ChatGPT Apps in 2026: Choose Connections and Control Permissions
Choose ChatGPT apps for live search, workspace sync and supported actions. Understand plugins, provider access, approvals and data handling before connecting your tools.
15 min read · estimateM.R. ValeOfficial-source-backed guide · no hands-on test
Connect for a specific task, then check the chosen app and connected account. This original conceptual artwork does not depict the ChatGPT interface, an executed action or a guarantee of access.
In this guide +
Your project brief is in Drive, the latest decision is in Slack, and the answer you need is buried in both. A connected app can spare you the copy-and-paste work. The harder question is whether you have connected the right account, requested enough context and allowed more actions than the task requires.
A sensible first connection solves one recurring problem: find the approved brief, explain a repository or prepare a meeting note. A directory full of installed tools is not a workflow. Start with the decision you need to make, then choose the smallest useful connection.
This guide reviews current official documentation on 9 October 2026. No provider account was connected or app action executed for the article. The prompts, project scenario and review checklist are original proposed examples, not successful product outputs. Our methodology explains the distinction between source review and hands-on evidence.
Apps, plugins and connectors: what the current names mean
OpenAI currently uses app for a connection to an external service and plugin for a package that can bring apps, skills and other capabilities together. A plugin can include several apps or only reusable instructions. Current documentation points users to Settings > Plugins, while some versions and administration views still show Apps. Follow the label available on your account, then inspect what the package contains.
This matters when searching for “ChatGPT plugins” or following an older connector tutorial. The name alone does not tell you whether a tool reads a service, writes to it, contributes instructions or offers an interactive view. Nor does an installed package prove that its service connection is authorized. Treat each included app as a separate capability to inspect.
Do not import assumptions from Claude Code plugin installation. Both products use the word plugin, but their setup, scopes and runtime behavior differ. Likewise, an MCP connection describes a way to expose tools; it does not establish that a particular ChatGPT app supports every tool or that your account may run it.
There is another similarly named feature: signing into a third-party site with ChatGPT and choosing to use your plan for eligible AI requests there. That does not by itself give the site your ChatGPT conversations or memories. It is separate from connecting Drive or Slack inside ChatGPT, and the external service can still charge separately.
Choose live search, indexed sync or an external action
Separate the information you need from what you want to change. Finding a file, searching an indexed knowledge source and updating a source document are different jobs. An app may support one, several or none of these on your current plan and surface. The practical choice is the capability that completes your task with the least unnecessary access.
Choose the connection mode by the result you needSwipe or scroll horizontally to compare every column.
Task
Useful starting point
Check before relying on it
Find one named brief or recent thread
Supported live search/reference
Correct account, content retrieval and source link
Indexed scope, member permissions and refresh state
Produce a researched report from several permitted sources
Supported deep research read access
Sources actually used and claims supported
Create or update a document or other record
A specifically supported write action
Exact target, enabled action, permission and actual result
Run a repeatable process with failure handling
A separately designed automation
Triggers, recovery, ownership and operating evidence
Live access retrieves permitted information when needed; it does not create a personal synced index. Current administrator-managed sync is configured by eligible workspace administrators. Individual app sync is no longer available. Supported organizational sources can include Drive, SharePoint and Teams, subject to workspace eligibility and region. A personal Drive connection therefore does not become a searchable organization-wide index.
Choose the supported capability for the task. Search, sync and direct actions have different requirements; an indexed source selection is not a direct-action scope. Original AI Tech Bench conceptual diagram, not a UI capture.
Indexed content is also not a live-state guarantee. New documents and permission changes can take time to appear. When an answer depends on the latest approval or a newly revised file, open the cited source and inspect its current state rather than inferring freshness from a confident summary.
For a longer research task, supported connected apps can supply read sources to deep research. OpenAI documents that deep research uses read actions, not app writes. A report that recommends changing a document has not thereby changed it. Review its evidence before starting a separate editing request.
Five useful connections, chosen by the work they support
These examples are a task map, not a ranked list or a claim that every reader has the same catalogue. Check the app description, supported actions and provider requirements available to your account. Current official documentation supports the following starting points.
