SpyBara
Go Premium

Documentation 2026-08-24 22:00 UTC to 2026-08-25 00:02 UTC

4 files changed +600 −14. View all changes and history on the product overview
2026
Tue 25 00:02 Mon 24 22:00 Sat 22 04:57 Fri 21 19:59 Thu 20 23:59 Wed 19 22:57 Tue 18 13:01 Mon 17 23:58 Sat 15 01:01 Fri 14 22:00 Thu 13 22:59 Wed 12 19:59 Tue 11 22:59 Mon 10 22:00 Sat 8 03:02 Fri 7 18:59 Thu 6 23:58 Wed 5 19:00 Tue 4 22:00 Mon 3 23:00 Sun 2 21:00
Details

35 href: "/codex/enterprise/chatgpt-work-overview",35 href: "/codex/enterprise/chatgpt-work-overview",

36 icon: "shieldCheck",36 icon: "shieldCheck",

37 },37 },

38 {

39 title: "ChatGPT Work cloud security",

40 description:

41 "Review hosted execution, connected accounts, access controls, retention, and audit visibility.",

42 href: "/codex/enterprise/chatgpt-work-cloud-security",

43 icon: "shieldCheck",

44 },

38 {45 {

39 title: "ChatGPT Work admin FAQ",46 title: "ChatGPT Work admin FAQ",

40 description:47 description:

codex-manual.md +298 −7

Details

33980 and delegated work after rollout. Use the findings to adjust access,33980 and delegated work after rollout. Use the findings to adjust access,

33981 guidance, training, and expansion.33981 guidance, training, and expansion.

33982 33982 

33983### ChatGPT Work cloud security

33984 

33985Source: [ChatGPT Work cloud security](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security.md)

33986 

33987ChatGPT Work runs cloud tasks in an isolated environment on OpenAI-managed

33988infrastructure. This guide explains what those tasks can access, which controls

33989administrators can apply, and how retention and auditing apply to different

33990categories of information.

33991 

33992Capabilities and controls depend on the workspace plan, rollout, configuration,

33993and connected integration. For the broader execution model, see the

33994[ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview).

33995 

33996#### Security at a glance

33997 

33998- Tasks in the cloud run on OpenAI-managed infrastructure, not on the user's

33999 device.

34000- A cloud task doesn't inherit local files, desktop applications, browser

34001 sessions, or private-network access from that device.

34002- Connected apps use the permissions of the authorized account, which can be an

34003 individual, shared, or agent-owned account.

34004- Workspace and feature-specific controls govern Work access, local

34005 execution, cloud browsing, connected apps, and code or shell networking.

34006- Business, Enterprise, and Edu workspace data is encrypted in transit and at

34007 rest and isn't used to train OpenAI models by default.

34008- Retention and audit visibility depend on the data category, storage location,

34009 event, and applicable product configuration.

34010 

34011#### Where cloud tasks run

34012 

34013People can start cloud tasks from supported ChatGPT web, mobile, or desktop

34014experiences. Work on the web and mobile runs in the cloud. The desktop app can

34015run cloud or local tasks when the corresponding permissions are available and

34016enabled.

34017 

34018The user's device sits within the organization's own IT-managed trust

34019boundary, outside OpenAI-operated systems. Starting a cloud task from the

34020desktop app doesn't give the task direct access to the user's computer.

34021Execution stays in the OpenAI-managed environment regardless of the surface

34022used to start it.

34023 

34024Work Cloud uses the Codex task-execution harness. Work and Codex share core

34025execution and isolation mechanisms, but their available tools, permissions, and

34026administrative controls aren't identical. The customer controls workspace

34027access, approved connections, and information intentionally supplied to a task;

34028OpenAI manages the hosted execution environment.

34029 

34030Work Cloud runs on shared, OpenAI-managed infrastructure. In the current

34031supported execution path, tasks run in VM-backed sandboxes, with execution state

34032associated with the authenticated account user in the workspace. Work can reuse

34033an environment across tasks or replace it while preserving eligible state. This

34034doesn't mean every task receives a new container or that each customer has a

34035dedicated physical host. Customers don't provide, host, or manage Work Cloud

34036containers.

34037 

34038#### What a cloud task can access

34039 

34040A cloud task can use information made available through an authorized path:

34041 

34042- Information a person enters into a conversation.

34043- Files intentionally uploaded, attached from Library, or made available

34044 through a project.

