OpenAI launched ChatGPT Work on 9 July 2026 as an agent for longer tasks that can research, analyse, create finished deliverables and work across connected apps and files. That makes it useful. It also changes the privacy question.
The right question is no longer, “Does the AI have access to my files?” It is: Which account granted access, what can the connected app expose, when will the agent ask again, and is this task appropriate for that boundary?
Before connecting email, cloud storage, calendars or workplace systems, complete the following seven checks.
The permission audit
| Check | Green | Amber | Red |
|---|---|---|---|
| Account | Dedicated, managed work account | Personal account used for mixed work | Shared or privileged administrator account |
| App scope | Narrow folder/project access | Broad read access | Write/delete access not required by task |
| Confirmation | Ask before consequential actions | Persistent approval for low-risk work | Never ask across sensitive apps |
| Data class | Public or routine internal material | Confidential work with approved controls | Secrets, regulated data or restricted client material without approval |
| Memory | Deliberately configured | Default not reviewed | Sensitive app context retained unintentionally |
| Output | Human review before use | Review owner unclear | Automatic external delivery |
| Recovery | Access can be disconnected quickly | Admin needed but available | No clear revocation owner |
Any red item should stop the connection until the boundary is redesigned.
1. Connect the right identity
Do not begin with the most powerful account because it is convenient. Use the least privileged identity that can complete the task.
A personal ChatGPT account connected to corporate storage may sit outside the organisation’s approved controls. A corporate account connected to a personal drive can create the opposite problem. Managed workspaces may apply administrator policies that personal users cannot see or reproduce.
Write down:
which ChatGPT account is being used;
who owns the connected app account;
whether the organisation has approved the combination;
who can revoke access if the user is unavailable.
If those answers are unclear, do not connect the app during a live task.
2. Inspect the app’s underlying access
OpenAI’s current Apps in ChatGPT guidance makes an important distinction: changing ChatGPT’s permission prompt does not grant or remove the connected app’s underlying access. The available data and actions are determined by the app, the access granted at connection and workspace controls.
In plain language, “Always ask” and “Never ask” govern when ChatGPT asks before using access it already has. They do not replace the need to inspect what the connection can read or write.
Before authorising:
review the scopes shown by the external service;
prefer project, folder or site-level access over an entire account;
avoid write permission when the task is research-only;
check whether shared drives expose other teams’ material;
verify whether delegated access follows the employee or the organisation.
3. Keep consequential actions on “ask”
The official ChatGPT Work page says Work asks for permission before taking action and lets the user decide what ships. Use that control deliberately.
Persistent approval can be reasonable for repeated low-risk retrieval from a bounded source. It is not a good default for sending messages, publishing a site, changing a record, moving money, deleting files or committing an organisation to a decision.
Use a reversible-action test:
Read and summarise: usually lower consequence.
Draft but do not send: controlled and reviewable.
Update an internal working file: depends on versioning and scope.
Send, publish, purchase or delete: require explicit approval and human review.
The more difficult an action is to reverse, the less suitable it is for standing permission.
4. Classify the data before the task
An AI agent cannot respect a data policy that the user has not applied.
Sort the intended inputs into four classes:
public;
routine internal;
confidential;
restricted or regulated.
Then ask whether the account, workspace, connected app and task are approved for that class. Do not paste credentials, private keys, full identity documents or unnecessary client records merely because the agent could use them.
Minimise the working set. A folder containing the three relevant documents is preferable to a connection exposing years of unrelated files.
5. Review memory and model-use settings
OpenAI’s help guidance says ChatGPT may use information from enabled apps as context and, when Memory is enabled, may remember relevant information unless the source restricts it. It also distinguishes business accounts from personal plans: information accessed from apps is not used to train models by default for Business, Enterprise and Edu, while personal-plan treatment can depend on the “Improve the model for everyone” setting.
Check the current policy and settings for the exact plan; do not rely on a screenshot from another account or an old article.
The practical controls are:
disable or limit memory for tasks where persistence is unnecessary;
review data-control settings before connecting personal accounts;
use a managed workspace for organisational data when required;
disconnect apps that are no longer needed;
start a clean, bounded task rather than carrying unrelated context forward.
6. Assign a human reviewer
Work can create reports, spreadsheets, presentations and sites. Completion is not verification.
Assign a named person to check:
source accuracy;
calculations and formulas;
confidential information in the output;
permissions on the finished file or site;
whether recommendations exceed the evidence;
whether external delivery is authorised.
The reviewer should be appropriate to the consequence. A polished financial summary may still require finance review; a legal interpretation still requires qualified legal judgement.
7. Practise revocation before you need it
Know how to disconnect each app and who can disable it at workspace level. Changing from “Never ask” to “Always ask” does not remove the app’s underlying access; OpenAI’s guidance says disconnection or administrator action is required for that.
Create a simple offboarding checklist:
stop scheduled tasks;
disconnect unused apps;
revoke external-service tokens where appropriate;
transfer ownership of outputs;
review shared links and public sites;
confirm that the user’s role change is reflected in connected systems.
An access path that is easy to create but difficult to remove is not ready for sensitive work.
What should you connect first?
Start with a low-consequence, bounded source: a folder of public research, a copied dataset without personal information or a project calendar created for the experiment.
Do not begin with the chief executive’s complete inbox, the finance drive or a shared administrator account. Capability should be demonstrated before privilege expands.
Permission belongs near the action
The useful principle is platform-independent: permission should be visible at the moment an action becomes consequential. A connection screen accepted months earlier is weak evidence of present intent.
For a consequence-based example of where automation should stop and human judgement should begin, use the AI-agent and human-concierge travel disruption matrix.
The final decision
Connect ChatGPT Work when the identity, app scope, data class, confirmation mode and reviewer are all explicit. Keep consequential actions on ask, minimise the source set and know how to disconnect it.
An agent becomes more valuable as it gains context. It also becomes more important to decide which context it never needed in the first place.
Frequently asked questions
Does choosing “Always ask” remove a connected app’s access?
No. It changes when the assistant must ask before acting. Disconnecting or revoking the app is a separate control and should be used when the connection is no longer needed.
What should a team connect first?
Start with a bounded, low-consequence workflow that has a clear owner, visible logs and an easy rollback path. Expand access only after the team understands the agent’s real behaviour.
Should an AI agent be allowed to send, publish or delete automatically?
Those actions should normally require explicit confirmation because they create an external or destructive consequence. Preparation can be automated more broadly than execution.




