Overview
Workspace administrators can manage plugins and their included apps in Admin > Plugins. Review installation, app access, actions, provider permissions, and supported indexing. The Apps administration page may also remain available. FedRAMP workspaces use Apps when Plugins is unavailable.
For plugin installation, see: Plugins in ChatGPT and Codex.
Admin controls
A plugin can include skills, apps, and app templates. Plugin installation and underlying app access are separate controls.
Default behavior by plan
ChatGPT Enterprise and Edu
New Enterprise and Edu workspaces start with a selected set of apps enabled. These defaults do not change existing workspace settings and do not apply to Healthcare workspaces. Administrators can review and change app availability. Plugin availability and installation are separate from app access. Review plugin and included-app settings in Admin > Plugins; the Apps administration page may also remain available.
Disabling an underlying app blocks the app-backed capability. It does not necessarily uninstall the plugin or remove skills that do not depend on that app.
Enterprise and Edu admins can use RBAC for plugin installation and app access. Those controls are evaluated separately: a member may have a plugin installed but still be unable to use an included app.
ChatGPT Business
In ChatGPT Business, apps are enabled by default, and administrators can change workspace-wide app availability. Review the app or its included plugin in Admin > Plugins. The Apps administration page may also remain available. Disabling an app does not necessarily uninstall a plugin or remove its skill-only capabilities.
Role-based access control
Enterprise and Edu workspaces may assign eligible plugins to custom roles when role-level plugin controls are available. Users can access plugins enabled for their workspace and applicable role. If a plugin shows Disabled by admin, its workspace settings, its applicable role settings, or an included app may be preventing access.
Plugins that include required apps inherit those apps’ role and action settings. If a member's role cannot access a required app, the plugin cannot use that app-backed capability for that member. Workspace plugin controls can also determine whether a plugin is Available or Installed for a role.
Manage plugin and app access
App access controls who can use a connected app in the workspace. App permissions control when ChatGPT asks before using an app.
Role-specific app access in this section applies to Enterprise and Edu workspaces. ChatGPT Business administrators manage whether an app is enabled for the workspace.
To manage who can use an app:
Go to Admin > Plugins.
Select the plugin and review the included app’s access settings.
When Role access is available, select the applicable roles and save when prompted.
The Apps administration page may also remain available in your workspace.
To manage which apps a role can use:
Go to Workspace settings > Permissions & roles.
Select Custom roles.
Select the role you want to edit.
Scroll to the Plugins & connected data section.
Turn on Allow members to use plugins, or Use plugins when that is the label shown, to allow plugin and app use for the role. FedRAMP workspaces may show Use apps.
Use Select to choose specific apps for that role.
Add apps and plugins
When enabling a new app, review its workspace availability and any supported action controls. In Enterprise and Edu workspaces, assign eligible roles when role-based controls are available.
App templates follow the same admin governance model after publishing. Workspace admins and owners review the template-generated draft app, publish it when ready, and manage workspace availability, supported actions, and app permissions from the relevant plugin detail page. Enterprise and Edu admins can also configure role-scoped access when available.
For template setup, see: ChatGPT app templates.
Go to Admin > Plugins and select a plugin to review its skills, included apps, and Installation policy. Available lets eligible members install the plugin, while Installed installs it by default. Where role-based controls are available, administrators can configure the policy for eligible roles. FedRAMP workspaces use the Apps administration page.
Plugins with required apps inherit those apps’ role and action settings. The required apps must be enabled for the affected role. Review other settings on the included app separately. Depending on the app state, admins may see Enable, Publish, Edit app configuration, or Disable.
Admins can configure a workspace-wide app permission and, when supported, a different setting for an individual app. The standard workspace-wide selector does not offer Allow all actions, although existing policy configurations can differ.
For permission details, see: Managing app permissions in ChatGPT.
App action controls
Role access controls who can use an app. Actions controls what the app can do. Permissions controls when ChatGPT asks before using an app.
These app permissions apply to ChatGPT conversations. Workspace Agents use per-agent controls set by the agent's builder to determine which app actions are available and when end users are asked to approve them. For agent behavior, see: ChatGPT Workspace Agents for Enterprise and Business.
Under Actions, enable the supported Read actions or Write actions you want to allow. Under New actions, select:
Enable all new actions
Only enable new read actions
Disable new actions
Disable new actions applies only to actions introduced later; it does not disable actions that were already enabled.
Some apps do not offer configurable Actions or New actions controls. For those apps, admins can manage app access but cannot individually configure unavailable action controls.
Provider approval, OAuth scopes, and ChatGPT action settings are separate checks. Approving a provider scope does not automatically enable a new action, and changing a future-action policy does not remove existing provider consent. Some changes may require a user to reconnect or reauthorize the app.
