33980 and delegated work after rollout. Use the findings to adjust access,33980 and delegated work after rollout. Use the findings to adjust access,
33981 guidance, training, and expansion.33981 guidance, training, and expansion.
33982 33982
33983### ChatGPT Work cloud security
33984
33985Source: [ChatGPT Work cloud security](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security.md)
33986
33987ChatGPT Work runs cloud tasks in an isolated environment on OpenAI-managed
33988infrastructure. This guide explains what those tasks can access, which controls
33989administrators can apply, and how retention and auditing apply to different
33990categories of information.
33991
33992Capabilities and controls depend on the workspace plan, rollout, configuration,
33993and connected integration. For the broader execution model, see the
33994[ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview).
33995
33996#### Security at a glance
33997
33998- Tasks in the cloud run on OpenAI-managed infrastructure, not on the user's
33999 device.
34000- A cloud task doesn't inherit local files, desktop applications, browser
34001 sessions, or private-network access from that device.
34002- Connected apps use the permissions of the authorized account, which can be an
34003 individual, shared, or agent-owned account.
34004- Workspace and feature-specific controls govern Work access, local
34005 execution, cloud browsing, connected apps, and code or shell networking.
34006- Business, Enterprise, and Edu workspace data is encrypted in transit and at
34007 rest and isn't used to train OpenAI models by default.
34008- Retention and audit visibility depend on the data category, storage location,
34009 event, and applicable product configuration.
34010
34011#### Where cloud tasks run
34012
34013People can start cloud tasks from supported ChatGPT web, mobile, or desktop
34014experiences. Work on the web and mobile runs in the cloud. The desktop app can
34015run cloud or local tasks when the corresponding permissions are available and
34016enabled.
34017
34018The user's device sits within the organization's own IT-managed trust
34019boundary, outside OpenAI-operated systems. Starting a cloud task from the
34020desktop app doesn't give the task direct access to the user's computer.
34021Execution stays in the OpenAI-managed environment regardless of the surface
34022used to start it.
34023
34024Work Cloud uses the Codex task-execution harness. Work and Codex share core
34025execution and isolation mechanisms, but their available tools, permissions, and
34026administrative controls aren't identical. The customer controls workspace
34027access, approved connections, and information intentionally supplied to a task;
34028OpenAI manages the hosted execution environment.
34029
34030Work Cloud runs on shared, OpenAI-managed infrastructure. In the current
34031supported execution path, tasks run in VM-backed sandboxes, with execution state
34032associated with the authenticated account user in the workspace. Work can reuse
34033an environment across tasks or replace it while preserving eligible state. This
34034doesn't mean every task receives a new container or that each customer has a
34035dedicated physical host. Customers don't provide, host, or manage Work Cloud
34036containers.
34037
34038#### What a cloud task can access
34039
34040A cloud task can use information made available through an authorized path:
34041
34042- Information a person enters into a conversation.
34043- Files intentionally uploaded, attached from Library, or made available
34044 through a project.
34045- Content retrieved through an enabled app and an authorized account
34046 connection.
34047- Website content accessed through an enabled cloud browser or another
34048 permitted web capability, subject to applicable access controls.
34049
34050A cloud task doesn't directly inherit access to local files, installed
34051applications, or the user's browser session. A device's access to a corporate
34052VPN, internal website, or private network doesn't grant the cloud task that
34053access.
34054
34055An authorized connection can make information from an internal system available
34056through its own access path. That connection doesn't give the cloud task
34057unrestricted access to the employee's device or network.
34058
34059#### Apps, plugins, and connected accounts
34060
34061An app can give Work access to information or actions in another system. A
34062plugin can use an app as one of its underlying tools. Making a plugin available
34063doesn't automatically enable the underlying app, authorize an account, or
34064approve every action the integration can perform.
34065
34066A task that uses an app or connector can proceed only when:
34067
34068- The workspace enables the app and any plugin that requires it.
34069- The person has the necessary workspace or role access.
34070- The connection is authorized for an individual, shared, or agent-owned
34071 account.
34072- The connected account, approved scopes, and available app action settings
34073 permit the requested information or operation.
34074
34075For apps that support **Action control**, administrators can allow read-only
34076actions, all actions, or a custom set. **App permissions** control when
34077ChatGPT asks for confirmation to work with an app. Depending on the app and
34078workspace, options can include **Always ask**, **Any changes**, **Important
34079actions**, and **Never ask**. With **Any changes**, supported reads can proceed
34080without a prompt while changes require confirmation.
