OpenAI

Role Based Access Controls for ChatGPT Enterprise

Role-Based Access Controls in your ChatGPT workspace.

Updated: 4 hours ago

Note: RBAC is currently available for Enterprise, Edu, ChatGPT for Healthcare, and ChatGPT for Teachers.

Overview

Role-based access control (RBAC) lets workspace owners create custom roles with specific permissions and assign those roles directly to users or groups in their ChatGPT workspace. A user can receive permissions from both direct role assignments and group memberships.

Workspace settings provide the default for eligible permissions. A custom role is a reusable set of permissions that owners can assign directly to members or through groups. A member may have more than one custom role.

For eligible permissions, a custom role can use Default to inherit the workspace setting, On to explicitly allow access, or Off to deny access through that role. When a member has multiple custom roles, their permissions combine additively: access granted by one role remains available even if another role is set to Off.

Lockdown Mode is evaluated separately and can further restrict network-enabled capabilities. A member’s seat type, plan, and product eligibility still apply.

Who can configure RBAC settings and permissions?

Workspace owners can create, delete, assign, and unassign custom roles, and manage workspace-wide permission defaults. Workspace admins may be able to view or update existing roles through supported administration surfaces, but they cannot create, delete, assign, or unassign custom roles. Members and analytics viewers cannot manage workspace-wide RBAC settings.


Are there any geography restrictions?

All supported countries access to this feature.

Is RBAC configuration available on web, mobile, and desktop?

RBAC configuration is available on web, under Workspace settings -> Permissions & roles.

What capabilities are included?

Workspace owners can use Workspace settings > Permissions & roles to:

  • Set the workspace baseline for eligible member permissions.

  • Create ordinary custom roles that use Default, On, and Off for eligible permissions.

  • Assign one or multiple custom roles to groups.

  • Assign roles directly to individual users where available.

  • View and manage custom roles in a centralized tab.

What permissions can I configure with RBAC?

You can control access to key ChatGPT features with RBAC. For a full list of available toggles and options, refer to Workspace settings > Permissions & roles.

Available permission states vary. Eligible ordinary-role permissions use Default, On, and Off. Some permissions, including certain Work and plugin controls, can remain two-state On or Off controls.

Lockdown Mode roles

Workspaces that have Lockdown Mode role support can use RBAC to create a custom role for members who need Lockdown Mode. Treat Lockdown Mode as a role-level security configuration, not as a single permission toggle.

When a member is assigned to a Lockdown Mode role, network-enabled capabilities may be limited, including live web search, deep research, agent mode, Canvas networking, and some app, MCP, or connector behavior, depending on workspace settings.

Before assigning a Lockdown Mode role, review which apps and actions the role allows and confirm that members have the permissions they need in each connected source system. App access in ChatGPT does not override permissions in the connected source system.

For more detail about what changes in Lockdown Mode, see Lockdown Mode.

We will continue to add features to RBAC permissions over time.


Note: You can control access to apps on a per-app basis. An app’s UI cannot be disabled independently.

What is Member RBAC and how is it different from current roles?

Member RBAC lets workspace owners create custom roles to control end-user access to tools. Existing roles such as Member, Admin, and Owner govern workspace-management rights.

Built-in workspace roles determine what someone can manage:

  • Owner: Manages workspace-wide settings, membership, and custom roles.

  • Admin: Manages supported workspace members, groups, and administrative settings.

  • Analytics viewer: Views analytics available to that role.

  • Member: Uses features allowed by their plan, seat type, and assigned roles.

A tenant global admin does not automatically receive a role in a ChatGPT workspace.

Only workspace owners and admins can create workspace Admin keys. Custom roles do not grant Admin key access, and sensitive compliance permissions require a workspace owner. For setup and role requirements, see: Managing Admin keys in Admin Console.

How do I assign roles to people or groups?

