ChatGPT workspace agents: access, approvals and admin controls
ChatGPT workspace agents are shared agents for repeatable team work in ChatGPT and Slack, for Business and Enterprise workspaces. Before a team rolls one out, the useful questions are who can run it, who can change it, what it can do without asking, and whose account it acts through. This guide summarises OpenAI's help article on those points. It describes what OpenAI documents, not what we tested, and the article can change.
Availability
OpenAI says workspace agents are off by default at launch for ChatGPT Enterprise workspaces and that admins can enable them for eligible workspaces. Role-based access controls apply in ChatGPT and in the Codex Workspace Agents plugin, and users can only see and run agents they have permission to access. Disabling the feature for a user or role also disables the Codex plugin for them.
Who can do what
| Access level | What OpenAI says it allows |
|---|---|
| Can chat | Chat with the agent and view its configuration, including instructions and tools. |
| Can edit | Everything in Can chat, plus editing the shared draft and publishing new versions. |
| Owner | Full editing, permission management, workspace distribution controls and deletion. |
- Editors cannot give edit access to others, change workspace-wide access or directory visibility, transfer ownership, delete the agent, or change owner-only setup such as channels and custom MCP servers.
- An agent can be private, shared by link within the organisation, or published to the organisation directory. Sharing by link or directory does not make everyone an editor.
- Agents can be shared with workspace groups. If someone gets access from several sources, the highest level applies.
- Viewers with Can chat can see the agent's instructions and tools, so do not put secrets in instructions.
- Version history lets you review, preview and republish earlier versions. Simultaneous edits are not merged live, so a save conflict can occur.
Whose account the agent acts through
For each connected app, a builder chooses between an end-user account, where each person running the agent signs in with their own account, and an agent-owned account, a shared connection where runners do not authenticate. OpenAI recommends a service account where possible, not a personal one, and limiting access to what the agent needs. An agent-owned connection means people can trigger actions with the owner's or service account's access, which is why this setting deserves review first.
Approvals and limits on actions
- Write actions. OpenAI says write actions for apps and connectors default to Always ask during a run. Depending on the app, builders may set Never ask or a custom approval for specific actions. It advises using approvals carefully for anything that can send, edit, post or delete.
- Connector Action Constraints. Builders can limit what a connector may do, for example only allow email to a specific domain, or only read one document. OpenAI says these limit what the agent can ask a connector to do, and do not filter the data the connector returns.
- API triggers. An agent can be started by API with a Workspace Agent access token created in the admin area. OpenAI says the call queues the run and returns 202 Accepted with no response body or run ID, and the agent's response cannot currently be retrieved through the API.
- Schedules and Slack. Agents can run on a schedule and be added to Slack channels, which may need Slack admin approval. While a Slack deployment is active, only the owner can change the agent's apps and connectors.
- Analytics. OpenAI lists an Agent Analytics page showing unique users and run counts.
Checklist before you roll one out
- Is the feature enabled for your workspace and seat type, and by whom?
- For each connector, is it end-user or agent-owned, and would a service account be safer?
- Have you left write actions on Always ask for anything that sends or deletes?
- Have you added constraints for recipients, documents or domains?
- Who is the owner, who can edit, and who reviews version changes?
- If triggered by API or schedule, who checks the outcomes, given no response is returned to the caller?
Use this with our privacy and approval checklist. See the ChatGPT workspace agents record, and Copilot Studio vs Agentforce for other business platforms.
Source: OpenAI Help Center, ChatGPT Workspace Agents for Enterprise and Business. Spot a change? Tell us.