30 Days Gen AI Risk Trial -Start Now
Skip to main content

Everyday AI data handling

  • ChatGPT

Set ChatGPT app access before linking data

For a ChatGPT Work connection that supports Action control, allow only the actions the task needs and choose an appropriate App permissions prompt policy. Verify the connected identity and source-system scope separately. A read-only action setting, a request for approval and a personal or shared account each govern a different part of the connection.

For Enterprise AI administrators and SaaS security

Aona field notesU07
Native app review
Allowed actions + connected identity

A prompt policy does not reduce the account’s source-system permissions.

Worked intended configuration and synthetic task. No app is connected or administrator setting changed.

01

Separate the administrative layers

OpenAI documents plugin availability, underlying app availability, workspace or role access, connection authorisation and source-system permissions as distinct requirements. Making a plugin available does not automatically connect an account or approve every action it could perform.

Choose one app and one task for the review. Confirm that the connection exposes the relevant native controls before following the example. If it does not support Action control, record that limitation rather than describing the proposed configuration as active.

Source context: OpenAI: Apps and connectors for enterprise · OpenAI: ChatGPT Work security

02

Configure a restrictive example in native controls

In the workspace’s app administration, locate the connection’s Action control and App permissions settings. For the worked example, select read-only actions and, where offered, Any changes as the prompt policy. Read-only limits the allowed action set; Any changes controls approval behaviour and does not add a permission to write.

The example task is to read one synthetic reference note. Keep the source-system account limited to that test resource. These are documented control names and an intended configuration, not an API payload or a claim that every app exposes identical options.

Configure a restrictive example in native controls
Native controlWorked example choicePurpose
Action controlRead-only actionsExclude unnecessary write capabilities
App permissionsAny changes, where offeredPrompt policy, not an action grant
Connected accountPersonal test connectionUse the authorised person’s source scope
Source-system accessSynthetic reference onlyLimit data visible to the connection

Source context: OpenAI: Apps and connectors for enterprise · OpenAI: ChatGPT Work security

03

Review personal and shared connections separately

A personal connection uses the connected employee’s source-system permissions. A shared or agent-owned connection uses the permissions of its connected account, which can differ from those of the person making the request. The same prompt can therefore have a different effective data boundary depending on the connection selected.

Do not reuse the personal-account approval for a shared connection. Record its owner, resource scope and who may use it. Limit that account at the source system as well as through available app action settings.

Source context: OpenAI: ChatGPT Work security

04

Run a synthetic least-privilege check

The pack provides a fictional reference note and a verification plan. If an authorised administrator performs a test in an approved isolated connection, first confirm that the permitted read works. Then check that an attempted change is unavailable or denied under the chosen read-only action scope, without performing a real write.

Keep the action-setting result separate from a permission prompt. A prompt asking for confirmation is not the same as the write capability being excluded. Record the connected identity, effective settings, observed tool behaviour and source-system evidence. All test results in the download start untested.

05

Review changes to capabilities and connections

OpenAI’s app guidance recommends reviewing how newly added actions are handled where controls support it. Revisit the record when an app gains capabilities, a connection changes identity or source permissions expand. Preserve a permitted read path without silently granting broader actions.

This page focuses on native app configuration and its verification, not a general agent inventory or rollout narrative. Aona’s supported endpoint policy paths are another question; no claim is made that Aona configures ChatGPT Work apps or blocks every connector action.

Source context: OpenAI: Apps and connectors for enterprise

Put it into practice

ChatGPT Work connected-app permission exercise

Use native action and prompt controls with a restricted test identity, then record a synthetic read/write distinction.

Worked intended configuration and synthetic task. No app is connected or administrator setting changed.

Three controls with different jobs
01

Action control

Which app actions may be used

Example: read-only

02

App permissions

When ChatGPT asks before using them

Example: Any changes where available

03

Connection identity

Which source-system data and actions the account can access

Review personal/shared accounts separately

ChatGPT Work connected-app permission exercise
Control or testIntended exampleObserved
Action controlRead-only actionsUnverified
App permissionsAny changes where offeredUnverified
AccountPersonal test identity, restricted resourceUnverified
Read synthetic noteAllowed if configuration supports itUntested
Attempted changeUnavailable or denied by read-only scopeUntested

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

README.mdInspect
# ChatGPT Work native app review

This is an inert configuration record and test plan, not an importable policy or API request. It connects no app and changes no settings.

