Connectors let ChatGPT search, read, and sometimes change things in your other tools, such as Google Drive, email, calendars, and Slack. Turn on only the ones a job truly needs, because each connector gives ChatGPT access you would otherwise control by hand.
Imagine a coworker asks whether ChatGPT can just pull the latest deck from the shared drive and draft the quarterly recap itself. Until now you have pasted or uploaded files one at a time, so you chose exactly what it saw. With a connector, it can look through the whole drive on its own. That saves time, and it also makes any mistake bigger.
This post continues Learn ChatGPT from scratch. Earlier posts covered what ChatGPT is, its plans, your first minutes with it, its desktop modes, what it remembers, and how to share voice, images, and files safely. Here you will learn what connectors and apps are, and a simple ladder for adding access only when plain chat and careful uploads are not enough. Product names and menus change often, so re-check OpenAI’s Help Center the week you set a policy.
What a connector actually is
A connector, in everyday speech, or an app, in OpenAI’s current product language, is a bridge between ChatGPT and another service. Once you connect and approve it, ChatGPT can pull context from that service. When the app allows it, ChatGPT can take actions there too. People usually mean one of these when they say “we wired ChatGPT up”: Google Drive or Microsoft files, Gmail or Outlook, calendars, Slack, CRMs, project tools, design tools, or a custom system your own company built.
That is different from uploading a PDF once. An upload is a one-shot attachment for this thread only. A connector is ongoing access under whatever scopes you, or your admin, granted it. The model is not “remembering your company.” It is calling tools with credentials you approved, subject to your plan, your workspace settings, your region, and the third party’s own rules.
Rule of thumb: use plain chat for ideas. Use upload when the file is temporary and stands on its own. Use a connector when the real record lives outside the chat and you need live search, many files at once, or actions. Prefer search-only access until you trust how the loop behaves. Start small.
Plugins, apps, and skills: stop mashing the words together
OpenAI has been merging how people find these tools. The public Help Center now describes a move toward a Plugins Directory as the main place to find workflow features across ChatGPT and Codex. In that model, three words mean three different jobs.
- Apps are the integrations that connect ChatGPT, or Codex, to external data and actions.
- Plugins are packages that can bundle apps, skills, and templates so a whole workflow is easier to turn on at once.
- Skills are reusable playbooks that shape how the work actually gets done once the plumbing is already in place.
You will still hear people say “connector,” “integration,” or the older word “plugin” to mean any of this. For your own mental model, keep the three jobs separate.
| Word people say | Job it usually means | Office analogy |
|---|---|---|
| App / connector | Pipe to Drive, mail, Slack, CRM, etc. | Key to a locked filing cabinet |
| Plugin (package) | Installable workflow kit that can bundle apps + skills | Labeled starter kit for a role |
| Skill | How to run a repeating job shape | Checklist your best ops hire follows |
| Permission / approval | When ChatGPT must ask before acting | Two-person rule on wire transfers |
If a teammate says “install the sales plugin,” ask what apps it turns on and whether any of those apps can write, meaning send, update, or delete something. The packaging is convenient, but the scopes are what actually decide your risk. Read them first.
What apps can actually do
Not every app is equal. OpenAI’s own app pages describe a wide range of features, and you do not need to memorize the marketing behind them. You do need to know which feature you just turned on.
Search and reference
This is the most common, safer-feeling use: ChatGPT searches connected services and pulls relevant snippets into the chat. For example, “find last week’s pricing one-pager in Drive and summarize the objections.” You still have to check the file was the right version. Finding it did not hand the model free rein to rewrite the source.
Deep research across sources
Some apps pull from many sources at once and link back to the originals. That is useful for pulling ideas together. It is still a summary someone else wrote, though, and the links help you check the work; they do not replace checking it yourself.
