Security & Governance

ChatGPT Business and Enterprise admins get new controls over connected-app access and ChatGPT Ads

Global admins can now govern whether ChatGPT Sites uses members' connected apps and whether external apps access ChatGPT Ads, via a redesigned Admin Console page.

security governance category

OpenAI has updated the Admin Console for ChatGPT Business and Enterprise workspaces with a redesigned External access page, giving global admins two new organisation-level permissions to manage. Both controls are off by default during the admin preview period, which gives IT and compliance teams the opportunity to review the implications before any data starts flowing.

Here is what the two new controls actually do and why they matter.

Two new permissions, two distinct data-access vectors

ChatGPT Sites and connected apps

ChatGPT Sites, launched in public beta on 9 July 2026, lets workspace members describe a site in chat and have ChatGPT build and host it as a client-side web app, served from OpenAI’s infrastructure, with no backend to configure. It is genuinely useful for internal dashboards, quick tools, and lightweight apps that would otherwise require a developer.

The new permission controls whether a Site built by a workspace member can invoke that member’s already-connected external apps, such as Google Drive or Slack, to pull in live data. Without this permission enabled at the organisation level, Sites remain sandboxed from those integrations even if the member has personally authorised the relevant apps.

To review or change this setting, a global admin opens the Admin Console, navigates to External access, selects ChatGPT Sites, and looks under Scopes for Connectors.

External applications and ChatGPT Ads

The second new permission governs whether third-party applications can programmatically access the ChatGPT Ads platform on behalf of your organisation. This is worth clarifying upfront: Business, Enterprise, and Education account members do not see ads in ChatGPT. OpenAI’s ad testing, which started on 9 February 2026, is limited to Free and Go plan users. This permission is specifically about whether external ad-management or analytics tools can access the ChatGPT Ads platform through your tenant, not about whether your staff will see adverts.

What this means if you are a global admin

Both new permissions sit on the redesigned External access page in the Admin Console and are off by default. That default-off stance is the important detail here. OpenAI is not enabling cross-product data access automatically and asking admins to opt out. Admins must make a deliberate decision to turn either permission on.

A few things worth knowing before you do:

Admin approval is a prerequisite, not a blanket override. Enabling the organisation-level permission does not automatically grant access. Members must still individually authorise the relevant apps using their own account permissions. The admin setting is a gate that must be open before member-level authorisation can take effect, not a switch that bypasses individual consent.

Identity sign-in is separate from data access. If your organisation uses Sign in with ChatGPT for identity purposes, that is an architecturally distinct permission from the delegated data access being managed here. Enabling one does not enable the other.

Sites access also depends on workspace and individual app settings. Even if you enable the organisation-level permission, access is still subject to the workspace-level app configuration and the individual member’s own app authorisations. The connected apps documentation notes that plugin availability, app access, role permissions, and provider-account authorisation are all separate controls.

Data residency is not yet available for Sites. OpenAI confirms that ChatGPT Sites does not support data residency or inference residency at launch, which covers deployed Sites, Site code, storage, artefacts, and logs. If your organisation has strict data residency requirements, factor that in before enabling the connected-apps permission for Sites.

What this means if you are a workspace member

Practically speaking, very little changes for you immediately. If your global admin has not yet enabled either permission (and during the admin preview, neither is on by default), your Sites will not be able to call your connected apps, and external applications will not be able to access ChatGPT Ads through your organisation’s account.

If and when your admin does enable the Sites permission, you will still need to authorise the relevant apps yourself. The admin turning on the organisation-level gate does not reach into your account and grant access on your behalf.

Why this matters for governance

ChatGPT Sites introduces a meaningful new surface area for data access. When a member builds a Site that connects to Google Drive or Slack, data from those services can be rendered in an app that is then shared via a public URL. That is a legitimate and powerful capability, but it is also one that IT and compliance teams reasonably want visibility over before it runs across an organisation.

The redesigned External access page, with both permissions off by default, reflects a more considered approach to that governance question. Rather than shipping the integration and relying on admins to discover and disable it, OpenAI has structured it as an explicit opt-in. That is a sensible default, and it is worth taking the admin preview period to assess which workloads, if any, justify enabling it.

If you manage a ChatGPT Business or Enterprise workspace, the External access page in your Admin Console is worth reviewing now, even if you decide to leave both permissions off for the time being.