For an authorised isolated test, choose a connection that actually supports Action control. In its native workspace app settings, review read-only actions and the offered App permissions choices. The worked example uses read-only plus Any changes where offered, with a personal account restricted to the synthetic note. Preserve all existing organisational restrictions.

Confirm the permitted read first. Check an attempted change through a safe non-writing verification that the capability is unavailable or denied. Do not approve a real write merely to complete the test. Repeat the identity review separately before considering a shared account.

## Guide and sources

Canonical guide: https://aona.ai/resources/guides/chatgpt-work-connected-app-security/
Source review: 2026-09-21
- OpenAI: Apps and connectors for enterprise: https://learn.chatgpt.com/docs/enterprise/apps-and-connectors
- OpenAI: ChatGPT Work security: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security
Download README.md
intended-native-settings.jsonInspect
{
  "notice": "WORKED INTENT ONLY; NOT AN IMPORTABLE CONFIGURATION",
  "required_control_support": "Action control must be available",
  "Action control": "Read-only actions",
  "App permissions": "Any changes where offered",
  "connection_kind": "Personal synthetic test connection",
  "source_scope": "Only the synthetic reference note",
  "applied": false
}
Download intended-native-settings.json
synthetic-reference-note.txtInspect
SYNTHETIC U07 REFERENCE
The fictional team reviews one example note and records an owner.
No company account, customer information or confidential data is included.
Download synthetic-reference-note.txt
verification.csvInspect
case,connected_identity,effective_action_control,effective_prompt_policy,intended_result,observed_result,evidence
Read synthetic note,PERSONAL_TEST_IDENTITY,Read-only actions,Any changes where offered,Allowed if supported,UNTESTED,
Attempted modification without executing a write,PERSONAL_TEST_IDENTITY,Read-only actions,Any changes where offered,Unavailable or denied,UNTESTED,
Shared account review,SHARED_ACCOUNT_TO_REVIEW,RECORD,RECORD,Separate source-scope decision,UNREVIEWED,
New action introduced,RECORD,REVIEW DEFAULT HANDLING,RECORD,No unreviewed expansion,UNTESTED,
Download verification.csv
connection-decision.mdInspect
# Connection decision

App/connection and native control availability: ____________________
Action control setting: ____________________
App permissions setting: ____________________
Personal/shared/agent-owned identity: ____________________
Source-system scope and owner: ____________________
Synthetic read result: UNTESTED
Write-capability exclusion evidence: UNTESTED
New-action handling and review owner: ____________________
Decision: NOT YET REVIEWED
Download connection-decision.md

Before you proceed

Keep these distinctions clear

Using a prompt policy as an action allowlist
When an app asks for approval and which actions it may use are separate controls.
Assuming shared means the requester’s permissions
A shared or agent-owned connection uses its connected account’s source-system scope.

Apply it to employee AI use

Bring your actual data path.

Aona can help review supported employee endpoint AI input paths as part of the broader workflow.

Aona does not configure native ChatGPT Work app controls or guarantee enforcement of every connected-app action.

Keep the native app/identity decision with the workspace administrator and scope any supported endpoint test separately.

Review your use case

FAQ

Questions for this decision

Does Any changes mean the app has read-only access?
No. It is a prompt policy where offered. Use Action control to restrict the allowed action set and source-system permissions to limit the connected account.
Does enabling a plugin automatically authorise its app connection?
No. OpenAI documents availability, app access, account authorisation and action permissions as separate layers.
Does a shared connection use the requesting employee’s permissions?
It uses the permissions of its connected shared or agent-owned account. Review that account and who may invoke it separately from a personal connection.
Can the downloaded JSON apply these settings?
No. It is a worked intent record, not an importable configuration or API request. An authorised administrator must use the supported native controls and verify their actual effect.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. OpenAI: Apps and connectors for enterprise

    Documents native Action control, App permissions, availability and source-system authorisation layers.

    vendor · checked 2026-09-21
  2. OpenAI: ChatGPT Work security

    Explains read-only/action prompting distinctions and personal versus shared connection permissions.

    vendor · checked 2026-09-21
ChatGPT Work connected-app permissions