30 Days Gen AI Risk Trial -Start Now
Skip to main content

Everyday AI data handling

Check who can open the chat link

Review the sharing feature, account, content and audience before initiating a share. On the documented local Codex snapshot feature in ChatGPT for macOS, opening Share begins uploading the snapshot; Copy link publishes it. Use only synthetic material for a rehearsal, and verify recipient access before sending the link. A private workspace or obscure URL does not make every sharing feature private.

For IT security and employee enablement

Aona field notesU05
Sharing review
Test the recipient’s view

The owner’s signed-in preview does not establish the audience.

Fictional conversation and intended audience. No link is created and all access tests are unperformed.

01

Identify the exact sharing feature

Record the provider, application, account type and command that creates the link. Sharing a conversation, a project, a generated site and a local thread snapshot are different features. Their audiences and retained copies may differ even within one product.

OpenAI provides a concrete documented example in the ChatGPT desktop app on macOS: a read-only snapshot of a local Codex thread. Its current guide distinguishes personal-account links, which anyone with the link can open, from authenticated workspace sharing with supported audience restrictions. Keep that rule attached to that surface rather than applying it to every ChatGPT or third-party link.

On that specific surface, opening Share starts the snapshot upload. Copy link publishes it using the chosen audience. Review permission to upload and the local content before opening the dialog, not only before sending a link. Any rehearsal should begin with a synthetic-only thread.

Source context: OpenAI: Using ChatGPT, thread sharing

02

Review the copy the recipient will see

For the documented local Codex snapshot, supported content can include visible messages, reasoning summaries, image attachments, viewed or generated images, and file paths and diffs. Original tool calls, shell commands and tool input/output are excluded. Known-secret redaction does not establish that all sensitive context is removed, and later messages do not update an existing snapshot.

Review the local thread before opening Share, then inspect the published shared view before distributing its link. Prepare a permitted excerpt or synthetic thread if the original is unsuitable. The pack supplies only a fake conversation and invalid example link label; it uploads and publishes nothing.

Source context: OpenAI: Using ChatGPT, thread sharing

03

Check access from the intended perspective

Use an authorised test with synthetic content to compare the owner view, intended recipient view and signed-out view where appropriate. Record the actual access result and the account state used. A link opening while you remain signed in as its owner does not prove it is restricted.

The populated exercise assumes an organisation wants only two fictional colleagues to see the material. The expected access follows that stated intent, while every observed result remains untested. If the selected sharing feature cannot enforce the intended audience, choose another approved way to provide the information.

Check access from the intended perspective
Viewer in the exerciseIntended accessObserved access
SYNTHETIC_COLLEAGUE_AAllowedUntested
SYNTHETIC_COLLEAGUE_BAllowedUntested
Signed-out visitorDenied for this intended scopeUntested
Unrelated accountDenied for this intended scopeUntested

04

Review removal and copies separately

Record who owns the shared link and how the supported product lets them restrict or remove it. Do not assume that removing a link deletes material a recipient already copied, exported or saved elsewhere. Those copies need their own handling decisions.

OpenAI’s Work security guidance distinguishes the controls of a conversation, project, Library file or shared artifact when retrieved content is saved into one of those locations. Follow the relevant sharing and retention rules for the actual copy rather than relying only on the source system’s permissions.

Source context: OpenAI: ChatGPT Work security

05

Make the sharing decision repeatable

Give employees a simple rule: establish the permitted upload and content before opening the sharing feature, select the intended audience, then verify recipient access before distributing the link. Recheck if the account type or feature changes. Do not use a confidential conversation as a rehearsal.

The final decision is about publication and audience, not account-password sharing or input DLP. A control that evaluated the original prompt does not decide who can open a later link, and this guide does not claim Aona can revoke every provider’s shared conversation.

Put it into practice

AI conversation-link audience exercise

Compare intended recipient access with actual sharing behaviour using only synthetic content.

Fictional conversation and intended audience. No link is created and all access tests are unperformed.

AI conversation-link audience exercise
CheckExample intentObservation
Before opening ShareReview local content and permission to upload; synthetic-only rehearsalDocumented Codex/macOS upload trigger; no upload performed
ContentSynthetic project-update conversation onlyTo inspect
AudienceTwo fictional colleaguesTo configure
Signed-out viewNo access intendedUntested
RemovalOwner-controlled supported processUnverified

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 4 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

README.mdInspect
# Conversation-link audience exercise

No real link is created by this pack. example.invalid is a reserved invalid domain. The conversation and people are fictional. Do not paste confidential chat history here.