Google Drive: briefs, documents and spreadsheets
Choose Drive when the source of truth is a file your Google account can already access. Current Docs, Sheets and Slides actions are available through the Drive app. Depending on permissions and workspace settings, it can find or reference content and perform supported file actions. Administrator-managed indexing is a separate setup; an individual connection is live only.
For a brief, ask for the source file before asking for a summary. For a spreadsheet, specify the sheet and cells, units and whether you want an explanation or an edit. “Fix the budget” is too broad: a useful request identifies the affected range and asks for a proposed change before a write. Keep the original open so you can compare the actual result.
Slack: decisions that have not reached the document
Slack can search messages and prepare summaries from conversations you may access. Some enabled Slack actions include reminders, uploads, joining channels and profile changes. Keyword search and semantic search are not universally interchangeable: semantic search depends on supported Slack tiers and Slack AI Search. Provider quotas can still affect the request.
A recent thread can explain why a decision changed, but recency is not approval. Ask for the relevant thread links, the speaker and unresolved disagreement. Do not merge a proposal into a settled decision simply because several people discussed it. Keep a channel search narrow enough that unrelated customer or employee conversations are not collected for a simple status note.
Notion: a bounded set of knowledge pages
The current Notion app guide supports searching and reading authorized pages. It does not support individual sync. Page access depends on the account, workspace and content authorized for the connection. Do not assume that reading a page means the app can also edit, publish or reorganize it.
Name the project and page, and ask which section supports the answer. If Notion is your maintained operating manual, compare the returned claim with that page. If the page is an old brainstorming note, say so in the request. A tool cannot make an obsolete source authoritative merely by citing it.
GitHub: understand permitted code and documentation
The documented GitHub app retrieves permitted repository content on demand, including code and README files. It does not create a GitHub synced index. Repository selection and organization approval can affect access, and availability differs between standard chat, deep research and agent experiences.
Use it to locate a handler, trace a documented configuration or review a proposed change against the repository. Request file paths and relevant symbols so you can inspect the evidence. Repository research access is not proof that a code change was applied or a test ran. If you need an execution environment, that is a separate coding workflow with its own controls.
Outlook: messages, contacts and calendar context
Outlook Email and Outlook Calendar are distinct apps. The current Email guide covers message retrieval, people lookup and enabled contact-management actions; the Calendar app covers supported event actions. A shared mailbox or calendar requires existing Microsoft access. Entra administrator consent and ChatGPT workspace action settings are separate checks.
Specify the intended mailbox or calendar rather than relying on an ambiguous “my account.” Preparing text for a reply is different from sending it; reading an event is different from changing attendees. Before any supported write, review the exact recipient, object and consequence. Do not infer a send capability from a prompt example about drafting a reply.
Understand the access checks before connecting an account
For a useful connection, three questions need distinct answers: what the provider identity can access, what the workspace and app make available, and when ChatGPT must ask before using an action. Other runtime and security controls can also apply. These are separate checks, not a fixed installation sequence or a promise that every request will succeed.
Three separate checks help explain an app action, not every possible control or a fixed execution sequence. Confirmation policy does not expand provider access or override workspace restrictions. Original AI Tech Bench conceptual diagram.
At the provider, choose the account that already has the required file, channel or repository access. Review requested services and scopes. If a Google flow requires all scopes for the selected apps, deliberately leaving required boxes unchecked can break the connection. Choose fewer apps or ask an administrator to disable unwanted actions instead of treating a partially approved connection as a reliable restriction.
In a managed workspace, enabling the plugin and enabling its included app can be separate decisions. Role access controls who can use the app; action controls determine which supported reads or writes are available. Where a future-action policy exists, disabling new actions does not disable actions already enabled. Review the current enabled set as well as future defaults.
For ChatGPT approvals, options can include Always ask, Allow read actions, Allow low-risk actions and an eligible app-specific Allow all actions. Standard account-wide and workspace-wide selectors do not offer Allow all actions. A more permissive setting does not override source permissions, workspace restrictions or safety controls. Some actions can still require review or be denied.
