ChatGPT Enterprise Admin Controls: September Update
OpenAI adds delegated group tasks, model-access inspection, Codex configuration logs and group APIs for workspace administration.
ChatGPT Enterprise admin controls gained group-manager delegation, member model-access testing, Codex policy audit logs and group-management APIs in OpenAI’s September 11, 2026 release notes. The update gives workspace administrators more specific ways to investigate access and organize routine administration. Here is what each addition does and where to begin.
ChatGPT Enterprise admin controls: what changed
The four administrative additions appear together in OpenAI’s Enterprise and Edu release notes. Choose the control that matches your immediate task:
| Your task | Relevant addition | First place to look |
|---|---|---|
| Delegate selected work for one group | Group manager designation | The group’s members and delegated permissions |
| Explain a member’s model access | Model Test | Models, then Test in Admin Console |
| Investigate a Codex configuration change | Workspace audit logs | The audit history or a permitted Compliance API integration |
| Automate recurring group changes | Groups Admin API | Workspace Admin key permissions and the API documentation |
The release also includes desktop features covered in our Pets, Quick Chat and Windows Appshots update. This article focuses on administrative work, so you can follow the desktop article for those user-facing controls.
Delegate group tasks without changing workspace roles
OpenAI documents groups for Enterprise and Edu, while group-manager delegation is available in Enterprise. Owners or admins can open the workspace in Admin Console, select a group, open Group members and change an existing member’s Group role to Group manager. Then review Group manager permissions separately; the designation alone does not define the delegated tasks.
Permissions can cover analytics, spend controls, model access and defaults, or permitted changes to assigned custom roles. Only an owner can enable or disable editing permissions on assigned roles. Delegation settings apply to all managers of that group.
A manager is not made a workspace admin. The designation cannot create or delete groups, appoint managers or change delegation settings. Editing a custom role shared across groups can affect all those groups. See the official group-manager instructions before delegating a task.
Inspect model access before changing settings
For an unexpected model-access result, the documented path is Admin Console, the relevant workspace, Models, then Test. Search for the member by name or email. The result shows effective model access alongside contributing saved settings, including roles, permissions, preferences and workspace defaults.
This is a diagnostic view. Running a test does not enable a model, increase a limit or override a member’s seat, plan or eligibility. A selected default model also does not grant access. OpenAI’s models and limits documentation explains the inspection steps and the surrounding model controls.
For example, if a colleague reports a missing model, our suggested first step is to record the affected workspace and product surface before changing anything. Compare the reported behavior with the saved settings shown for that person. If the question is which product or subscription to use, start with our GPT-6 access guide; Model Test addresses the workspace-admin part of that investigation.
Use Codex audit logs to investigate configuration changes
Changes made through Codex Policies & Configurations are recorded in workspace audit logs. Authorized administrators can inspect the history in Admin Console or retrieve records through the Compliance API with suitable log permissions. OpenAI describes these records as a way to investigate changes to workspace Codex controls.
The Compliance Platform documentation distinguishes event logs from queries of current state. That distinction matters when investigating a report: a current setting tells you what is configured now, while a historical event can help establish what changed. The documented Compliance Logs Platform retention is 30 days; organizations needing longer retention must arrange continued collection and storage.
Our suggested investigation record is small: the reported symptom, affected workspace, approximate time and the relevant policy change. Keep the member’s account of what happened separate from what the log actually establishes. An event near the reported time is a lead to investigate, not proof that it caused the symptom. Link the finding to the next diagnostic step instead of treating every logged change as an incident.
Automate groups with the right Admin key
The Groups Admin API supports creating, updating and deleting groups in eligible workspaces. Requests need a key scoped to the relevant ChatGPT workspace and permissions for the intended endpoint. A read-only key cannot authorize changes. A group-manager designation alone does not authorize creating Admin keys or using the API.
Owners and admins create keys through Admin Console: select the workspace, open Credentials, then Admin keys, and choose Create new admin key. Review the available permissions and expiration, then securely store the secret shown at creation. Owners have broader permission options; admins choose supported categories within their role.
OpenAI’s Admin key guide covers this setup and links the endpoint reference. These credentials administer a ChatGPT workspace; they do not authorize model inference or manage an API Platform organization. SCIM-managed groups should continue through the identity provider’s synchronization workflow.
A practical first review for your team
The following is our suggested way to evaluate the additions, not a workflow we have executed inside a customer’s workspace.
Choose one existing support question, such as a team lead needing a limited administrative task or a member reporting unexpected access. Write the expected outcome in one sentence. Identify who owns the decision, which workspace is affected and what evidence would settle the question.
Use the matching control from the table and record the result before broadening the work. For a proposed automation, list the group operations it actually needs. Start with a small, reversible test in an approved environment and compare the resulting group state with the intended change. Do not use a successful authentication request as evidence that the whole workflow works.
Finish with a short handoff: what was checked, what changed, what stayed unresolved and who handles the next step. This makes the new controls useful for a real administrative question without turning the first review into a workspace-wide reconfiguration.