The word “Business” in the workspace name answers only one question. It does not show which account is active, which plugins or apps can reach company material, or whether the proposed task has been approved.
This reference uses OpenAI documentation checked from September 18 to 21, 2026. It is a configuration checklist, not a hands-on product review or a purchase recommendation.
This article provides general operational education. It is not legal advice or a compliance determination. No attorney-client relationship exists, and none of its protections apply.
Verify the workspace the user is actually in
OpenAI describes ChatGPT Business as a dedicated workspace with admin controls, SAML single sign-on, and multi-factor authentication. It also says Business data is not used to train its models by default.
Those statements do not establish that a task is suitable or that information is privileged. They also do not describe every connected service. Confirm that the user is inside the intended Business workspace rather than a personal account.
Ask the administrator how identity is managed. OpenAI's current admin documentation says Business does not include SCIM or synced identity groups. OpenAI's plan page lists SCIM, audit logs, and retention and residency controls under its Enterprise and Edu plans. Users can enable account-level MFA, while workspace-wide enforcement requires SSO with MFA through the identity provider.
Describe the task before uploading material
Write down the proposed input, output, reviewer, and destination. Identify information that must remain out of the workflow.
For an initial test, draft an internal meeting agenda from approved, non-sensitive notes. A named person reviews the result before it leaves the draft.
Do not upload matter-specific confidential material before the team has checked the workspace, contract, settings, permissions, and applicable professional duties. A vendor statement about data use does not answer those questions.
Treat plugins, apps, and actions as separate decisions
OpenAI's current documentation uses both terms. An app is a connected capability; a plugin can use an app as an underlying tool and can also contain other capabilities. Business workspace admins control plugin availability, but availability is not the same as authorization. OpenAI says apps are enabled by default for Business workspaces, subject to admin controls. Connected services also keep their own permissions, retention, logging, access, and residency characteristics.
For each enabled plugin and underlying app, record the account it connects to, the sources the user may retrieve, and any action it can take. Test with an allowed record and a record that must remain unavailable. If the configuration can create, update, or send something, keep that action disabled until the owner has approved and tested it.
Do not infer one blanket retention period. OpenAI's documentation says retention can vary by plan, admin setting, capability, and data class. Connected services can follow separate rules.
The account question comes first
Most of this reference is about accounts, plugins, and retention rather than about what the model can do. That order is deliberate. A strong result from the wrong workspace is a result the team cannot keep. A weak result from the right one is at least a finding.
So the first test is small and checkable. Draft an internal agenda from approved notes, in the confirmed Business workspace, with plugins and apps limited to what the task needs. Name a reviewer who can compare the output with the notes. Save the prompt purpose, source list, output, corrections, and date.
If the account, the sources, or the reviewer's ability to check cannot be confirmed, keep the work manual. A new subscription does not decide whether the task is ready. The confirmed account, sources, and reviewer do. When they are confirmed, the team may want the workflow configured rather than improvised. Ortaire's AI Implementation Support covers configuration, testing, and team enablement in your own environment.
Sources used
- ChatGPT plans and features, checked September 21, 2026. Business workspace, identity, admin-control, and default data-use statements; Enterprise and Edu control list.
- Workspace admin FAQ, checked September 19, 2026. MFA, SSO, plugin and app permissions, connected-service, and retention boundaries.
- ChatGPT security for work, checked September 19, 2026. Business data handling and plugin-and-app-control statements.