For a first pilot, our recommendation is to allow only the access you can explain and use a review setting appropriate to the task. This is an editorial rollout choice, not a universal product default. A draft brief often needs no write capability. A working document update needs an exact target and a practical way to compare or undo the change.
Start with a small project-brief exercise
The following is an unexecuted exercise for a fictional project called Harbor. Use your own authorized, non-sensitive sample documents if you try it. The intended result is a short brief whose decisions can be checked, not an automatic message to colleagues. Begin with one provider, two known source files and no external writes.
1. Establish the source set
Confirm that you can open both files in the provider. Record which account and workspace should be used. Create a harmless sample with clearly different approved and proposed dates so an incorrect merge is easy to notice. Choose a read request that asks for the file links and evidence before a summary.
Proposed read-only source request
Use the connected Google Drive account that contains my Harbor sample project. Find the files titled “Harbor approved brief” and “Harbor change proposal”. Return their exact titles, links and any available modification information. Confirm whether you retrieved their contents. Do not create, edit, share or send anything. If either file is missing or unreadable, say which one instead of guessing.
Open the returned links yourself. A matching filename is insufficient; a different file with the same title can produce a polished but irrelevant answer. If the contents cannot be retrieved, use a supported export only when you are allowed to share it. Do not present the file listing as proof that its paragraphs were read.
2. Ask for a brief that preserves uncertainty
Proposed evidence-first brief
Using only the two verified Harbor files, write a short internal brief with: approved scope, approved date, proposed changes and unresolved questions. For each important statement, name the file and relevant section or excerpt and include its link. Keep proposals separate from decisions. If the files conflict, show both positions without choosing an authority that the files do not establish. Do not add facts from memory, the web or another app. Do not write the brief to a provider or send it.
A useful result makes review easier. Compare the date, owner and scope with the underlying passages. Check that “proposed change” has not become “approved change,” and that an unanswered question remains unanswered. A source link helps you verify the claim; it does not guarantee that the summary interpreted the source correctly.
If you genuinely need Slack context next, make that a separate, bounded search for the named project and date range. Ask what the thread adds or contradicts. Do not give a message the authority of the approved brief unless the project process actually makes that person or channel authoritative. This extra step earns context, not permission to collect every conversation.
3. Make any write a separate decision
Proposed document-write review request
Prepare a proposed update for the existing Harbor review note. Show the exact target document link, the section to change, the current text and proposed replacement. Preserve unrelated sections. Do not change sharing, overwrite the source briefs or send messages. Wait for my review before any write, and report clearly if the connected app cannot perform that action.
This prompt expresses the intended boundary; it is not an access-control mechanism. Keep the action settings and provider permissions consistent with it. If you later approve a supported edit, open the destination and compare the changed section with the proposal. A model saying “done” is not sufficient evidence of a saved write.
For recurring automation, a conversation-only pilot is not the whole system. You need triggers, failure handling, ownership and evidence that the process operates as intended. Our n8n workflow guide explains those design decisions without claiming that its illustrative workflow was executed.
Review data handling, cost and risky inputs
Check what leaves your provider and what reaches another app. A connection can supply context to ChatGPT, while an app request can pass relevant conversation information to the external service. Read the provider terms as well as ChatGPT controls. A public source, an internal draft and a regulated customer record should not be treated as interchangeable input.
Model-training controls are separate from Memory and retention. OpenAI documents that turning off Improve the model for everyone prevents new eligible conversations from being used for training; it does not delete saved history. Business, Enterprise and Edu connected-app information is not used for model training by default. Review your workspace agreement and controls rather than inferring confidentiality from a plan name.
Google app data has a specific policy: direct connected data is subject to restrictions with exceptions that include feedback, manually copied or uploaded content and content appearing in responses. Turning model improvement off adds the documented exclusion for conversation content. Do not flatten that policy into “all connected Google data can never be used” or assume a pasted file follows exactly the same path.