To change the workspace default app permission:
Go to Workspace settings.
Open General and find Settings.
Under Plugin permissions, select the workspace-wide approval setting.
To set a different permission for an app:
Go to Admin > Plugins and select the plugin that includes the app. If Plugins is unavailable, use the Apps administration page.
In the plugin’s Apps section, open the included app’s Permissions control. In the older Apps view, use the app’s available permission controls.
Select Workspace default or another available permission.
Select Save if the interface asks you to confirm the change.
Available options depend on the workspace and app:
Always ask: ChatGPT asks before reading app information or making changes.
Allow read actions: ChatGPT can read app information without asking but asks before making changes.
Allow low-risk actions: ChatGPT automatically approves low-risk actions. Higher-risk actions may require confirmation or be denied.
Allow all actions: When supported for an individual app, ChatGPT can perform available actions without additional prompts. This option carries elevated risk and is not offered in the standard workspace-wide selector.
These settings do not override action controls, provider authorization, workspace restrictions, or safety protections.
For details, see: Managing app permissions in ChatGPT.
Manage Google Drive indexing controls
Google Docs, Sheets, and Slides actions are now available through the Google Drive app. Standalone Google Docs, Sheets, and Slides apps are no longer listed separately. Users should connect Google Drive for Docs, Sheets, and Slides access.
For ChatGPT Enterprise and Edu, these unified Google Drive actions are off by default until a workspace administrator enables them. For ChatGPT Business, they are on by default. After enablement, Google Workspace administrators may need to reauthorize updated Google Drive scopes before users can use these actions or new users can connect. If users cannot connect to Google Drive, check your Google Workspace scope authorizations for Google Drive, Docs, Sheets, and Slides. Confirm that all actions in the app have scopes that have been authorized, or turn off actions you do not want to authorize.
Administrator-managed Google Drive sync is configured separately from live Google Drive actions. Individually authorized sync is no longer available.
File restriction and setup
For an eligible workspace and supported Google Drive connection, administrators may be able to:
Limit the administrator-managed Google Drive source to specific shared drives or folders.
Exclude specific file types from indexing.
Configure administrator-managed access for centralized setup and supported source-selection controls. Individually authorized sync and Quick setup are unavailable.
For provider setup, see: Google Drive app and setup in ChatGPT.
Sync controls and live app-action controls are separate. Depending on the app, restrictions on direct actions may not limit content retrieved from a synced index, and sync content-selection settings may not restrict separate live app actions. Review both configurations.
Before disabling an app or removing a sync connection, review the warning. Indexed data may be permanently deleted, and other users or plugins may be affected.
For sync details, see: Administrator-managed apps with sync in ChatGPT.
Manage Google Drive sync access in Enterprise and Edu
Access to administrator-managed Google Drive sync depends on app availability, role or group access, the configured sync source, and each member’s underlying Google Drive permissions. Live actions and indexed content can require separate authorization or configuration.
If your workspace previously used a Google Drive allow-list or legacy connector roles, review existing app access, role assignments, and administrator-managed sync settings before changing them.
Confirm which roles or groups can use the Google Drive app and whether administrator-managed sync is enabled for the intended source.
Verify affected members can access the indexed files in Google Drive. When a live action requires individual authorization, confirm the member has connected an eligible provider account.
Update role access or source permissions only when the current configuration requires it, then ask an affected member to test the workflow.
Changing app access, live-action authorization, or sync configuration can affect different users and capabilities. Review each control separately.
Microsoft apps permissions required
Some actions in the Outlook Email, Outlook Calendar, Microsoft Teams, and SharePoint apps require Microsoft Graph permissions that a Microsoft Entra administrator must grant for the organization. A ChatGPT workspace owner or admin and a Microsoft Entra administrator may be different people, so coordinate with the person who can grant organization-wide consent.
Review permissions in ChatGPT
If you see Configure Microsoft permissions in Admin > Plugins, select it to review the combined permission request for your enabled Microsoft apps.
If your workspace still uses the Apps settings page, follow these steps for the Microsoft app you want to review:
Sign in to ChatGPT as a workspace owner or admin.
Open Apps in your workspace settings and select the Microsoft app you want to review.
Open the app’s more options menu (•••) and select Manage app.
Select Microsoft permissions when that option is available.
Review each Microsoft Graph permission and the ChatGPT actions listed beneath it. Upcoming means an action is included for advance permission review but is not currently available. Approved means the permission was included in the last successful approval flow completed through ChatGPT for that app and workspace.
