> For the complete documentation index, see [llms.txt](https://handbook.harmonic.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://handbook.harmonic.security/by-ai-vendor/openai/chatgpt-work.md).

# ChatGPT Work

Security guidance for ChatGPT Work, including managed workspace use, connectors, browser and Computer Use policy, scheduled work, artifacts, sandbox boundaries, and evidence gaps.

{% hint style="warning" %}
**In short:** ChatGPT Work turns ChatGPT into a general business agent for research, analysis, documents, spreadsheets, presentations, Sites, connected apps, browser tasks, and recurring work. Treat it as a workforce agent surface, not ordinary chat.
{% endhint %}

## What to focus on first

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><h3><i class="fa-user-shield" style="color:$primary;">:user-shield:</i></h3></td><td><strong>Bring usage under management</strong></td><td>Find desktop and web usage, force managed sign-in where available, enforce SSO and MFA, and assign Work by group and use case.</td><td><a href="/handbook/1.-identity-and-access/1.1-sso-and-scim-for-ai-platforms.md">1.1 SSO &amp; SCIM for AI platforms</a></td></tr><tr><td><h3><i class="fa-plug" style="color:$primary;">:plug:</i></h3></td><td><strong>Review connectors and plugins</strong></td><td>Separate read access from write, send, delete, publish, and share actions. Source-system permissions still apply, but Work makes them easier to combine.</td><td><a href="/handbook/2.-supply-chain-and-extensibility/2.1-connectors-and-apps-the-integration-backbone.md">2.1 Connectors and apps: the integration backbone</a></td></tr><tr><td><h3><i class="fa-box" style="color:$primary;">:box:</i></h3></td><td><strong>Do not overclaim sandbox coverage</strong></td><td>Desktop Work can use local permission controls, while hosted Work runs under ChatGPT workspace controls. Match the control to the execution path.</td><td><a href="/handbook/3.-runtime-sandbox-and-autonomy/3.1-what-even-is-an-ai-sandbox.md">3.1 What Even is an AI Sandbox?</a></td></tr><tr><td><h3><i class="fa-globe" style="color:$primary;">:globe:</i></h3></td><td><strong>Gate browser and Computer Use</strong></td><td>Signed-in browser state, screen contents, clipboard data, and desktop apps can become agent-visible. Disable or scope these surfaces for baseline users.</td><td><a href="/handbook/3.-runtime-sandbox-and-autonomy/3.5-computer-use-desktop-control-risks.md">3.5 Computer Use / desktop control risks</a></td></tr><tr><td><h3><i class="fa-clock" style="color:$primary;">:clock:</i></h3></td><td><strong>Constrain scheduled work and artifacts</strong></td><td>Scheduled tasks, generated files, Sites, and shared artifacts need owners, destinations, expiry or review dates, and DLP coverage.</td><td><a href="/handbook/3.-runtime-sandbox-and-autonomy/3.6-scheduled-and-background-tasks.md">3.6 Scheduled and background tasks</a></td></tr><tr><td><h3><i class="fa-magnifying-glass-chart" style="color:$primary;">:magnifying-glass-chart:</i></h3></td><td><strong>Build the evidence trail</strong></td><td>Compliance logs help, but they do not capture every file, action, approval, or tool call. Join platform records with endpoint and source-system logs.</td><td><a href="/handbook/6.-observability-audit-and-evidence/6.6-evidence-by-surface-and-investigation-paths.md">6.6 Evidence by surface and investigation paths</a></td></tr></tbody></table>

## What is ChatGPT Work?

ChatGPT Work is OpenAI's general-purpose agentic workspace for business tasks. Use it for research, analysis, documents, spreadsheets, presentations, Sites, and workflows that need context from conversations, files, workspace resources, or connected systems.

Work is distinct from **ChatGPT Codex**, which is the software-development agent for repositories, terminals, code review, cloud tasks, and developer automation. Approve Work and Codex separately, even when both appear in the same ChatGPT desktop app.

## Security boundary

Work can run in hosted ChatGPT contexts and, through the desktop app, on a local computer with selected local permissions. Those paths do not share one security boundary.

For every rollout, record:

* whether the task is web, mobile, desktop, local, remote, or hosted;
* which connected apps, plugins, files, folders, browser sessions, and artifacts it can reach;
* which actions require approval before write, send, delete, publish, share, purchase, or external transfer;
* whether generated files and Sites are covered by DLP, retention, and sharing policy; and
* which evidence sources can reconstruct prompts, responses, files, tool calls, approvals, and downstream actions.

## Security review checklist

* Work usage is discovered across managed and personal accounts.
* SSO, MFA, SCIM, workspace membership, and group-based access are enforced.
* Connectors and plugins have reviewed owners, scopes, actions, and revocation paths.
* Browser, Chrome, Computer Use, Appshots, Remote Control, and scheduled work are disabled or scoped for the baseline role.
* Sensitive app categories such as admin, finance, HR, legal, security, customer systems, and production systems require approval or are blocked.
* Sites, generated files, and artifacts have sharing, retention, and DLP controls.
* Compliance exports are paired with endpoint, browser, source-system, repository, and SIEM evidence.
* Prompt injection, exfiltration, destructive action, connector abuse, and public sharing tests are run before broad rollout.

## Provider documentation

* [ChatGPT Work and Codex](https://help.openai.com/en/articles/20001275/)
* [ChatGPT desktop app](https://learn.chatgpt.com/docs/app)
* [Admin controls for apps and connectors](https://help.openai.com/en/articles/11509118-admin-controls-security-and-compliance-in-apps-enterprise-edu-and-business)
* [Built-in browser](https://help.openai.com/en/articles/20001277-using-the-built-in-browser-in-the-chatgpt-desktop-app)

## Applicable Harmonic guidance

* [Securing ChatGPT Work: A Practitioner's Guide](https://www.harmonic.security/resources/securing-chatgpt-work-a-practitioners-guide)

*Last reviewed: August 18, 2026*

## Related handbook guidance

* [OpenAI](/by-ai-vendor/openai.md)
* [2.1 Connectors and apps: the integration backbone](/handbook/2.-supply-chain-and-extensibility/2.1-connectors-and-apps-the-integration-backbone.md)
* [3.5 Computer Use / desktop control risks](/handbook/3.-runtime-sandbox-and-autonomy/3.5-computer-use-desktop-control-risks.md)
* [4.6 Cross-app data flow and live artifacts](/handbook/4.-data-protection-and-residency/4.6-cross-app-data-flow-and-live-artifacts.md)
* [6.3 Compliance APIs by platform](/handbook/6.-observability-audit-and-evidence/6.3-compliance-apis-by-platform.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://handbook.harmonic.security/by-ai-vendor/openai/chatgpt-work.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
