ChatGPT Enterprise Starts With the Control Plane
Buyer and implementation guide for ChatGPT Enterprise: controls, SSO/SCIM, residency, HIPAA boundary, and a 12-step rollout.

Buyer and implementation guide for ChatGPT Enterprise: controls, SSO/SCIM, residency, HIPAA boundary, and a 12-step rollout.

ChatGPT Enterprise is OpenAI's managed ChatGPT plan for organizations: enterprise-grade privacy, centralized admin controls, and advanced ChatGPT in a sales-led workspace. Individuals cannot sign up. Team became Business on 2025-08-29; that sibling has SAML, not SCIM, residency, or Compliance Logs.
"ChatGPT Enterprise is a managed ChatGPT plan for organizations. It combines enterprise-grade privacy and security with centralized admin controls and access to advanced ChatGPT capabilities."
You provision identity and data residency before you invite seats. Then you decide when Microsoft 365 Copilot, Claude Enterprise, Gemini Enterprise, Glean, or Amazon Quick is the better default.
OpenAI sells a managed workspace that an owner or IdP provisions. Members join after an invite or a SCIM assignment, then a seat type. The workspace gives you domain verification, SSO, usage insights, and longer context than consumer ChatGPT.
Edu is a variant of the same family, not a different product. The API platform is a separate membership with its own billing and an SSO-enable switch. Azure OpenAI is a build surface under Azure, not this workspace.
If a vendor page talks about "Enterprise ChatGPT" as a chatbot you train on your domain, that is the wrong product. This SKU is ChatGPT with an admin control plane.

Most companies already have ChatGPT. They have personal Plus seats on corporate cards, free accounts on work laptops, and a policy PDF nobody opened. The purchase is how you replace that mess with one sanctioned tenant.
On r/ciso, the pattern is carrot then stick: one approved path with a DPA, then block the rest. A block with no official tool pushes people onto phones, where you lose network visibility.
OpenAI's enterprise research (August 12, 2026) is vendor research. As of June, OpenAI says Codex generated 64% of combined Codex plus ChatGPT output tokens among enterprise customers.
The other 2026 reason is irreversible provisioning. Residency, SCIM, and custom RBAC are not upgrades you click later on Business.
The workspace is a set of boundaries that do not grant each other. A ChatGPT seat is not a Codex admin role. A plugin that is "available" is not an app that can write to Salesforce.
Learn's admin rollout guide splits ownership across workspace access, local runtime policy, Codex cloud, Platform API access, plugins and connectors, and permissions in connected systems.
Built-in roles are Owner, Admin, Member, and Analytics Viewer. An explicit Off in any applicable role blocks the action even if another role would grant it. Seat, admin role, and custom RBAC are three different switches.
ChatGPT Business is the self-serve sibling, formerly Team (renamed 2025-08-29). Independent posts from 2025 and 2026 still teach "Business has no SSO." That is stale.
Business has SAML SSO. It does not have the rest of the Enterprise control plane.

Control | Business | Enterprise |
|---|---|---|
No-train default | Yes | Yes |
SAML SSO | Yes | Yes |
Admin console | Yes | Yes |
Company Knowledge | Yes | Yes |
GPTs, apps, Codex | Yes | Yes |
SCIM | No | Yes |
Custom RBAC | No | Yes |
Data residency | No | Yes |
EKM | No | Yes |
IP allowlisting | No | Yes |
Compliance Logs | No | Yes |
ISO 27001 family | No | Yes |
New plugins default | On | Off |
GPT Instant context | 54K | 128K |
Shared features versus Enterprise-only controls
Shared does not mean interchangeable. Enterprise restricts invites to Admins and Owners.
On Business, members can invite other members. Only admins and owners can remove users.
New Enterprise and Edu workspaces start with a selected set of apps enabled; new plugins and apps are disabled by default until an admin reviews them. Business turns apps on by default.
