Rollout guide
Rolling out ChatGPT Enterprise: a plan for the first 90 days
Roll out ChatGPT Enterprise in this order: owners and sign-in first, then data controls and a written use policy, then connectors with read-only access, then a pilot group with champions and training, and only then the wider launch, measured against a baseline taken before day one. OpenAI's own admin guidance recommends single sign-on (SSO) for every workspace and, on Enterprise, SCIM directory sync, which adds and removes staff automatically from your company directory, both before the first broad invite. It also says to start connectors with read actions, and suggests tracking impact at 30, 60 and 90 days. The order matters more than the pace, because sign-in, compliance logging and connector permissions are cheap to set before launch and expensive to fix after it.
ChatGPT Enterprise rollout. The ordered work of setting up a ChatGPT Enterprise workspace, from identity and data controls to connectors, policy, training and measurement, so that staff use it and the security team can sign it off.
Checked . OpenAI's admin documentation on learn.chatgpt.com, its OpenAI Academy admin guides and the HIPAA Privacy Rule text on eCFR were read on this date. OpenAI changes settings, labels and plan features often, and points admins to its Help Center for current procedures, so check each setting in your own workspace before relying on it. This page is not legal advice.
The first 90 days, in order
OpenAI's admin rollout guide lists its steps with a plain instruction: complete them in order for a new rollout. The table below puts that order on a calendar. The week counts are mine, not OpenAI's, and access requests, security review and procurement will move them more than anything in the product does. Each stage should end with something you can check in the admin console.
| Dimension | What gets set up | Decision it forces | Done when |
|---|---|---|---|
| Weeks 1 to 2: owners, sign-in and a baseline | Named owners for each part of the rollout, SSO, domain verification, SCIM directory sync, roles and a pilot group. | Who owns workspace access, connected systems and compliance records; whether staff join through SCIM or by invitation; what happens to personal ChatGPT accounts on company email. | A test user joins, gets the right seat and role, and loses access when removed in the identity provider. The baseline metrics are written down. |
| Weeks 3 to 4: data controls and the use policy | Retention settings, workspace feature defaults, Compliance API collection and a written AI use policy. | How long conversations are kept, which features are on for everyone, which data staff may never paste in, and whether regulated data is allowed at all. | Compliance records are flowing into your own security or eDiscovery system, and legal, security and HR have signed the policy. |
| Weeks 5 to 6: connectors, read-only first | A short list of connectors, typically email, calendar and file storage, with read actions only, plus the rules for sharing GPTs and plugins. | Which systems ChatGPT may read, who owns each connection, and which write actions, if any, come later. | Each connector has a named owner, a note of the data it may reach and a removal contact, and has been tested with a low-privilege account. |
| Weeks 7 to 10: a pilot cohort | One or two teams, a champions group, role-specific training and two or three workflows tied to goals the business already has. | Which workflows count, who owns each one, and what result would justify a wider launch. | The pilot teams use it weekly on the named workflows, and each workflow has a measured result against the baseline. |
| Weeks 11 to 13: wider launch and the day-90 review | Access for the next groups, a monthly analytics review and a written day-90 decision. | Expand, adjust or cut seats, on activation, weekly use and the workflow results. | The sponsor has a day-90 note with the funnel from seats bought to weekly users, the workflow results, the costs and the next quarter's plan. |
Weeks 1 to 2: owners, sign-in and a baseline
Start by naming owners. OpenAI's rollout guide asks for an owner for each part: workspace access, local runtime policy for its desktop and coding tools, Codex in the cloud, connected systems, and reporting and compliance. Its Academy adds the people side: an executive sponsor who sets the vision and unblocks budget, a project lead who runs the plan, departmental leaders, HR and learning teams, the workspace admins and a group of champions. If nobody on that list can make the day-90 decision, fix that before you configure anything.
Then sign-in. OpenAI strongly recommends SSO for all workspaces and SCIM for Enterprise workspaces, and says to pilot the login flow with a small group before a wide rollout. With SSO, staff sign in with their company credentials and your identity provider's rules apply, including multi-factor authentication and conditional access. SCIM (System for Cross-domain Identity Management) keeps workspace membership in step with your directory, so joiners arrive and leavers go without a ticket. Verify your email domain too, so only people on that domain can join.
