Desk Trials

ARCHIVE / Automation & agents

ChatGPT's agent mode still asks before it spends money

OpenAI's launch post and its connector-permissions documentation describe where agent mode pauses for a person and where it does not.

Preserved retrospective record

Historical source and event dates are not site publication dates. Product plans, policies and availability may have changed since retrieval.

Visual for this record: ChatGPT's agent mode still asks before it spends money
Visual published by images.ctfassets.net, shown for identification of the record. Credit: images.ctfassets.netPreserved source visual · owner review pending

The setup

On 17 July 2025, OpenAI's announcement made a new agent mode available to Pro, Plus and Team subscribers directly from the composer's tools dropdown, without a separate product or sign-up. Selecting it hands ChatGPT a visual browser, a text-based browser, a terminal and API access in the same conversation, and lets it draw on any connected app the account already authorizes, such as Gmail or a calendar, through what OpenAI calls connectors. The announcement frames this as folding the earlier standalone Operator product into ChatGPT itself, so the setup cost for an existing subscriber is choosing a menu item rather than adopting a new tool.

What the documents show

The announcement states three checkpoints by name: an explicit user confirmation before any action with real-world consequences such as a purchase, a Watch Mode that requires active oversight for tasks like sending an email, and a secure browser takeover mode in which the model does not collect anything a person types directly into the browser, including passwords. OpenAI's separate help-center article on apps in ChatGPT, read as it stands today, adds the permission mechanics behind that claim: a default setting lets ChatGPT read from a connected app automatically but asks before an action that could have an outside effect, expose sensitive information, or be hard to undo, and a workspace admin can restrict which actions a given app is allowed to take at all.

The friction

The same help-center article discloses a less-restrictive option a person or admin can choose instead — approving an app's actions in advance so future ones do not prompt again — and states plainly this carries elevated risk because actions may run without another confirmation. It also notes some especially risky actions can be blocked outright rather than offered for approval, and a less restrictive setting does not override certain safety or workspace protections. None of that is invented friction: it is the vendor's own account of a tradeoff between fewer interruptions and less oversight, left for the account holder to choose.

What changed in the work

The documents support a specific description of what changed: a task that once required opening each application in turn can now be described once, with the agent moving between a browser, a terminal and connected apps, while the documented default keeps a confirmation step in front of anything consequential. Whether that nets out as faster is not something either document measures; the editorial read is that time saved on assembly is partly spent reviewing what the agent proposes before it ships.

  • Which connected apps have been switched to the less-restrictive approve-once setting, and by whom?
  • Does a given task touch a connector an admin has already restricted to read-only?
  • What does Watch Mode actually show a person in the moment they are meant to be supervising?

Agent mode's arrival inside an existing product, rather than as a new destination, is itself a change in how the setup cost shows up: it is buried in a permissions menu instead of a sign-up page, which makes it easier to turn on and easier to overlook.

Sources & verification

Preserved from the earlier archive. These sources have not all been freshly rechecked for this expansion.

  1. Introducing ChatGPT agentSource date: 2025-07-17 · Retrieved: 2026-09-16

    States the launch date, the tool suite granted to agent mode, and the three named user-control safeguards.

  2. Apps in ChatGPTSource date: not stated · Retrieved: 2026-09-16

    Living help-center documentation describing default versus less-restrictive app permission settings and admin-level action controls, as it reads on the retrieval date.

Continue the workflow

  1. Prevent duplicate records before an automation goes live

    Stop retries, webhook repeats, and double clicks from creating duplicate business records or actions.

  2. Separate retryable failures from work that needs a person

    Keep an automation from hammering a failing service or losing records that cannot complete automatically.

  3. Design approval gates that reviewers can actually use

    Add human review to a consequential workflow without creating blind approvals or permanently stuck runs.

  4. Release an automation change like a small software change

    Change a live automation without discovering mapping or logic errors across the entire workload at once.