adaptius
Agents & workflows · Oct 6, 2026

Every AI agent should leave a receipt.

OpenAI's new always-on agents come with custom rules and an activity view. Useful. Neither tells you whether the work is still on brand. A receipt does.

A worn matchbox printed with an aqua chameleon holds a long curling paper receipt.
The short answer

An AI agent's receipt is a short record of one run: the approved context it used, the rules and permissions in force, what it changed, which decisions a person made, and what is still open. It lets someone who was not watching check the work in minutes, which is what you need before an agent works while nobody is watching.

On September 29, OpenAI introduced dots, which it calls always-on agents. A dot gets its own cloud computer, connects to the apps you allow, and can work toward your goals around the clock. One of OpenAI's own examples is a product launch: the dot learns your audience, positioning, and creative standards, and when the scope changes it revises the launch materials and has drafts ready for your review.

That is brand work, done while your team is asleep. So the question for a marketing leader moves. It is no longer whether an agent can finish the task. It is whether anyone can tell, the next morning, what the agent relied on, what it changed, and whether you would approve it again.

The definition

What is an AI agent receipt?

A receipt is the record an agent leaves after a run, written for the person who has to stand behind the result. It names the approved context, the rules in force, what changed, who decided what, and what is still open. If it takes longer to read than the work takes to check, it is a log, not a receipt.

Logs matter, and most agent tools keep them. But a system can record every click and still leave you unable to answer the question that comes up on Monday: was this allowed, and is it still the brand we approved?

What changed

Don't always-on agents already keep an activity log?

Always-on agents keep the first half of a receipt. OpenAI says dots start with built-in rules for when to act alone and when to ask, that Custom Rules let you allow, require approval for, or block specific actions, and that an Activity View lets you follow the work, including background work. That covers what the agent did. It cannot cover whether the work matches your brand, because the agent only knows the version of your positioning someone gave it.

OpenAI is plain about the limit on its own launch page: “Dots can still make mistakes, so always review consequential work.” A receipt is what turns that review from an afternoon of retracing steps into a few minutes of checking five lines.

Six days later, OpenAI gave qualifying ChatGPT advertisers Negative Phrases, for “narrow placement requirements specific to a brand’s own policies.” Different product, same lesson. The platform supplies the control. Your company has to supply the rules, in writing, before the system runs.

The five lines

What should a brand agent's receipt show?

Five lines, each one answerable by a person who was not watching. Longer lists exist for security teams. For a marketing team, these five decide whether the work can ship.

The context it used. Which approved source, and which version: the positioning, the claims you can prove, the voice rules. “Our brand guidelines” is not an answer. A dated file is.

The rules in force. What it could do alone, what needed a person, and what was off limits for this run.

What it changed. The drafts, files, records, and messages it touched, listed where a reviewer can see them.

Who decided. Every approval, edit, or stop a person made, with a name and a time.

What is still open. The claim it could not support, the question it parked, and the next move it is waiting on.

The list is ours, and it lines up with what researchers and security groups are asking for. The Shared AI Findings Exchange proposal, a proposed initiative for sharing AI incidents and near misses, asks members to preserve evidence including tool calls, the permissions available during the run, human approval and intervention events, and the files created or modified. The paper Agent Safety Should Be a Runtime Contract argues that an agent should show “hard evidence” such as file diffs and log captures before a task counts as done. One is a proposal and the other a position paper. Neither is an adopted standard.

Ours

What does a receipt look like in practice?

This article has one. Before our blog publisher releases a post, a reviewer who did not write it has to return a go, and that go is sealed to the exact article and the exact desktop and phone screenshots it reviewed. Change a word after the review and the publisher refuses to release it.

We built it that way after a mistake we kept. On September 17, one of our articles went live with “Cover pending” where its cover should have been, and a reviewer had passed it. We changed the review and the publisher that day. Now the publisher refuses any article without its approved cover, and the rule sits in the file every later run reads.

A receipt will not stop every mistake. It makes each one traceable to the check that missed it, so the fix lands on the check and not only on the post.

Where it points

Where should the receipt point?

To a source your company owns and approves. A receipt that says the agent used “the brand” proves nothing. One that names the approved file, its version, and who last changed it can be checked by anyone on the team.

That is the job of a customer-owned Brand Brain: your approved positioning, voice, claims, and boundaries in plain, versioned files your company keeps, changed only when a person approves the change. Agents read it before they work. Their receipts point back to it after.

If you are writing the rules an agent follows, read how to test a brand rule without blocking the work. If you are still deciding where AI fits in your brand plan, start with what an AI brand strategy is for.

Start here

What can I do this week?

Pick one agent or automation that already touches customer-facing work. Ask it, or the person who runs it, for the five lines from its last run. Every line nobody can answer is the next thing to fix, before you give that agent more access.

If you are about to switch on an always-on agent, write two lists first: what it may never say about your company, and which claims it may make only with proof attached. Those lists are what its receipt gets checked against.

Sources

Where this comes from.

Published
2026-09-29

Event
2026-09-29, launch at DevDay 2026
First-party product announcement

OpenAI · Introducing dots

Vendor description of dots: always-on agents, built-in rules, Custom Rules to allow, require approval, or block actions, the Activity View, and the quoted advice to review consequential work. Not independent evidence of how well these controls work. Opened 2026-10-05.

Published
2026-10-05

Event
2026-10-05

Quoted: Negative Phrases for narrow placement requirements specific to a brand's own policies, available to qualifying advertisers. No reach figures, prices, or partner results carried. Opened 2026-10-05.

Published
2026-08-11

Event
Research publication; not applicable

Quoted from the abstract: task completion gated on hard evidence such as file diffs and log captures. A position paper, not an adopted standard. Opened 2026-10-05.

If you want help

Talk it through with Kip and Kevin.

A free 30-minute conversation about the rules your agents should follow and what their receipts should show. No obligation.

Start the conversation →