AI news

Shared agent memory shipped at DevDay. The open question is whose disk it is on

By Baalda Team · · 7 min read

Short answer

In files your team owns. OpenAI's dots form their own memories, and OpenAI's FAQ says you cannot view, delete or directly modify an individual one; resetting deletes the whole agent. A vault of plain markdown inverts that: the agent writes notes over MCP, so correcting what it knows means editing a line.

There is a line running through last week's announcements that has nothing to do with model quality. It is whether the thing your agent remembers is a file you can open.

What did OpenAI ship at DevDay 2026?

Two things that matter here, both announced on 29 September 2026.

The first is dots. OpenAI describes them as always-on agents that keep making progress between conversations, running on GPT-6 Astra, each with its own cloud computer, working across more than 4,000 apps you choose to connect. The memory behaviour is the part worth reading twice. OpenAI's own documentation says a dot "receives memories from ChatGPT and can create its own memories, including from connected apps," and that it "can also review that information proactively and form memories from it, even when you haven't asked a specific question about it." Dots are on paid tiers only, Pro and Business Premium, with the first one included; Free and Plus do not get one.

The second is ChatGPT Space, a shared workspace where a team and its agents work from common project knowledge, with Pages, a document built for people and agents to edit together.

Put those two side by side and something has shifted. The largest AI company in the world has just shipped a team's knowledge in one place, with agents reading and writing it alongside the humans. That is not a threat to the idea of a shared second brain. It is the idea going mainstream, which is good for everyone who has been arguing for it. What it leaves open is a narrower question, and it is the only one worth a post: when the agent remembers something about your team, where does that memory physically sit, and can a person fix it?

Can you read what your agent remembers?

With a dot, no. OpenAI's dots privacy, security and safety FAQ is direct about it: you currently cannot view, delete or directly modify individual dot memories, including specific details that enter the dot's context from plugins. The only lever is total. Resetting deletes the dot, "including its conversations, saved memories, and scheduled tasks."

Now hold that against a team of five to fifty people rather than one person.

An agent that forms memories proactively, from connected apps, without being asked, will eventually form a wrong one. It will decide a deprecated service is the current one, that a customer churned when they renewed, or that a decision your team reversed in March still stands. For a personal assistant that is an annoyance you work around. For a team it is worse, because a wrong belief held confidently by a system several people lean on is how bad calls get made quietly and at scale.

The repair available is to delete the agent and start it again. There is no line to correct, because there is no line. This is the same structural problem Baalda was built around, and it is why the vault is a folder of markdown rather than a store the app owns: a team's knowledge has to be a thing a human can open, read end to end, and change one sentence of.

What changes when the memory is a file on your disk?

Baalda is a team second brain made of ordinary markdown files on your own machine. Several people edit the same note at once over a CRDT, access is set per folder and per note, the core is Apache-2.0 and self-hostable, and the vault is served over MCP at /api/mcp so an agent reads and writes the same files a person does. Running it locally is free, with an optional managed Team plan for hosted sync.

The practical difference is what "the agent learned something wrong" costs you.

json
{
  "mcpServers": {
    "baalda": {
      "url": "https://api.baalda.com/api/mcp",
      "headers": { "Authorization": "Bearer mcp_your_token_here" }
    }
  }
}

Connected that way, the vault arrives as tools rather than as an opaque store: list_notes, read_note, search_notes, create_note, update_note, append_note, edit_note and the rest. When the agent concludes that your billing provider changed, it does not file that into a hidden index. It writes it into Decisions/billing-provider.md, and that note is sitting in a folder you can open in any editor. Correcting it is editing a line. Auditing what the agent believes is reading the folder.

Two details make this safe when the agent is writing rather than only reading, and both are the reason this is a different thing from giving an AI a scratchpad.

read_note returns a revision. Pass it back as expectedRevision on a write and the write is refused if the note changed in between, rather than landing on top of what a teammate just typed. edit_note works on anchors, and each anchor has to match exactly once unless you deliberately set all. An anchor that matches zero times, or more than once, refuses the whole call and writes nothing, so there is no half-applied edit to find later.

The token carries one person's access, not a service account's. A folder you cannot open is a folder the agent cannot read, which is the part most "connect your AI to your docs" setups skip. If the concept is new, a second brain over MCP covers the mechanics before any of this, and what a team second brain is covers the category.

Is ChatGPT Space a team second brain?

