ChatGPT Connectors: Admin and Security Guide for Business and Enterprise (2026)
ChatGPT connectors bring Drive, SharePoint, Slack and custom MCP data into ChatGPT. What admin controls and RBAC cover, what they miss, how to redact data.
ChatGPT connectors, which OpenAI now calls apps, let ChatGPT read from and act on Google Drive, SharePoint, Slack, GitHub and custom MCP servers. Admins can decide which apps are enabled, which groups can use them on Enterprise, and which actions are on. None of those controls inspect the data an app returns, so an SSN in a SharePoint file or a card number in a database row lands in the conversation unchanged. Strac MCP DLP sits on the tool-call path and masks, pseudonymizes or blocks sensitive values per user and group before ChatGPT reads them, and Strac browser DLP covers what people type and upload into chatgpt.com. Strac also blocks the connection itself when the identity is not allowed, such as a personal ChatGPT account reaching company data.
ChatGPT connectors are integrations that let ChatGPT search, read and in some cases write to your other systems: Google Drive, SharePoint, Slack, GitHub, Gmail and custom tools built on the Model Context Protocol (MCP). OpenAI now calls them apps in ChatGPT, and the admin screens use both words. Whatever the name, every connector does the same thing: it moves your company's data into a ChatGPT conversation.
If you run IT or security for a company on ChatGPT Business or Enterprise, that raises two questions. What sensitive data will flow through these connectors, and can you stop it in the flow? And can you give a connector to the teams that need it without giving its data to everyone? This guide answers both, data first. It is part of our AI agent security series, and the companion guide for Anthropic's product is Claude connectors.

A connector gives ChatGPT a set of tools. When a user asks "find the latest pricing deck" or "summarize the open tickets for Acme," ChatGPT picks a tool, the connector fetches the data, and the result goes into the model's context. Read tools search and fetch. Write tools create a Jira issue, post a message or update a record.
There are three kinds to keep straight:
On availability, OpenAI's documentation says full MCP support, including write actions, is rolling out in beta to Business, Enterprise and Edu workspaces on the web. Pro users can connect MCP servers in developer mode for read and fetch only. Only admins and owners can turn on developer mode and publish custom apps.
The mental model is simple: every tool result is data entering ChatGPT. If the connector can return it, ChatGPT can read it, quote it, summarize it and carry it into the next step.
The risk is that sensitive data now moves into a new system through a path your existing DLP never watched. A user who could always open the HR site can now have its contents summarized into a chat, pasted into an email draft or passed to a write action in one prompt. For how OpenAI handles that data once it arrives, see ChatGPT data privacy and is ChatGPT safe. On training, OpenAI states it does not train on Business, Enterprise or Edu workspace data by default. Training is a separate question from exposure.
OpenAI's admin controls are real, and Enterprise gets the most of them. Here is what each one does and does not do.

Four gaps show up in almost every rollout:
DLP is Strac's core engine. The same detectors that find PII, PHI, PCI and secrets in Slack, Google Drive, SharePoint, browsers and endpoints run inline on connector traffic. Strac MCP DLP sits between ChatGPT and the MCP server, and the diagram at the top of this page shows its four checks.
1. Identify. Strac resolves the person behind the call and their groups from Okta, Entra ID or Google Workspace, even when the app authenticates with a shared key.
2. Authorize. Strac checks that group's policy: is this app allowed, and is this specific tool allowed? A read may pass while a write is blocked for the same group.
3. Inspect. Strac scans both directions: the arguments ChatGPT sends and the result the server returns, using 100+ built-in detectors plus your custom data elements, with OCR for images and scanned PDFs.
4. Remediate. Each sensitive value gets the action your policy sets for that data type and group.
***-**-******** **** **** 4412EMAIL_7f3a2c, consistent across the chat
The user still gets a useful answer. ChatGPT can say "Jordan Alvarez was charged twice on the card ending 4412," and it cannot repeat the SSN, because it never saw it. Every decision is logged with user, group, app, tool, data types and action, and raw values stay in the Strac vault. The architecture is covered in depth in MCP DLP.
ChatGPT Enterprise RBAC answers "can this group use the app." Strac answers the next question: "what should this group see when it does."

A Strac policy has three layers, and the strictest matching rule wins:
Patterns that work:
Groups sync from your identity provider, so access follows people through joins, moves and departures. And because Strac applies the policy of the human who asked, a custom app on one shared key stops being a blank check.
Redaction controls what flows through an approved connection. Some connections should never exist at all, and Strac blocks them before any data moves. The question is which identity sits on each side: the ChatGPT account making the request, and the account that owns the data.

Strac enforces this where the connection actually happens:
Identity rules and data rules stack. An allowed identity still gets redaction on every result, and a blocked identity never gets a result at all.
Not everything reaches ChatGPT through an app, so Strac covers the other paths with the same detectors and policy.
Strac sees connectors as AI agents with identities and permissions, the same model we use for every agent in AI agent identity governance and protecting AI agents.
👉 Book a demo and we will route one of your ChatGPT connectors through Strac MCP DLP on the call and show you the redacted result for two different groups.
ChatGPT connectors, which OpenAI now calls apps, are integrations that let ChatGPT search, read and sometimes write to other systems such as Google Drive, SharePoint, Slack, GitHub and custom MCP servers. Each tool result a connector returns goes into the ChatGPT conversation. Admins on Business and Enterprise decide which connectors are enabled.
They are as safe as the data they return and the permissions behind them. OpenAI gives admins controls over which apps are on, who can use them on Enterprise and which actions are enabled, but those controls do not inspect the data in results. Pair connectors with DLP that redacts sensitive values and with least-privilege access per group.
Yes. Strac requires a corporate account for AI apps at sign-in, blocks the connection during OAuth consent when a personal ChatGPT account tries to reach company Drive, Gmail or SharePoint, and finds and revokes grants that already exist. Contractors, guests and unmanaged devices can be blocked from connecting at all.
On Enterprise, RBAC lets you decide which groups can use each app. To go further, such as letting Support use an app while masking SSNs and card numbers in what it returns, you need a data-layer policy. Strac applies per-group rules for each tool and data type, synced from Okta, Entra ID or Google.
Put DLP in the path. Route custom MCP apps through Strac MCP DLP so PII, PHI, PCI and secrets are redacted before ChatGPT reads them, redact at the source in SharePoint, Drive and Slack for built-in apps, and use browser DLP for what people type and upload into chatgpt.com.
Developer mode lets admins and owners connect and test custom MCP servers as apps before publishing them to the workspace. OpenAI warns that connecting to untrusted MCP servers increases security risks such as prompt injection, and leaves vetting custom apps to the customer.
OpenAI states that it does not train on Business, Enterprise or Edu workspace data by default, and that includes connector content. Training is a separate question from exposure: data a connector returns still lands in conversations, can be summarized and shared, and should be redacted if it is regulated.
.avif)
.avif)
.avif)
.avif)
.avif)


.gif)

