Your inbox is a mess, the shared Drive has three versions of the same brief, and someone pings Slack: “Can ChatGPT just pull the latest QBR deck and draft the recap?” That sentence jumps you from “helpful chat” into “product that can reach systems of record.” Uploads (Part 6) were already a trust exercise. Connectors and apps go further: ChatGPT can search, reference, and sometimes change things in Drive, mail, calendars, Slack, CRMs, and other tools without you hand-pasting every file. Power goes up. So does blast radius.
This is Part 7 of Learn ChatGPT from scratch. Parts 1 through 6 covered what ChatGPT is, plans without FOMO, first minutes, desktop modes (Chat / Work / Codex), memory and Projects, and multimodal inputs (voice, images, files). Here we map the outer layer: connectors, apps, and the plugins packaging that wraps them in ChatGPT’s current product language. The goal is a complexity ladder so you add access only when plain chat and careful uploads are not enough. Product names, directory labels, and admin screens move. Treat this as a field guide. Re-check OpenAI’s Help Center the week you set real policy.
What you’ll learn
- What connectors and apps are in plain English (pipes to external systems, not a second brain)
- How plugins, apps, and skills fit together in ChatGPT’s current directory model
- How to invoke an app in chat (including typing
@plus the app name) - Why read access and write actions sit on different risk floors
- A ladder: plain chat → upload → read connector → write actions → scheduled / agentic jobs
- How IT and workspace policy should gate work use before you connect shared mail or CRM
- A practice plan that does not turn your account into a connector zoo
Plain English: what a connector actually is
A connector (in everyday speech) or an app (in OpenAI’s current product language) is a bridge between ChatGPT and another service. Once connected and authorized, ChatGPT can pull context from that service and, when the app allows it, take actions there. Common examples people mean when they say “we wired ChatGPT”: Google Drive or Microsoft files, Gmail or Outlook, calendars, Slack, CRMs, project tools, design tools, and custom internal systems.
That is different from uploading a PDF once. Upload is a one-shot attachment for this thread. A connector is ongoing access under the scopes you (or your admin) granted. The model is not “remembering your company.” It is calling tools with credentials you approved, subject to plan, workspace settings, region, and the third party’s own rules.

Rule of thumb: Use plain chat for ideas. Use upload when the file is temporary and self-contained. Use a connector when the system of record lives outside the chat and you need live search, multi-file context, or actions. Prefer search-only until you trust the loop.
Plugins, apps, skills: stop mashing the words
OpenAI has been consolidating discovery. As of mid-2026, the public Help Center describes a migration toward a Plugins Directory as the main place to find workflow capabilities across ChatGPT and Codex. In that model:
- Apps are the integrations that connect ChatGPT (or Codex) to external data and actions.
- Plugins are packages that can include apps, skills, and templates so a workflow is easier to enable as a unit.
- Skills are reusable playbooks or capabilities that shape how work gets done once the plumbing is there.
You will still hear people say “connector,” “integration,” or the older “plugin” meaning. For your mental model, separate three jobs:
| Word people say | Job it usually means | Office analogy |
|---|---|---|
| App / connector | Pipe to Drive, mail, Slack, CRM, etc. | Key to a locked filing cabinet |
| Plugin (package) | Installable workflow kit that can bundle apps + skills | Labeled starter kit for a role |
| Skill | How to run a repeating job shape | Checklist your best ops hire follows |
| Permission / approval | When ChatGPT must ask before acting | Two-person rule on wire transfers |
If a teammate says “install the sales plugin,” ask what apps it enables and whether any of those apps can write (send, update, delete). Packaging is convenient. Scopes decide risk.
What apps can do (search, sync, write, UI)
Not every app is equal. OpenAI’s apps documentation describes a range of capabilities. You do not need to memorize product marketing. You do need to know which capability you just enabled.
Search and reference
The most common “safe-ish” use: ChatGPT searches connected services and pulls relevant snippets into the conversation. Example: “Find last week’s pricing one-pager in Drive and summarize objections.” You still verify the file was the right version. You did not hand the model free rein to rewrite the source.
Deep research across sources
Some apps work with multi-source research flows and citations back to originals. That is useful for synthesis. It is still synthesis. Citations help you check; they do not replace checking.
Sync / indexed knowledge
Some apps can sync content so answers feel faster and more complete. Sync is a bigger data decision than “search this one folder when I ask.” It may index more of a corpus for speed. At work, sync settings are often admin-controlled for a reason. Ask who enabled sync, what corpus it covers, and what training/retention rules apply on your plan.
Write actions
Write actions change the outside world: create or update records, send mail or messages, move files, change calendar events, adjust sharing. OpenAI’s help content treats many of these as important actions: things with meaningful effect outside ChatGPT, sensitive exposure, or hard undo. That is the right mental category even if your UI labels shift.
Interactive UI
Some apps render rich in-chat experiences (cards, maps, playlists, design surfaces). Fun for demos. Still check what data left the chat into the third-party app’s terms.