Confirm GPT Instant context on OpenAI's live pricing matrix before you write the labels into a procurement deck. Those Enterprise-only rows cannot be bolted onto a Business workspace later.
Enterprise is quote-only. You contact sales. There is no self-serve checkout for this SKU.
Fifty One Degrees, an OpenAI Select Partner (2026-08-05): "The Business versus Enterprise decision is usually made on price per seat. That is the wrong axis for a regulated firm, because the difference is a set of controls, not a discount."
On r/sysadmin, that gap shows up as ops pain.
u/MysticFists (Oct 2025) ran Business with JIT and hit the wall at a few hundred users: no SCIM, and a portal that does not scale.
u/oxidizingremnant in the same thread: that SKU also lacks audit logging, so it is only marginally better than a personal account.
Plus, Pro, and Free are personal. There is no admin console, and Plus has no contractual no-train default. Do not run the company on a personal plan, even if finance already pays the card.
A Codex-only seat is not ChatGPT. A Codex seat does not include ChatGPT access; the user is told ChatGPT is unavailable for that seat type. Treat Codex as a software agent with its own seat, not a cheaper Enterprise license.
ChatGPT for Healthcare, ChatGPT FedRAMP, ChatGPT for Clinicians, ChatGPT Gov, and Enterprise with Regulated Workspace are adjacent SKUs. Healthcare or Regulated Workspace is the HIPAA path, not vanilla Enterprise.
People also use "ChatGPT for Work" as shorthand for Business plus Enterprise seats. That phrase is not a plan you buy.
OpenAI's business-data and enterprise-privacy pages (privacy page dated 2026-01-08) plus the Trust Portal are the source of record.

OpenAI's no-train default covers Enterprise, Business, Edu, Healthcare, Teachers, and the API platform, including inputs and outputs. Encryption is AES-256 at rest and TLS 1.2+ in transit. EKM is customer-held keys.
API zero data retention is an API option. It is not the ChatGPT UI default. Do not tell a CISO the chat workspace is ZDR because the API can be.
The Trust Portal lists a SOC 2 Type 2 report covering July 1, 2025 through June 30, 2026. OpenAI also publishes ISO/IEC 27001 for API, Enterprise, and Edu, plus ISO 27017, 27018, 27701, ISO 42001, CSA STAR, and PCI-DSS for delegated payments.
Badges are not enforcement. SOC 2 does not sit on the path between a prompt and a SharePoint file. You still need connector scopes, Compliance Logs into a SIEM, and file ACLs that were true before Company Knowledge existed.
On Enterprise, Edu, and Healthcare, end users view their own conversations. Workspace admins get an audit log through the Compliance API, not a casual "open anyone's chat" screen.
On Business, workspace admins can view, access, export, and delete end-user conversations.
Deleted conversations are removed within 30 days unless legally required. Compliance Logs themselves are immutable JSONL and retain 30 days. Pull continuously if you need a longer archive.
The stateful conversation-logs route was deprecated 2026-03-05 and removed 2026-06-05.
Conversation-messages permission is owner-only. Export partners on OpenAI's list include Microsoft Purview, CrowdStrike, Netskope, Palo Alto Networks, Varonis, Zscaler, and Cyberhaven. Wire this on day one, not after the first incident.
Data residency is storage-at-rest for in-scope content: prompts, files, outputs, conversations, memory, Code Interpreter artifacts, custom GPTs, and image I/O. Regions at research time: Australia, Canada, Europe (EEA plus Switzerland), India, Japan, Singapore, South Korea, UAE, UK, and US. Included at no extra cost on Enterprise and Edu.
Inference residency (GPU in-region) requires data residency in the same region first. Supported inference regions at research time are the US, Europe, and UAE.
UAE inference has extra limits (no ChatGPT Work, no improved memory). Out of scope: account and billing, workspace metadata, and data from external integrations such as web search.
Eligibility is new Enterprise and Edu customers, plus eligible API. You cannot add residency to a workspace that was born without it. Residency workspaces cannot set GPT sharing to "Anyone."