Two details are easy to miss, and both are in OpenAI's documentation. Do not run Automatic Account Creation alongside SCIM: people who joined that way may not be managed by SCIM, so removing them from a directory group might not remove their access. And remove leavers in the identity provider, not only in the workspace, because if the directory still assigns them the next sync can add them back. Decide as well what happens to staff who already use a personal ChatGPT account on a company email address, since OpenAI treats merging those into the workspace as your choice.
Last, write down the baseline. OpenAI's Academy suggests metrics your teams already track, such as average ticket resolution time or hours spent on requests for proposal, measured again at 30, 60 and 90 days alongside survey feedback. Skip it and the day-90 review becomes an argument about impressions, and seat counts win that argument.
Weeks 3 to 4: data controls and a use policy people can follow
Set retention before anyone starts working in the workspace, and set it with legal in the room. OpenAI's documentation for ChatGPT Work, the agent inside the workspace, says conversations follow the workspace's retention setting and that deleting a chat schedules permanent deletion within 30 days, subject to published exceptions. Files saved to the Library, project files and saved memories each follow their own rules, and deleting a conversation does not delete a file saved to the Library. So the retention decision has to cover files, projects and memories as well as chats.
Then switch on compliance collection. The Compliance API is how your security, legal-hold and eDiscovery tools pull auditable records out of the workspace, and OpenAI is clear that it is for audit and investigation, not a productivity dashboard. OpenAI's ChatGPT Work cloud security page says Compliance Logs Platform records are available for 30 days, and its Compliance API guide warns against assuming that the source retention window replaces your own retention policy. So the collector has to be running into your security information and event management (SIEM) or eDiscovery system before the pilot starts. Switch it on in month two and the first month's records may already have aged out.
Review the workspace-wide settings while you are there. On Enterprise, owners decide for the whole workspace whether features such as web search, code execution in canvas, meeting recording and Codex are on. Web search, for example, may send search queries and general location information to Bing, which OpenAI says is not linked to user accounts. None of these is wrong to enable, but someone should decide each one on purpose and write the decision down. If data location matters to you, check what the region you buy actually covers: OpenAI says residency applies only to eligible content and supported workloads, and that connected apps and some processing can follow separate location rules.
OpenAI states that ChatGPT Enterprise does not train on business data by default and that the data is encrypted in transit and at rest. That answers the first question a security team asks. It does not answer the second, which is what your staff are allowed to put into it.
That is the use policy's job, and it should be signed before launch rather than written after the first incident. OpenAI's Academy gives a sensible skeleton. Staff check facts and own the final output. The policy says what data may and may not be shared, which uses are encouraged and which are off-limits. A working group from legal, security, privacy, HR, communications and the champions drafts it, executives approve it, and it carries a review date so new features do not outrun it. Our AI governance framework guide, linked at the end of this page, has a clause-by-clause template if you need a starting point.
US healthcare organisations need one more line in that policy, on protected health information (PHI). OpenAI's Academy tells admins to instruct staff not to put PHI into ChatGPT unless the workspace has signed a healthcare addendum. OpenAI's HIPAA guide for Codex ties PHI use to an applicable OpenAI Business Associate Agreement (BAA), says that agreement does not cover Codex in the cloud, and says it does not make another vendor's connected service a HIPAA-compliant destination. Under the HIPAA Privacy Rule, the assurances a covered entity obtains from a business associate must be documented in a written contract or other written agreement (45 CFR 164.502(e)). That describes the documents as read on 29 September 2026. It is not legal advice, and your privacy officer or counsel makes the call.
Weeks 5 to 6: connectors, read-only first
Connectors are where ChatGPT Enterprise starts earning its seat price, and where much of the risk sits, because they let it read, and sometimes act on, your other systems. OpenAI's advice is to begin a broad rollout with the categories teams use every day, such as email, calendar and file or document systems, and, whatever the first set, to start with read actions.
Two facts shape the permissions. Making a connector available in ChatGPT does not give anyone access to files or records they could not already reach, because the connected service's own permissions still apply to the account that signs in. And verifying your domain does not by itself stop staff connecting company accounts from a personal ChatGPT workspace. OpenAI documents a separate verified-domain restriction for supported apps that you have to activate, and existing connections are not disconnected when you do.