Sync and indexed knowledge
Some apps copy content ahead of time so answers feel faster and more complete. That is a bigger data decision than “search this one folder when I ask,” because it may pull in far more of a document library for speed. At work, this setting is often locked to admins for exactly that reason. Ask who turned it on, what it actually covers, and what rules apply to your plan for keeping or training on that data.
Write actions
Write actions change the outside world: creating or updating records, sending mail or messages, moving files, changing calendar events, or adjusting who can see what. OpenAI’s help pages treat many of these as important actions. That means they have a real effect outside ChatGPT, expose sensitive information, or are hard to undo. That is the right way to think about them, even if the exact label on your screen changes later.
Interactive interfaces
Some apps render richer in-chat experiences, such as cards, maps, playlists, or design surfaces. These are fun for demos, but you should still check what data left the chat and landed under that third-party app’s own terms.
How you actually use one in chat
The exact menus differ by surface (web, desktop, mobile) and change from month to month, but the durable habits look like this.
- Discover: open the Plugins Directory, or Settings then Apps on a managed workspace, and read what a listing actually includes: the apps, the skills, the connection requirements, and any privacy notes.
- Connect: complete the third-party login and its permission scopes. Read those scopes closely: “read mail” is not the same grant as “send mail.” “See files you open” is not the same as “see all of Drive.”.
- Invoke: select the app from the tools list, or type
@followed by the app’s name in chat, for example@Drive, find the Q3 hiring plan and list open roles. Naming the app cuts down on the chat guessing the wrong tool. - Approve: when ChatGPT proposes an important action, read the approval card before you click anything. Denying it is a perfectly valid answer, and “allow once” is usually smarter than “always allow” on your first day.
- Verify: open the source system yourself and confirm the file, message, or record actually matches what the chat claimed.
Voice mode, in OpenAI’s current help language, has not been the place to lean on apps. Do any high-stakes connector work in text, where you can actually see the tool call and the approval screen before it fires.
A ladder to climb before you connect more
Every connector adds one more thing to worry about: credentials, a third party’s own privacy policy, an accidental write, a tool your IT team never approved, or the chance the model summarized the wrong folder. Climb to the next rung only when the one you are on fails a real job.
| Rung | What you do | When it is enough | Main risk |
|---|---|---|---|
| 1. Plain chat | Type the problem; no external systems | Drafting, brainstorming, explaining with public knowledge | Hallucinated facts if you skip verification |
| 2. Upload | Attach a PDF, sheet, or screenshot for this thread | One-off review of a self-contained file | Sensitive data in a chat; wrong file version |
| 3. Read connector | Search/reference Drive, mail, Slack, etc. | Live context across many docs without zip dumps | Over-broad permissions; wrong corpus; sync surprise |
| 4. Write actions | Send, create, update, delete, reschedule, share | Repetitive ops where human approval still runs | Hard-to-undo mistakes at scale |
| 5. Scheduled / agentic jobs | Recurring or multi-step work with less babysitting | Stable workflows with logs, owners, and rollback | Silent drift; zombie automations; spend |
Many teams skip straight from step one to step four because the demo looked smooth in a meeting. A better default at work: stay on rungs one and two for a full month. Then add exactly one read connector for a narrow set of files. Keep write access off until the team has a written approval habit that people actually follow.
Write actions are a different sport
Reading a document and summarizing it is easy to undo, because the source still exists afterward. Sending the wrong customer email, canceling the wrong meeting, or changing CRM ownership is a different kind of problem entirely. OpenAI’s own permission model for ChatGPT apps covers a range of options here.
- Always ask: confirm even before reads happen. High friction, but high caution too.
- Any changes: auto-read is fine, but ask before anything that changes the outside world.
- Important actions, often the default: auto-read is fine, but ask before actions that matter, expose sensitive data, or are hard to undo.
- Never ask: elevated risk, since actions can fire without any prompt at all. Treat this as an advanced setting, not something you turn on your first day.