Honestly, yes, by most working definitions. Shared context, a document people and agents edit together, meeting summaries, Slack and Teams integration. If your team already lives in ChatGPT on a paid plan and the question is "where do we put the stuff our agents need to know," Space answers it today with no setup, and it will do several things a markdown vault does not: it is wired directly into the dots, the connectors and the usage model, and nobody has to mint a token.

Where it sits differently is ownership and format. The pages live in OpenAI's product, in OpenAI's shape, under OpenAI's terms, and they are as portable as the export OpenAI chooses to offer. That is a trade, not a scandal, and plenty of teams will take it knowingly. It is the same trade Notion asks for, with the agent layer added. The teams it does not work for are the ones whose written knowledge is the asset: the ones with a compliance reason the notes cannot leave their own storage, the ones who expect to still be reading these files in ten years, and the ones who want to point three different agents at the same knowledge rather than the one vendor's.

Dots and ChatGPT SpaceBaalda
Where the memory livesOpenAI's productplain .md files on your disk
Editing one thing the agent believesnot possible for a dot memoryopen the file, change the line
Deleting itreset deletes the whole dotdelete a paragraph
Who the agent is forone dot per personone vault, whole team, per-folder access
Always-on background workyesno
LicenceproprietaryApache-2.0, self-hostable

Where does a vault lose to an always-on agent?

This is the part a comparison table flatters, so it is worth saying plainly.

Baalda has no always-on agent. Nothing in it runs while you sleep, nothing wakes up to check a connected app, nothing schedules itself, and it does not connect to 4,000 services. A dot does all of that, and for a lot of people that background work is the entire value of the announcement. If what you want is an agent that handles a recurring task without being asked each time, a vault is not a substitute and no amount of markdown will make it one.

There is also a real cost to files. A folder of notes only stays useful if someone prunes it, and a vault that nobody tends becomes the same stale wiki every company already has. A proactive agent that maintains its own memory never asks you to do that work. The fact that you can edit a Baalda note is the same fact as: someone has to.

How do you run a dot and a vault together?

They are not competing for the same slot, which is the conclusion most of this points at.

The dot does the work. It watches the inbox, runs the recurring task, pulls from the connected apps, and brings results back. The vault holds what the work produced and what the team decided, in files the team owns, which the agent reads at the start of a task and appends to at the end. One is a worker, the other is the record. Teams get into trouble when they ask the worker to also be the record, because the record then inherits every property of the worker: invisible, per-person, and deleted when you reset.

If you want to try the second half of that, pointing an agent at a vault is the same shape in every MCP client. The per-client specifics are in the setup posts, Claude Code being the shortest one because the files are already on the same disk.

What will date fastest in this post is the dots FAQ. OpenAI may well add per-memory editing, and if it does, that is a genuinely better product and worth saying so. The structural point survives it, because a memory you can edit inside a vendor's product is still a memory that lives there. The question the DevDay announcements asked out loud, and did not answer, is whose disk it is on.

FAQ

Frequently asked questions

Can you edit what an OpenAI dot remembers?

Not an individual memory. OpenAI's dots privacy, security and safety FAQ says you currently cannot view, delete or directly modify individual dot memories, including specific details that enter the dot's context from plugins. The control you do have is a reset, which deletes the dot along with its conversations, saved memories and scheduled tasks. Memory a dot has shared back into ChatGPT Memory can be managed separately in ChatGPT's own memory settings.

What is ChatGPT Space?

A shared workspace OpenAI announced at DevDay on 29 September 2026, where a team and its agents work from common project knowledge. It includes Pages, a document built for people and agents to edit together, plus meeting summaries and Slack and Microsoft Teams integration. It is available on paid tiers rather than Free or Plus.

Does pointing an agent at a markdown vault replace its built-in memory?

No, and it should not. The two hold different things. A model's own memory is session and personalisation state that belongs to one person's account. A vault is the team's written record: decisions, runbooks, specs, the things that have to outlive the session and be readable by someone who was not in it. Run both and give each the job it is shaped for.

What stops the agent reading a folder it should not see?

The token. A Baalda MCP token is minted per person and carries that person's access to one vault, rather than a shared service account's. Access is set per folder and per note, so a folder you cannot open is a folder the agent acting for you cannot read. Everyone on the team mints their own.

Can a person and an agent edit the same note at the same time?

Yes. Baalda merges edits over a CRDT, so simultaneous changes to one note combine rather than overwrite. On top of that, `read_note` returns a revision you can pass back as `expectedRevision`, and the write is refused if the note changed in between, so an agent working from a stale read fails loudly instead of clobbering a teammate.

Start your team’s brain

Free and open source. No account needed.