Dot 4 / Boundaries
Set boundaries before giving more responsibility
Separate preparation, approval, and work that should stay out of scope.
Write down three kinds of action
A useful brief answers three different questions: what may proceed, what needs approval, and what must not happen. Avoid a broad “do whatever is needed” instruction. It hides the decisions you should make deliberately.
For a follow-up assistant, the arrangement could be:
- May proceed: read the selected, authorized records and prepare a private summary.
- Ask first: send a message, make a purchase, delete a record, change access, or change a production system.
- Do not do: contact a customer about a legal dispute or include unrelated personal information.
The third list wins if it conflicts with the other two. A prohibition does not become an approval request just because another sentence sounds permissive.
Be specific about approval
“Ask before important things” leaves “important” undefined. Name the action, recipient or target, scope, and any limit. For a proposed message, review the actual recipient and wording. For a proposed edit, review the specific file and change.
Approval for one action should not be silently stretched to cover unrelated future work. Our builder uses conservative defaults and flags ambiguous permission text rather than broadening it.
Review actual product controls separately
A brief expresses your intentions. It does not enforce permissions, connect accounts, or override product safeguards.
OpenAI documents separate plugin permissions, Custom Rules, and built-in safety checks. Custom Rules cannot disable mandatory safeguards. Official Dots safety explanation.
OpenAI also distinguishes proactive research from authorized action: research tools cannot directly message people, modify connected content, or control a browser or computer. Official privacy FAQ.
Check the current settings and documentation in your account. Do not assume a pasted paragraph has configured them.
Decide when work should stop
Write interruption rules for missing authorization, conflicting facts, a request outside scope, an unexpected cost, or an action that cannot be undone. Give the helper a useful alternative: explain what is blocked, show the evidence, and suggest a smaller permitted next step.
“Stop and ask” is easier to act on when it includes what the question should contain.
Try this now
Take one responsibility and list three actions it might lead to. Assign each to “may proceed,” “approval,” or “prohibited.” If you cannot decide, keep it out of autonomous work for the first test.
Read the resulting brief for contradictions. Pay attention to phrases such as “always,” “anything,” and “without asking.”
Common mistakes
Confusing instructions with enforcement. Review settings as well as wording, then inspect consequential work.
Allowing a whole category after one example. Keep permission narrow enough that you can describe what you approved.
Expecting perfect compliance. Clear boundaries help communicate intent; they are not a guarantee. Keep first tests reversible and reviewable.
Your next dot
A working arrangement needs a review loop. Continue to Give feedback that improves the next result.
Official references
Source check: September 29, 2026. A source check is not hands-on testing.