34081
34082When the approval policy allows it, an authorized action, including a write,
34083can run without a prompt. This doesn't expand the app's allowed actions,
34084workspace access, or the connected account's permissions. ChatGPT can still
34085block some high-risk actions.
34086
34087Confirm the plugin and each underlying app are available in the workspace.
34088Review role access, connected-account authorization, and action permissions as
34089distinct decisions. See
34090[Plugin controls](https://learn.chatgpt.com/docs/enterprise/apps-and-connectors).
34091
34092#### Personal and shared connections
34093
34094A personal connection uses the connected employee's permissions in the source
34095system. A shared or agent-owned connection uses the permissions of its
34096connected account instead. That account might access information or perform
34097actions that the requesting person couldn't access with a personal account.
34098
34099Before enabling a shared connection, limit the account's permissions and
34100scopes, choose who can use it, and review the actions it can perform. See
34101[Workspace Agent connections and permissions](https://help.openai.com/en/articles/20001143-chatgpt-workspace-agents-for-enterprise-and-business).
34102
34103Content retrieved from a connected app isn't automatically saved as a Library
34104file. If the content is later saved to a conversation, project, Library, or
34105synced index, that copy follows the rules for its saved location.
34106
34107#### Cloud browser and network access
34108
34109The cloud browser, web search, connected apps, and code or shell networking are
34110separate capabilities, and can each be configured. Restricting one doesn't
34111automatically disable the others.
34112
34113#### Cloud browser
34114
34115The cloud browser is a hosted tool a Work task can use to interact with
34116websites. Opening ChatGPT in a web browser or desktop app doesn't enable cloud
34117browsing; a cloud task can run without it.
34118
34119The hosted browser doesn't inherit the user's local browser profile, open tabs,
34120existing sign-ins, saved passwords, password manager, or browsing history.
34121
34122Supported website interactions can include public forms and can combine
34123information from an authorized app with a website task. Where available,
34124website permissions include **Always ask**, **Auto approve**, and **Always
34125allow**. **Auto approve** applies automated risk checks; **Always allow**
34126removes the interactive website-access review. Neither grants new app
34127permissions or approves every action on a website. Consequential actions can
34128still require separate confirmation.
34129
34130For a Work task to use the cloud browser in an Enterprise workspace,
34131administrators must enable both Work access and cloud browser access. See
34132[Using cloud browser in ChatGPT](https://help.openai.com/en/articles/20001280-using-cloud-browser-in-chatgpt).
34133
34134#### Code and shell networking
34135
34136Public internet access for code or shell execution follows its own network
34137policy. When public internet access is off, network destinations required for
34138ChatGPT Work can remain reachable through a managed destination allowlist.
34139
34140The allowlist governs network destinations, not shell commands. Disabling
34141public internet access for code or shell execution doesn't, by itself, disable
34142the cloud browser, web search, or connected apps. Changes to the network
34143setting apply after the current code run or shell command finishes and the
34144execution environment refreshes.
34145
34146See [Code and shell sandboxing](https://learn.chatgpt.com/docs/sandboxing?surface=web).
34147
34148#### Data handling and retention
34149
34150Business, Enterprise, and Edu workspace data is encrypted in transit and at
34151rest. OpenAI doesn't use an organization's business inputs or outputs to train
34152or improve its models by default. See
34153[Enterprise privacy](https://openai.com/enterprise-privacy/).
34154
34155Information associated with a cloud task doesn't follow one universal
34156retention schedule:
34157
34158| Data category | Retention and deletion behavior |
34159| ------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
34160| Work conversations | Follow the workspace conversation-retention settings. Deleted chats are generally scheduled for permanent deletion within 30 days, subject to published security, legal, and de-identification exceptions. |
34161| Hosted execution state and snapshots | Follow a separate lifecycle from conversations and files. Access to execution state is scoped to the account user, and the workspace conversation-retention setting informs eligible stored snapshots. Ending a task or deleting a chat doesn't immediately purge every related artifact. |
34162| Files saved to Library | Uploaded or generated files follow applicable Library and workspace retention rules. Deleting a conversation doesn't delete a file saved to Library. |
34163| Project files | Remain associated with their project until removed or the project is deleted, subject to applicable deletion rules. |
34164| Saved memories, when enabled | Follow separate memory controls. Deleting a conversation doesn't necessarily delete an existing saved memory. |
34165| Transient uploads | Eligible temporary Enterprise uploads outside Library can expire after 48 hours unless another applicable retention setting applies. |
34166| Connected-app content | Source-system records follow that system's policies. Copies saved to a conversation, project, Library, or synced index follow the rules for their saved location. |
34167| Cloud browser data | Hosted browser data is separate from local browser data. Users can remove saved cloud browser cookies through the applicable settings. |
34168| Compliance records | Compliance Logs Platform records are available for 30 days. Exported copies follow the receiving system's retention policy. |
34169
34170Deleting a conversation, removing a Library file or saved memory,
34171disconnecting an app, and clearing hosted browser data are separate actions.