Select only the permissions your organization wants to include in the request. The available permissions and actions can differ by app. If your organization does not want to grant a permission, leave it out of the request and keep every action that depends on it disabled.
Complete the request in Microsoft Entra
Select Review permissions in Microsoft Entra. If Microsoft Entra does not open, allow pop-ups for ChatGPT and try again.
Sign in with a Microsoft Entra administrator account that can grant organization-wide consent.
Confirm that the correct organization and the verified ChatGPT / OpenAI, L.L.C. application are shown.
Review the selected permission request. The Microsoft Entra confirmation screen does not provide per-permission checkboxes: select Accept to grant the complete selected request, or select Cancel to make no change.
Return to ChatGPT and confirm that the approval flow completed.
Review the action settings for every enabled Microsoft app. Microsoft permissions are granted to the Entra tenant and OpenAI application, and a single permission request in ChatGPT may cover multiple apps.
After permissions are approved
Microsoft permission approval does not enable ChatGPT actions or connect an individual user’s Microsoft account. Workspace owners and admins must separately enable the actions they want to make available. Users may also need to connect or reconnect their Microsoft account after permissions change.
If an action still does not work, confirm that:
The action is enabled in the ChatGPT workspace’s app settings.
The permission grant still exists in Microsoft Entra.
The user’s Microsoft connection has been created or refreshed with the required permissions.
If an Entra administrator later changes or revokes the grant directly in Microsoft, review the grant in Entra and rerun the ChatGPT approval flow.
Review the following Help Center pages for the permissions required by each app:
Each app page describes the scopes required by that app. For the current permissions and associated actions, review the Microsoft permission request available in your workspace.
Custom apps
Workspace owners, administrators, and members who have been explicitly granted custom-app or developer-mode permissions can create or add custom apps, subject to their plan and workspace policy.
When an app requires individual provider authorization, users connect an eligible account before using those features. Other apps can use no-auth access or an administrator-managed workspace connection.
For an overview of developer mode, custom apps, and MCP connectors in ChatGPT, see: Developer mode and custom apps in ChatGPT.
For a technical walkthrough of creating a custom MCP connector, see: Creating custom MCP apps.
Custom apps are not verified by OpenAI and are intended for developer use only. You should only add custom apps to your workspace if you know and trust the underlying application. For details, see: Custom app risks and safety.
Apps may allow end users to share data, which could include protected health information (PHI), with third parties. You should ensure that your use of apps complies with your obligations under HIPAA.
---
Security and compliance
Security
OpenAI protects customer content within its covered services using encryption in transit and at rest. Depending on the app and workspace configuration, access may use an individual provider account, an administrator-managed connection, or another supported authorization method. Source permissions still apply.
OpenAI uses testing, monitoring, access controls, and layered safeguards to reduce prompt-injection and unauthorized-access risks. These measures do not eliminate third-party or prompt-injection risk. Review each app’s source permissions, enabled actions, access settings, and provider terms.
Model training and app data
By default, OpenAI does not use ChatGPT Business, Enterprise, or Edu workspace content, including information accessed through apps, to train its models. For current terms and applicable opt-ins, see: Enterprise Privacy.
Administrator-managed synced sources maintain a separate index of administrator-selected source content. Information included in chats or research outputs follows the applicable conversation, feature, and workspace-retention policies.
Data storage and residency
Sync availability depends on the app, its administrator-managed connection type, and your workspace’s configured data residency region. For supported sync setup regions, see: Administrator-managed apps with sync in ChatGPT.
For data residency boundaries and instructions to check the configured region, see: Data residency and inference residency for ChatGPT.
If an app with sync is not supported in your workspace’s selected data-residency region, the sync connection may be unavailable. Unsupported sync does not automatically fall back to storage in another region.
Non-synced apps: Information sent to a connected third-party service is subject to that provider’s storage, processing, privacy, and data-residency terms.
Data residency applies to in-scope customer content stored at rest for supported features. It does not mean that every processing step, system record, external integration, or third-party app remains in the selected region.
Compliance
ChatGPT Business administrators manage workspace settings and app availability; they do not automatically gain access to members’ ordinary private conversations. The Compliance Platform is available only to eligible Enterprise and Edu workspaces, subject to configuration and the administrator’s assigned permissions.
When available, app-activity records can include an app request and related response information. App-authentication records can show account connection and disconnection events. Retention depends on the applicable Compliance Platform endpoint, workspace retention settings, and any records exported by the organization.
For current enterprise compliance guidance, see: OpenAI Compliance Platform for Enterprise and Edu Customers.
Google Drive indexing security
Eligible managed workspaces can configure Google Workspace domain-wide delegation when the supported administrator-managed Google Drive setup requires it.
