Skip to content
AI Primer
breaking

User reports Codex searched Gmail after connecting it to Dots

Ben Hylak reports his work Codex app unexpectedly searched Gmail after he connected it to Dots. The thread disputes whether approval instructions adequately protect shared access.

5 min read
User reports Codex searched Gmail after connecting it to Dots
User reports Codex searched Gmail after connecting it to Dots

TL;DR

OpenAI documents shared connections and permissions across Dots, ChatGPT, ChatGPT Work, and Codex, an awkward boundary for personal email beside work code. Dots can also read connected apps proactively, even without a specific request.

Gmail in a work Codex session

Ben Hylak says connecting Gmail to Dots gave the Codex app he uses for work access to the same mailbox. He described searches happening at “pretty random times” and argued that Dots should have been a separate app.

Hylak subsequently resurfaced the complaint in a post aimed at Google, writing “google needs @raindrop_ai.”

Shared app permissions

OpenAI explicitly says both plugin connections and their permissions are shared across the four products in its Dots privacy FAQ.

App permissions control when available capabilities can run. They do not grant provider access, disconnect accounts, or override workspace policies, according to OpenAI's permissions guide.

The guide lists four options, where supported:

  • Always ask: confirmation before reading information or making changes.
  • Allow read actions: reads without asking; changes require confirmation.
  • Allow low-risk actions: automatic approval for low-risk actions; higher-risk actions can require confirmation or be denied.
  • Allow all actions: supported actions without additional approval prompts, subject to applicable safety protections.

Availability depends on the account, app, connection, and workspace. “Allow all actions” is absent from the standard account-wide and workspace-wide selectors, but can be available for an individual app or connected account.

Dots in ChatGPT and Codex

OpenAI's October 5–9 release notes expand the work a dot can initiate across its products:

  • Mobile setup: create and customize a dot in ChatGPT on iOS and Android, as shown in the mobile announcement.
  • Codex delegation: start work or follow up on existing Codex threads.
  • Context: draw on ChatGPT conversations, Codex threads, and automations when deciding whether to continue a thread or start fresh.
  • Scheduled Tasks: review and edit recurring work in ChatGPT Work.

Before the Gmail complaint, Hylak had questioned a cheek-shaped avatar and shared a Grok Bot joke.

Email confirmation dispute

The email skill requires confirmation and is “very good at always asking first,” according to pvncher. Hylak replied that he could make Codex send an email without his explicit approval “in any number of ways.”

pvncher subsequently reported no incidents despite having kept the connection active “for ages.”

Four custom-rule modes

For supported dot actions, OpenAI's setup guide exposes four behaviors:

  1. Take action without asking.
  2. Take action if pre-approved.
  3. Ask before taking action.
  4. Hand off to you.

“Pre-approved” means the user explicitly requested the action in their prompt. The guide also warns that a dot can make mistakes when following these rules.

The Android discoverability complaint in that thread was later resolved: koltregaskes reported finding the settings after another user pointed them out.

Auto-review

OpenAI lists five protection layers for Dots:

  • Model safeguards: refusals for harmful requests.
  • Plugin permissions: limits on accessible information and capabilities.
  • Custom Rules: additional boundaries for supported actions.
  • Auto-review: checks on certain planned actions before execution.
  • Safety monitoring: checks for potentially harmful behavior during work.

For email, Auto-review checks the recipient and message for problems such as a wrong address or unintended disclosure. Custom Rules cannot disable required Auto-review checks, and action rules also apply when a dot delegates work or continues in the background.

Proactive research has narrower tools: it can read permitted sources and save private notes, but cannot directly send messages, change content through plugins, or control a browser or computer. OpenAI says its protections reduce prompt-injection risk without eliminating it.

Delegated approvals

A separate user reported the opposite failure mode: a specific approval given to a dot was rejected by the task performing the work. In an October 9 community report, cedar_circuit described this sequence:

  1. Request a read-only check of a private operational dashboard and logs.
  2. Approve browser access in the main conversation.
  3. Have the assistant relay the exact approval question and affirmative reply to a local task.
  4. Receive a rejection saying that relayed approval could not authorize the action there.
  5. Open the task and approve again, after which the browser workflow succeeded.

The user identified the environment as the macOS desktop app with a delegated task using Brave. They described direct approval inside the task as a workaround for that case.

Task backlog

koltregaskes said Dots struggled with roughly 30 jobs introduced during a two-hour conversation. Their desired behavior was 30 agents working in the background while the conversation continued, an expectation rather than a reported feature.

They also wondered whether their own customization was contributing to the failures.

Memory retention

Disconnecting an app stops future access through that connection, but leaves information already incorporated into a dot's context, according to OpenAI's retention FAQ.

The same FAQ distinguishes three deletion boundaries:

  • Individual dot memories currently cannot be viewed, deleted, or directly modified, including details learned through plugins.
  • Deleting the dot deletes its own context.
  • Files, Codex threads, and ChatGPT conversations created by the dot are stored separately and survive deletion of the dot.

Further reading

Discussion across the web

Where this story is being discussed, in original context.

On X· 5 threads
TL;DR1 post
Gmail in a work Codex session1 post
Dots in ChatGPT and Codex3 posts
Email confirmation dispute2 posts
Four custom-rule modes1 post
Share on X