34045- Content retrieved through an enabled app and an authorized account

34046 connection.

34047- Website content accessed through an enabled cloud browser or another

34048 permitted web capability, subject to applicable access controls.

34049 

34050A cloud task doesn't directly inherit access to local files, installed

34051applications, or the user's browser session. A device's access to a corporate

34052VPN, internal website, or private network doesn't grant the cloud task that

34053access.

34054 

34055An authorized connection can make information from an internal system available

34056through its own access path. That connection doesn't give the cloud task

34057unrestricted access to the employee's device or network.

34058 

34059#### Apps, plugins, and connected accounts

34060 

34061An app can give Work access to information or actions in another system. A

34062plugin can use an app as one of its underlying tools. Making a plugin available

34063doesn't automatically enable the underlying app, authorize an account, or

34064approve every action the integration can perform.

34065 

34066A task that uses an app or connector can proceed only when:

34067 

34068- The workspace enables the app and any plugin that requires it.

34069- The person has the necessary workspace or role access.

34070- The connection is authorized for an individual, shared, or agent-owned

34071 account.

34072- The connected account, approved scopes, and available app action settings

34073 permit the requested information or operation.

34074 

34075For apps that support **Action control**, administrators can allow read-only

34076actions, all actions, or a custom set. **App permissions** control when

34077ChatGPT asks for confirmation to work with an app. Depending on the app and

34078workspace, options can include **Always ask**, **Any changes**, **Important

34079actions**, and **Never ask**. With **Any changes**, supported reads can proceed

34080without a prompt while changes require confirmation.

34081 

34082When the approval policy allows it, an authorized action, including a write,

34083can run without a prompt. This doesn't expand the app's allowed actions,

34084workspace access, or the connected account's permissions. ChatGPT can still

34085block some high-risk actions.

34086 

34087Confirm the plugin and each underlying app are available in the workspace.

34088Review role access, connected-account authorization, and action permissions as

34089distinct decisions. See

34090[Plugin controls](https://learn.chatgpt.com/docs/enterprise/apps-and-connectors).

34091 

34092#### Personal and shared connections

34093 

34094A personal connection uses the connected employee's permissions in the source

34095system. A shared or agent-owned connection uses the permissions of its

34096connected account instead. That account might access information or perform

34097actions that the requesting person couldn't access with a personal account.

34098 

34099Before enabling a shared connection, limit the account's permissions and

34100scopes, choose who can use it, and review the actions it can perform. See

34101[Workspace Agent connections and permissions](https://help.openai.com/en/articles/20001143-chatgpt-workspace-agents-for-enterprise-and-business).

34102 

34103Content retrieved from a connected app isn't automatically saved as a Library

34104file. If the content is later saved to a conversation, project, Library, or

34105synced index, that copy follows the rules for its saved location.

34106 

34107#### Cloud browser and network access

34108 

34109The cloud browser, web search, connected apps, and code or shell networking are

34110separate capabilities, and can each be configured. Restricting one doesn't

34111automatically disable the others.

34112 

34113#### Cloud browser

34114 

34115The cloud browser is a hosted tool a Work task can use to interact with

34116websites. Opening ChatGPT in a web browser or desktop app doesn't enable cloud

34117browsing; a cloud task can run without it.

34118 

34119The hosted browser doesn't inherit the user's local browser profile, open tabs,

34120existing sign-ins, saved passwords, password manager, or browsing history.

34121 

34122Supported website interactions can include public forms and can combine

34123information from an authorized app with a website task. Where available,

34124website permissions include **Always ask**, **Auto approve**, and **Always

34125allow**. **Auto approve** applies automated risk checks; **Always allow**

34126removes the interactive website-access review. Neither grants new app

34127permissions or approves every action on a website. Consequential actions can

34128still require separate confirmation.

34129 

34130For a Work task to use the cloud browser in an Enterprise workspace,

34131administrators must enable both Work access and cloud browser access. See

34132[Using cloud browser in ChatGPT](https://help.openai.com/en/articles/20001280-using-cloud-browser-in-chatgpt).

34133 

34134#### Code and shell networking

34135 

34136Public internet access for code or shell execution follows its own network

34137policy. When public internet access is off, network destinations required for

34138ChatGPT Work can remain reachable through a managed destination allowlist.

34139 

34140The allowlist governs network destinations, not shell commands. Disabling

34141public internet access for code or shell execution doesn't, by itself, disable

34142the cloud browser, web search, or connected apps. Changes to the network

34143setting apply after the current code run or shell command finishes and the

34144execution environment refreshes.