Memory can retain eligible context separately from the original conversation. Turning Memory off does not delete existing chats, and deleting a chat does not necessarily remove a separately saved memory. Library, project and conversation copies also have distinct retention. Review the objects you actually created; disconnection is not a deletion request.
Treat instructions inside retrieved files, messages and webpages as untrusted source material. A document telling an assistant to forward private files should not supply permission to do so. OpenAI documents remaining prompt-injection risks for connected capabilities and recommends least privilege and validation for plugin developers. Review an unexpected destination or extra tool request instead of approving it to finish faster.
For custom tools, the server must enforce its own authorization and validate inputs. A well-worded instruction does not replace those controls. For cloud tasks, also check the actual execution surface: local restrictions do not automatically become cloud restrictions. That is a reason to review the workflow where it runs, not to assume the desktop settings cover every environment.
Budget for the capability you will use. Directory discovery is not a promise that an app or extension is included on every plan; some capabilities need an eligible higher tier. App activity can use ChatGPT feature allowances and provider quotas, while the external service can have its own subscription. Confirm those requirements before upgrading for one task. No universal per-request price or measured saving is claimed here.
When the connection does not work, inspect the right layer
Repeatedly reconnecting an app can be tempting, but it does not repair an unsupported action, an inaccessible file or an unavailable interface. Record the failure and inspect the corresponding layer. Do not include credentials, complete private documents or authorization headers in a support screenshot.
Match the symptom to the next useful checkSwipe or scroll horizontally to compare every column.
Symptom
Inspect first
Useful next step
Listed or installed, but unavailable
Plan, surface, workspace role and included app
Read the specific availability message; ask the appropriate admin
Connected, but a file or channel is missing
Selected account and provider access
Open the source yourself; check authorization and account choice
Filename found, content unavailable
Supported format and actual retrieval
Use an authorized supported export or state the limitation
Summary uses an obsolete document
Source identity, version and index refresh
Open the source; compare current content and approved status
Read works, write fails
Supported action, scopes and enabled actions
Review provider/admin approval; do not infer edit access
An approval prompt appears unexpectedly
Account-specific policy and sensitive action
Review the proposed effect; saved defaults may not cover it
Timeout during a write
Actual destination state
Establish whether it saved before repeating the action
Quota or limit reached
ChatGPT feature allowance and provider response
Check the relevant limit/reset; avoid blind retries
For a failed write, inspect the destination before retrying. An uncertain response can leave you unsure whether the first request completed. Duplicating a reminder, file or record is an avoidable second problem. The product-specific recovery path matters; this is a proposed operating practice, not a claim that every app provides an undo or idempotency feature.
Keep a small connection record: the task it serves, provider account, permitted data, supported actions, workspace owner and review date. This makes troubleshooting and later removal easier. Our MCP server guide applies the same task-and-permission reasoning to a different integration environment; its installation advice should not be copied into ChatGPT setup.
Keep only the connections you can justify
Review a connection when its purpose changes, you change workspaces or a new action becomes available. Prefer a narrow useful set over an unattended collection. If an app only needed to help with a short project, decide whether future access is still warranted.
To stop future access through an individual account, use the app or plugin settings and the supported Disconnect control; review warnings before uninstalling a package. Another connected account or administrator-managed source can remain active. Changing approval preferences does not revoke provider access. If you also need to remove retained information, review chats, files, memories and provider copies separately.
A practical first step is one harmless read request against a source you know. Verify the file identity and the claims in the answer. Only then consider another source or a clearly specified write. Our AI Productivity Tools topic groups this kind of task-led decision; installing more integrations is useful only when the work becomes clearer and the remaining controls are understood.
Sources & further reading
Product facts are checked against the sources below. Access dates describe research, not hands-on testing.
Apps connect external services for supported search, reference, interactive experiences and actions. Availability depends on plan, region, workspace, role, model and interface. App permissions do not expand provider access.
Current plugins package skills, apps, templates and extensions; some contain no connected app. Directory availability is distinct from individual capability eligibility. Installation does not complete provider authorization or administrator-managed sync.
