FIELD NOTE

ChatGPT Enterprise Plugin Admin Controls: New Console

OpenAI's October 1 Enterprise update brings plugin and marketplace management to Admin Console. Review installation, app access, approvals and GitHub sync.

ChatGPT Enterprise plugin admin controls now have an Admin Console entry point. OpenAI’s October 1 update lets workspace owners and admins manage plugins and plugin marketplaces there, while retaining the Apps page for legacy workflows. Start by selecting the correct workspace, then review the plugin’s installation policy, required apps, and account permissions.

ChatGPT Enterprise plugin admin controls: what changed

The Enterprise release notes announce the navigation change: open Admin Console, select your ChatGPT workspace, and use Plugins or Marketplaces. Existing app controls remain in Workspace settings > Apps; Manage Legacy Apps also opens that page from the new Plugins view.

The dated announcement names Enterprise owners and admins. It does not say every plan received the same rollout or that existing permissions were reset. The controls explained below are current operating guidance, not a claim that every permission first launched on October 1.

This differs from the September additions covered in our Enterprise admin controls report, which introduced group-manager delegation, model-access testing, configuration logs, and group APIs.

Separate installation from a working app connection

OpenAI’s plugin guide explains that a plugin can package skills, connected apps, templates, and extensions. A skill-only plugin may need no external account. An app-backed workflow has additional requirements.

Installation policy determines how eligible members get the plugin. Available lets them install it; Installed installs it automatically for eligible members or supported roles. Neither choice grants access to the provider’s data. Required apps must be usable; an unavailable optional app may leave other capabilities working.

Members should review the plugin’s included apps and complete any required connection flow. Some features need an individual provider account; others use no sign-in or a workspace-managed connection. Desktop only plugins require the desktop app and cannot run on ChatGPT web.

For a connection involving more than one account, use our multiple-account plugin report to keep account selection separate from workspace installation.

Our suggested inventory records the plugin name, intended team, included apps, client, and source. Add the expected task in one sentence. That gives the administrator a concrete target when a member reports a missing capability.

Check access, actions, and approval separately

The admin controls documentation distinguishes three decisions: who can use an app, which supported actions it can perform, and when ChatGPT asks for approval. Enterprise and Edu role settings apply where supported; Business app availability is workspace-wide.

Review supported read and write actions before selecting a future-action policy. Disable new actions blocks later additions, not actions already enabled. Some apps do not expose individual action controls. Provider consent and OAuth scopes remain separate checks.

The app-permissions guide describes Always ask, Allow read actions, and Allow low-risk actions. Available options depend on the app and workspace. Allow all actions is not in the standard workspace-wide selector; an individual app may offer it. A permission choice cannot override a blocked action, missing provider access, or workspace restriction.

Changing an approval setting also does not disconnect an account. Treat connection removal as a separate operation rather than assuming a stricter approval option revokes provider access.

Review GitHub marketplace imports and sync results

A plugin marketplace here is a GitHub JSON catalog, not the partner-software purchasing program announced at DevDay. OpenAI’s GitHub marketplace instructions support public and private repositories on github.com. The importing account needs access to the catalog repository and every referenced repository.

Use Add > Import marketplace in the selected workspace’s Plugins view. Enter the repository URL, put a subdirectory in Path when needed, and choose a branch, tag, or commit. A fixed commit stays at that revision; a branch can receive updates.

New marketplaces enable daily sync. Sync now requests an update; Refresh plugin list only reloads the displayed list. A completed sync with errors can include successful imports alongside failures. An invalid update retains the existing plugin’s last working version.

Repository removal does not delete an imported workspace copy. Deleting a marketplace does delete its imported plugins, so do not use deletion to repair account ownership. Sync follows the importing admin’s GitHub connection. Content synchronization does not authorize members’ app accounts.

A focused diagnostic example for an affected team

The following is our proposed check, not a test performed in a customer workspace. Consider a project-update plugin that is visible to a team member but cannot retrieve an expected issue. Write down the exact symptom before changing settings: the plugin appears, the requested issue is missing, and the member expects read-only retrieval.

Ask the member for the workspace, client, intended account, and a reproducible request using approved test data. Have the administrator inspect the relevant settings and the provider administrator check access to the specific issue. Record each observation against the same request. This keeps a catalog problem from being confused with a data-access problem.

Change only the setting supported by that evidence, then repeat the request as the affected member. An administrator’s successful run would answer a different question. If the requested issue is retrieved, compare its identifier and content with the source rather than treating a plausible summary as proof.

For a catalog update, record the source revision, sync result, and expected plugin version. Compare those records with what the member can actually use. Our access guide covers the separate product, plan, and country or region checks when the mismatch concerns model availability.

What to put in the administrator handoff

Keep a small change record: affected workspace, plugin, member or role, previous setting, tested setting, source revision when relevant, and observed result. Include the person responsible for provider access if that sits outside the ChatGPT administration team.

For an unresolved request, name the failing step and preserve the relevant error. For a successful request, attach the concrete result that matched the original expectation. This makes the October 1 console change useful in daily administration without turning a single reported problem into a broad permission change.