34145 

34146See [Code and shell sandboxing](https://learn.chatgpt.com/docs/sandboxing?surface=web).

34147 

34148#### Data handling and retention

34149 

34150Business, Enterprise, and Edu workspace data is encrypted in transit and at

34151rest. OpenAI doesn't use an organization's business inputs or outputs to train

34152or improve its models by default. See

34153[Enterprise privacy](https://openai.com/enterprise-privacy/).

34154 

34155Information associated with a cloud task doesn't follow one universal

34156retention schedule:

34157 

34158| Data category | Retention and deletion behavior |

34159| ------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

34160| Work conversations | Follow the workspace conversation-retention settings. Deleted chats are generally scheduled for permanent deletion within 30 days, subject to published security, legal, and de-identification exceptions. |

34161| Hosted execution state and snapshots | Follow a separate lifecycle from conversations and files. Access to execution state is scoped to the account user, and the workspace conversation-retention setting informs eligible stored snapshots. Ending a task or deleting a chat doesn't immediately purge every related artifact. |

34162| Files saved to Library | Uploaded or generated files follow applicable Library and workspace retention rules. Deleting a conversation doesn't delete a file saved to Library. |

34163| Project files | Remain associated with their project until removed or the project is deleted, subject to applicable deletion rules. |

34164| Saved memories, when enabled | Follow separate memory controls. Deleting a conversation doesn't necessarily delete an existing saved memory. |

34165| Transient uploads | Eligible temporary Enterprise uploads outside Library can expire after 48 hours unless another applicable retention setting applies. |

34166| Connected-app content | Source-system records follow that system's policies. Copies saved to a conversation, project, Library, or synced index follow the rules for their saved location. |

34167| Cloud browser data | Hosted browser data is separate from local browser data. Users can remove saved cloud browser cookies through the applicable settings. |

34168| Compliance records | Compliance Logs Platform records are available for 30 days. Exported copies follow the receiving system's retention policy. |

34169 

34170Deleting a conversation, removing a Library file or saved memory,

34171disconnecting an app, and clearing hosted browser data are separate actions.

34172Review the relevant storage location instead of assuming one action removes

34173every copy. See

34174[Chat and file retention policies](https://help.openai.com/en/articles/8983778-chat-and-file-retention-policies-in-chatgpt).

34175 

34176Retaining appropriate conversation and execution context can help Work resume

34177interrupted tasks, refer to previous steps, and produce more consistent results.

34178Shorter retention or deletion can reduce that continuity, so choose settings

34179that balance security requirements with the usefulness of the workflow.

34180 

34181Eligible Enterprise and Edu workspaces can use Enterprise Key Management for

34182supported stored content, including supported hosted execution snapshots when

34183customer-managed encryption is required. Coverage varies by data category and

34184deployment. Rotating a key doesn't delete existing data or, by itself, deny

34185access to earlier encrypted content. Revoking or disabling key access is a

34186separate action that can disrupt supported workflows. Neither replaces a

34187retention or deletion policy.

34188 

34189Data residency and inference residency apply only to eligible content and

34190supported workloads, subject to the organization's agreement, region, and

34191configuration. Connected apps, external providers, and some processing or

34192synced indexes can follow separate location rules. Verify support for the

34193product, integration, and region. See

34194[Data residency and inference residency](https://help.openai.com/en/articles/9903489-data-residency-and-inference-residency-for-chatgpt).

34195 

34196OpenAI API [Zero Data Retention](https://developers.openai.com/api/docs/guides/your-data#zero-data-retention)

34197is an API-specific control and doesn't define retention for ChatGPT Work.

34198 

34199#### Administrator access controls

34200 

34201Review the controls that apply to each part of a cloud task:

34202 

34203- **Work Cloud and Work Local:** Where independent controls are available,

34204 manage cloud and local Work as distinct controls in **Workspace settings** >

34205 **Permissions & roles**. In other workspaces, local Work can share a control

34206 with Codex Local.

34207- **Apps and plugins:** Choose which integrations are available and which

34208 people or roles can use them.

34209- **Connected-account actions:** Review account permissions, application

34210 scopes, and available action or confirmation controls.

34211- **Browser and networking:** Assess cloud browser access and code or shell

34212 public-network access independently.

