Once you enable @ChatGPT in Slack or Microsoft Teams, your ChatGPT seat count stops being your access control. Anyone in an enabled channel can tag the assistant, licensed or not, and it acts through a service account and company-managed app connections that an admin configured, with that account's permissions rather than the asker's. Before you switch it on, the decisions that matter are which channels get it, which shared connections it holds, how its credit spend is capped, and who answers for an action no individual's license triggered.
OpenAI announced the feature at DevDay on September 29, 2026, alongside Teams and shared tasks, listing both as available on Business and Enterprise plans. Trade coverage put the licensing point plainly: The Decoder reported that team members can reach it "in channels, threads, or direct messages without needing their own ChatGPT license," and Nerdschalk, quoting OpenAI's help text, wrote that "team members without an individual ChatGPT license can use @ChatGPT in enabled channels."
Who Can Act Through @ChatGPT, and With Whose Permissions?
@ChatGPT acts with the permissions of a shared service account, not those of the person who typed the mention. OpenAI's own setup guide for Slack and Teams says the assistant "uses configured connections and conversation context. It does not inherit a person's file, app, or private-channel access." The same page says surface plugins use "the configured company account's permissions, which may differ from participants' personal access."
That cuts both ways. The assistant cannot reach a private folder just because the asker can, which is the safe direction. It can also reach things the asker cannot, which is the direction your access reviews were never built for. A service account here is a non-human workspace identity that holds its own roles and connections; OpenAI's service-account documentation says these accounts "don't inherit the creator's permissions" and that their runs are attributed to the account itself in workspace analytics.
Think about what that means for a contractor in a shared channel. If your admin connected a company GitHub or Google Drive account to the @ChatGPT surface, the contractor's question gets answered with that account's reach. The workspace connections page states it directly: "A workspace connection may read sources you cannot open."
There is a partial check for write actions. OpenAI's user-side Slack guide describes a private approval card with Allow and Deny controls "when a request needs your authorization," and Nerdschalk quotes the help text saying the assistant "asks for your approval before taking action in a connected tool." The approval comes from the person asking. If that person has no ChatGPT license and no stake in the target system, nobody who owns the system has signed off. We covered why most approval gates end up rubber-stamped in our human-in-the-loop buyer's guide.
What Do Team Tasks Run, and What Keeps Running After You Stop Them?
Team Tasks are scheduled or event-triggered jobs that run in OpenAI's cloud on a team's service account, with no person logged in. The Teams admin guide gives an example trigger: "When a message arrives in the launch Slack channel, summarize launch progress." Nerdschalk quotes the help page confirming a task "runs in the cloud on the team's service account" and does not use anyone's memories or chat history.
Four lines in that admin guide deserve a place in your rollout notes:
- Stopping is not immediate. "Pausing prevents future scheduled and event-triggered runs. Neither pausing nor deleting a task should be relied on to interrupt an active run." Your kill switch for a misbehaving task is revoking the connection, not pausing the task.
- Access is all or nothing inside a team. "New members can see all earlier runs and generated files; individual tasks and runs cannot have separate access restrictions." Adding someone to a team for one task gives them the history of every task.
- Departures break things. "Owners must transfer ownership before leaving. Connections the new owner cannot access become disabled for the entire team." Offboarding a team owner without a handover can silently stop a production digest.
- Two permissions govern creation. Workspace owners control "Create teams" and "Create and manage team automations." Both should start restricted.
If you have watched what happens when an agent task runs under a broad default role, Snowflake's agent tasks running as all of a user's roles is the closest precedent. The fix there was least privilege on the identity, and the same applies here.
How Is @ChatGPT Usage Billed When Nobody Holds a Seat?
Usage from channel requests and Team Tasks draws on shared workspace credits, so cost moves from a seat line you can count to a pool you have to cap. OpenAI's ChatGPT Work usage and cost page describes a "shared pool of workspace credits" and three controls: per-user monthly limits with workspace and group defaults, a workspace overage limit, and usage alerts that "don't stop spending." When credits run out and overages are not allowed, "eligible features can pause until credits become available." When a user sits in several groups, "the highest applicable group limit applies."
For tasks specifically, the Teams guide says "Team Tasks use workspace credits. Team spending limits are separate from user limits." That separation is the point to plan around. A per-user cap does nothing about a task that fires on every message in a busy channel, because the task's spend is attributed to the team's service account, not to whoever posted.
OpenAI also says on the same cost page that "role-based estimates support planning but aren't fixed per-user prices," so there is no published per-request price to model against. You will learn your burn rate from the first month of usage, which is why the caps have to exist before the first month starts.
