> ## Documentation Index
> Fetch the complete documentation index at: https://academy.pathfindr.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Setup ChatGPT Enterprise

> Roll out a secure, governed ChatGPT Enterprise workspace with minimal moving parts.

<Info>
  **Audience:** IT, Security, and Operations administrators.

  **Goal:** Launch a secure and governed ChatGPT Enterprise workspace that scales without creating policy debt.
</Info>

<Info>
  **Security baseline — quick view**

  * Verify domains → enable SSO → optionally enable automatic account creation → connect SCIM.
  * Keep RBAC simple with 3–4 groups mapped to lightweight custom roles.
  * Default sharing to invite-only or workspace-only; allowlist Actions domains before enabling.
  * Leave connectors off by default and grant per role or group.
  * Finalize retention, residency, and IP allowlists *before* pilots sign in.
  * Automate Compliance API exports to your eDiscovery or SIEM tooling.
</Info>

<Columns cols={3}>
  <Card title="Secure workspace access" icon="key" href="#secure-workspace-access">
    Verify domains, enforce SSO, connect SCIM, and nail baseline policies before launch.
  </Card>

  <Card title="Configure AI policy reminders" icon="file-shield" href="#configure-ai-policy-reminders">
    Set up recurring policy modals to keep organizational AI guidelines visible to users.
  </Card>

  <Card title="Design roles & guardrails" icon="user-shield" href="#design-roles-and-guardrails">
    Keep permissions predictable with simple groups and lightweight custom roles.
  </Card>
</Columns>

<Columns cols={3}>
  <Card title="Govern GPT publishing" icon="lock" href="#govern-gpt-publishing">
    Default to safe sharing, allowlist Actions domains, and gate connectors tightly.
  </Card>

  <Card title="Automate compliance & discovery" icon="shield-halved" href="#automate-compliance-and-discovery">
    Export audit data, integrate Purview, and keep regulated content discoverable.
  </Card>

  <Card title="Launch & onboard teams" icon="rocket" href="#launch-and-onboard-teams">
    Enforce endpoint protections, prep admins, and guide employees through rollout.
  </Card>
</Columns>

***

## Secure workspace access

Confirm identity, provisioning, and baseline workspace policies before inviting a broad audience.

<Steps>
  <Step title="Verify corporate domains" icon="globe">
    Go to **Manage workspace → Identity & provisioning**, add TXT records, and verify each domain. This is required for SSO, automatic account creation, and SCIM.
  </Step>

  <Step title="Enable SAML SSO" icon="key">
    Configure SSO with your IdP (Okta, Entra ID, Ping, etc.). If you use both ChatGPT Enterprise and the API platform, enable SSO on both.
  </Step>

  <Step title="(Optional) Automatic account creation" icon="user-plus">
    Allow anyone with a verified domain to join after authenticating via SSO. Helpful for phased, self-serve rollouts.
  </Step>

  <Step title="Provision with SCIM" icon="users">
    Sync users and groups from your IdP. Start with pilot groups, confirm mappings, then expand.
  </Step>

  <Step title="Harden workspace policies" icon="shield-check">
    Set IP allowlists, retention windows, and data residency. Enterprise data is excluded from model training by default—confirm it aligns to policy.
  </Step>

  <Step title="Configure AI policy modal" icon="file-shield">
    From **Workspace Settings → General**, customize the AI policy modal that reminds users of your organization's AI policies. The modal displays to users every 30 days or when updated.
  </Step>
</Steps>

<Info>
  **Quick start checklist**

  * Add TXT records and verify all corporate domains.
  * Turn on SAML SSO and test with a 3–5 person pilot group.
  * Decide whether automatic account creation is in scope for phase one.
  * Connect SCIM and sync pilot groups first.
  * Lock IP allowlists, retention, and data residency before rollout.
  * Configure the AI policy modal to remind users of organizational policies.
</Info>

***

## Configure AI policy reminders

Keep your organization's AI policies visible with the Enterprise AI Policy Modal.

### Enterprise AI Policy Modal

From **Workspace Settings → General**, admins and owners can customize a modal that reminds users of your organization's AI policies. In the **Workspace Policy** section, you can define specifics of your organization's AI policy.