34213 

34214Where separate **Work Cloud** and **Work Local** controls are available, enable

34215**Work Cloud** and disable **Work Local** for the intended role to permit cloud

34216Work without local execution. Where local Work and Codex share a control,

34217review the effect on both before disabling local execution. These controls

34218don't prevent an authorized person from intentionally uploading a file to a

34219cloud task.

34220 

34221For supported role permissions with **Default**, **On**, and **Off** states,

34222**Default** inherits the workspace setting, **On** grants access, and an

34223explicit **Off** in any applicable ordinary role denies access. Some Work and

34224plugin settings use different, two-state controls. Verify each person's

34225effective access, especially when more than one role applies. See

34226[Role-based access control](https://help.openai.com/en/articles/11750701-rbac).

34227 

34228Where available, the **Work Cloud** permission applies across supported web,

34229mobile, and desktop experiences. It doesn't independently select which of those

34230surfaces can run cloud tasks. Consider device-management or other access

34231controls if a deployment must exclude a particular surface.

34232 

34233#### Audit and compliance visibility

34234 

34235For eligible Enterprise and Edu workspaces, the Compliance Logs Platform can

34236include supported Work prompts and responses. Connected-app calls have separate

34237logs, and available source-system audit records vary by integration.

34238Supported compliance endpoints can provide access to eligible Library files.

34239 

34240Coverage depends on the event and the system where it occurs. Don't assume

34241every shell command, browser interaction, app invocation, file operation, or

34242approval appears in a customer-visible compliance export.

34243 

34244Endpoint monitoring can observe the ChatGPT client or network traffic on managed

34245devices, but can't inspect actions inside the hosted execution environment. Use

34246supported Work, compliance, and connected-system records instead.

34247 

34248Review current compliance event coverage alongside workspace reporting,

34249connected-system audit logs, and the retention policies of systems receiving

34250exported records. See the

34251[OpenAI Compliance Platform](https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers).

34252 

34253#### Start with a restricted, useful workflow

34254 

34255A security team can upload a current vendor advisory, compare it with an

34256authorized asset inventory, and review a draft exposure assessment before

34257taking action. If cloud browsing or an app connection isn't enabled, the team

34258can provide the advisory and an approved inventory extract directly.

34259 

34260Start with a small group and enable only the access needed for the task. Verify

34261connected-account permissions, data retention, human review points, and

34262available logs before expanding the rollout. For rollout planning, see the

34263[Admin rollout guide](https://learn.chatgpt.com/docs/enterprise/admin-setup).

34264 

33983### ChatGPT Work Overview34265### ChatGPT Work Overview

33984 34266 

33985Source: [ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview.md)34267Source: [ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview.md)


33999web. Availability and administrative controls depend on your plan and workspace34281web. Availability and administrative controls depend on your plan and workspace

34000configuration.34282configuration.

34001 34283 

34284For a focused review of hosted execution, connected-account permissions,

34285browser and network settings, retention, and audit visibility, see

34286[ChatGPT Work cloud security](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security).

34287 

34002#### Execution isolation, files, and device access34288#### Execution isolation, files, and device access

34003 34289 

34004The files and tools available to ChatGPT Work depend on where Work is running,34290The files and tools available to ChatGPT Work depend on where Work is running,


34077browser. It can't access local tabs, extensions, browsing history, saved34363browser. It can't access local tabs, extensions, browsing history, saved

34078passwords, or authenticated local sessions.34364passwords, or authenticated local sessions.

34079 34365 

34080The cloud browser supports public, signed-out websites. It can navigate pages,34366The cloud browser can navigate public websites, enter information into supported

34081enter information into supported public forms, and combine relevant information34367public forms, and combine relevant information from an approved app with a

34082from an approved app with a website task. It can't accept credentials, use a34368website task. Depending on workspace configuration and available browser

34083password manager or saved form entries, sign in to a website, or complete34369capabilities, supported workflows can request a separate, user-authorized

34084payments. If a task requires one of those unsupported steps, it stops. Browser34370sign-in or passkey action. This doesn't grant access to the user's existing

34371local browser sessions, saved passwords, or password manager. Browser

34085availability depends on your plan, region, rollout, and workspace permissions.34372availability depends on your plan, region, rollout, and workspace permissions.

34086For Enterprise workspaces, an administrator must enable cloud browser access in34373For Enterprise workspaces, an administrator must enable cloud browser access in

34087addition to Work access.34374addition to Work access.


