I would begin a team rollout with a map of where the data goes. A license count tells you who can open the product; it does not tell you which CRM records, local folders or external actions a workflow can reach.
The practical goal is an explainable boundary. Your team should know which workspace to use, which inputs are approved and who owns the connections that turn an answer into an action.
Map the workflow before assigning seats
For the fictional Cedar Metrics account-brief workflow, draw the path from CRM records and meeting notes to the generated brief. Identify the workspace, connected identity, execution environment and people who receive the output. That is the meaningful data path to review.
A seat grants product access according to the plan and configuration. It does not automatically authorize every connected service or give the member administrative control. Workspace roles and source-system permissions answer different questions.
I would use a small approved workflow as the rollout unit. It is easier to verify one account brief from end to end than to approve an abstract promise that everyone will use AI responsibly. The concrete workflow reveals which controls and training the team actually needs.
TipWrite down the input, connected identity, output audience and owner for the first workflow.
Distinguish roles from service permissions
Current workspace documentation describes roles such as owner, admin, member and analytics viewer, along with feature controls that can vary by configuration. Administrative authority over ChatGPT does not automatically grant access to every record in an external service.
A CRM connection uses the permissions of its authorized identity. If a member cannot read an account in the source system, the assistant should not be assumed to retrieve it through ordinary access. Conversely, a broadly privileged service account may expose more than the task requires.
Test with the identity the workflow will actually use. An administrator’s successful demo can conceal access gaps for ordinary members or excessive access in a shared connection. The desired result is appropriate access, not simply the absence of errors.
TipKeep workspace-role tests and connected-service tests separate.
Read privacy claims precisely
OpenAI’s current Work cloud security documentation says Business, Enterprise and Edu workspace data is encrypted in transit and at rest and is not used to train models by default. That statement is useful, but it does not answer every question about storage, sharing or connected services.
Retention and audit visibility depend on the data category, storage location, event and applicable configuration. Treat those as separate requirements to verify for the workflow. A broad privacy slogan cannot establish how a specific artifact or tool event is retained.
I would make a short list of concrete questions: what is supplied, where it is stored, who can access it and which records the organization can inspect afterward. Use the current documentation and workspace settings to answer those questions before adding sensitive inputs.
TipDo not use “not used for training” as a synonym for “never stored” or “visible only to me.”
Separate local and cloud work
Cloud tasks run on OpenAI-managed infrastructure and do not inherit local files, desktop applications, browser sessions or private-network access from the device used to start them. Inputs must be supplied through an authorized cloud-accessible path.
Local execution happens within the organization’s device environment and needs its own filesystem, application and network controls. A workspace decision to allow one mode should not be treated as proof that every capability in another mode is configured identically.
For Cedar Metrics, a cloud account brief might use approved connected records, while a local website edit uses a checked-out repository. Document those as different workflows even if the same teammate starts both from the desktop app. The location of execution changes the access questions.
TipAsk where execution happens, not merely which app window started the task.
Review actions as well as data access
A connected tool may retrieve information, change records or communicate externally. Current Work controls include different action-permission policies, and some authorized actions can execute without another prompt. Do not assume every external write always pauses for human confirmation.
For the first account-brief workflow, keep the output a draft with source links. If the team later adds CRM updates, specify the fields, allowed records and review boundary. If it adds email, define the recipient and final-content approval process explicitly.
The business workflow and technical configuration should agree. A policy document saying “always review” is incomplete if the configured automation can send directly and no review step is actually enforced. Test the real path with a harmless example.
TipCheck the effective permissions of the specific connection used by the workflow.
Run a limited member pilot
Choose a few representative users and one approved task. Provide the source packet, expected output and examples of missing-data behavior. Ask participants to report both useful results and cases where access or interpretation failed.
For Cedar Metrics, compare the generated brief with source records under an ordinary member account. Check whether the reader can open the citations and whether private notes remain appropriately scoped. A source link that the recipient cannot open may still leave the workflow difficult to review.
I would measure whether the brief improves preparation and reduces repeated work, while tracking corrections and review effort. Avoid declaring success from the number of prompts sent. Usage is activity; useful, checked output is the outcome.
TipInclude one incomplete source and one restricted record in the pilot’s agreed test cases.
Where team rollouts go wrong
The common failure is approving a product in general while nobody owns the specific workflows built on top of it. Another is using an admin account for every test, then discovering that ordinary members cannot access the evidence or that a shared identity sees too much.
A third failure is collapsing training policy, retention, sharing and tool actions into one vague word: privacy. Ask separate questions and preserve their answers. This makes both onboarding and troubleshooting more precise.
Start with a small workflow, prove the member experience and expand from the evidence. The team should be able to explain what the assistant can see and do without calling the person who built it. Which workflow is clear enough to become your first shared standard?
How to set it up
Map one approved workflow
Record inputs, workspace, execution environment, connected identity, output audience and owner.
Check applicable controls
Review workspace roles, source permissions, action settings and the relevant data-handling documentation.
Test as a member
Run the fictional or approved account-brief exercise under representative member access and inspect the evidence.
Roll out with maintenance
Document the accepted procedure, correction process and owner. Recheck when access, sources or features change.
Frequently asked questions
Is business workspace data used for training by default?
Current OpenAI documentation says Business, Enterprise and Edu workspace data is not used for model training by default.
Does that mean the data is never stored?
No. Training policy and retention are separate questions; verify the relevant data category and configuration.
Does an admin role grant CRM access?
Not automatically. Connected-service permissions depend on the authorized identity and source system.
Can cloud tasks read local folders?
They do not inherit local filesystem access. Supply inputs through supported authorized paths.
Will every write request require confirmation?
No universal promise applies. Check the effective action policy for the workflow and connection.
Why test with a member account?
It reveals access and review problems that an administrator’s broader permissions can hide.
Does ChatGPT workspace access cover API projects?
API project access, keys, billing and application controls need their own review.
Who should own a shared assistant?
Name a maintainer who can update sources, repair access, respond to issues and retire the workflow.
Sources & further reading
ChatGPT and Codex change quickly. This page was last reviewed September 22, 2026; verify time-sensitive details against the official docs above before relying on them.
Related GTM workflows
Use these existing playbooks to explore the business workflow. Adapt their tool-specific steps to your chosen environment and check the result.