Guide

Where workplace ChatGPT data goes

In brief

An approved summary task can take a new data path when a connector is added. Account controls, retention and output sharing apply at different points along that path.

5 min read

Sources
An existing summary route stays intact while an excerpt waits before an unconnected branch toward an empty external bowl.
Conceptual data-path review for the hypothetical summary workflow: a proposed connector adds a recipient that needs its own decision. No workplace data has reached the external bowl, and no universal account or retention approval is represented.
On this page4 sections

A familiar prompt can send workplace data along a new route. Adding an external search connector to an approved summarization task may change which service receives information even when the person using it types exactly the same request. The product name and task description have stayed familiar; the data path has changed.

Before supplying operational material, trace that path from source to AI account, through any connected tool and into the final destination. This turns a broad question about whether AI is allowed at work into specific questions about the account, information, recipients and action involved.

Approval follows the account and workflow

An organization may permit a managed workspace for some data while excluding personal accounts or unreviewed connectors. Check the applicable policy and the account actually in use. Approval for a product does not necessarily answer which datasets, connected services or output audiences are permitted.

For the hypothetical summary workflow, the review now has two parts: the material sent for summarization and any excerpt or query passed to the added search service. Approval of the first does not settle the second.

Check the approved identity, data, destination and action before the connector receives the material. Looking at those four parts preserves useful work already within policy while identifying the particular new step that needs a decision.

Make any clarification request concrete: describe the task, a sanitized input example, intended account and destination for the result. Ask which part is allowed and which needs a different route. The responsible team can evaluate a bounded workflow more readily than a broad request to approve AI for operations.

Trace where workplace data will travel
Trace where workplace data will travel
A data-path review, not an authorization diagram. Check the approved account, connector permissions and destination for the actual task before supplying workplace material.
Read diagram description

A data-path review, not an authorization diagram. Check the approved account, connector permissions and destination for the actual task before supplying workplace material. Diagram labels: Source material: Data classification and minimum needed content; AI account: Organization-approved use and controls; Connected tool, if used: Permissions and information sent onward; Destination: Who can receive or access the result?.

Training, retention and access are separate questions

Training concerns whether supplied material is used to improve models. Retention concerns how long it is kept. Access concerns who or what can reach it. A favorable answer about one does not settle the others.

OpenAI's API data documentation states that API data is not used for training by default unless the customer opts in, and separately describes retention and application-state behavior. That API statement is not a complete policy for a ChatGPT account or a third-party application. The deployment, product settings and contract still determine which controls apply.

Check the current terms and settings for the exact environment. A training opt-out does not necessarily mean no storage, and a provider's controls do not automatically govern another service reached through a connector. In the summary example, the new search destination therefore needs its own place in the review.

The route continues after generation. Prompts and outputs belong in approved locations too; copying a permitted summary into a public document can disclose information to a new audience. The processing decision and final sharing decision need to cover the same actual task.

Smaller inputs still need the relevant context

A short excerpt may answer the summary question without supplying the whole document. Remove unnecessary personal identifiers, credentials and proprietary payloads while retaining the information the task needs. Incident analysis may depend on timing and relationships among events, so sanitization should preserve those relationships where authorized.

Read the resulting input before sending it. Replacing names alone can leave sensitive details in the text, while aggressive removal can make the events impossible to connect. The useful goal is a smaller adequate input, rather than a cosmetically redacted copy or an excerpt stripped of its meaning.

If sensitive material is necessary, use the authorized process rather than treating a legitimate purpose as permission for every destination. This is an operational checklist, not a determination that a particular use satisfies legal or contractual obligations.

Rules depend on the organization and deployment. Use the current approved controls rather than assuming a universal retention policy or blocking every useful task because another use would be inappropriate.

Where the output and tool actions go next

Check the output's factual claims, source attribution, code behavior and intended audience. A plagiarism detector cannot establish originality or clear intellectual-property rights. Material legal or contractual questions belong with the people responsible for resolving them.

If an assistant has tools, inspect the proposed destination and change before consequential execution. The agent operations guide explains why action permissions need enforcement outside the prompt. An approved analysis task should not silently become authority to modify the system described in its answer.

If information reaches an unapproved destination, follow the organization's incident process promptly. Preserve enough information for the response team to establish what was shared without copying the sensitive material into more places. The policy should make that reporting route as clear as the route for requesting permission.

For the summarization workflow, the new connector is the change to resolve: which excerpt or query will it receive, under which account controls, and who can access the resulting document? A sanitized example gives the responsible team enough detail to approve that route or choose another one. Work already covered by the existing arrangement can continue within its approved scope.

Sources & context

Sources linked in this article. Read alongside the author’s analysis; a citation does not independently verify a publisher’s claims.

Report an error or outdated detail

More on OpenAI

All OpenAI coverage

Related reading

Explore a related question