playbook
ChatGPT connector approval template for small teams
A practical approval template for ChatGPT apps and connectors that can reach Gmail, Drive, Slack, GitHub, calendars, tickets, CRM records, or internal knowledge.
Bottom line
Do not treat a ChatGPT app or connector as a normal plugin install. A connected app can let ChatGPT search or reference content from another system, so the real approval question is:
Should this person, in this workspace, use ChatGPT to access this source system for this exact workflow?
OpenAI’s current help documentation uses “apps” as the broader term for what many teams still call connectors. This template uses both terms because employees and admins may see either wording during rollout. For ChatGPT Business, Enterprise, and Edu workspaces, OpenAI says information accessed from apps and connectors is not used to train models by default, but that does not replace internal approval, source-system permissions, retention rules, or customer-data controls.
Before enabling a connector for a team, run the AI Tool Risk Checker and record the result in the Small Team AI Security Checklist. If the workflow touches customer tickets, support records, sales notes, contracts, source code, or executive documents, use the approval record below.
Connector approval decision table
| Requested app or connector | Data it can expose | Default decision | Approval owner |
|---|---|---|---|
| Google Drive, SharePoint, Dropbox, Box, or Notion | Docs, spreadsheets, board materials, customer files, internal plans | Pilot only with folder boundaries and named users. | Operations or data owner |
| Gmail or Outlook | Customer emails, attachments, invoices, contracts, personal data | Restrict until a specific workflow is approved. | Support, sales, or operations lead |
| Slack or Microsoft Teams | Customer escalations, incident channels, internal decisions, HR discussions | Restrict by channel and team. | Workspace admin and department owner |
| GitHub or GitLab | Source code, issues, pull requests, security discussions, private roadmap details | Engineering approval required. | Engineering lead |
| CRM or helpdesk | Customer records, ticket history, account notes, renewal context, billing-adjacent notes | High-risk approval required. | Revenue/support owner |
| Calendar or contacts | Meeting metadata, invitees, customer names, hiring loops, confidential events | Allow only when the business purpose needs it. | Department owner |
| Custom MCP app | Internal tools, databases, workflow actions, read or write operations | Block until technical and business review are complete. | Admin owner and technical owner |
The safest default for a small team is to enable one app for one workflow, not every connector for every employee.
Approval template
Copy this into a ticket, spreadsheet, Notion page, or security review issue before enabling the app.
ChatGPT app / connector approval
App or connector name:
OpenAI plan:
Workspace:
Requested by:
Business owner:
Admin owner:
Technical owner:
Users or group:
Business purpose:
Source system:
Source-system owner:
Data classes involved:
Customer data involved:
Regulated or sensitive data involved:
Folders, channels, labels, repos, projects, or objects in scope:
Explicitly out of scope:
Allowed prompt types:
Prohibited prompt types:
Output destinations allowed:
Admin settings checked:
Source-system permissions checked:
Logging or review method:
Retention expectation:
Offboarding step:
Incident contact:
Approval decision:
Approval date:
Renewal date:
Evidence links:
If the requester cannot fill in the source system, owner, data class, and renewal date, keep the connector disabled.
Admin checks
OpenAI’s admin documentation says apps and connectors can be managed by workspace owners, with plan-specific defaults and controls. Enterprise and Edu workspaces have apps disabled by default; Business workspaces can control which apps are enabled for the workspace. OpenAI also describes user authorization: after an app is enabled, each user authorizes their own account, and ChatGPT accesses content within that user’s existing permissions.
That means the source system remains a critical boundary. Before approval:
- Confirm whether the workspace calls the feature Apps, Connectors, or both.
- Check whether the app is enabled by default for the plan.
- Disable apps that are not needed for the first rollout.
- Confirm the requesting user actually needs the source-system access.
- Remove stale users, broad groups, old shared folders, and unmanaged external collaborators.
- Separate customer, executive, legal, finance, hiring, and incident-response content before allowing search access.
- Decide whether the connector may be used in normal chat, deep research, synced knowledge, or custom MCP workflows.
- Document where output can go: private chat, shared link, document draft, ticket, CRM note, or pull request.
- Write the offboarding step for each connected app.