Some examples deserve a pause even when the model sounds confident: sending or editing email or Slack messages on your behalf, deleting content, making purchases or refunds, moving or renaming cloud files, changing sharing settings, or pushing personal or financial details into an app. Saving a private draft is usually lower risk than sending it to a whole distribution list. Updating a cart is lower risk than placing the order. Use that same instinct whenever an approval card pops up.
App permissions do not grant new access on their own. They only control when ChatGPT has to ask before using access you already gave it. Disconnecting the app, or having an admin disable it, is how you actually remove that access. Do not confuse setting “always ask” with the CRM key being gone.
Work rules come before cool demos
Personal Plus on your own credit card is not company approval. If your employer has a Business, Enterprise, or Edu workspace, use that account for work data instead. Admins control whether apps are turned on, which roles can use them, and sometimes whether write actions exist at all.
These patterns come from OpenAI’s own workspace guidance, so re-check them before you freeze any policy around them.
- Business: apps may be turned on by default, so owners should still review the action controls and allowed domains.
- Enterprise / Edu: apps may be off by default until an owner enables specific ones, sets role-based access rules, and publishes the settings for everyone.
- Action control: admins can allow all actions, only reads, or a custom mix, and decide how a new action behaves once an app adds a capability later.
- Domain restrictions: limit which third-party accounts members can connect at all, for example only company Google domains.
- Compliance logs: enterprise customers may get app call logging through OpenAI’s compliance tooling. A personal plan does not give you that same story.
If Security has not approved a connector for customer data, payroll, health information, or other regulated content, do not “just try it on a small file.” Small files teach bad habits that scale badly later. Use made-up sample data on personal plans while you are learning, and put real company data only on paths your organization has actually approved.
Training and data handling, at a high level
Consumer plans and business plans are not the same privacy story. OpenAI’s public pages generally say Business, Enterprise, and Edu workspace data is not used to train models by default. Personal accounts (Free, Plus, Pro, and similar) may use your content to improve models unless you opt out under Data Controls. Apps can also share context with third parties under those apps’ own terms, so read the approval screens as you go. Turn off “improve the model for everyone” on personal accounts if you want to be careful, and even then, do not put off-limits work data into a personal chat just because a toggle feels reassuring.
Worked example: a weekly status update without a connector zoo
Say you own a Friday status note for a product squad, and the sources live in three different places: a Drive folder of meeting notes, a Slack channel for blockers, and a sheet of ship dates.
Rung 2 path, and often that is enough
Export or download this week’s notes as a PDF, paste the three Slack threads that actually matter, attach the sheet tab as a CSV (a plain text file where commas separate the columns), and ask ChatGPT to draft a status update with three sections: shipped, at risk, and asks. You review every claim against the files yourself. No login scopes, no write access, slightly more manual work, and fine for many teams as it stands.
Rung 3 path: a read connector
Connect Drive, and only Drive, with the narrowest scopes your admin allows. In chat:
@Drive Search only in folder "Squad status / 2026".
Find notes from the last 7 days.
Draft a Friday status with:
- Shipped
- At risk (with evidence quotes)
- Decisions needed
Do not invent metrics. If a number is missing, write "not in sources."
Do not send email or post to Slack.Then open the cited files yourself. If the draft invents a “94% on-time” claim that was never actually in the notes, fix your prompt and your verification habit before you ever turn on write access.
Rung 4 path: write, only after trust is earned
Maybe you eventually allow posting a draft to a private channel after someone approves it. Keep customer-facing sends off the table until the team has a written rule for who reviews it, what “done” means, and how to recall a bad post. Prefer “allow once” for your first ten times using it.
