Skip to content
Administer

Admin permissions for ChatGPT Work

Work is not one switch. Cloud and local access are governed independently, Codex sits outside both, and model defaults are set somewhere else entirely. Getting this wrong is why one team member has Work and another doesn't.

VERIFIED 2026-08-23 · OPENAI HELP CENTER

Where the controls live

SettingLocationGoverns
Work Cloud Workspace settings → Permissions & roles Starting and viewing cloud tasks across web, mobile and desktop
Work Local Workspace settings → Permissions & roles Working locally in the desktop app. Enabled without Work Cloud, members work locally but cannot start cloud tasks
Codex Local Workspace settings → Permissions & roles Codex — independent of both Work switches
Browser use & network access Separate controls Continue to apply where supported
Starting model, reasoning level, speed, Fast Mode, new-chat behaviour Workspace settings → Models Work & Codex, as one unit — separate from Chat's default

Source: OpenAI Help Center, ChatGPT Work and Codex.

The three combinations worth understanding

Cloud on, local off. The conservative default for most organisations. Members get Work everywhere, but no agent ever reads a folder on a company laptop.

Local on, cloud off. Explicitly supported: members work locally in the desktop app but cannot start cloud tasks. Sensible where the concern is what leaves the building rather than what the agent can touch.

Both on. The full product — and the configuration where scoping discipline matters most, because members grant folder access themselves, per task.

Model defaults are not access grants

Workspace settings → Models lets owners and admins configure a starting model, reasoning level, speed, Fast Mode availability, and new-chat behaviour for Work & Codex. Three things follow that trip people up:

  1. Chat has its own separate default. Changing the Work & Codex setting does not change the starting model for a regular Chat conversation.
  2. Role overrides are evaluated separately for Chat and for Work & Codex, where role-specific controls are available.
  3. A starting default does not grant access. Pointing a role at a model it is not entitled to use does not entitle it. Fix entitlement first, defaults second.

Eligibility and what members see

Work is available for eligible ChatGPT Enterprise and Edu workspaces with Enterprise Key Management (EKM) enabled. For eligible workspaces it is enabled by default for members on the default workspace role unless an owner or admin turns it off, with workspace settings and RBAC still determining each member's access.

Chat remains available in every configuration. When Work or Codex Local is off for a member's role, that member sees the product marked unavailable and can request access from a workspace admin — so an access request is a signal your role config is doing its job, not that something broke.

Common questions

Does turning off Work remove ChatGPT for my team?

No. Chat remains available in every configuration. Members whose role has Work or Codex Local switched off see the product marked unavailable and can request access from an admin.

If I disable Work Local, does Codex lose local access too?

No. Codex Local is controlled separately, so changing Work Local or Work Cloud does not change access to Codex Local.

Does setting a starting model grant access to that model?

No. A starting default does not grant access to a model or feature that is unavailable to the member’s role.

Is Work on by default for our workspace?

For eligible workspaces, Work is enabled by default for members using the default workspace role unless an owner or admin turns it off. Workspace settings and role-based access controls still determine each member’s access.