Overview
ChatGPT Sites lets workspace members create and share hosted Sites from ChatGPT. Workspace owners and admins can help determine who can create Sites, who can publish them, how Sites are shared, and how Sites should be reviewed or removed when needed.
Availability
This article is for ChatGPT Business, Enterprise, and Edu owners and admins. Available controls depend on your plan and workspace configuration.
The delegated-access admin preview for connected-app access is available to ChatGPT Business and Enterprise customers.
Set workspace policies
Before enabling Sites broadly, decide who should be able to create Sites, whether public publishing should be allowed, what content can be published, and how your organization will handle support, review, takedown, and compliance questions.
Sites is currently in beta, and is not eligible for data or inference residency.
Enable or limit Sites
Business workspaces have Sites enabled by default. Enterprise owners and admins can use role-based access controls (RBAC) to decide who can create Sites and who can publish them.
In Enterprise workspaces, public publishing is off by default. To enable it, turn on public publishing in Workspace settings, then grant the appropriate users or groups permission to create and publish Sites through RBAC.
If a workspace member cannot use Sites, check whether Sites is enabled for the workspace, whether the member is in an eligible role or group, and whether the member is signed in to the correct workspace.
These settings control Site creation and publishing. They do not enable Sites to use members’ connected apps. Connected-app access requires separate organization approval.
Manage connected-app access
For ChatGPT Business and Enterprise customers, Sites can request permission to use each visitor’s own connected apps. For example, a shared dashboard can retrieve live information using the signed-in visitor’s account and existing permissions.
In the OpenAI Admin Console, a global admin opens External access, selects ChatGPT Sites, and reviews Connectors under Scopes. Tenant-level connected-app access for Sites is off by default during the admin preview. A ChatGPT workspace owner or admin does not automatically have permission to change this tenant-level setting.
For the organization approval steps, see: Managing your tenant in Admin Console.
Check access for a workspace member
If a Site cannot use a member’s connected app, check that:
A global admin has turned on Connectors for ChatGPT Sites in External access for the correct organization.
The Sites connected-app capability is available in the member’s workspace.
The individual app is enabled for the workspace and connected to the member’s account.
The member has signed in, reviewed the Site’s requested permissions, and authorized access.
The member has the required permissions in the connected app.
The organization-level approval covers current and future ChatGPT Sites. Each visitor still authorizes access through their own account; organization approval does not give every Site access to every member’s data.
Sharing a Site, enabling public publishing, and inviting external viewers do not independently authorize connected-app access.
Manage publishing and access
A Site can be limited to its owner and workspace admins, shared with active members of the workspace, or shared with selected active users or groups where supported. Public access is available only when public publishing is enabled and the member has permission to publish.
With co-editing, a Site owner can give an eligible active member of the same workspace Can edit access. Editors can update and save a shared Site. After the owner publishes the Site for the first time, editors can publish later versions to the same Site URL.
Only the Site owner can manage who has access, change the Site name or URL, transfer ownership, or configure owner-only settings such as secrets and custom domains. The owner can change an editor to Can view or remove them. These changes stop the person from editing; whether they can still view the Site depends on its remaining audience settings.
Public sharing makes a Site available outside the workspace according to the audience selected in the publishing flow.
Available controls vary by plan and workspace configuration. Custom domains are not available in Enterprise workspaces at launch. If you cannot find or use a control, contact OpenAI Support.
External viewers
Site owners can share a Site with named people outside the workspace as viewers, instead of publishing the site to the broad internet. Sites creators in Business workspaces have this enabled, as a part of the overall Sites permissions in Workspace settings; in Enterprise workspaces, the inviter needs the external-viewer invitation permission (see below). Workspace owners and admins can manage external viewers through the available Site access controls, in Workspace settings > Sites.
In Enterprise/Edu workspaces:
Go to Workspace settings > Permissions & roles.
Select the role that should be allowed to invite external viewers or choose workspace defaults.
Under Early access > Sites, make sure Sites is enabled for that role, or for the workspace.
Turn on Allow members to invite external visitors to sites for the selected role.
External viewers receive view-only access. They do not become workspace members or Site editors, and an invitation does not make the Site public. Public-publishing controls and external invitation permission are separate checks.
When granting or removing an external viewer, review the Site's existing audience. Removing a direct invitation may not remove access provided by another audience setting. Confirm the saved access list and the intended visitor experience after changes.
If the external invitation option is unavailable or a change does not take effect, confirm the selected workspace, the actor’s role and invitation permission, and the surface being used. If the issue persists, see: Contacting OpenAI Support.
Data, compliance, and residency considerations
Sites can involve prompts, instructions, files, site code, generated artifacts, hosted URLs, storage, and logs needed to operate and secure the Site.
ChatGPT Sites does not support data residency or inference residency at launch. This includes deployed Sites, Site code, D1/R2 data and file storage, artifacts, and logs. For more information, see: Data residency and inference residency for ChatGPT.
Recommended workspace policy
Give members clear guidelines for creating Sites that comply with your organization’s security, confidentiality, privacy, and other requirements.
Define a policy for when public publishing is allowed.
Require review before publishing sites that include confidential, sensitive, or third-party content.
Decide who can approve public Sites and who can remove them.
Document where members should report suspicious, malicious, infringing, or unsafe Sites.
