ChatGPT Enterprise Compliance and Administrative Tools Update

OpenAI introduces programmatic compliance and administrative controls for ChatGPT Enterprise

OpenAI has released a suite of new compliance and administrative tools for ChatGPT Enterprise and ChatGPT Edu, designed to help regulated industries—including finance, healthcare, legal services, and government—manage data security, audit requirements, and user access at scale.

Programmatic Compliance and Data Security

OpenAI has launched the Enterprise Compliance API and eight third-party integrations from eDiscovery and Data Loss Prevention (DLP) providers to enable programmatic auditing of workspace data. These tools allow workspace owners to maintain time-stamped records of conversations, uploaded files, workspace GPT configurations, metadata, memories, and workspace users.

The OpenAI Compliance Logs Platform

As of December 11, 2025, the Compliance API has evolved into the OpenAI Compliance Logs Platform. This unified platform exports observability and compliance data via immutable, time-windowed JSONL log files, providing minutes-level latency and improved reliability. The platform now includes specific log categories for:

  • Admin Audit
  • User Authentication
  • Codex Usage

Compliance Use Cases

Enterprise customers can use the API and third-party integrations for the following regulatory and security activities:

  • Regulatory Compliance: Meeting requirements for frameworks such as GDPR, HIPAA, and FINRA.
  • eDiscovery and Legal Holds: Maintaining and preparing data for legal proceedings.
  • Data Loss Prevention (DLP): Monitoring and removing sensitive information, including Protected Health Information (PHI), Personally Identifiable Information (PII), and financial data.

Automated User Management via SCIM

To simplify the scaling of user access, OpenAI has implemented SCIM (System for Cross-domain Identity Management). This allows administrators to sync internal employee directories with their ChatGPT Enterprise workspace for the programmatic provisioning and deprovisioning of user accounts.

The system supports custom SCIM implementations as well as major company directories, including:

  • Microsoft Entra ID
  • Okta Workforce
  • Google Workspace
  • Ping

Granular GPT Administration and Controls

OpenAI has expanded the administrative controls available for custom GPTs to ensure safe deployment within the enterprise. Administrators can now implement more precise restrictions beyond simply allowing or blocking GPT actions.

Domain-Level Action Controls

Administrators can now create an approved list of specific domains that GPT actions are permitted to interact with, restricting access to all other domains.

Additional GPT Management Tools

Workspace admins also have access to the following controls:

  • Group Permissions: The ability to create and edit user groups to manage GPT access and permissions.
  • Comprehensive Settings: Tools to manage sharing permissions, view GPT configurations, remove GPTs, transfer ownership, and set global capabilities.
  • Third-Party GPT Controls: The ability to approve specific external GPTs or set global restrictions on all third-party GPTs.

Enterprise Security Foundation

These new tools augment existing ChatGPT Enterprise security features, which include:

  • Model Training: No customer data or metadata is used to train OpenAI models.
  • Encryption: Data is encrypted both at rest and in transit.
  • Compliance Standards: Adherence to SOC 2 Type 2, CSA STAR, and CCPA.
  • Access Control: Support for Single Sign-On (SSO), domain verification, and custom data retention windows.

Sources