For each connector, OpenAI suggests recording the business owner, the permitted data, the read or write actions allowed, the authentication method and a contact for support or removal. I would add a review date. Before any write action goes live, OpenAI asks for a named owner, a review of scopes and service permissions, and a documented recovery path. Where an action changes a system of record, put a check in front of it: our write-up of the pattern where the model proposes and a deterministic check decides shows one way to build that step.
Custom GPTs need the same treatment. Admins control who can build GPTs and whether they can be shared with named people, groups or the whole workspace, and can restrict GPT actions to approved external domains; with no domains allowed, custom GPT actions cannot run. OpenAI also documents a route for migrating custom GPTs to plugins, so settle which of the two your builders should use before the pilot produces a pile of each.
Weeks 7 to 10: a pilot cohort, champions and training
Give the pilot to one or two teams with real, repeated work, and put them in a group of their own. OpenAI's documentation suggests groups for exactly this, naming a pilot cohort as an example, and a group synced from your directory keeps its membership honest. Pick two or three workflows tied to goals the business already has. OpenAI's Academy suggests mapping early work to two or three existing strategic themes, so staff can see a line from the tool to a number that matters.
Training decides whether the seats get used. OpenAI's Academy calls the first 30 days the best time to build habits, and recommends foundational training for everyone, a network of champions who coach peers and report friction, hands-on workshops on real tasks, and HR and learning teams folding AI training into existing paths. Give each workflow an owner who refines it and a written playbook (the problem, the prompt, the steps and the measure), so a win in one team can be copied by the next. Tell users what OpenAI's own guidance tells them: check outputs and important claims before using or sharing them, and approve consequential actions before they run.
If engineers are in scope, treat Codex as a track of its own. It sits behind separate workspace permissions and local policy for the desktop app, command line and IDE extension, and Codex in the cloud is off by default for Enterprise workspaces until an admin enables it. Our guide to rolling out coding agents to engineers, linked at the end of this page, covers that side.
Some pilot workflows will need a build rather than a setting, such as an agent that updates a system of record. Treat each one as an implementation of its own, with its own tests and owner. Our guide to what an AI implementation should produce in its first month sets out what to see each week.
Weeks 11 to 13: wider launch and the day-90 review
Widen access in steps, and read the workspace analytics as a funnel. OpenAI's analytics guide tracks seats purchased, seats enabled, seats activated and weekly active users, and gives the rule I would follow: if progress slows at one stage, fix that bottleneck before investing further down. Bought but not enabled points to provisioning. Enabled but not active points to onboarding. Active but not weekly means people have not yet found a workflow worth coming back for.
Run the review monthly and keep it narrow. OpenAI's suggested rhythm is to check the funnel, read the trend, compare one lagging group with a healthy one, form a view of what is driving the difference, pick a single intervention and compare the two to four weeks before and after.
For the day-90 decision, count the money honestly. OpenAI's usage guidance says to compare the value of the improvement with the costs of the AI, setup, training and ongoing support, to include the time spent reviewing and correcting the work, and it notes that time saved is not automatically a cash saving. A slide of seat counts usually leaves that out.
Keep analytics and compliance records apart. OpenAI says workspace analytics is aggregated and does not expose message text, and its task insights, which group usage by kind of work, are on by default and can be switched off by an admin. Treat analytics exports as identifiable organisational data all the same, as OpenAI's documentation asks.
Where rollouts stall
Each of these is cheap to prevent in the week the table puts it in, and costly to unpick once hundreds of people are working in the workspace.
- Seats counted, not work
- Seats activated measures procurement. Weekly use on named workflows, against the baseline, measures the rollout.
- Leavers who come back
- Removed in the workspace but still assigned in the identity provider, they return on the next sync. Remove access where SCIM manages it.
- Compliance collection started late
- OpenAI says Compliance Logs Platform records are available for 30 days, so a collector switched on after launch can miss the pilot's first weeks.
- Write actions on day one
- Read-only first is OpenAI's own advice. A connector that can change a record needs an owner, a scope review and a recovery path before it is switched on.
- A policy published after the incident
- Sign the policy before launch, so staff know from the first day what they may paste in.
- Nobody owns the day-90 decision
- Without a sponsor who can expand or cut seats, the renewal date makes the decision instead.
Where 1AYM fits
1AYM is an OpenAI Select Partner, and the controls this guide puts first, identity, provisioning and audit, are core work for us. Our AI platform enablement case describes that work at a large international marketing agency, and its identity side includes the SCIM provisioning system we built, which ends a person's access when their HR record changes, across more than 1,000 users. The plan on this page is drawn from OpenAI's public documentation, and OpenAI has not reviewed it.
