You are about to connect your email, calendar or messages to an AI agent that keeps working after you close the app. OpenAI’s dots, Grok Bot and Meta’s Muse are three such agents. [1] [2] [3] Their official pages are reassuring: OpenAI calls the tools a dot uses for background research “read-only”, Grok Bot has “Ask first” rules, and Meta’s small-business announcement for Muse says “You’re in control”. [4] [5] [6]
Each phrase means something narrower in the product’s own documentation. Three points from those pages, as they read on 30 September 2026:
- Reading and acting are separate permissions. Meta says that for email, people choose “whether it reads their mail or can also send on their behalf”. [3]
- “Read-only” describes what the tools can change in your apps. It leaves open what the agent keeps. OpenAI’s read-only research still saves “private notes”, and a dot can “form memories” from connected information. [7] [1]
- An approval is not an undo. The Grok Bot documentation says: “An approval controls the proposed action. It does not reverse work already completed.” [5]
What the official pages say
Each of the three works on a computer in the cloud. [1] [8] [3] Each cell below is what that product’s pages say. The designs differ, so this is not a ranking.
| Question | dots (OpenAI) | Grok Bot | Muse (Meta) |
|---|---|---|---|
| 1. What it does without being asked | Background “proactive research” with read-only tools. Authorized and scheduled tasks also run in the background, under the action rules [4] [9] [1] | Routines run on a schedule or after an event; a test run “performs real work”. The launch post says Bots “become more proactive”. A read-only research mode is not documented in the pages we read [10] [11] [5] | Proactive by default, and adjustable. Works “on a schedule and in response to relevant events”. Some connectors send it updates [12] [13] |
| 2. What it keeps from reading | Private notes, and memories formed from connected apps. Individual memories cannot be viewed or edited [7] [1] [9] | A Bot can retain “stable preferences, role context, and summaries of prior work”. A memory editor for a personal Bot is not documented in the pages we read [2] [14] | Memories from conversations, observed patterns and connectors, in a file you can open and edit [15] [16] [17] |
| 3. What asks you by default | Built-in rules decide. Auto-review, a separate check, runs before actions such as sending email or changing files. Purchases need approval [4] [7] | Depends on the tool, the risk and your Auto Review rules. “Sensitive or consequential actions can stop for approval.” [2] | By default it will not take “many important actions, like sending an email” without approval [13] |
| 4. What you can approve ahead | Custom Rules, from “Take action without asking” to “Hand off to you”. Advance approval for some things, such as recurring messages [1] [9] | “Always allow” can save a rule. “Allow automatically” rules still pass through the automated review [5] | “Allow for this task”, “Allow for this site”, or “Always allow” for a connector [18] |
| 5. What comes back to you every time | Each time: permanently deleting data, software from an unrecognized source, new security-sensitive access. Handed back: password changes, money transfers [7] | Passwords, passkeys, two-factor codes, CAPTCHAs, payment confirmations. “Ask first” rules always stop, and win over “Allow automatically” [5] | Checkout on a site holding your payment details: approval “every time”. Under “Always ask”: any action [17] [18] |
| 6. Whether the checking can be switched off | Custom Rules cannot remove mandatory confirmations or change Auto-review; a dot cannot turn off required checks [7] [9] | Members can turn Auto Review off unless an Enterprise admin enforces it. It does not review memory writes or most settings changes [19] [20] | Muse “can’t override” Sentinel, a separate agent on the same machine that decides whether to allow, deny or ask. Whether you can switch it off is not documented in the pages we read [17] [3] |
| 7. Your own computer | Optional; “starts turned off” [1] | A separate setting. “The default is Ask every time.” [5] | The Mac app works under macOS permissions such as Full Disk Access [21] |
| 8. How you stop it | Pause it from its profile; ask it to stop in Activity View [1] [7] | “Stop now” message; pause or delete routines. Hiding a Bot does not pause it [22] [5] [14] | Ask it in chat to stop some actions; disconnect a connector [18] |
What “read-only” leaves out
OpenAI’s help page says a dot can review connected information proactively “and form memories from it, even when you haven’t asked a new question.” [1] Disconnecting an app later “does not delete information your dot has already obtained from it.” [1]
In Muse, reading can go ahead without a prompt. Meta’s safety post says: “Read-only, previously allowed, or demonstrably low-risk actions can proceed without interruption.” [17] After you disconnect a connector, the data Muse used from it “may remain in Muse’s memories and your conversation history.” [13]
In Grok Bot, saving to memory sits outside the automated check. The security page says of Auto Review: “It does not review every side effect. Memory writes and most settings changes are examples.” [20]
Our reading of these pages: an agent limited to reading can still build its own record of what it read. “Read-only” tells you whether it can change your apps; row 2 is about what it remembers.
What an approval does not do
Approving lets a proposed action run, and stopping ends work that is still going. Neither is an undo. In the Grok Bot docs, a “Stop now” message ends work immediately but “does not undo actions the Bot already completed.” [22] OpenAI’s FAQ says: “You can ask your dot to help correct a mistake, but some actions cannot be undone.” [9] Meta’s help page gives an example: “Some other actions, like sending an email, cannot be reversed”. [18]
An approval can also last longer than the moment you gave it. In Grok Bot, choosing Always allow “can save a matching rule”. [5] In Muse, “Always allow” means it “can take this type of action for this Connector in the future without asking again”. [18] OpenAI’s FAQ says that for dots, “Approving one message does not give your dot ongoing permission to contact people on your behalf”, and that any advance approval “remains limited to what you authorized.” [9]
What the pages say about mistakes
OpenAI and Meta both say outright that their agents can make mistakes. OpenAI’s help page: “Your dot can make mistakes, including when following your rules.” [1] Meta’s: “Your Muse can make mistakes or take unexpected actions.” It adds: “You’re responsible for fixing errors, including with third party services or recipients.” [18]
The Grok Bot pages we read do not use the word “mistake”. They do warn that a Bot can work from out-of-date information: “Memory is not a substitute for an authoritative source”, and one instruction is to “Correct stale assumptions directly”. [14] Of the automatic check they say: “Auto Review is model-based and should complement, not replace, least privilege and explicit approval boundaries.” [5]
Eight things to decide before you switch on background work
Row numbers refer to the table.