If you already have personal ChatGPT history on a work domain, plan an export before you join a residency tenant. Data-residency workspaces do not support transferring that history in place.
Set the region at provisioning, before the first bulk invite. That is one of three decisions you do not get to revisit.
Vanilla Enterprise is not the BAA product. OpenAI's HIPAA matrix lists eligible services with a BAA: ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, and API with Modified Retention.
ChatGPT Business and consumer plans are not Eligible Services. Improved memory is disabled by default in Healthcare and Enterprise with Regulated Workspace, and is not covered under a BAA. Event-triggered scheduled tasks stay off by default in Enterprise, Edu, and Healthcare, and are not covered under a BAA in Healthcare.
Secondary blogs that say "Enterprise and Team offer a BAA" contradict the official matrix. Use OpenAI's list. If the workload is PHI, you are on a different OpenAI product.
SSO is how people authenticate. SCIM is how accounts appear and disappear. Automatic Account Creation (AAC) is a third switch that fights SCIM.
SSO is SAML via WorkOS. Common IdPs: Okta, Entra ID, Google Workspace, Duo. The ChatGPT workspace and the API org share one SSO connection and org-id, but you enable SSO separately per product.
ChatGPT SSO is domain and workspace based: only provisioned workspace members. Platform SSO is entirely domain-based: every Platform user on that domain loses password login.
Enforce SSO disables social and password login for verified-domain provisioned users. ChatGPT does not provide workspace-wide MFA. Enforce MFA at the IdP.
SCIM is Enterprise and Edu, not standalone Business. Tenant-wide, workspace-level, and API-org SCIM are mutually exclusive with mixed product-level connections.
Tenant-wide SCIM cannot change emails on existing accounts. Syncing a user to the tenant does not grant product access. You still assign groups to workspaces.
Supported directories: Okta, Entra, Google Workspace, PingFederate, OneLogin, Rippling. Do not enable AAC if you use SCIM.
AAC invites anyone on the verified domain who signs up. Disable external-domain invites.
Reddit sysadmins hit a hostname problem. There is no company.chatgpt.com, so you cannot allow the company workspace while blocking consumer chatgpt.com with a simple DNS rule.
u/xxdcmast (Dec 2025) called that out as a Business customer already paying for Enterprise. u/rcopley in the same thread named the SSL-inspection workaround: send a ChatGPT-Allowed-Workspace-Id header so ChatGPT restricts login to your tenant.
WorkOS's 2026 line is broader than a hostname: an AI app becomes enterprise software when it hits the security team.
An AI app becomes an enterprise software product the moment it reaches a customer's security team. https://t.co/QGeYqWRj4d
Skip "analyze needs, then negotiate." OpenAI's admin quickstart, Learn admin setup, and Academy planner all put identity and defaults before training decks.
requirements.toml), Codex cloud, Platform API, plugins and connectors, connected-system permissions. Access in one does not grant another.Fatimh Al-Jaber (Ooredoo Qatar), via Collibra on LinkedIn: "You can't have trusted AI on untrusted data." Company Knowledge will prove that in a week if file permissions were already a mess.
public-plugins-security-review.csv and actually read it.OpenAI's IT-admin post (July 2026) treats ChatGPT Work as an admin-gated rollout, not an ungoverned agent dump.
Partner workshops that promise an "85% Rule" are one firm's methodology, not a universal law. A four-to-five-week engagement is typical for that kind of help.
Chat is the interactive assistant.
ChatGPT Work (July 2026) is Codex technology inside ChatGPT for multi-step tasks. Work Cloud, Work Local, and Codex Local are separate toggles and share a credit pool with Codex.
Action categories: Read, Draft, Write, Share, Schedule, Execute. See the Work admin FAQ.
Workspace agents arrived in an OpenAI post dated 2026-04-22. They are Codex-powered, run in the cloud, and can share to Slack. OpenAI later described them as generally available in Business, Enterprise, and Edu, while the same post still called the experience a research preview.