34172Review the relevant storage location instead of assuming one action removes
34173every copy. See
34174[Chat and file retention policies](https://help.openai.com/en/articles/8983778-chat-and-file-retention-policies-in-chatgpt).
34175
34176Retaining appropriate conversation and execution context can help Work resume
34177interrupted tasks, refer to previous steps, and produce more consistent results.
34178Shorter retention or deletion can reduce that continuity, so choose settings
34179that balance security requirements with the usefulness of the workflow.
34180
34181Eligible Enterprise and Edu workspaces can use Enterprise Key Management for
34182supported stored content, including supported hosted execution snapshots when
34183customer-managed encryption is required. Coverage varies by data category and
34184deployment. Rotating a key doesn't delete existing data or, by itself, deny
34185access to earlier encrypted content. Revoking or disabling key access is a
34186separate action that can disrupt supported workflows. Neither replaces a
34187retention or deletion policy.
34188
34189Data residency and inference residency apply only to eligible content and
34190supported workloads, subject to the organization's agreement, region, and
34191configuration. Connected apps, external providers, and some processing or
34192synced indexes can follow separate location rules. Verify support for the
34193product, integration, and region. See
34194[Data residency and inference residency](https://help.openai.com/en/articles/9903489-data-residency-and-inference-residency-for-chatgpt).
34195
34196OpenAI API [Zero Data Retention](https://developers.openai.com/api/docs/guides/your-data#zero-data-retention)
34197is an API-specific control and doesn't define retention for ChatGPT Work.
34198
34199#### Administrator access controls
34200
34201Review the controls that apply to each part of a cloud task:
34202
34203- **Work Cloud and Work Local:** Where independent controls are available,
34204 manage cloud and local Work as distinct controls in **Workspace settings** >
34205 **Permissions & roles**. In other workspaces, local Work can share a control
34206 with Codex Local.
34207- **Apps and plugins:** Choose which integrations are available and which
34208 people or roles can use them.
34209- **Connected-account actions:** Review account permissions, application
34210 scopes, and available action or confirmation controls.
34211- **Browser and networking:** Assess cloud browser access and code or shell
34212 public-network access independently.
34213
34214Where separate **Work Cloud** and **Work Local** controls are available, enable
34215**Work Cloud** and disable **Work Local** for the intended role to permit cloud
34216Work without local execution. Where local Work and Codex share a control,
34217review the effect on both before disabling local execution. These controls
34218don't prevent an authorized person from intentionally uploading a file to a
34219cloud task.
34220
34221For supported role permissions with **Default**, **On**, and **Off** states,
34222**Default** inherits the workspace setting, **On** grants access, and an
34223explicit **Off** in any applicable ordinary role denies access. Some Work and
34224plugin settings use different, two-state controls. Verify each person's
34225effective access, especially when more than one role applies. See
34226[Role-based access control](https://help.openai.com/en/articles/11750701-rbac).
34227
34228Where available, the **Work Cloud** permission applies across supported web,
34229mobile, and desktop experiences. It doesn't independently select which of those
34230surfaces can run cloud tasks. Consider device-management or other access
34231controls if a deployment must exclude a particular surface.
34232
34233#### Audit and compliance visibility
34234
34235For eligible Enterprise and Edu workspaces, the Compliance Logs Platform can
34236include supported Work prompts and responses. Connected-app calls have separate
34237logs, and available source-system audit records vary by integration.
34238Supported compliance endpoints can provide access to eligible Library files.
34239
34240Coverage depends on the event and the system where it occurs. Don't assume
34241every shell command, browser interaction, app invocation, file operation, or
34242approval appears in a customer-visible compliance export.
34243
34244Endpoint monitoring can observe the ChatGPT client or network traffic on managed
34245devices, but can't inspect actions inside the hosted execution environment. Use
34246supported Work, compliance, and connected-system records instead.