- Which accounts it may read (rows 1 and 2). Check what is already connected. OpenAI says plugin permissions “are shared across dots, ChatGPT, ChatGPT Work, and Codex”, and Meta says Facebook, Instagram and Threads “are connected automatically if you have your accounts in the same Accounts Center.” [9] [23]
- Whether reading may become memory you cannot open (row 2). Find out where notes and memories are kept, whether you can read and edit them, and what remains after you disconnect a source.
- Which actions must always ask (rows 3 and 5). The Grok Bot docs give a sample rule: “Ask first before sending any external email.” [5]
- What you will pre-approve, and for how long (row 4). Our suggestion: take the narrowest grant on offer, such as once or for one task.
- What you check before approving a send (row 3). OpenAI suggests being specific about “who it should go to, what it should say, and when or under what conditions it should be sent.” [9] See what to check before an AI sends your message.
- Whether the automatic check can be switched off, and by whom (row 6).
- Whether it can reach your own computer (row 7). On a Mac that can involve Full Disk Access, which Meta’s help page says “covers all the files on your Mac”. [21]
- How you stop it (row 8). Find the pause or stop control before you need it.
Where Kluro sits
Kluro publishes this article and makes a Mac app in the same broad area; it overlaps with these agents on the reading side. It searches the conversations in the sources you have connected and brings back the relevant exchange, which you can open to check. Kluro’s pages describe finding, remembering and preparing; they do not describe Kluro sending messages or acting in other apps for you. Row 2 applies to it too: saved memory stays encrypted on your Mac, and enabled hosted AI processes relevant content for answers and background understanding (privacy), so not everything happens on the device. None of the three agents is among the sources Kluro connects to.
How we checked
We read the products’ public announcements, help pages, documentation and policies on 30 September 2026. We did not install, operate or test dots, Grok Bot or Muse, and ran no comparison, so this article cannot tell you how they behave. “Not documented in the pages we read” means only that. Settings screens behind a login were not seen.
Official pages disagree in two places. OpenAI’s safety post says some actions “require your confirmation each time”, while its help FAQ says such actions “may require approval each time”. [7] [9] Meta’s small-business page says “Nothing publishes, sends or spends without your approval, and you can undo it”, while its help page says sending an email cannot be reversed. [24] [18] Help pages change without notice, so reread the current wording before you connect an account.
Sources
- Getting started with your dot — OpenAI Help Center. Living documentation. Checked 30 September 2026.
- Frequently asked questions — SpaceXAI Docs. Updated 29 September 2026. Checked 30 September 2026.
- Introducing Muse: The World’s First Personal AI Agent Built for Everyone — Meta Newsroom. Published 8 September 2026; updated 30 September 2026. Checked 30 September 2026.
- Introducing dots — OpenAI. Published 29 September 2026. Checked 30 September 2026.
- Approvals, security, and privacy — SpaceXAI Docs. Updated 28 September 2026. Checked 30 September 2026.
- The Future Is for Everyone: Muse for Small Business — Meta Newsroom. Published 29 September 2026. Checked 30 September 2026.
- How we build safety, security, and privacy into dots — OpenAI. Published 29 September 2026. Checked 30 September 2026.
- Grok Bot (overview) — SpaceXAI Docs. Updated 21 September 2026. Checked 30 September 2026.
- Dots privacy, security, and safety FAQs — OpenAI Help Center. Living documentation. Checked 30 September 2026.
- Skills and routines — SpaceXAI Docs. Updated 14 September 2026. Checked 30 September 2026.
- Introducing Grok Bot — SpaceXAI. Published 11 August 2026. Checked 30 September 2026.
- How We Designed Muse — Meta. Published September 2026. Checked 30 September 2026.
- Muse Privacy Policy — Meta. Effective 17 September 2026. Checked 30 September 2026.
- Create and manage Bots — SpaceXAI Docs. Updated 29 September 2026. Checked 30 September 2026.
- How to customize Muse's personality and memories — Meta Help Center. Updated 30 September 2026. Checked 30 September 2026.
- How to manage your Muse data — Meta Help Center. Updated 10 September 2026. Checked 30 September 2026.
- How We Built Safety Into Muse — Meta AI Research. Published 8 September 2026. Checked 30 September 2026.
- How Muse works with your guidance and approval — Meta Help Center. Updated 8 September 2026. Checked 30 September 2026.
- Grok Bot for teams and enterprises — SpaceXAI Docs. Updated 29 September 2026. Checked 30 September 2026.
- Grok Bot security — SpaceXAI Docs. Updated 28 September 2026. Checked 30 September 2026.
- How Muse works with files and apps in your Mac — Meta Help Center. Updated 21 September 2026. Checked 30 September 2026.
- Message and collaborate — SpaceXAI Docs. Updated 21 September 2026. Checked 30 September 2026.
- How Muse works with Connectors — Meta Help Center. Updated 8 September 2026. Checked 30 September 2026.
- Muse for Small Business: Build Your Company with AI — Meta (muse.ai). Living documentation. Checked 30 September 2026.