How you actually use one in chat
Exact chrome moves by surface (web, desktop, mobile) and by week. The durable habits look like this:
- Discover: Open the Plugins Directory (or Settings → Apps on managed workspaces) and review what a listing includes: apps, skills, connection requirements, privacy notes.
- Connect: Complete the third-party login and OAuth scopes. Read scopes. “Read mail” is not the same as “send mail.” “See files you open” is not the same as “full Drive.”
- Invoke: Select the app from tools, or type
@followed by the app name in chat (for example:@Drive, find the Q3 hiring plan and list open roles). Naming the app reduces “model guessed the wrong tool” thrash. - Approve: When ChatGPT proposes an important action, read the approval card. Deny is a valid answer. “Allow once” is often smarter than “always allow” on day one.
- Verify: Open the source system. Confirm the file, message, or record matches what the chat claimed.
Voice mode, in OpenAI’s current FAQ language, has not been the place to lean on apps. Do high-stakes connector work in text where you can see the tool call and the approval UI.
The complexity ladder (use this before you connect more)
Every connector is a little more surface area: credentials, third-party privacy policy, accidental writes, shadow IT, and “the model summarized the wrong folder.” Climb only when the lower rung fails a real job.

| Rung | What you do | When it is enough | Main risk |
|---|---|---|---|
| 1. Plain chat | Type the problem; no external systems | Drafting, brainstorming, explaining with public knowledge | Hallucinated facts if you skip verification |
| 2. Upload | Attach a PDF, sheet, or screenshot for this thread | One-off review of a self-contained file | Sensitive data in a chat; wrong file version |
| 3. Read connector | Search/reference Drive, mail, Slack, etc. | Live context across many docs without zip dumps | Over-broad OAuth; wrong corpus; sync surprise |
| 4. Write actions | Send, create, update, delete, reschedule, share | Repetitive ops where human approval still runs | Hard-to-undo mistakes at scale |
| 5. Scheduled / agentic jobs | Recurring or multi-step work with less babysitting | Stable workflows with logs, owners, and rollback | Silent drift; zombie automations; spend |
Most people skip from 1 to 4 because demos look smooth. A better default at work: live on rungs 1 and 2 for a month, add one read connector for a narrow corpus, keep write off until the team has a written approval habit.
Write actions are a different sport
Reading a doc and summarizing it is reversible in the sense that the source still exists. Sending the wrong customer email, canceling the wrong meeting, or changing CRM ownership is a different class of problem. OpenAI’s app permission model (as documented for ChatGPT) includes options along this spectrum:
- Always ask: Confirm even before reads (high friction, high caution).
- Any changes: Auto-read OK; ask before anything that changes the outside world.
- Important actions (often default): Auto-read OK; ask before actions that matter, expose sensitive data, or are hard to undo.
- Never ask: Elevated risk; actions can fire without a prompt. Treat as an advanced setting, not a day-one default.
Examples that deserve a pause even when the model sounds confident: sending or editing email/Slack on your behalf, deleting content, purchases or refunds, moving or renaming cloud files, changing sharing or security settings, and pushing sensitive personal or financial details into an app. Saving a private draft is usually lower risk than sending that draft to a distribution list. Updating a cart is lower risk than placing the order. Use that intuition when the approval card appears.
App permissions do not grant new OAuth scopes. They only control when ChatGPT asks before using access you already gave. Disconnecting the app (or having an admin disable it) is how you remove access. Do not confuse “I set Always ask” with “the CRM key is gone.”
Work rules: IT policy before cool demos
Personal Plus on a credit card is not company approval. If your employer has a Business, Enterprise, or Edu workspace, use that for work data. Admins control whether apps are on, which roles can use them, and sometimes whether write actions exist at all.
Patterns from OpenAI’s workspace guidance (re-check before you freeze policy):
- Business: Apps may be enabled by default; owners still should review action controls and domains.
- Enterprise / Edu: Apps may be disabled by default until an owner enables specific ones, configures RBAC, and publishes settings.
- Action control: Admins can allow all actions, only reads, or a custom set, and decide how new actions behave when an app adds capabilities later.
- Domain restrictions: Limit which third-party accounts members can connect (for example, only company Google domains).
- Compliance logs: Enterprise customers may have app call logging through OpenAI’s compliance tooling. Personal plans do not replace that story.
If Security has not approved a connector for customer PII, payroll, health data, or regulated content, do not “just try it on a small file.” Small files teach bad habits. Use synthetic samples on personal plans for learning. Put real company data only on approved paths.
Training and data handling (high level)
Consumer plans and business plans are not the same privacy story. OpenAI’s public materials generally state that Business, Enterprise, and Edu workspace data is not used to train models by default, while consumer settings (Free, Plus, Pro, and similar personal workspaces) may use content to improve models unless you opt out under Data Controls. Apps can also share context with third parties under those apps’ terms. Read the approval screens. Turn off “Improve the model for everyone” on personal accounts if your risk tolerance is low, and still do not put forbidden work data into a personal chat because a toggle feels comforting.
Worked example: weekly status without a connector zoo
Scenario: You own a Friday status note for a product squad. Sources live in three places: a Drive folder of meeting notes, a Slack channel for blockers, and a sheet of ship dates.