Common mistakes
| Mistake | What goes wrong | Better habit |
|---|---|---|
| Connect everything day one | A wide-open setup with no muscle memory for approvals | One read-only app; one corpus; one month |
| Personal plan + work CRM | Unapproved tools in use; training/retention mismatch; no admin logs | Company workspace or approved stack only |
| Trust summaries without opening sources | Wrong file version becomes “truth” | Click through citations; check dates |
| “Never ask” for convenience | Silent sends and updates | Default to Important actions or Any changes |
| Confuse upload with connector | People think access ends when the tab closes | Disconnect unused apps; review Settings → Apps |
| Skip admin for write tools | Policy surprise after an incident | IT/Security before CRM write or company-wide mail |
| Custom connections with no owner | Forgotten credentials; orphan automations | Named owner, rotation plan, least privilege |
Custom apps and MCP, a light map only
Teams can build custom apps so ChatGPT talks directly to their own internal tools. OpenAI’s own docs cover building with the Model Context Protocol (MCP), a shared standard that lets an AI chat call outside tools, plus a kit of code called the Apps SDK for building the app itself. Workspace admins can allow or block custom apps entirely. That path is real and useful for a company’s own internal systems. It is also how an unreviewed internal server quietly turns into something the whole company depends on. If you do not own the server, its credentials, and its logs, do not be the person who “just connects it” for everyone else.
For most learners finishing this series, you do not need to build any of that yet. You need the judgment to work in order: plain chat first, upload second, an approved read connector third, and write access only with your eyes fully open.
A one-week practice plan, no zoo required
- Day 1: list three weekly jobs you do, and mark each one as rung one, rung two, or “needs live systems.”.
- Day 2: for one of those jobs, succeed with upload only. Time yourself, and note what still felt painful.
- Day 3: read your company’s AI or software policy, or ask IT where it lives, and write one sentence naming which data classes are allowed in ChatGPT.
- Day 4: if policy allows it, connect one read-focused app on the correct workspace. Invoke it with
@, and keep write access disabled or set to always-ask. - Day 5: run the same job through the connector and compare the quality and time against Day 2. Keep a verification checklist of at least three source clicks.
- Day 6: review Settings then Apps, and disconnect anything you are not actually using weekly.
- Day 7: write a five-line team note covering which app, which folder or corpus, read versus write, and who owns approvals, then share it before anyone else copies your setup blind.
Quick recap
- Connectors and apps are bridges to Drive, mail, Slack, CRM, and similar systems, not a guarantee of truth.
- Plugins package workflows, apps are the pipes, and permissions decide when ChatGPT must ask first.
- Type
@plus the app name whenever you want a specific tool in the loop. - Climb the ladder in order: plain chat, then upload, then a read connector, then write, then scheduled jobs.
- Write actions carry higher risk, so keep the approval friction on until the team has real habits and logs.
- At work, IT and workspace admin settings beat personal demos every time. Policy comes first.
Series notes
This post continues Learn ChatGPT from scratch, picking up right after uploads and file handling. The next post closes out the series with privacy, work rules, and how to recognize when ChatGPT is simply the wrong tool for the job. After that, AMS (Analytics Made Simple) continues into deeper tutorials on Work mode, Codex, and Custom GPTs, where connectors show up again with more surface-specific detail, though the same ladder still applies.
Sources
Product surfaces and admin labels change often. Use these as starting points and verify the live details before you write policy around them.
- OpenAI Help: Apps in ChatGPT (connectors/apps, plugins directory notes, permissions, write actions, workspace admin patterns).
- ChatGPT: Plugins feature overview (directory,
@invocation pattern, everyday tool examples). - OpenAI Help: Admin controls, security, and compliance for plugins and apps (enterprise/business controls, training notes for apps).
- OpenAI Help: Data Controls FAQ (consumer vs business training toggles).
- OpenAI: Enterprise privacy (business data handling overview).
- OpenAI: Apps SDK (building custom app experiences, MCP-backed tools).
- Model Context Protocol (standard for AI clients talking to external tools).
- Analytics Made Simple: Learn ChatGPT from scratch (series home).
- Analytics Made Simple: Learn (related learning paths).
Keep going
Same lessons in your feed
Short diagrams, hooks, and weekly tutorials on Substack, Instagram, X, and Facebook.