Select the provider account with existing source access; supported multiple-account, reconnect and disconnect controls vary. Google selected apps require all requested scopes. Disconnecting stops future access through that account, not other connections or retained conversations/memories.
Approval options differ by account/app/workspace. Standard global selectors do not offer Allow all actions. Approval does not override provider authorization, workspace/action policies or safety controls. Sync content selection and live action restrictions are separate.
Plugin availability, app/role access, enabled actions, new-action policy, approval settings and provider consent are distinct. New-action policies do not remove existing enabled actions. Google Docs/Sheets/Slides are managed through the Drive app; configurable action controls are not universal.
Capability chain includes plugin availability, skills, MCP/app access, actions/permissions, external service authorization and runtime permissions. Apps/MCP servers describe connected integrations in this guide; provider access and runtime controls remain separate.
Connected-account scopes, app/plugin availability and execution controls remain relevant to cloud tasks. Local restrictions do not automatically carry over to cloud execution; review controls for the actual execution surface.
Only eligible workspace administrators configure supported sync; individually authorized sync is unavailable. Source scope/member permissions and refreshed index state constrain retrieval. Live actions can require a separate account connection.
Drive provides supported Docs/Sheets/Slides access and permitted actions. Personal/individual connection is live only. Workspace/admin Google scopes, account access and action settings constrain use; administrator indexing has separate setup and refresh timing.
Slack app can search permitted messages and make briefs; enabled actions include supported reminders, file uploads, joining channels or profile updates. Semantic search depends on supported Slack tiers/AI Search; app/API quotas still apply.
Current Notion guidance supports search/read of authorized pages and no individual sync. Provider-account/workspace/page authorization determines access; no blanket Notion editing or publishing capability is inferred.
Supported GitHub app retrieves permitted repository content on demand; no GitHub sync/index is created. Repository selection and organization approval matter. Standard app research access is distinct from other coding workflows.
Eligible connected sources can be used in deep research, subject to existing permissions. Deep research uses app read actions, not write actions; availability and limits depend on plan/region/workspace/provider.
Turning off Improve the model for everyone excludes new eligible conversations/tasks from model training but does not remove history. Memory, retention and training controls are distinct; feedback can have separate use consequences.
Direct connected Google data has specific model-training restrictions and exceptions for feedback, manual copying/uploading and response content; turning model improvement off provides broader exclusion. Memory/disconnection/retained conversations and administrator indexes require separate review.
Memory can use eligible information from chats/files/apps; turning it off does not delete original chats. Deleting a chat does not necessarily delete separately saved memories. Controls vary by account/workspace.
Chats, Library files, project/GPT files and saved memories are separate retained objects. Deleting a chat does not delete a Library file; deletion has documented timing and security/legal exceptions.
Connected/network features can have prompt-injection risk not fully eliminated by existing mitigations; an Elevated Risk label calls for review, not a guarantee or universal safety assessment.
Developer guidance recommends least privilege, minimal data, explicit consent, server-side input/scope validation and review of irreversible writes. Prompt text and confirmation do not replace server authorization.
Connected does not prove usable on the current model/surface, file listing does not prove content retrieval, and read access does not imply write. Match issue to provider access, workspace policies, sync state, approved action or quota; avoid repeated blind reconnection.
Sign in with ChatGPT and optional participating-app plan usage are distinct from connecting services inside ChatGPT. Plan usage alone does not grant conversations/Memory/API-key access; external subscriptions and usage limits remain separate.
Plugin directory discovery is available, but individual apps/templates/capabilities may require eligible higher plans. API usage is independently billed and directory listing alone is not a purchase recommendation.
Build an n8n AI workflow with clear data boundaries, validated output, identified human approval and safe recovery. Learn when to use an agent, what Cloud and self-hosting cost, and what to verify before production.
Choose an MCP server for the work you need: library docs, repository context, browser inspection, design, project knowledge, incidents or backend development. Compare access, setup and privacy before connecting.
Choose a Claude Code plugin for a real task, install it at the right scope, review its permissions, and manage configuration, updates and removal without confusing installed files with a loaded session.