Confirm current availability in your workspace. GPTs remain during the transition. Workspace agents are off by default at launch for Enterprise workspaces.
Christina, on OpenAI's Build Hour (2:19): "workspace agents are for teams. They're built for shared work, for tasks that run in the cloud even when your computer is closed." That is why default-off for write actions matters.
GPT access RBAC covers who can create and edit, sharing (invite-only, workspace, or broader), third-party GPTs (all, owner-approved, or none), and an action domain allowlist (empty means no actions).
Plugin capability is a chain: plugin availability, then skills, then app access, then actions, then service authorization, then runtime. Installed is not usable.
Workspace agents use per-agent action controls, not the conversation app-permission selector. Making a plugin available does not grant source-system access. If you are wiring MCP-style tools, the same permission lesson sits in the MCP guide.
Do not lead a rollout with a frontier model. CSO Online (2026-09-07) reported Sam Altman calling the GPT-6 Astra rollout "messy," with Plus, Pro, Business, and Enterprise initially left out. Model GA is not workspace GA.
In Zenity's webinar (3:07): "CHP is not a chatbot, at least not anymore." Later in the same talk (5:41): "It's not a productivity tool. It's an operator." Once GPTs have write, delete, or CRM tools, a poisoned knowledge file is an operator incident, not a chat incident.
Zenity and the Cloud Security Alliance, in a 2026 survey of 445 IT and security professionals, said 53% of organizations had AI agents exceed intended permissions and 47% had an agent-related security incident. That is vendor and CSA research, not a ChatGPT-Enterprise-specific census. Use it as a control question: build-time review is not runtime control.
Zenity: "Every agentic horror story you've read happened within the bounds of what the agent was allowed to do." Permission is not appropriateness. Pair this page with LLM observability if you need traces after the agent is live.
Shadow AI is the reason to buy a sanctioned workspace.
On r/ITManagers, u/blud_13 described the default pattern: somebody buys Copilot or a few ChatGPT seats for whoever asked loudest, the other 40 keep using personal accounts, and the tenant side never gets touched. The cheapest first move is turning on reporting you already pay for.
On r/sysadmin, u/mixduptransistor was blunt about phones and home computers: even good DLP will not stop someone typing into ChatGPT off-network. You still need DLP, and you still need HR and legal to mean the policy.
The workable recipe from those threads: one approved tenant (this SKU, Claude Enterprise, or Copilot), SSO, a DPA, then block the rest. Visibility first (Entra logs, Defender for Cloud Apps, reporting you already pay for), policy second, network and endpoint block third. A domain block with no approved path is how you lose the audit trail.
Okta's 2026 warning is the agent version of the same visibility gap.
Think your AI agent rollout is moving at a manageable pace? Think again. 📈 Speaking on @Bloomberg, our CEO @toddmckinnon shared a concrete story from a recent Okta for AI Agents deal. When the evaluation started, Okta's tools detected 50 agents in the customer's environment. https://t.co/T3cYK4cMD6
Adoption metrics should follow work, not vanity WAU. OpenAI says frontier firms (top 10% usage) generate 8.3× output tokens per active user versus typical, up from 2.6× in January, and that 21% of frontier WAU use plugins versus 9% typical. Use those as vendor benchmarks, then measure your own ticket time and RFP hours.
If you are still choosing whether any enterprise AI program belongs in the company, start with the broader AI solutions implementation map, then come back here for this SKU.
ChatGPT sits beside the suite. Copilot and Gemini sit inside it.
