AgentComparison
Governance guide ยท OpenAI documentation, attributed

ChatGPT workspace agents: access, approvals and admin controls

ChatGPT workspace agents are shared agents for repeatable team work in ChatGPT and Slack, for Business and Enterprise workspaces. Before a team rolls one out, the useful questions are who can run it, who can change it, what it can do without asking, and whose account it acts through. This guide summarises OpenAI's help article on those points. It describes what OpenAI documents, not what we tested, and the article can change.

Checked 1 October 2026OpenAI help centreNo hands-on test

Availability

OpenAI says workspace agents are off by default at launch for ChatGPT Enterprise workspaces and that admins can enable them for eligible workspaces. Role-based access controls apply in ChatGPT and in the Codex Workspace Agents plugin, and users can only see and run agents they have permission to access. Disabling the feature for a user or role also disables the Codex plugin for them.

Who can do what

Access levelWhat OpenAI says it allows
Can chatChat with the agent and view its configuration, including instructions and tools.
Can editEverything in Can chat, plus editing the shared draft and publishing new versions.
OwnerFull editing, permission management, workspace distribution controls and deletion.

Whose account the agent acts through

For each connected app, a builder chooses between an end-user account, where each person running the agent signs in with their own account, and an agent-owned account, a shared connection where runners do not authenticate. OpenAI recommends a service account where possible, not a personal one, and limiting access to what the agent needs. An agent-owned connection means people can trigger actions with the owner's or service account's access, which is why this setting deserves review first.

Approvals and limits on actions

Checklist before you roll one out

  1. Is the feature enabled for your workspace and seat type, and by whom?
  2. For each connector, is it end-user or agent-owned, and would a service account be safer?
  3. Have you left write actions on Always ask for anything that sends or deletes?
  4. Have you added constraints for recipients, documents or domains?
  5. Who is the owner, who can edit, and who reviews version changes?
  6. If triggered by API or schedule, who checks the outcomes, given no response is returned to the caller?

Use this with our privacy and approval checklist. See the ChatGPT workspace agents record, and Copilot Studio vs Agentforce for other business platforms.

Source: OpenAI Help Center, ChatGPT Workspace Agents for Enterprise and Business. Spot a change? Tell us.