Hand off the work. Keep the keys.
DotJobs is built so that giving your Dot a job never means giving anyone else access. Here is exactly how that works, and what is still on the way.
Your data never leaves your Dot
A job is a set of instructions, not a service. It runs inside your own Dot, with your own connected accounts. Builders publish the workflow; they never receive your data, credentials or results.
Connections are scoped to the job
Each job declares exactly which apps it needs and why. You grant those connections at install time and can revoke any of them in one tap — the job simply stops running until they are restored.
Sensitive actions wait for you
Jobs that write to your systems — editing a directory, opening a pull request, sending a message — can run in approval mode. Your Dot prepares the change and nothing is applied until you confirm it.
Everything is logged and reversible
Every run records what was read, what was changed and why. Changes are grouped so you can review and roll back a whole run, not just a single edit.
How jobs are reviewed
Enforced by the runtime, not promised in a description
All jobs in the catalogue today are first-party and maintained by the DotJobs team. When third-party publishing opens, every job goes through the same review and the same runtime constraints.
Read about the package format →- Every job declares its inputs, connections, steps and outputs in a package the runtime enforces — not a prose description.
- Jobs cannot request connections they have not declared, write outside their declared destinations, or change their own permissions.
- Third-party jobs are reviewed before listing and re-reviewed on every version change. Breaking changes require a new major version.
- Guarantees in a package (for example “every field has a source” or “no writes outside the destination”) are checked by the runtime on every run.
Crypto and on-chain jobs
Read-only by design
- On-chain jobs in the catalogue are read-only: they watch, decode, price and report. None of them sign transactions or hold keys.
- Wallet addresses you provide are used only for the job that needs them and are never shared with builders or other users.
- Alerts link to the underlying transaction so you can verify every claim yourself.
Where things stand
Status, honestly
- Scoped connections and revocationAvailable with Dot connection
- Approval mode for write actionsAvailable with Dot connection
- Run log and rollbackAvailable with Dot connection
- Third-party job reviewOpens with the builder program
- Security disclosure programmeComing soon
- Data export and account deletionDeletion available today · export coming soon
Found something that worries you?
A formal disclosure programme is on the way. Until then, you can report a job or a security concern and we will get back to you.