34117For Enterprise and Edu workspaces, plugins and their underlying apps are off by34404For Enterprise and Edu workspaces, plugins and their underlying apps are off by

34118default. For Business workspaces, plugins and apps are on by default. Making a34405default. For Business workspaces, plugins and apps are on by default. Making a

34119plugin available doesn't automatically enable its required app or grant access34406plugin available doesn't automatically enable its required app or grant access

34120to a user's account. The user must enable the plugin and authenticate before34407to an account. The required connection must be authorized for an individual,

34121ChatGPT Work can access it.34408shared, or agent-owned account before ChatGPT Work can access it. A shared or

34409agent-owned connection uses the connected account's source-system permissions,

34410which can differ from the requesting user's permissions.

34122 34411 

34123Where supported, administrators can restrict an app to read-only actions or an34412Where supported, administrators can restrict an app to read-only actions or an

34124approved set of actions. App permission settings can also determine whether34413approved set of actions. App permission settings can also determine whether


36549 36838 

36550- [ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview): Understand hosted execution, network controls, data boundaries, and audit visibility.36839- [ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview): Understand hosted execution, network controls, data boundaries, and audit visibility.

36551 36840 

36841- [ChatGPT Work cloud security](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security): Review hosted execution, connected accounts, access controls, retention, and audit visibility.

36842 

36552- [ChatGPT Work admin FAQ](https://learn.chatgpt.com/docs/enterprise/work-admin-faq): Review access, data, governance, usage, and incident controls for ChatGPT Work.36843- [ChatGPT Work admin FAQ](https://learn.chatgpt.com/docs/enterprise/work-admin-faq): Review access, data, governance, usage, and incident controls for ChatGPT Work.

36553 36844 

36554#### Identity and authentication36845#### Identity and authentication

Details

1# ChatGPT Work cloud security

2 

3> For the complete documentation index, see [llms.txt](https://learn.chatgpt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to the page URL.

4 

5ChatGPT Work runs cloud tasks in an isolated environment on OpenAI-managed

6infrastructure. This guide explains what those tasks can access, which controls

7administrators can apply, and how retention and auditing apply to different

8categories of information.

9 

10Capabilities and controls depend on the workspace plan, rollout, configuration,

11and connected integration. For the broader execution model, see the

12[ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview).

13 

14## Security at a glance

15 

16- Tasks in the cloud run on OpenAI-managed infrastructure, not on the user's

17 device.

18- A cloud task doesn't inherit local files, desktop applications, browser

19 sessions, or private-network access from that device.

20- Connected apps use the permissions of the authorized account, which can be an

21 individual, shared, or agent-owned account.

22- Workspace and feature-specific controls govern Work access, local

23 execution, cloud browsing, connected apps, and code or shell networking.

24- Business, Enterprise, and Edu workspace data is encrypted in transit and at

25 rest and isn't used to train OpenAI models by default.

26- Retention and audit visibility depend on the data category, storage location,

27 event, and applicable product configuration.

28 

29## Where cloud tasks run

30 

31People can start cloud tasks from supported ChatGPT web, mobile, or desktop

32experiences. Work on the web and mobile runs in the cloud. The desktop app can

33run cloud or local tasks when the corresponding permissions are available and

34enabled.

35 

36The user's device sits within the organization's own IT-managed trust

37boundary, outside OpenAI-operated systems. Starting a cloud task from the

38desktop app doesn't give the task direct access to the user's computer.

39Execution stays in the OpenAI-managed environment regardless of the surface

40used to start it.

41 

42Work Cloud uses the Codex task-execution harness. Work and Codex share core

43execution and isolation mechanisms, but their available tools, permissions, and

44administrative controls aren't identical. The customer controls workspace

45access, approved connections, and information intentionally supplied to a task;

46OpenAI manages the hosted execution environment.

47 

48Work Cloud runs on shared, OpenAI-managed infrastructure. In the current

49supported execution path, tasks run in VM-backed sandboxes, with execution state

50associated with the authenticated account user in the workspace. Work can reuse

51an environment across tasks or replace it while preserving eligible state. This

52doesn't mean every task receives a new container or that each customer has a

53dedicated physical host. Customers don't provide, host, or manage Work Cloud

54containers.

55 

56## What a cloud task can access

57 

58A cloud task can use information made available through an authorized path:

59 

60- Information a person enters into a conversation.

61- Files intentionally uploaded, attached from Library, or made available

62 through a project.

63- Content retrieved through an enabled app and an authorized account

64 connection.

