Persistent AI coworkers can continue work beyond a chat session, retain context, and operate inside connected business tools. The deployment decision is therefore broader than conversational quality. Before adopting Dots, Grok Team Bots, or another persistent agent, determine whose authority it uses, what it remembers, which actions need review, and how work recovers after a failure. Those answers define the practical responsibility you can safely delegate.
What Dots and Team Bots actually introduce
OpenAI introduced Dots on September 29 with a cloud computer, connected apps, ongoing work, and action controls. Its announcement distinguishes read-only proactive research from work that can take actions. Enterprise beta access depends on administrator enablement. SpaceXAI's September 28 Team Bots release combines shared skills, context, plugins, credentials, and memory, while describing separate private conversations for individual users.
That difference is operationally important: a personal assistant working on behalf of one person and a shared agent used by a department need different ownership rules. Product descriptions do not settle every edge case in your environment. Treat access and memory behavior as items to verify during configuration and testing.
Assign a responsibility that has an observable finish
“Help the sales team” is too broad to evaluate. “Prepare a daily brief of accounts whose renewal dates are within the next month, using approved CRM fields, and leave a draft for the account owner” has a defined input, output, and reviewer. It also exposes where stale data or missing permissions could cause a failure.
Begin with a workflow that creates a reviewable output before it creates an external consequence. A draft invoice, proposed CRM update, or prepared support response lets a team assess accuracy and context handling. Expanding from preparation to execution should be an explicit decision supported by observed results.
Check identity and access before adding tools
| Control | Question to answer | Why it matters |
|---|---|---|
| Identity | Does the agent use an individual or dedicated service identity? | Defines authority, audit attribution, and offboarding |
| Resource scope | Which records, folders, workspaces, and channels can it access? | Prevents broad credentials from becoming accidental broad authority |
| Mutation | What can it create, change, send, or delete? | Separates information gathering from consequential action |
| Review | Which actions require approval, and who approves them? | Makes the permission boundary operational |
| Revocation | What happens to queued work when access is removed? | Avoids leaving unattended work with obsolete authority |
A browser connection deserves the same attention as an API connection. Logged-in browser state can expose actions the team did not intend to delegate. Document the actual resources and actions, not just the connector's friendly name. Approval requirements should reflect the impact of the action, including messages sent to customers or edits to canonical business records.
Make memory useful without making it authoritative
An agent's remembered preference can improve a draft. It should not override current policy or become the sole record of a customer commitment. Keep canonical data in the systems that own it. Treat agent memory as context to be checked when it conflicts with updated instructions or current records.
For shared agents, test what information transfers between users and what stays private. Include a case where one employee provides confidential context and another asks a related question. Also test corrections: when a policy changes, can the agent stop applying the previous version? A polished demonstration of memory is not enough to answer those governance questions.
Design for interruption, partial work, and review queues
A long-running task may complete one action before a tool or network failure interrupts the next. Re-running the entire task can produce duplicate invoices, messages, or record updates. Inspect whether your workflow can detect completed work and resume safely. Consequential operations need a reliable way to identify what already happened.
Review queues also need ownership and response expectations. If an agent produces hundreds of drafts no one has time to assess, it has moved the bottleneck rather than removed it. Measure accepted work, correction time, and unresolved approvals alongside the number of tasks attempted.
Choose by workflow fit, then expand cautiously
Evaluate the product that fits your existing identity, tool, and collaboration environment. Use the same bounded task to compare setup effort, permission visibility, quality of completed work, and recovery behavior. Record subscription allowances and any usage costs separately from the amount of human review the workflow needs.
This article does not rank products from hands-on testing. Its recommendation is a deployment sequence: define the responsibility, constrain access, inspect memory, validate recovery, and measure accepted output. A persistent coworker becomes useful when its operating boundaries are as clear as its capabilities.