On a ChatGPT Enterprise rollout we would take the parts this guide calls expensive to fix later, sign-in and provisioning, retention and compliance collection into your own systems, connector permissions and the review rhythm, and build them as controls under our AI governance implementation work. That can be a small fixed-scope statement of work, which can start within a day of the scope being signed, or a longer engagement alongside your IT and security teams. If you have already scoped the rollout, we can resource it on contract from the associates who work with us, held to the same standard, and US clients can contract through our US entity. If a second opinion on your plan would help, book a call or email tayyeb@1aym.com.
For engineers: identity, logging and connector controls to check
What an identity, security or platform engineer should verify in the admin console and the identity provider, each from OpenAI's documentation as read on the date above. Labels move between releases, so check each one against your own workspace.
- SSO, provisioning and seats are separate
- SSO verifies identity and provisioning adds a member; neither sets the seat, feature permissions, local runtime policy or access to an external system. SCIM-provisioned users inherit the workspace's default seat type, and a custom role cannot grant access the seat does not include. Directory sync through SCIM is listed for ChatGPT Enterprise, Edu and Healthcare workspaces.
- Role evaluation
- Custom roles use Default, On and Off, and an explicit Off in any assigned role overrides On in another. Check effective permissions across direct and group-assigned roles after every team change, and remove obsolete direct roles by hand.
- Group name collisions
- If a synced identity-provider group has the same name as an existing workspace group, the existing group becomes SCIM-managed and its membership switches to the directory. Reconcile names, and the sharing attached to them, before enabling Directory Sync.
- SCIM and Automatic Account Creation
- Do not run both. Users created by Automatic Account Creation may not be SCIM-managed, so removing them from a directory group may not remove their workspace access.
- Leavers and access tokens
- Remove the ChatGPT application assignment and every access-granting group in the identity provider; a workspace-only removal can be reversed by the next sync. Removing someone's local Codex permission suspends their access tokens without revoking them, and restoring it reactivates them, so revoke tokens explicitly and move automation to a service account or a named owner.
- Compliance API collection
- Use the append-only compliance log stream for continuous collection. OpenAI publishes Bash and PowerShell scripts that page through log files after a timestamp and write JSONL, for event types such as AUTH_LOG. Test ingestion into a non-production SIEM first, keep the Compliance API key in your secret manager, and apply your own retention and legal hold, since OpenAI says Compliance Logs Platform records are available for 30 days.
- Connector control layers
- Plugin availability, bundled skills, MCP server access by role, action control (read-only or an approved set), authorisation in the connected service and runtime permissions are separate layers. Disabling a connector-backed capability does not necessarily uninstall the plugin or its skills.
- Plugin security review
- Enterprise owners and admins can export the public plugin catalogue from Admin, Plugins, Public as public-plugins-security-review.csv. The snapshot can be up to 48 hours old, leaves out plugins built for your workspace and is not offered in FedRAMP workspaces.
- GPT actions
- Restrict actions to approved external domains; with none allowed, custom GPT actions cannot execute. A GPT can use connected apps or custom actions, not both, and domain approval does not replace API authentication or user authorisation.
- Codex local policy and PHI
- Local behaviour in the desktop app, CLI and IDE extension is constrained by requirements.toml delivered through a cloud, device or system channel, separate from workspace roles. For PHI, OpenAI's guide says its BAA does not cover Codex cloud, and that pinning sign-in to one workspace needs allowed_login_methods and allowed_chatgpt_workspaces set through system requirements.toml or MDM.
- Analytics exports
- Workspace analytics can be segmented by SCIM groups, and admins can export Users and Projects data for a week or a month, with no custom ranges. Analytics carries no message text; item-level records come from the Compliance API.