65- Website content accessed through an enabled cloud browser or another

66 permitted web capability, subject to applicable access controls.

67 

68A cloud task doesn't directly inherit access to local files, installed

69applications, or the user's browser session. A device's access to a corporate

70VPN, internal website, or private network doesn't grant the cloud task that

71access.

72 

73An authorized connection can make information from an internal system available

74through its own access path. That connection doesn't give the cloud task

75unrestricted access to the employee's device or network.

76 

77## Apps, plugins, and connected accounts

78 

79An app can give Work access to information or actions in another system. A

80plugin can use an app as one of its underlying tools. Making a plugin available

81doesn't automatically enable the underlying app, authorize an account, or

82approve every action the integration can perform.

83 

84A task that uses an app or connector can proceed only when:

85 

86- The workspace enables the app and any plugin that requires it.

87- The person has the necessary workspace or role access.

88- The connection is authorized for an individual, shared, or agent-owned

89 account.

90- The connected account, approved scopes, and available app action settings

91 permit the requested information or operation.

92 

93For apps that support **Action control**, administrators can allow read-only

94actions, all actions, or a custom set. **App permissions** control when

95ChatGPT asks for confirmation to work with an app. Depending on the app and

96workspace, options can include **Always ask**, **Any changes**, **Important

97actions**, and **Never ask**. With **Any changes**, supported reads can proceed

98without a prompt while changes require confirmation.

99 

100When the approval policy allows it, an authorized action, including a write,

101can run without a prompt. This doesn't expand the app's allowed actions,

102workspace access, or the connected account's permissions. ChatGPT can still

103block some high-risk actions.

104 

105Confirm the plugin and each underlying app are available in the workspace.

106Review role access, connected-account authorization, and action permissions as

107distinct decisions. See

108[Plugin controls](https://learn.chatgpt.com/docs/enterprise/apps-and-connectors).

109 

110### Personal and shared connections

111 

112A personal connection uses the connected employee's permissions in the source

113system. A shared or agent-owned connection uses the permissions of its

114connected account instead. That account might access information or perform

115actions that the requesting person couldn't access with a personal account.

116 

117Before enabling a shared connection, limit the account's permissions and

118scopes, choose who can use it, and review the actions it can perform. See

119[Workspace Agent connections and permissions](https://help.openai.com/en/articles/20001143-chatgpt-workspace-agents-for-enterprise-and-business).

120 

121Content retrieved from a connected app isn't automatically saved as a Library

122file. If the content is later saved to a conversation, project, Library, or

123synced index, that copy follows the rules for its saved location.

124 

125## Cloud browser and network access

126 

127The cloud browser, web search, connected apps, and code or shell networking are

128separate capabilities, and can each be configured. Restricting one doesn't

129automatically disable the others.

130 

131### Cloud browser

132 

133The cloud browser is a hosted tool a Work task can use to interact with

134websites. Opening ChatGPT in a web browser or desktop app doesn't enable cloud

135browsing; a cloud task can run without it.

136 

137The hosted browser doesn't inherit the user's local browser profile, open tabs,

138existing sign-ins, saved passwords, password manager, or browsing history.

139 

140Supported website interactions can include public forms and can combine

141information from an authorized app with a website task. Where available,

142website permissions include **Always ask**, **Auto approve**, and **Always

143allow**. **Auto approve** applies automated risk checks; **Always allow**

144removes the interactive website-access review. Neither grants new app

145permissions or approves every action on a website. Consequential actions can

146still require separate confirmation.

147 

148For a Work task to use the cloud browser in an Enterprise workspace,

149administrators must enable both Work access and cloud browser access. See

150[Using cloud browser in ChatGPT](https://help.openai.com/en/articles/20001280-using-cloud-browser-in-chatgpt).

151 

152### Code and shell networking

153 

154Public internet access for code or shell execution follows its own network

155policy. When public internet access is off, network destinations required for

156ChatGPT Work can remain reachable through a managed destination allowlist.

157 

158The allowlist governs network destinations, not shell commands. Disabling

159public internet access for code or shell execution doesn't, by itself, disable

160the cloud browser, web search, or connected apps. Changes to the network

161setting apply after the current code run or shell command finishes and the

162execution environment refreshes.

163 

164See [Code and shell sandboxing](https://learn.chatgpt.com/docs/sandboxing?surface=web).