<Info>
  The policy modal is displayed to users every 30 days, or when updated.
</Info>

<Info>
  **Source:** [What workspace settings can I control for my workspace?](https://help.openai.com/en/articles/8411955-what-workspace-settings-can-i-control-for-my-workspace)
</Info>

<Steps>
  <Step title="Navigate to workspace settings" icon="gear">
    Click your profile icon and select **Workspace settings**, then go to the **General** tab.
  </Step>

  <Step title="Define your AI policy" icon="file-pen">
    In the **Workspace Policy** section, enter your organization's AI policy text. Include key guidelines, acceptable use rules, and data handling requirements.
  </Step>

  <Step title="Save and deploy" icon="check">
    Save your changes. The modal will display to all users immediately and then every 30 days thereafter.
  </Step>
</Steps>

<Info>
  **Policy modal best practices**

  * Keep the policy concise and actionable—users should understand key rules at a glance.
  * Reference your full Acceptable Use Policy for detailed guidance.
  * Update the modal when policies change to trigger an immediate reminder to all users.
  * Coordinate with your legal and compliance teams to ensure the policy text aligns with organizational standards.
</Info>

***

## Design roles and guardrails

Keep permissions predictable without slowing pilots.

<Columns cols={2}>
  <Card title="Roles" icon="id-badge">
    Create lightweight custom roles that expose only what teams need (GPT authoring, connectors, browsing, agents, Records). Prefer group inheritance over one-off user grants.
  </Card>

  <Card title="Groups" icon="people-group">
    Map groups to how you deploy: default users, builders who create GPTs, technical teams with connectors, and higher-sensitivity functions (finance, legal).
  </Card>
</Columns>

| Group              | Role(s) assigned         | Connectors enabled                      |
| ------------------ | ------------------------ | --------------------------------------- |
| All employees      | Default employee         | none                                    |
| Builders           | Builder                  | none (sandbox only)                     |
| Engineering & data | Default + connector user | GitHub, Drive, SharePoint (allowlisted) |
| Finance & HR       | Default (no connectors)  | none                                    |
| Legal & compliance | Default                  | internal tooling only                   |
| Frontline & field  | Default (reduced)        | none                                    |
| Contractors        | Default (reduced)        | none                                    |

<Info>
  Connectors are off by default on enterprise plans. Turn on only the ones you need and scope use by role or group.
</Info>

<Info>
  **RBAC quick checks**

  * Create high-level groups and assign pilot members.
  * Build custom roles with only the required toggles.
  * Assign roles to groups (not individuals) and test with a sample user.
  * Keep sensitive connectors fenced to specific groups.
  * Schedule a quarterly RBAC and connector review.
</Info>

***

## Govern GPT publishing

Default to safe sharing, then widen scope as governance and review processes mature.

<Tabs>
  <Tab title="Sharing policy">
    Default to **invite-only** or **workspace-only** sharing. Hold off on external GPTs until guardrails and review processes are in place.
  </Tab>

  <Tab title="Actions domains">
    Maintain a domain allowlist for GPT Actions before enabling API calls. Start empty or with a narrow set of internal endpoints.
  </Tab>

  <Tab title="Connectors">
    Enable only the connectors required for early, well-scoped use cases—and gate them with roles and groups.
  </Tab>
</Tabs>

### Recommended publish flow

<img src="https://mintcdn.com/pathfindr/0Og7YOK8gX91P7mj/images/download.webp?fit=max&auto=format&n=0Og7YOK8gX91P7mj&q=85&s=842ee2d269a17b8d8d9e9ca4ab26aa2e" alt="download.webp" width="1851" height="212" data-path="images/download.webp" />

<Info>
  **Publishing guardrails**

  * Set default sharing to invite-only or workspace-only.
  * Create and maintain an Actions domain allowlist.
  * Gate each connector behind a business case plus RBAC scope.
  * Require review for GPTs that touch regulated or customer data.
  * Schedule a 90-day lifecycle review to archive unused GPTs.
</Info>

***

## Automate compliance and discovery

Turn on audit-grade logging, plan discovery workflows, and keep regulated content traceable.

### Compliance API exports

Export conversation metadata, GPT events, and Records for eDiscovery, DLP, or SIEM. Compliance endpoints respect IP allowlists—configure IP restrictions before issuing API keys. Use **User Analytics** for adoption trends and reserve the **Compliance API** for audit logging.