Rung 2 path (often enough)
Export or download this week’s notes PDF, paste three Slack threads that matter, attach the sheet tab as CSV, and ask ChatGPT to draft a status with sections: shipped, at risk, asks. You review every claim against the files. No OAuth. No write. Slightly more manual. Fine for many teams.
Rung 3 path (read connector)
Connect Drive (and only Drive) with the narrowest scopes your admin allows. In chat:
@Drive Search only in folder "Squad status / 2026".
Find notes from the last 7 days.
Draft a Friday status with:
- Shipped
- At risk (with evidence quotes)
- Decisions needed
Do not invent metrics. If a number is missing, write "not in sources."
Do not send email or post to Slack.Then open the cited files yourself. If the draft invents a “94% on-time” claim that was never in the notes, fix your prompt and your verification habit before you ever enable write.
Rung 4 path (write, only after trust)
Maybe you allow posting a draft to a private channel after approval. Keep customer-facing send off the table until the team has a written rule: who reviews, what “done” means, how to recall a bad post. Prefer “Allow once” the first ten times.
Common mistakes
| Mistake | What goes wrong | Better habit |
|---|---|---|
| Connect everything day one | Huge blast radius; no muscle memory for approvals | One read-only app; one corpus; one month |
| Personal plan + work CRM | Shadow IT; training/retention mismatch; no admin logs | Company workspace or approved stack only |
| Trust summaries without opening sources | Wrong file version becomes “truth” | Click through citations; check dates |
| “Never ask” for convenience | Silent sends and updates | Default to Important actions or Any changes |
| Confuse upload with connector | People think access ends when the tab closes | Disconnect unused apps; review Settings → Apps |
| Skip admin for write tools | Policy surprise after an incident | IT/Security before CRM write or company-wide mail |
| Custom MCP apps with no owner | Forgotten credentials; orphan automations | Named owner, rotation plan, least privilege |
Custom apps and MCP (light map only)
Teams can build custom apps so ChatGPT talks to internal tools. OpenAI documents building with the Model Context Protocol (MCP) and packaging experiences with an Apps SDK. Workspace admins can allow or block custom apps. That path is real and useful for unique systems of record. It is also how an unreviewed internal server becomes a production dependency. If you are not the owner of the server, tokens, and logging story, do not be the person who “just connects it” for the whole org.
For most learners finishing this series, you do not need to build MCP servers yet. You need the judgment to say: plain chat first, upload second, approved read connector third, write only with eyes open.
Practice plan (one week, no zoo)
- Day 1: List three weekly jobs you do. Mark each as rung 1, 2, or “needs live systems.”
- Day 2: For one job, succeed with upload only. Time yourself. Note what still hurt.
- Day 3: Read your org’s AI / SaaS policy (or ask IT where it lives). Write one sentence: allowed data classes for ChatGPT.
- Day 4: If policy allows, connect one read-focused app on the correct workspace. Invoke it with
@. Keep write disabled or always-ask. - Day 5: Run the same job with the connector. Compare quality and time to Day 2. Keep a verification checklist of three source clicks.
- Day 6: Review Settings → Apps. Disconnect anything you do not use weekly.
- Day 7: Write a five-line team note: which app, which folder/corpus, read vs write, who owns approvals. Share it before anyone else copies your setup.
How this fits the rest of Learn ChatGPT
Part 6 taught you to treat uploads as data decisions. Part 7 teaches the same discipline for always-on pipes. Part 8 closes the series with privacy, work rules, and when ChatGPT is simply the wrong tool. After that, AMS continues into product maps and deeper tutorials (Work mode, Codex, Custom GPTs). Connectors show up again there with more surface-specific detail. The ladder stays the same.
Quick recap
- Connectors/apps are bridges to Drive, mail, Slack, CRM, and similar systems, not a guarantee of truth.
- Plugins package workflows; apps are the pipes; permissions decide when ChatGPT must ask.
- Type
@plus the app name when you want a specific tool in the loop. - Climb: plain chat → upload → read connector → write → scheduled jobs.
- Write actions are higher risk; keep approval friction until the team has habits and logs.
- At work, IT and workspace admin settings beat personal demos. Policy first.
- Next: Part 8 on privacy, work rules, and when not to use ChatGPT at all.
Sources
Product surfaces and admin labels change. Use these as starting points and verify live details before you write policy.
- OpenAI Help: Apps in ChatGPT (connectors/apps, plugins directory notes, permissions, write actions, workspace admin patterns)
- ChatGPT: Plugins feature overview (directory,
@invocation pattern, everyday tool examples) - OpenAI Help: Admin controls, security, and compliance for plugins and apps (enterprise/business controls, training notes for apps)
- OpenAI Help: Data Controls FAQ (consumer vs business training toggles)
- OpenAI: Enterprise privacy (business data handling overview)
- OpenAI: Apps SDK (building custom app experiences, MCP-backed tools)
- Model Context Protocol (standard for AI clients talking to external tools)
- Analytics Made Simple: Learn ChatGPT from scratch (series home)
- Analytics Made Simple: Learn (related learning paths)