165 

166## Data handling and retention

167 

168Business, Enterprise, and Edu workspace data is encrypted in transit and at

169rest. OpenAI doesn't use an organization's business inputs or outputs to train

170or improve its models by default. See

171[Enterprise privacy](https://openai.com/enterprise-privacy/).

172 

173Information associated with a cloud task doesn't follow one universal

174retention schedule:

175 

176| Data category | Retention and deletion behavior |

177| ------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

178| Work conversations | Follow the workspace conversation-retention settings. Deleted chats are generally scheduled for permanent deletion within 30 days, subject to published security, legal, and de-identification exceptions. |

179| Hosted execution state and snapshots | Follow a separate lifecycle from conversations and files. Access to execution state is scoped to the account user, and the workspace conversation-retention setting informs eligible stored snapshots. Ending a task or deleting a chat doesn't immediately purge every related artifact. |

180| Files saved to Library | Uploaded or generated files follow applicable Library and workspace retention rules. Deleting a conversation doesn't delete a file saved to Library. |

181| Project files | Remain associated with their project until removed or the project is deleted, subject to applicable deletion rules. |

182| Saved memories, when enabled | Follow separate memory controls. Deleting a conversation doesn't necessarily delete an existing saved memory. |

183| Transient uploads | Eligible temporary Enterprise uploads outside Library can expire after 48 hours unless another applicable retention setting applies. |

184| Connected-app content | Source-system records follow that system's policies. Copies saved to a conversation, project, Library, or synced index follow the rules for their saved location. |

185| Cloud browser data | Hosted browser data is separate from local browser data. Users can remove saved cloud browser cookies through the applicable settings. |

186| Compliance records | Compliance Logs Platform records are available for 30 days. Exported copies follow the receiving system's retention policy. |

187 

188Deleting a conversation, removing a Library file or saved memory,

189disconnecting an app, and clearing hosted browser data are separate actions.

190Review the relevant storage location instead of assuming one action removes

191every copy. See

192[Chat and file retention policies](https://help.openai.com/en/articles/8983778-chat-and-file-retention-policies-in-chatgpt).

193 

194Retaining appropriate conversation and execution context can help Work resume

195interrupted tasks, refer to previous steps, and produce more consistent results.

196Shorter retention or deletion can reduce that continuity, so choose settings

197that balance security requirements with the usefulness of the workflow.

198 

199Eligible Enterprise and Edu workspaces can use Enterprise Key Management for

200supported stored content, including supported hosted execution snapshots when

201customer-managed encryption is required. Coverage varies by data category and

202deployment. Rotating a key doesn't delete existing data or, by itself, deny

203access to earlier encrypted content. Revoking or disabling key access is a

204separate action that can disrupt supported workflows. Neither replaces a

205retention or deletion policy.

206 

207Data residency and inference residency apply only to eligible content and

208supported workloads, subject to the organization's agreement, region, and

209configuration. Connected apps, external providers, and some processing or

210synced indexes can follow separate location rules. Verify support for the

211product, integration, and region. See

212[Data residency and inference residency](https://help.openai.com/en/articles/9903489-data-residency-and-inference-residency-for-chatgpt).

213 

214OpenAI API [Zero Data Retention](https://developers.openai.com/api/docs/guides/your-data#zero-data-retention)

215is an API-specific control and doesn't define retention for ChatGPT Work.

216 

217## Administrator access controls

218 

219Review the controls that apply to each part of a cloud task:

220 

221- **Work Cloud and Work Local:** Where independent controls are available,

222 manage cloud and local Work as distinct controls in **Workspace settings** >

223 **Permissions & roles**. In other workspaces, local Work can share a control

224 with Codex Local.

225- **Apps and plugins:** Choose which integrations are available and which

226 people or roles can use them.

227- **Connected-account actions:** Review account permissions, application

228 scopes, and available action or confirmation controls.

229- **Browser and networking:** Assess cloud browser access and code or shell

230 public-network access independently.

231 

232Where separate **Work Cloud** and **Work Local** controls are available, enable

233**Work Cloud** and disable **Work Local** for the intended role to permit cloud

234Work without local execution. Where local Work and Codex share a control,

235review the effect on both before disabling local execution. These controls

236don't prevent an authorized person from intentionally uploading a file to a

237cloud task.

238 

239For supported role permissions with **Default**, **On**, and **Off** states,

240**Default** inherits the workspace setting, **On** grants access, and an

241explicit **Off** in any applicable ordinary role denies access. Some Work and

242plugin settings use different, two-state controls. Verify each person's

243effective access, especially when more than one role applies. See

244[Role-based access control](https://help.openai.com/en/articles/11750701-rbac).

