OpenAI
Security configuration, governance controls, and risk guidance for ChatGPT Work and ChatGPT Codex.
Products covered in this handbook
Security considerations specific to OpenAI
Unmanaged usage is the first risk. ChatGPT Work and Codex are available through the unified desktop app and can appear on corporate devices through personal accounts. Find unmanaged use, claim accounts into the managed workspace, and assign access by group and use case before tuning fine-grained controls.
Work and Codex share technology, but not one policy surface. Work is for research, analysis, documents, spreadsheets, presentations, Sites, and business workflows. Codex is for codebases, terminals, repositories, cloud tasks, and development automation. Review them separately even when they run in one desktop app.
Connectors, plugins, browser access, and Computer Use need explicit decisions. Source-system permissions still apply, but Work and Codex can combine data and actions across systems. Separate read, write, send, delete, publish, and share permissions.
Evidence is split across systems. Compliance exports are useful for supported messages and responses, but they do not prove every file, action, approval, or tool call. Pair platform evidence with endpoint, browser, source-system, repository, SIEM, and OpenTelemetry records where applicable.
Current provider documentation
Last reviewed: August 18, 2026
Applicable Harmonic guidance
Related handbook guidance
Was this helpful?