# ChatGPT Work native app review This is an inert configuration record and test plan, not an importable policy or API request. It connects no app and changes no settings. For an authorised isolated test, choose a connection that actually supports Action control. In its native workspace app settings, review read-only actions and the offered App permissions choices. The worked example uses read-only plus Any changes where offered, with a personal account restricted to the synthetic note. Preserve all existing organisational restrictions. Confirm the permitted read first. Check an attempted change through a safe non-writing verification that the capability is unavailable or denied. Do not approve a real write merely to complete the test. Repeat the identity review separately before considering a shared account. ## Guide and sources Canonical guide: https://aona.ai/resources/guides/chatgpt-work-connected-app-security/ Source review: 2026-09-21 - OpenAI: Apps and connectors for enterprise: https://learn.chatgpt.com/docs/enterprise/apps-and-connectors - OpenAI: ChatGPT Work security: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security