create.

OpenAI's statement at launch was that it is "working with Microsoft to bring specialist dots to Agent 365". Three qualifications belong next to that sentence.

  • No date. None of the launch material we checked gives one.
  • Not listed yet. Microsoft's page of ecosystem partner agents, updated 1 October 2026, lists 23 partners from Achievers to Zoho. OpenAI is not among them.
  • Specialist dots only. Nothing published says standard dots will get a directory identity. The dot most companies can run today is outside the scope of the announced fix.

So Agent 365 is a sound destination and a poor plan for this quarter. Until specialist dots ship with that integration, governance of standard dots happens inside ChatGPT's admin settings and inside your own policy.

The control surface that exists today

These are the levers reported from OpenAI's help centre and admin guide as of 4 October 2026.

Control What it does Limit
Workspace switch (Enterprise)Dots are off until an admin enables the betaBusiness Premium rolls out without that default
Role permissionsFour: Use dots, Add dots to Slack, Allow local computer access, Use custom rules for dotsCoarse: per role, not per action
Plugin controlsAllow read-only actions or an approved custom set per connectionApplies to plugins, not to browser sign-ins
Custom RulesPer action type: act without asking, act if pre-approved, ask first, hand offWritten by the user. If an admin disables custom rules, saved rules stop applying
Auto-reviewChecks planned actions against instructions, rules and OpenAI's safety requirementsOpenAI states dots can make mistakes, including when following rules
Fixed floorPassword changes and money transfers always go to the humanSending, sharing and editing are not on the floor

Two observations. The strongest lever for attribution is plugin scope: a dot whose mailbox connection is read-only cannot send anything in the employee's name, whatever its rules say. And the "ask before acting" level does more than reduce risk. It produces an approval by a human for each action, which is the closest thing to an attribution record the product offers today. Whether those approvals reach the Compliance Platform as exportable events is one of the coverage questions to put to OpenAI.

What to write into the AI usage policy

Most company AI policies were written for chat assistants. They cover what may be pasted into a prompt. An agent that acts under a staff member's name needs clauses the chat era never required.

  1. Accountability. State that an employee is responsible for actions their dot takes under their identity, and that the company in turn limits what a dot may do unattended. One without the other is unfair to the employee.
  2. Unattended action list. Name the action types that may run without approval. A reasonable starting list is read, search, draft and summarise. Sending external email, sharing files outside the organisation and editing shared documents stay at "ask before acting".
  3. Plugin inventory. Require a review of each pilot user's existing ChatGPT plugin connections before their dot is enabled. The dot inherits them with no new consent step.
  4. No saved passwords for company systems. Browser sign-in is the path with the least attribution. Keep it to systems that hold no company data until there is a better answer.
  5. Local computer access off. Leave the role permission disabled for the pilot.
  6. Disclosure. Decide whether messages sent by a dot must say so. A one-line signature rule is cheap and gives recipients and investigators a marker the logs do not.
  7. Log export. If the workspace has the Compliance Platform, export continuously to your own store. Thirty days is shorter than most incident timelines.
  8. Offboarding. Add "delete dots and revoke ChatGPT plugin grants" to the leaver checklist, and record that deletion does not recall anything already sent.

The Swedish and EU angle

Attribution is a compliance requirement under several regimes a Swedish company already lives with, well beyond good security hygiene. GDPR's accountability principle in Article 5(2) expects a controller to demonstrate how personal data was processed, and Article 32 expects security measures appropriate to the risk. An organisation that cannot say whether a person or an agent sent a file containing personal data will find both harder to evidence. Entities covered by NIS2, implemented in Sweden through the Cybersecurity Act, have incident reporting duties with short deadlines, and an incident report that cannot separate human from automated action starts from a weak position. This is general orientation, not legal advice. The assessment for a specific deployment belongs with your data protection officer.

There is also a workplace dimension that Swedish employers will recognise. A log that names an employee as the actor is evidence about that employee. If it can be wrong in a systematic way, that is a matter to raise with employee representatives before the pilot, in the same conversation as any other monitoring or logging change.

Availability sharpens all of this. ChatGPT Pro subscribers in the EEA, Switzerland and the UK are still excluded, while Business Premium rolls out across all supported ChatGPT regions. The route open to Swedish companies is therefore the plan where the default-off switch and, as far as published material shows, the Compliance Platform are least certain. Part four tomorrow covers the EU position in full.

When the answer is your own tenant

Some workloads need an actor in the log that is unambiguously an agent: invoice handling, anything touching customer personal data at volume, anything a regulator may ask about. For those, the pattern innFactory describes is available now without waiting for specialist dots: "an agent is a principal in the directory, with its own rights, its own lifecycle and its own log". An agent built in Azure AI Foundry on the same GPT-6 Astra family can run under an Entra agent identity, show up under the "Is Agent" filter, and write to a Log Analytics workspace you control with retention you set. The cost is that you build and operate it, and it will not have 4,000 plugins on day one. Our earlier post on the GPT-6 Astra capabilities covers what the model can carry, and the Azure OpenAI integration offers describe how we scope that build.

Checklist before the first dot is enabled

  • Ask OpenAI in writing which dot events the Compliance Platform exports, whether approvals are among them, and whether your plan includes it.
  • Find the ChatGPT application IDs in your Entra sign-in and Purview audit logs, and build a saved query for them.
  • Set mailbox and file plugins to read-only for the pilot group.
  • Keep "Allow local computer access" disabled.
  • Publish the unattended action list and the disclosure rule before anyone names their dot.
  • Add dots to the offboarding checklist.
  • Ask your Microsoft and OpenAI account teams for a date for specialist dots in Agent 365, and record the answer.

subscribe # the AI news that matters, minus the noise

Book a Call

Sources

Tags

Related posts