<Info>
  **Compliance API setup**

  * Issue a Compliance API key to your security or legal owner.
  * Apply IP allowlists to the compliance endpoints.
  * Automate daily exports to your SIEM or data lake.
</Info>

### Integrate Microsoft Purview

<Steps>
  <Step title="Pick your ingestion route" icon="inbox">
    Choose mailbox archiving via partner connectors or direct import to eDiscovery (Premium) review sets based on retention and legal needs.
  </Step>

  <Step title="Configure ingestion" icon="plug">
    In Purview, set up the connector or import job, then map custodians to the correct mailboxes or review sets.
  </Step>

  <Step title="Enable discovery & supervision" icon="magnifying-glass">
    Run Content Search or eDiscovery across imported data; enable Communication Compliance if communications monitoring is required.
  </Step>
</Steps>

***

## Launch and onboard teams

Deliver a great first-run experience while enforcing endpoint controls and change management.

### Enforce endpoint DLP for browsers

Deploy the Purview extension for Chrome on Windows. macOS enforcement does not require the extension. Roll out only after devices are onboarded to Endpoint DLP so policies take effect immediately.

### Admin playbook

Pilot with admins, security, and builders before broad access. Track adoption in User Analytics (export CSVs for deeper reviews) and share guardrails plus department-specific starter prompts ahead of go-live.

### Individual setup

<AccordionGroup>
  <Accordion title="Sign in with SSO" icon="right-to-bracket">
    Always use corporate SSO on web, desktop, and mobile. Bookmark the enterprise login URL so users avoid personal accounts.
  </Accordion>

  <Accordion title="Set Custom Instructions" icon="gear">
    Encourage role, tone, and compliance reminders in Custom Instructions. Avoid confidential data and review periodically.
  </Accordion>

  <Accordion title="Join the right groups" icon="users">
    Confirm each user is in the correct groups—permissions and GPT access inherit from group membership.
  </Accordion>

  <Accordion title="Use internal GPTs first" icon="robot">
    Promote GPTs your builders publish for internal use. Allow public GPTs only after controls are in place.
  </Accordion>

  <Accordion title="Handle files and data carefully" icon="file-circle-exclamation">
    Reinforce data-classification rules. If a connector or dataset isn't available to a group, the data shouldn't be pasted manually.
  </Accordion>
</AccordionGroup>

<Info>
  **Rollout quick checks**

  * Pilot with builders and security, and publish a small internal GPT library.
  * Share "Start here" guidance plus role-specific prompt packs.
  * Monitor weekly adoption and coach low-usage teams.
  * Review RBAC, connectors, and GPT inventory quarterly.
</Info>

***

## Appendix

<AccordionGroup>
  <Accordion title="Roles and capabilities" icon="id-badge">
    Roles (Owner, Admin, Member) and their default capabilities.
  </Accordion>

  <Accordion title="RBAC design" icon="user-shield">
    RBAC design (custom roles → groups → users inherit).
  </Accordion>

  <Accordion title="Group-level sharing" icon="share-nodes">
    Group-level sharing for GPTs and Projects.
  </Accordion>

  <Accordion title="Identity & provisioning" icon="key">
    Identity & provisioning (SSO, automatic account creation, SCIM).
  </Accordion>

  <Accordion title="Connector administration" icon="plug">
    Connector administration (off by default; enable per connector and group).
  </Accordion>

  <Accordion title="Compliance API logging" icon="file-shield">
    Compliance API logging for eDiscovery, DLP, SIEM ingestion.
  </Accordion>

  <Accordion title="User Analytics dashboards" icon="chart-line">
    User Analytics dashboards for adoption tracking.
  </Accordion>

  <Accordion title="Data retention & residency" icon="database">
    Data retention, data residency, and training exclusions.
  </Accordion>

  <Accordion title="IP allowlisting" icon="shield-check">
    Workspace and Compliance API IP allowlisting.
  </Accordion>

  <Accordion title="Microsoft Purview controls" icon="microsoft">
    Microsoft Purview controls (connectors/import, eDiscovery (Premium), Content Search, Chrome DLP extension).
  </Accordion>
</AccordionGroup>

## Self-check: First-time admin test

<Check>
  **Can a new admin follow this in 5 minutes?**

  * I can see the five focus areas above the fold and know where to start.
  * Each section begins with Steps/Tabs and ends with a quick checklist I can tick through.
  * I know the safe defaults (SSO on, connectors off, invite-only sharing, domain allowlist for Actions).
  * I have a clear path to auditability (Compliance API + Purview) and a 90-day review loop.
</Check>
