Apps and plugins: what ChatGPT may read and what it may do
ChatGPT
This page covers tools outside your selection. You can still read it. Find matching guides
Reading is granted by default. Actions are gated by a risk judgement ChatGPT makes per request, and the default differs depending on which plan your workspace is on.
Connecting Drive or Slack to a chat window is two grants wearing one button. The first lets ChatGPT read what you can read. The second lets it change things in those services. They are governed differently, and the second one is where attention belongs.
Reading is the default, actions are judged
The permission model has four settings, and the names are worth learning because the defaults are not the same everywhere: Always ask, Allow read actions, Allow low-risk actions, and Allow all actions where an app and account support it.
Out of the box ChatGPT uses Important actions. That reads from connected apps automatically and asks before anything with a meaningful effect outside ChatGPT, anything that exposes sensitive information, and anything hard to undo.
OpenAI's own list of what counts as important is concrete:
- Sending or editing an email, message, comment, post, invitation or appointment on your behalf
- Deleting content, cancelling an appointment, removing a reservation
- Making a purchase, issuing a refund, managing a transaction or subscription
- Uploading a file, or moving or renaming one in cloud storage
- Changing sharing permissions, account access, security settings, or creating credentials
The judgement is contextual. There is no fixed list. Saving a private draft ranks lower than sending it; updating a cart ranks lower than placing the order; changing a preference ranks lower than changing a security setting. Where one request bundles several actions, the highest applicable risk level governs.
Injected instructions are part of the model
One line in the documentation deserves lifting out: suspicious or hidden instructions found in app content can cause ChatGPT to ask for approval or block the request outright.
That is prompt injection treated as a first-class case. It is also the reason an approval prompt deserves reading before you click through. A prompt you did not expect, on a request you did not make, is the signal.
Your access sets the ceiling
Apps are built so you can only reach through ChatGPT what you could already reach in the underlying service, and OpenAI states that existing permissions are respected and kept current. On Business and Enterprise plans two people can give the same prompt and get different answers, because their access differs.
That is a genuine protection and it is not a small footprint. If your account can open every folder in a shared drive, so can the connection. The number that matters is not what you normally open; it is what you could.
Some apps also support sync, which indexes content in advance rather than fetching on demand. Faster, and a larger standing surface.
Try this
Connect one app, then ask ChatGPT to do something that would change data, such as renaming a file. Watch whether you get an approval prompt. That tells you what your account's permission setting actually is, which is more reliable than reading the settings page.
What goes wrong
Reading the connect button as read-only access. Write actions come with it where the app supports them.
Selecting Allow all actions to stop the prompts. That removes the confirmation on exactly the operations that are hard to undo.
Estimating exposure from what you normally open. The ceiling is everything your account could open.
Assuming Enterprise defaults match Business ones. Apps start enabled on one and generally disabled on the other.
Clicking through an unexpected approval prompt. It can be the injection check firing on content the app pulled in.
How to check it worked
Ask ChatGPT to list what it can see through a connected app, then compare that against what you believed you had shared. For a workspace, check the plugin and app settings separately rather than assuming one implies the other, and confirm whether administrator-managed sync is indexing content nobody remembers approving.
Sources
- Apps in ChatGPT — OpenAI Help Center Tier 1 2026-09-10
- Admin controls, security, and compliance for plugins and apps — OpenAI Help Center Tier 1 2026-09-10
- Enterprise privacy — OpenAI Tier 1 2026-09-10
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.