245 

246Where available, the **Work Cloud** permission applies across supported web,

247mobile, and desktop experiences. It doesn't independently select which of those

248surfaces can run cloud tasks. Consider device-management or other access

249controls if a deployment must exclude a particular surface.

250 

251## Audit and compliance visibility

252 

253For eligible Enterprise and Edu workspaces, the Compliance Logs Platform can

254include supported Work prompts and responses. Connected-app calls have separate

255logs, and available source-system audit records vary by integration.

256Supported compliance endpoints can provide access to eligible Library files.

257 

258Coverage depends on the event and the system where it occurs. Don't assume

259every shell command, browser interaction, app invocation, file operation, or

260approval appears in a customer-visible compliance export.

261 

262Endpoint monitoring can observe the ChatGPT client or network traffic on managed

263devices, but can't inspect actions inside the hosted execution environment. Use

264supported Work, compliance, and connected-system records instead.

265 

266Review current compliance event coverage alongside workspace reporting,

267connected-system audit logs, and the retention policies of systems receiving

268exported records. See the

269[OpenAI Compliance Platform](https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers).

270 

271## Start with a restricted, useful workflow

272 

273A security team can upload a current vendor advisory, compare it with an

274authorized asset inventory, and review a draft exposure assessment before

275taking action. If cloud browsing or an app connection isn't enabled, the team

276can provide the advisory and an approved inventory extract directly.

277 

278Start with a small group and enable only the access needed for the task. Verify

279connected-account permissions, data retention, human review points, and

280available logs before expanding the rollout. For rollout planning, see the

281[Admin rollout guide](https://learn.chatgpt.com/docs/enterprise/admin-setup).

Details

17web. Availability and administrative controls depend on your plan and workspace17web. Availability and administrative controls depend on your plan and workspace

18configuration.18configuration.

19 19 

20For a focused review of hosted execution, connected-account permissions,

21browser and network settings, retention, and audit visibility, see

22[ChatGPT Work cloud security](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security).

23 

20## Execution isolation, files, and device access24## Execution isolation, files, and device access

21 25 

22The files and tools available to ChatGPT Work depend on where Work is running,26The files and tools available to ChatGPT Work depend on where Work is running,


95browser. It can't access local tabs, extensions, browsing history, saved99browser. It can't access local tabs, extensions, browsing history, saved

96passwords, or authenticated local sessions.100passwords, or authenticated local sessions.

97 101 

98The cloud browser supports public, signed-out websites. It can navigate pages,102The cloud browser can navigate public websites, enter information into supported

99enter information into supported public forms, and combine relevant information103public forms, and combine relevant information from an approved app with a

100from an approved app with a website task. It can't accept credentials, use a104website task. Depending on workspace configuration and available browser

101password manager or saved form entries, sign in to a website, or complete105capabilities, supported workflows can request a separate, user-authorized

102payments. If a task requires one of those unsupported steps, it stops. Browser106sign-in or passkey action. This doesn't grant access to the user's existing

107local browser sessions, saved passwords, or password manager. Browser

103availability depends on your plan, region, rollout, and workspace permissions.108availability depends on your plan, region, rollout, and workspace permissions.

104For Enterprise workspaces, an administrator must enable cloud browser access in109For Enterprise workspaces, an administrator must enable cloud browser access in

105addition to Work access.110addition to Work access.


135For Enterprise and Edu workspaces, plugins and their underlying apps are off by140For Enterprise and Edu workspaces, plugins and their underlying apps are off by

136default. For Business workspaces, plugins and apps are on by default. Making a141default. For Business workspaces, plugins and apps are on by default. Making a

137plugin available doesn't automatically enable its required app or grant access142plugin available doesn't automatically enable its required app or grant access

138to a user's account. The user must enable the plugin and authenticate before143to an account. The required connection must be authorized for an individual,

139ChatGPT Work can access it.144shared, or agent-owned account before ChatGPT Work can access it. A shared or

145agent-owned connection uses the connected account's source-system permissions,

146which can differ from the requesting user's permissions.

140 147 

141Where supported, administrators can restrict an app to read-only actions or an148Where supported, administrators can restrict an app to read-only actions or an

142approved set of actions. App permission settings can also determine whether149approved set of actions. App permission settings can also determine whether