Do not approve a connector to work around messy permissions. Fix source-system permissions first.
Source-system permission review
Use this quick review before enabling the connector.
| Permission question | Why it matters | Pass condition |
|---|---|---|
| Can the user see more data than the workflow needs? | ChatGPT can only be as scoped as the connected account and app behavior allow. | The user has least-privilege source access. |
| Are customer folders mixed with internal planning folders? | Broad search can retrieve adjacent sensitive records. | Customer data is separated by folder, label, project, repo, or channel. |
| Are old employees, vendors, or shared links still present? | Connectors inherit existing access problems. | Stale users and public links are removed. |
| Is the app read-only, write-capable, or action-capable? | Write or action tools require stronger approval. | Read-only is preferred for the first pilot. |
| Can admins review activity or connected accounts? | Small teams need a way to investigate misuse or mistakes. | Logging, review owner, and escalation path are documented. |
| Is custom MCP involved? | Custom apps may expose internal tools or actions and are not the same risk as a standard app directory integration. | Technical owner verifies tools, scopes, auth, and data flow. |
Rollout policy
Use this policy for the first two weeks:
- Enable one low-risk app for one named group.
- Approve one documented workflow, not broad exploration.
- Require scoped prompts that name the source, date range, and excluded data.
- Prohibit prompts that ask for “everything about” a customer, employee, candidate, account, or incident.
- Review five sample outputs for over-collection before expanding access.
- Record all exceptions in the approval template.
- Reapprove the connector after two weeks or disable it.
Example allowed prompt:
Using only the approved Support Escalations folder and tickets from the last 30 days, draft a neutral summary of Customer A's open support themes. Exclude billing details, contract terms, personal contact details, and unrelated customer names.
Example blocked prompt:
Search Gmail, Drive, Slack, and CRM for everything about Customer A and tell me what we should do.
Approval outcomes
| Decision | When to use it | Required follow-up |
|---|---|---|
| Approved | Narrow use case, known owner, clean permissions, no high-risk data beyond the approved workflow. | Review in 30 days. |
| Pilot | Useful workflow but limited evidence or immature admin process. | Review samples after two weeks. |
| Restricted | Workflow is valid, but source data includes customer, legal, financial, HR, or production context. | Require named users and narrower sources. |
| Blocked | No owner, unclear data source, unmanaged personal account, broad customer data, write-capable custom app, or missing security evidence. | Reapply after remediation. |
| Needs legal/security review | Regulated data, contractual limits, customer commitments, cross-border data questions, or external sharing. | Route outside the lightweight small-team process. |
Evidence checked
- OpenAI admin controls, security, and compliance in apps and connectors
- OpenAI Apps in ChatGPT
- OpenAI developer mode and MCP apps in ChatGPT
- OpenAI business data privacy, security, and compliance
- ChatGPT connectors and customer data checklist
- Can employees paste customer data into ChatGPT?
FAQ
Are ChatGPT apps the same as connectors?
OpenAI’s current documentation describes a rename where “apps” is the broader term, including interactive apps and connectors that search or reference information. Many teams still say connectors, so internal policy should mention both.
Does ChatGPT Business train on connector data?
OpenAI says ChatGPT Business, Enterprise, and Edu data from apps and connectors is not used to train models by default. Small teams still need approval rules because training is only one risk. Access scope, retention, output sharing, source-system permissions, and customer commitments still matter.
Should a small team enable Gmail or Drive first?
Usually no. Start with the lowest-risk source that supports a narrow workflow, such as a restricted documentation folder. Email, broad file drives, CRM, helpdesk, and Slack history often expose more customer or internal context than the first use case needs.
What is different about custom MCP apps?
Custom MCP apps may expose internal tools, custom data sources, or actions. Treat them as higher risk than a standard read-only app until a technical owner has reviewed tools, scopes, authentication, logging, and write capability.
How often should connector approvals be renewed?
For a new rollout, renew after two weeks. After the workflow is stable, renew monthly or quarterly depending on the data class. Renew immediately after permission changes, employee offboarding, a customer incident, or a vendor documentation change.
Recommended next step
Run the AI Tool Risk Checker for the requested app, then add the approved connector and renewal date to the Small Team AI Security Checklist.