An HR folder sits over-shared for years and nobody notices, because noticing requires knowing where to look. Then the workspace gets a drive connector, and looking becomes asking. The connector did not create the exposure. It made the exposure conversational.
ChatGPT workspace security changes the moment the workspace connects to company systems. Files, drives, repositories, calendars, internal knowledge, and actions turn a chat surface into a business-data access surface. Workspace security is not just who can log in; it is what the workspace can reach and do.
Start with connector governance. Decide which connectors are allowed, who can enable them, which groups can use them, and what approval a new app needs before it reaches company data.
Review OAuth scopes and connected-app permissions. Broad scopes, stale grants, personal installs, and unclear ownership can give connected AI more reach than any workspace admin intended.
Connected AI inherits the permissions of connected systems. If a drive, wiki, or ticketing system already has messy sharing, connector policy alone will not fix it. The exposure stays in place — just easier to query.
Actions need explicit control. Tools that can send messages, change records, call APIs, or trigger workflows should have approval rules, logs, and boundaries that match the consequence of the action.
Use groups and roles deliberately. Workspace owners, admins, builders, connector users, and ordinary users should not collapse into one informal access tier. The more connected the workspace becomes, the more the role boundaries matter.
Review trusted domains, sharing controls, retention settings, and company-knowledge permissions. These decide where content can travel and how long it lingers after the immediate work is done.
Make audit logs routine reading: connector changes, app approvals, role changes, unusual access, new actions, and data sources added without a clear owner.
What to check now: enabled connectors, app approvals, OAuth scopes, allowed groups, trusted domains, action confirmation settings, source-system sharing, workspace roles, audit logs, retention — and an owner for every connected data source.
The rule is simple: connected AI should not inherit accidental access. It should inherit deliberate, reviewed, revocable access.