User reports Codex searched Gmail after connecting it to Dots
Ben Hylak reports his work Codex app unexpectedly searched Gmail after he connected it to Dots. The thread disputes whether approval instructions adequately protect shared access.

TL;DR
- Gmail connected for Dots became available in the Codex app used for work, with unexpected searches, according to benhylak's report.
- Dots can now start Codex work and follow up on existing threads, drawing on shared conversation and automation context, per the product announcement.
- Email confirmation became the dispute: pvncher said the skill reliably asks first, while Hylak claimed he could get Codex to send without explicit approval.
- Long-running task management also drew complaints: koltregaskes reported difficulty handling roughly 30 jobs introduced over two hours.
OpenAI documents shared connections and permissions across Dots, ChatGPT, ChatGPT Work, and Codex, an awkward boundary for personal email beside work code. Dots can also read connected apps proactively, even without a specific request.
Gmail in a work Codex session
Ben Hylak says connecting Gmail to Dots gave the Codex app he uses for work access to the same mailbox. He described searches happening at “pretty random times” and argued that Dots should have been a separate app.
Hylak subsequently resurfaced the complaint in a post aimed at Google, writing “google needs @raindrop_ai.”
Shared app permissions
OpenAI explicitly says both plugin connections and their permissions are shared across the four products in its Dots privacy FAQ.
App permissions control when available capabilities can run. They do not grant provider access, disconnect accounts, or override workspace policies, according to OpenAI's permissions guide.
The guide lists four options, where supported:
- Always ask: confirmation before reading information or making changes.
- Allow read actions: reads without asking; changes require confirmation.
- Allow low-risk actions: automatic approval for low-risk actions; higher-risk actions can require confirmation or be denied.
- Allow all actions: supported actions without additional approval prompts, subject to applicable safety protections.
Availability depends on the account, app, connection, and workspace. “Allow all actions” is absent from the standard account-wide and workspace-wide selectors, but can be available for an individual app or connected account.
Dots in ChatGPT and Codex
OpenAI's October 5–9 release notes expand the work a dot can initiate across its products:
- Mobile setup: create and customize a dot in ChatGPT on iOS and Android, as shown in the mobile announcement.
- Codex delegation: start work or follow up on existing Codex threads.
- Context: draw on ChatGPT conversations, Codex threads, and automations when deciding whether to continue a thread or start fresh.
- Scheduled Tasks: review and edit recurring work in ChatGPT Work.
Before the Gmail complaint, Hylak had questioned a cheek-shaped avatar and shared a Grok Bot joke.
Email confirmation dispute
The email skill requires confirmation and is “very good at always asking first,” according to pvncher. Hylak replied that he could make Codex send an email without his explicit approval “in any number of ways.”
pvncher subsequently reported no incidents despite having kept the connection active “for ages.”
Four custom-rule modes
For supported dot actions, OpenAI's setup guide exposes four behaviors:
- Take action without asking.
- Take action if pre-approved.
- Ask before taking action.
- Hand off to you.
“Pre-approved” means the user explicitly requested the action in their prompt. The guide also warns that a dot can make mistakes when following these rules.
The Android discoverability complaint in that thread was later resolved: koltregaskes reported finding the settings after another user pointed them out.
Auto-review
OpenAI lists five protection layers for Dots:
- Model safeguards: refusals for harmful requests.
- Plugin permissions: limits on accessible information and capabilities.
- Custom Rules: additional boundaries for supported actions.
- Auto-review: checks on certain planned actions before execution.
- Safety monitoring: checks for potentially harmful behavior during work.
For email, Auto-review checks the recipient and message for problems such as a wrong address or unintended disclosure. Custom Rules cannot disable required Auto-review checks, and action rules also apply when a dot delegates work or continues in the background.
Proactive research has narrower tools: it can read permitted sources and save private notes, but cannot directly send messages, change content through plugins, or control a browser or computer. OpenAI says its protections reduce prompt-injection risk without eliminating it.
Delegated approvals
A separate user reported the opposite failure mode: a specific approval given to a dot was rejected by the task performing the work. In an October 9 community report, cedar_circuit described this sequence:
- Request a read-only check of a private operational dashboard and logs.
- Approve browser access in the main conversation.
- Have the assistant relay the exact approval question and affirmative reply to a local task.
- Receive a rejection saying that relayed approval could not authorize the action there.
- Open the task and approve again, after which the browser workflow succeeded.
The user identified the environment as the macOS desktop app with a delegated task using Brave. They described direct approval inside the task as a workaround for that case.
Task backlog
koltregaskes said Dots struggled with roughly 30 jobs introduced during a two-hour conversation. Their desired behavior was 30 agents working in the background while the conversation continued, an expectation rather than a reported feature.
They also wondered whether their own customization was contributing to the failures.
Memory retention
Disconnecting an app stops future access through that connection, but leaves information already incorporated into a dot's context, according to OpenAI's retention FAQ.
The same FAQ distinguishes three deletion boundaries:
- Individual dot memories currently cannot be viewed, deleted, or directly modified, including details learned through plugins.
- Deleting the dot deletes its own context.
- Files, Codex threads, and ChatGPT conversations created by the dot are stored separately and survive deletion of the dot.