34247
34248Review current compliance event coverage alongside workspace reporting,
34249connected-system audit logs, and the retention policies of systems receiving
34250exported records. See the
34251[OpenAI Compliance Platform](https://help.openai.com/en/articles/9261474-compliance-api-for-chatgpt-enterprise-edu-and-chatgpt-for-teachers).
34252
34253#### Start with a restricted, useful workflow
34254
34255A security team can upload a current vendor advisory, compare it with an
34256authorized asset inventory, and review a draft exposure assessment before
34257taking action. If cloud browsing or an app connection isn't enabled, the team
34258can provide the advisory and an approved inventory extract directly.
34259
34260Start with a small group and enable only the access needed for the task. Verify
34261connected-account permissions, data retention, human review points, and
34262available logs before expanding the rollout. For rollout planning, see the
34263[Admin rollout guide](https://learn.chatgpt.com/docs/enterprise/admin-setup).
34264
33983### ChatGPT Work Overview34265### ChatGPT Work Overview
33984 34266
33985Source: [ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview.md)34267Source: [ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview.md)
33999web. Availability and administrative controls depend on your plan and workspace34281web. Availability and administrative controls depend on your plan and workspace
34000configuration.34282configuration.
34001 34283
34284For a focused review of hosted execution, connected-account permissions,
34285browser and network settings, retention, and audit visibility, see
34286[ChatGPT Work cloud security](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security).
34287
34002#### Execution isolation, files, and device access34288#### Execution isolation, files, and device access
34003 34289
34004The files and tools available to ChatGPT Work depend on where Work is running,34290The files and tools available to ChatGPT Work depend on where Work is running,
34077browser. It can't access local tabs, extensions, browsing history, saved34363browser. It can't access local tabs, extensions, browsing history, saved
34078passwords, or authenticated local sessions.34364passwords, or authenticated local sessions.
34079 34365
34080The cloud browser supports public, signed-out websites. It can navigate pages,34366The cloud browser can navigate public websites, enter information into supported
34081enter information into supported public forms, and combine relevant information34367public forms, and combine relevant information from an approved app with a
34082from an approved app with a website task. It can't accept credentials, use a34368website task. Depending on workspace configuration and available browser
34083password manager or saved form entries, sign in to a website, or complete34369capabilities, supported workflows can request a separate, user-authorized
34084payments. If a task requires one of those unsupported steps, it stops. Browser34370sign-in or passkey action. This doesn't grant access to the user's existing
34371local browser sessions, saved passwords, or password manager. Browser
34085availability depends on your plan, region, rollout, and workspace permissions.34372availability depends on your plan, region, rollout, and workspace permissions.
34086For Enterprise workspaces, an administrator must enable cloud browser access in34373For Enterprise workspaces, an administrator must enable cloud browser access in
34087addition to Work access.34374addition to Work access.
34117For Enterprise and Edu workspaces, plugins and their underlying apps are off by34404For Enterprise and Edu workspaces, plugins and their underlying apps are off by
34118default. For Business workspaces, plugins and apps are on by default. Making a34405default. For Business workspaces, plugins and apps are on by default. Making a
34119plugin available doesn't automatically enable its required app or grant access34406plugin available doesn't automatically enable its required app or grant access
34120to a user's account. The user must enable the plugin and authenticate before34407to an account. The required connection must be authorized for an individual,
34121ChatGPT Work can access it.34408shared, or agent-owned account before ChatGPT Work can access it. A shared or
34409agent-owned connection uses the connected account's source-system permissions,
34410which can differ from the requesting user's permissions.
34122 34411
34123Where supported, administrators can restrict an app to read-only actions or an34412Where supported, administrators can restrict an app to read-only actions or an
34124approved set of actions. App permission settings can also determine whether34413approved set of actions. App permission settings can also determine whether
36549 36838
36550- [ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview): Understand hosted execution, network controls, data boundaries, and audit visibility.36839- [ChatGPT Work Overview](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-overview): Understand hosted execution, network controls, data boundaries, and audit visibility.
36551 36840
36841- [ChatGPT Work cloud security](https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security): Review hosted execution, connected accounts, access controls, retention, and audit visibility.
36842
36552- [ChatGPT Work admin FAQ](https://learn.chatgpt.com/docs/enterprise/work-admin-faq): Review access, data, governance, usage, and incident controls for ChatGPT Work.36843- [ChatGPT Work admin FAQ](https://learn.chatgpt.com/docs/enterprise/work-admin-faq): Review access, data, governance, usage, and incident controls for ChatGPT Work.
36553 36844
36554#### Identity and authentication36845#### Identity and authentication