30 Days Gen AI Risk Trial -Start Now
Skip to main content

Everyday AI data handling

Review files that stay in an AI project

A project file can supply context to more than one chat and remain available beyond the original upload. Review the project’s participants, shared sources, reuse and ordinary removal process before adding confidential material. Keep project access separate from connected-service permissions and from legal erasure or preservation decisions.

For Team workspace administrators and privacy

Aona field notesU06
Project-file review
One upload can support many chats

Record who can use the source and how its lifecycle ends.

Fictional project and intended access. No file is uploaded, collaborator invited or project deleted.

01

Identify what the project shares

OpenAI documents ChatGPT projects as a way to keep related chats, files, instructions and sources together. On the web, a project’s chats can use its shared files and instructions. This differs from attaching a file for one isolated request.

Record the project, file purpose and participants before upload. Review both uploaded material and connected context. Do not infer that the original source system’s permissions automatically describe every later project copy or generated answer containing information from it.

Source context: OpenAI: Projects and chats · OpenAI: ChatGPT Work security

02

Review the actual collaborator boundary

Identify who owns the project, who is intended to use its files and what controls the current product exposes for those participants. Record effective access rather than inventing a role model from another collaboration tool. Changes to membership can change who obtains context from the project.

The populated exercise uses a fictional owner, an intended collaborator and an unrelated account. It states the desired access without asserting that a particular product grants those roles automatically. Verify that the actual project configuration can enforce the intended boundary before confidential files are added.

Review the actual collaborator boundary
Fictional participantIntended useEvidence required
SYNTHETIC_OWNERManage the example sourceActual project-control scope
SYNTHETIC_COLLABORATORUse approved example contextActual access to this project
UNRELATED_ACCOUNTNo access intendedSeparate-account observation

03

Follow reuse into chats and outputs

A project source can inform later work, so review whether the content is appropriate for the project’s overall purpose rather than only its first question. A generated summary or exported result can become another copy with its own audience.

Keep a source record linking the file to its owner, allowed purpose and review date. If the file is replaced, note which version should be used and whether earlier chats or outputs still contain older content. Updating the current source is not proof that every earlier answer was rewritten.

Source context: OpenAI: Projects and chats · OpenAI: ChatGPT Work security

04

Separate ordinary removal from other copies

OpenAI’s Work security guidance states that project files remain associated with the project until removed or the project is deleted, subject to applicable deletion rules. Review the actual removal action and record what it affects. Do not describe it as immediate deletion from every possible location.

Connected-service records, Library files, downloaded outputs and earlier conversations may have separate handling. This page covers ordinary project-file lifecycle. Legal erasure requests, preservation duties or holds need the responsible legal/privacy process and the linked guides.

Source context: OpenAI: ChatGPT Work security

05

Keep the project’s source list current

Assign an owner to periodically review participants and source files, particularly when the project’s purpose changes or a colleague leaves. Retire unnecessary material using the supported process and record unresolved retained copies.

Use the synthetic file and lifecycle sheet to practise the review without creating a real shared project. The pack does not upload, invite, delete or connect anything. Aona input protection, provider project access and source-system permissions remain separate controls that need their own evidence.

Put it into practice

Shared project-file lifecycle exercise

Track a fictional source file from upload decision through reuse and ordinary removal.

Fictional project and intended access. No file is uploaded, collaborator invited or project deleted.

Shared project-file lifecycle exercise
StageExample decisionObservation
Add sourceUse synthetic-project-note.txt onlyNot uploaded
Share contextOwner and one intended collaboratorAccess unverified
ReuseKeep the example purpose and versionUntested
RetireReview project and other copies separatelyNot performed

Work through your review

Use the checks to organise the evidence you need. Your selections stay in this tab.

0 of 3 reviewed

Example files for this task

Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.

README.mdInspect
# Shared AI project file exercise

All participants, project names and source text are fictional. This pack performs no upload, invite, connection or deletion.

Use the supplied note and populated intended-access example to plan a review. Record the actual project’s available roles and permissions instead of assuming the example labels are product roles. Keep ordinary file removal separate from legal erasure/hold decisions and from copies in other systems.

## Guide and sources

Canonical guide: https://aona.ai/resources/guides/shared-ai-projects-confidential-files/
Source review: 2026-09-21
- OpenAI: Projects and chats: https://learn.chatgpt.com/docs/projects
- OpenAI: ChatGPT Work security: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security
Download README.md
synthetic-project-note.txtInspect
SYNTHETIC PROJECT SOURCE
Project: SYNTHETIC_U06_TRAINING
Version: 1
Purpose: prepare a fictional training checklist.
Content: review the sample, note an owner, then record a next step.
No customer, employee or confidential company information is included.
Download synthetic-project-note.txt
project-lifecycle.csvInspect
stage,fictional_example,intended_scope,actual_evidence,status
Owner,SYNTHETIC_OWNER,Manage example source,TO_RECORD,UNVERIFIED
Collaborator,SYNTHETIC_COLLABORATOR,Use approved project context,TO_RECORD,UNVERIFIED
Unrelated account,UNRELATED_ACCOUNT,No access,TO_RECORD,UNTESTED
Source file,synthetic-project-note.txt,Training purpose and version1,TO_RECORD,NOT UPLOADED
Generated output,Fictional checklist,Same approved audience,TO_RECORD,NOT CREATED
Removal,Project source and other copies reviewed separately,Record supported action,TO_RECORD,NOT PERFORMED
Download project-lifecycle.csv
review-record.mdInspect
# Project source review

Project purpose and owner: ____________________
Actual participants/roles and access evidence: ____________________
File owner, purpose and version: ____________________
Chats/outputs that may reuse it: ____________________
Ordinary removal action and effect: ____________________
Copies governed elsewhere: ____________________
Legal/privacy escalation if required: ____________________
Decision: NOT YET REVIEWED
Download review-record.md

Before you proceed

Keep these distinctions clear

Approving only the first chat
A project source can be reused across related chats, so review its continuing purpose and audience.
Equating source replacement with erased history
Earlier conversations or exported results can remain separate records.

Apply it to employee AI use

Bring your actual data path.

Aona can help evaluate supported employee input paths when files are submitted to AI.

This does not establish control of project membership, provider deletion or every retained project copy.

Bring the permitted file purpose and actual submission path to a scoped review while the workspace owner verifies project access.

Review your use case

FAQ

Questions for this decision

Is a project file the same as a one-off attachment?
Not necessarily. OpenAI documents project files and instructions as shared context for related chats. Review the source’s continuing purpose and access.
Does this worksheet define ChatGPT’s exact collaborator roles?
No. Its labels describe intended participants. Record the roles and permissions the current product actually exposes and verify access.
Does removing the project file remove all earlier summaries?
Do not infer that. Earlier chats, downloads, Library items or other saved copies can have separate handling rules.
Does this page decide legal erasure or preservation obligations?
No. It covers ordinary access, reuse and removal. Refer legal erasure, holds or retention conflicts to the responsible process and linked guides.

Evidence behind the guide

Sources and scope

Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.

  1. OpenAI: Projects and chats

    Documents shared project files, instructions and sources across related chats.

    vendor · checked 2026-09-21
  2. OpenAI: ChatGPT Work security

    Describes project-file association and separate retained-copy/control boundaries.

    vendor · checked 2026-09-21
Shared AI projects and confidential files