Microsoft prices the comparable case explicitly. Under Microsoft's pay-as-you-go meter, Copilot Chat agent usage is billed to an Azure subscription at "$0.01 per message." A single answer can count as several billable messages (Copilot Studio rate guides list 2 for a generative answer and 10 more for tenant graph grounding), but the unit rate is published and you can model it. We traced the same seat-to-consumption shift in Microsoft's Autopilot billing change and in our guide to capping agentic consumption.
Where the Controls Stop Short
The channel scoping is coarser than it looks. The setup guide lets a Slack admin restrict @ChatGPT to "Selected channels only," but adds that "Channel restrictions do not block direct messages." For Teams, user assignment is handled in Microsoft's admin tools rather than in ChatGPT. Plan on one surface per Slack workspace: the guide says to "configure one surface per Slack workspace, including each connected workspace in Enterprise Grid," so a single connection set serves every enabled channel in that workspace.
Audit is available but conditional. The Teams guide points admins to the Compliance API and warns them to "confirm which team, task, and connection records are available before relying on them for an audit." The connections page, as fetched, gives setup and testing guidance but does not describe an audit log of which participant triggered which connected action. If your SOX or SOC 2 evidence depends on tying an action to a named human, test that before go-live. Our agent audit logging guide lists the event set you will want.
Plan scope is not fully settled in OpenAI's own pages. DevDay roundups list @ChatGPT and shared tasks for Business and Enterprise, while OpenAI's DevDay 2026 feature page files Slack and Teams under its Enterprise documentation. The service-account page also says those accounts are "available only on pay-as-you-go plans." Confirm with your account team which of these applies to your contract before you write an architecture around it.
Shared replies also carry a disclosure cost. The setup guide notes that "shared replies are visible to conversation participants." In a channel that includes guests, the assistant can read from a company account and post the answer where every participant can see it. Security Online's DevDay write-up highlights OpenAI's promise not to train on confidential enterprise documents; that covers training, and it does nothing to stop the assistant posting a document's contents to a channel.
The Case for Turning It On Anyway
The strongest argument for @ChatGPT in channels is that it moves AI usage onto an identity you manage. Today, unlicensed staff paste company data into personal accounts. A service account with named connections, a spend cap and Compliance API records is easier to govern than that. It also removes the per-user credential sprawl that comes with everyone connecting their own Drive or GitHub, which is the risk OpenAI's connection model is designed to centralize.
It works only if you treat the service account as you would any privileged non-human identity. That means a named owner, a narrow scope, a rotation and review cadence, and a revocation path that someone has actually exercised. Our comparison of Okta, Entra Agent ID and SailPoint covers the tooling, and Claude Tag's channel-read rollout is the earlier version of the same lesson: in a channel assistant, the channel invite is the access grant.
What to Do Before You Enable It
This Week:
- Pull the list of every app connection your admins plan to attach to the @ChatGPT surface and, for each, write down what that account can read and write that a typical channel member cannot. If the answer is "a lot," narrow the account or drop the connection.
- Set the Slack surface to "Selected channels only" and pick a pilot of two or three internal channels with no guests or Slack Connect members.
- Restrict "Create teams" and "Create and manage team automations" to a named group, so Team Tasks start with a small owner list.
This Month:
- Set a team spending limit and a workspace overage limit before the first Team Task goes live, and configure an alert at 50% of the monthly budget. Alerts do not stop spend, so the limit is the control.
- Add Team Task ownership transfer to your offboarding checklist, and test that revoking a workspace connection actually stops a running task.
- Ask your security team to pull Compliance API records for a test task and confirm they show the trigger, the connection used and the requesting user.
Before Renewal:
- Get written confirmation from OpenAI of which plan tiers include @ChatGPT, Team Tasks and service accounts, and how credit consumption from unlicensed users is priced against your commitment.
- Compare that against Microsoft's metered per-message rate for Copilot Chat agent use if you run both, counting how many billable messages a typical answer consumes, so the renewal conversation starts from a cost per request rather than a seat count.
If you already run OpenAI's Dots beta or the ChatGPT Enterprise workspace, the same admins will own this, so put the connection list in front of them first.
Continue Reading
- OpenAI's Dots Beta Skips Data Residency and Your OTel Collector
- Claude Reads the Whole Channel Now. Invites Are IAM.
- Agent Audit Logging: Platform Logs Miss the Decision You Must Prove
- Microsoft's New Copilot Bills Autopilot Outside the $30 Seat
- Okta vs Entra Agent ID vs SailPoint: Two Issue, One Governs
- SalesBleed Turned a Public Web Form Into an Agentforce Data Leak