Sources
- [1]OpenAI, Admin rollout guide (ChatGPT Enterprise), read 29 September 2026
- [2]OpenAI, User lifecycle management, read 29 September 2026
- [3]OpenAI, Groups and provisioning, read 29 September 2026
- [4]OpenAI, Plugin controls (apps and connectors), read 29 September 2026
- [5]OpenAI, GPTs and Sharing, read 29 September 2026
- [6]OpenAI, Compliance API and audit events, read 29 September 2026
- [7]OpenAI, ChatGPT Work cloud security (data handling and retention), read 29 September 2026
- [8]OpenAI, ChatGPT Work admin FAQ, read 29 September 2026
- [9]OpenAI, Workspace analytics, read 29 September 2026
- [10]OpenAI, Usage Insights, read 29 September 2026
- [11]OpenAI, HIPAA configuration guide for Codex, read 29 September 2026
- [12]OpenAI Academy, Planning your ChatGPT rollout (last updated 29 May 2026), read 29 September 2026
- [13]OpenAI Academy, Inviting and managing your team (last updated 17 September 2026), read 29 September 2026
- [14]OpenAI Academy, Feature controls and integrations with your tools (last updated 17 September 2026), read 29 September 2026
- [15]OpenAI Academy, Empowering and supporting your team (last updated 17 September 2026), read 29 September 2026
- [16]OpenAI Academy, ChatGPT Enterprise workspace analytics guide (last updated 17 September 2026), read 29 September 2026
- [17]OpenAI Academy, Communicating about ChatGPT Enterprise to your team (last updated 14 July 2026), read 29 September 2026
- [18]eCFR, 45 CFR 164.502(e), the Privacy Rule on business associate disclosures (title 45 current as of 25 September 2026), read 29 September 2026
Frequently asked questions
How long does a ChatGPT Enterprise rollout take?
OpenAI's guidance sets an order for the steps but no timeline. It puts SSO and SCIM before the first broad invite and suggests measuring impact at 30, 60 and 90 days. The plan on this page is my shape for that order: two weeks on owners, sign-in and a baseline, two on data controls and the use policy, two on connectors, four on a pilot and three on the wider launch and review. Access requests and security review usually set the real pace.
Do we need SCIM, or is SSO enough?
SSO controls how people sign in; SCIM controls who is in the workspace. Without SCIM, joiners are invited and leavers removed by hand, and OpenAI asks you to plan periodic audits of the member list. OpenAI lists SCIM directory sync for ChatGPT Enterprise, Edu and Healthcare workspaces. Beyond a handful of staff, I would treat it as part of the minimum.
What is the ChatGPT Enterprise Compliance API for?
Exporting auditable records into your security, legal-hold and eDiscovery systems, and supporting approved investigations. OpenAI says it is not a productivity dashboard and should not be used to judge individual performance; workspace analytics is the tool for adoption. OpenAI's ChatGPT Work cloud security page, read on 29 September 2026, says Compliance Logs Platform records are available for 30 days, so set up continuous collection before launch.
Which ChatGPT Enterprise connectors should we enable first?
OpenAI suggests starting a broad rollout with the categories teams use every day, such as email, calendar and file or document systems, and starting with read actions whatever the set. Add write actions later, one at a time, each with an owner, a review of its scopes and a documented recovery path.
Does OpenAI train its models on our ChatGPT Enterprise data?
OpenAI states that it does not train on ChatGPT Enterprise business data by default, and that the data is encrypted in transit and at rest. Its connector guidance says the same of information accessed through connectors on Business, Enterprise and Edu. Confirm the position in your order form.
Can staff use ChatGPT Enterprise with patient data?
Only on the terms your agreement with OpenAI covers. OpenAI's Academy tells admins to instruct staff not to input protected health information unless the workspace has signed a healthcare addendum, and its HIPAA guide for Codex ties that use to an applicable Business Associate Agreement, which it says does not cover Codex in the cloud. Connected services need their own agreements. This is not legal advice; your privacy officer or counsel should decide.
Who should own a ChatGPT Enterprise rollout?
An executive sponsor who can make the day-90 decision, and a project lead who runs the plan week to week, with named owners for workspace access, connected systems and compliance records. OpenAI's rollout guide and its Academy both start there. IT can configure the workspace, but it cannot decide on its own which workflows matter to the business.
Further
- ChatGPT Enterprise vs Claude Enterprise · Prices, seat rules and controls, if the plan itself is not settled yet.
- AI governance implementation · Identity, logging and permissions built as controls rather than written as policy.
- AI governance framework · An eight-clause policy template, each clause mapped to a control, an owner and the evidence.
- Rolling out Codex and Claude Code · The engineering track, if developers are in scope.
- 1AYM's OpenAI partner status · What the company status covers, and what it does not.
We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.
Last reviewed · 1AYM