ChatGPT Learn Docs
Administration
Set access and policy boundaries for ChatGPT, Codex developer tools, APIs, plugins, and connected systems.
Explore authenticationAdministration covers six related boundaries: ChatGPT workspace access; local runtime policy for covered capabilities in the ChatGPT desktop app, Codex CLI, and IDE extension; Codex cloud eligibility; Platform API access; plugin availability and connector permissions; and permissions in connected systems. Start with workspace identity and access, then apply the runtime and source-system controls required for each deployment.
Getting started
Start with the rollout guide, then use the reference pages for each control boundary.
ChatGPT Work
Review the hosted and local Work execution model, security boundaries, administration, and usage.
- ChatGPT Work Overview Understand hosted execution, network controls, data boundaries, and audit visibility.
- ChatGPT Work cloud security Review hosted execution, connected accounts, access controls, retention, and audit visibility.
- ChatGPT Work local security Review local execution, device and browser access, managed policies, data handling, and audit limitations.
- ChatGPT Work admin FAQ Review access, data, governance, usage, and incident controls for ChatGPT Work.
- ChatGPT Work: usage and cost Understand shared credits, billing impact, spending controls, and adoption planning.
Identity and authentication
Choose how people sign in and issue credentials for programmatic workflows.
Workspace access, policy, and models
Assign ChatGPT workspace access and keep it separate from local runtime policy, Codex cloud access, and Platform API access.
- Groups and provisioning Manage manual and SCIM groups, provisioning, and rollout cohorts.
- User lifecycle management Provision employees, update group-based permissions, and remove workspace access and Codex tokens.
- Roles and workspace permissions Use the canonical map of workspace, runtime, API, plugin, and source-system controls.
- GPTs and Sharing Manage GPT sharing, ownership, connected apps, and third-party actions across your workspace.
- Managed configuration Distribute managed settings where supported and enforce runtime requirements for covered capabilities in the ChatGPT desktop app, Codex CLI, and IDE extension.
- Prisma AIRS Apply workspace-wide security policies to Codex prompts.
- HIPAA configuration Configure local runtime safeguards for workflows that may handle protected health information.
- Workspace model availability Separate model access for ChatGPT, Codex in the ChatGPT desktop app, Codex CLI, the IDE extension, Codex cloud, and the Platform API.
Plugin and connector controls
Control plugin installation, bundled skills, connector-backed capabilities, and connected-service access.
Usage, governance, and compliance
Measure adoption and route reporting or audit data to the system that owns it.
- Governance Choose the right analytics, spend, and audit surface for each question.
- Admin plugin Use the Admin plugin for permissions, approvals, and supported administrative workflows.
- Workspace analytics Review workspace-level ChatGPT adoption and Codex usage.
- Usage Insights Explore usage across ChatGPT Work and Codex and assess workflow results with your team.
- Analytics API Automate developer activity and code review reporting with the Codex Analytics API.
- Compliance API and audit events Export activity records for audit and investigation workflows.
Deployment and model providers
Deploy and update desktop apps, connect managed hosts, or configure a supported external model provider.
- Manage app updates Control desktop app updates and deploy approved versions through your device management platform.
- Windows app deployment Choose an installation and update path for managed Windows devices.
- Remote connections Start and control work on connected computers.
- Amazon Bedrock Configure supported local clients to use models available through Bedrock.