If the org is | Default gravity | This SKU's job |
|---|---|---|
Deep M365 (Teams, Purview, Graph) | Frontier-model and agent workspace beside the suite, via connectors. Microsoft's compare page is an ad. Connectors exist; they are not Graph-native. | |
Deep Google Workspace | Gemini Enterprise (rebuilt as an agent platform 2026-04-22) | Same pattern via Drive and Gmail. Google is selling an agent development system, not only a chat workspace. |
Model-first or mixed suite | ChatGPT or Claude Enterprise | ChatGPT is the UX employees already opened. Claude is the safety, interpretability, and coding motion. For a model-level split, see Claude vs ChatGPT. |
AWS-stack | Q Business is closed to new customers. One sentence; do not write a Q Business how-to. | |
Permission-aware search on our corpus | Glean ( | Adjacent layer, not a ChatGPT clone. Glean's Series F (2025-06-10) was $150M at $7.2B. |
Cited web research | Perplexity Enterprise | One sentence. Treat homepage org counts as vendor-only. |
HIPAA BAA on the chat surface | ChatGPT for Healthcare or Regulated Workspace | Not this SKU. |
Azure identity plus build | Azure OpenAI | People-facing app versus APIs and SDKs. Not a bake-off. |
Where this SKU wins versus adjacent defaults
Three questions before anyone schedules a bakeoff: which suite do you already live in (M365, Google Workspace, or mix)? How many weekly active users, not headcount? What is the primary job this year: chat workspace, suite-native assistant, model-first coding, company search, or API build?
Arvind Jain's 2026 point is that the constraint is organizational context, not another model.
The enterprise AI stack is being rebuilt. Models are becoming more capable, and increasingly interchangeable. As AI moves from answering questions to doing mission-critical work, the constraint is no longer raw intelligence. It is organizational context: understanding how a https://t.co/6hMf7fHco3
Copilot wins when Purview labels, Graph connectors, and an existing M365 bill dominate. DeepInspect (2026-07-03) puts the split this way: OpenAI secures the provider boundary, not the request path inside your tenant.
Users on Reddit still describe Copilot as worse than ChatGPT or Claude at the prompt. That complaint does not beat Graph-native DLP if Graph-native DLP is the requirement.
Claude wins when the builders bounced off Copilot and want Anthropic's no-training plus retention story. Some shops then run Claude inside Copilot or Foundry to keep the Microsoft wrapper. That is a wrapper decision, not a model decision.
Glean wins when the job is a permission-aware context graph over your corpus. It is not a ChatGPT replacement. Glean's gateway pitch is one governed layer for LLMs and MCP, which is a different layer of the stack.
Business has SAML. It does not have SCIM, custom RBAC, residency, EKM, IP allowlisting, or Compliance Logs.
Those controls do not appear after a successful Business pilot. Pick the control plane against the requirement list, then issue seats.
A web filter without a sanctioned tenant moves usage onto phones and home computers. You lose the logs you were trying to create. Approve one workspace, then block the rest.
Company Knowledge inherits SharePoint and Drive permissions as they already exist. Overshared folders become overshared answers. Fix ACLs and start connectors read-only.
Automatic Account Creation invites anyone on the verified domain. SCIM is supposed to be the source of truth for who exists.
Enabling both produces duplicate identities and surprise seats. Pick SCIM, disable AAC, disable external-domain invites.
ChatGPT Work is the July 2026 agent. "ChatGPT for Work" is not a third plan. A Codex seat is not ChatGPT.
Brief the launch comms with those three nouns or the help desk will spend a quarter untangling them.
A BAA attaches to Healthcare, Regulated Workspace, FedRAMP, Clinicians, or API Modified Retention. Business is not an Eligible Service. Do not paste PHI into this SKU because the logo says Enterprise.
Astra-class launches can leave Enterprise out on day one. Identity, defaults, and connectors are the rollout. Models arrive on OpenAI's schedule, not yours.

Voluntary NIST AI 100-1 guidance (26 January 2023). Map GOVERN, MAP, MEASURE, and MANAGE to owners, evidence, and cadence.

Run enterprise AI as a Fund, Defer, or Kill portfolio. Covers operating models, platform layers, shadow AI, and conflicting ROI numbers.

AI governance is named owners, written policy, risk-tiered approvals, a living inventory, and a review cadence that continues after go-live.