playbook

ChatGPT connectors and customer data: small-team security checklist

How small teams should approve ChatGPT connectors to Gmail, Drive, Slack, GitHub, CRM, and other systems before customer data becomes searchable.

Audience: Founders, operators, support leads, and workspace admins Risk: High Evidence: OpenAI business data, connectors, admin controls, app logging, and data residency documentation

Bottom line

ChatGPT connectors are higher risk than copy-paste prompts. A prompt exposes what an employee enters. A connector can expose email, files, tickets, code, calendars, or customer records that the employee can access in another system.

Small teams should approve connectors as separate workflows, even when ChatGPT Business or Enterprise is already approved.

Pair this page with the broader customer data in ChatGPT playbook.

Connector approval matrix

Connector targetTypical data exposedDefault posture
Google Drive or Microsoft 365Docs, spreadsheets, decks, customer files, board materialsPilot only with named users and folder rules.
Gmail or OutlookCustomer messages, attachments, contracts, invoices, personal dataRestrict until use case and retention are documented.
Slack or TeamsInternal discussions, customer escalations, incident threadsRestrict by workspace/channel rules.
GitHubSource code, issues, PRs, security discussionsEngineering approval required.
CRM or helpdeskCustomer records, tickets, account history, payment contextHigh-risk workflow approval required.
CalendarMeeting metadata, invitees, customer names, confidential eventsAllow only when the use case needs it.

The right question is not “does the connector work?” The right question is “what can this user already access, and is it appropriate for ChatGPT to retrieve it for this use case?”

Minimum approval record

Use this template before enabling a connector:

ChatGPT connector approval

Connector:
Workspace:
Business owner:
Admin owner:
Users or group:
Business purpose:
Data sources:
Customer data involved:
Restricted folders, channels, labels, or repos:
Allowed prompt types:
Prohibited prompt types:
Retention expectations:
Logging and review owner:
Approval date:
Renewal date:

If you cannot name the owner and the data source, do not enable the connector.

Admin checks

OpenAI’s connector documentation says each user authorizes their own account and ChatGPT accesses content within that user’s existing permissions. That is useful, but it also means source-system permissions become the security boundary.

Before rollout:

  1. Review source-system groups and permissions.
  2. Remove stale users before enabling connectors.
  3. Separate customer folders, internal planning folders, and restricted executive/legal folders.
  4. Disable broad sharing links where possible.
  5. Decide whether synced data is acceptable for the workspace and region.
  6. Confirm app calls and compliance logs are available to the right admins where plan support exists.
  7. Document the offboarding step for each connected system.

Do not approve a connector to fix messy permissions. Fix permissions first.

Customer-data prompt rules

For connector-backed workflows, employees should not ask broad questions such as:

Summarize everything about Customer A from Drive, Gmail, and Slack.

Use scoped prompts:

Using only the approved support folder and the last 30 days of tickets for Customer A, draft a support escalation summary. Do not include personal billing details, contract terms, or unrelated customer names.

Even better, use a pre-approved workflow where the source, data class, and output destination are known.

Rollout sequence

PhaseAction
InventoryList every requested connector and source system.
Permission cleanupRemove stale users, broad groups, and old shared folders.
PilotEnable one connector for one low-risk use case and a small user group.
ReviewCheck logs, sample outputs, and employee prompts.
ExpandAdd only the next specific use case, not every connector at once.
RenewReapprove connectors monthly while the program is new.

Evidence checked

FAQ

Are connectors safer than pasted customer data?

Not automatically. Connectors can reduce manual copying, but they can also retrieve more records than the employee intended. Treat connector approval as a higher-risk decision.

Does ChatGPT train on connector data in Business workspaces?

OpenAI says information accessed from apps is not used to train models for ChatGPT Business, Enterprise, and Edu customers. That does not remove retention, access, logging, contract, or customer-trust concerns.

What is the first connector a small team should approve?

Pick the lowest-risk connector tied to a clear workflow. For many teams, that is a restricted documentation folder, not email, Slack, CRM, or helpdesk.

Run the AI Tool Risk Checker for the proposed connector workflow before enabling it for a whole team.