For the documented local Codex snapshot feature in ChatGPT for macOS, opening Share starts the snapshot upload. Copy link publishes it to the selected audience. Review the local content and permission to upload BEFORE opening Share. A rehearsal must use a separate synthetic-only thread; cancelling publication is not evidence that no upload occurred.

That snapshot may include visible messages, reasoning summaries, images, file paths and diffs, but excludes original tool calls, shell commands and tool input/output. Known-secret redaction is not a guarantee that all sensitive context is removed. Later thread messages do not update the existing snapshot.

If the organisation authorises a manual test, create a link only from the synthetic conversation through the actual approved sharing surface. Record the provider, feature and account type. Compare intended recipients, unrelated accounts and a signed-out view. The expected access in audience-check.csv reflects the fictional exercise’s private intent, not a promised default for any provider.

## Guide and sources

Canonical guide: https://aona.ai/resources/guides/ai-chat-shared-links-company-data/
Source review: 2026-09-21
- OpenAI: Using ChatGPT, thread sharing: https://learn.chatgpt.com/docs/use-chatgpt
- OpenAI: ChatGPT Work security: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security
Download README.md
synthetic-conversation.txtInspect
SYNTHETIC U05 CONVERSATION
User: Summarise our fictional training plan.
Assistant: The example team will review the sample and record a next step.
No real project, customer or employee information is included.
Link label only: https://example.invalid/share/SYNTHETIC_U05
Download synthetic-conversation.txt
audience-check.csvInspect
viewer,intended_access,actual_feature_and_account,observed_access,evidence
SYNTHETIC_COLLEAGUE_A,Allowed,TO_RECORD,UNTESTED,
SYNTHETIC_COLLEAGUE_B,Allowed,TO_RECORD,UNTESTED,
Signed-out visitor,Denied for this example,TO_RECORD,UNTESTED,
Unrelated account,Denied for this example,TO_RECORD,UNTESTED,
Download audience-check.csv
sharing-decision.mdInspect
# Sharing decision

Exact provider/app/sharing feature: ____________________
Account/workspace type: ____________________
Permission to upload and local content review BEFORE opening Share: ____________________
Upload trigger and separate publication trigger for this surface: ____________________
Content included in the shared copy: ____________________
Intended audience and access evidence: ____________________
Owner and supported removal process: ____________________
Saved/exported copies to consider: ____________________
Decision: NOT YET REVIEWED
Download sharing-decision.md

Before you proceed

Keep these distinctions clear

Testing only as the owner
Owner access does not establish what a signed-out person or another account can open.
Treating a link as secret because it is hard to guess
Review the actual access rule and intended audience, not the appearance of the URL.

Apply it to employee AI use

Bring your actual data path.

Aona can help evaluate supported employee AI input paths before data enters a conversation.

This does not establish control over provider sharing audiences or revocation of existing chat links.

Review the input policy and the provider’s sharing controls as separate parts of the workflow, using synthetic content.

Review your use case

FAQ

Questions for this decision

Are all ChatGPT sharing links public?
Do not generalise across surfaces and account types. The cited local Codex snapshot feature in the ChatGPT macOS app distinguishes personal links from authenticated workspace sharing. Verify the actual feature being used.
Does a link opening for me prove my colleagues can access it?
No. Test the intended recipient’s account state. Owner access, workspace membership and invited audience restrictions can produce different results.
Does removing the link delete copies recipients saved?
Do not assume it does. A saved, exported or copied artifact has its own handling and access lifecycle.
Does opening Share upload the thread before a link is published?
For the documented local Codex snapshot feature in ChatGPT for macOS, yes. Opening the dialog starts upload; selecting Copy link publishes the snapshot. Review content and upload permission first, and use only a synthetic thread for rehearsal. The supplied pack performs neither action.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. OpenAI: Using ChatGPT, thread sharing

    Documents the distinct upload/publication triggers, supported snapshot content and audience rules for local Codex threads in ChatGPT for macOS, not every sharing surface.

    vendor · checked 2026-09-21
  2. OpenAI: ChatGPT Work security

    Distinguishes controls of saved conversations, projects, Library files and shared artifacts.

    vendor · checked 2026-09-21
AI chat shared links and company data