In Workspace settings > Permissions & roles > Custom roles, assign roles to individual users or to groups created in Groups or synced through SCIM. To assign a role to a specific user, open the user’s profile, go to Direct roles, and select Assign direct role. Users receive permissions from both direct role assignments and group role assignments.

Can I create my own roles?

Yes. Use Add new role in the Custom roles tab to define roles with tailored permissions.

What is required to enable RBAC for my workspace?

Nothing extra. RBAC is available to eligible workspace owners in the admin dashboard. Create or sync groups, assign roles to groups, or use direct role assignments where available.

How does RBAC evaluate roles, assignments, and defaults?

Workspace settings provide the baseline for eligible permissions. In an ordinary custom role:

  • Default inherits the workspace setting.

  • On explicitly grants the permission.

  • Off denies access through that role.

A member can receive multiple ordinary roles through direct and group assignments. Permissions from these roles combine additively: if any role grants a permission, either explicitly or by inheriting an enabled workspace setting, the member retains access. An Off setting denies access through that role only. If every applicable role is set to Off, access is denied. If all applicable ordinary roles use Default, the workspace setting applies.

Lockdown Mode is a separate veto path. A Lockdown assignment can restrict a capability even when an ordinary role grants it. A member’s seat type and other plan or product eligibility requirements also continue to apply.

How to configure RBAC in your workspace

  1. Open Workspace settings.

  2. Select Permissions & roles in the left panel. Workspace owners and authorized workspace admins can access this area, but only owners can create, delete, assign, or unassign custom roles.

  3. Open the Workspace tab to review the baseline permissions for members.

For eligible permissions, the workspace setting is inherited by a custom role when that role is set to Default. A role set to On grants the permission through that role. A role set to Off denies access through that role, but access remains available if another assigned role grants or inherits the permission.

Settings & permissions page with Workspace and Custom roles tabs for configuring baseline and custom access

As you scroll through the page, configure the workspace baseline for eligible permissions.

To create a custom role:

  1. Open the Custom roles tab.

  2. Select Create role.

  3. Enter a role name and description.

  4. Select Save.

Settings & permissions page with Custom roles tab selected and Create role button
New custom role dialog with the role name Full GPT Access, an optional description, and Save and Cancel buttons.

On the custom role permission page, choose Default, On, or Off for each eligible permission. Two-state permissions continue to use On or Off.

GPT permission settings for a custom role, with creation, workspace publishing, external publishing, and both GPT access options enabled.
Workspace Search settings with Web search and Deep research enabled, Agent mode disabled

To assign the role to groups:

  1. Open Role assignments at the top of the custom-role page.

  2. Select + Add.

  3. Choose one or more groups.

  4. Select Done.

Full GPT Access role assignments tab with no groups found and an Add button
Assign groups to role dialog with Marketing added and R&D available to add

Group members receive the updated permissions after the change takes effect. Changes can take up to 5 minutes to take effect.

Examples

One ordinary role inherits the workspace setting

If the workspace setting for Web search is On and a member’s only ordinary custom role uses Default, the member inherits On.

One role is Off and another role is On

If one ordinary role sets Web search to Off and another ordinary role sets it to On, access is allowed because permissions across ordinary roles combine additively.

Every applicable ordinary role is Off

If all applicable ordinary roles set Web search to Off, the member does not receive access through ordinary RBAC, even if the workspace baseline is On.

Lockdown Mode applies

If an ordinary role grants a network-enabled capability but the member also has a Lockdown Mode role that restricts it, the Lockdown restriction applies.

FAQ

Are groups required for RBAC?

No. Roles can be assigned through groups, and direct role assignments are available where supported. Groups remain the recommended way to manage access at scale.

How long do RBAC changes take to apply?

Changes can take up to 5 minutes to take effect.

Does RBAC override a member’s seat type?

No. RBAC controls feature permissions within the access allowed by the member’s seat type and workspace plan.

What if a permission has only On and Off?

Some controls do not support Default. For those controls, configure On or Off explicitly for the workspace and relevant roles.

Was this article helpful?