OpenAI announced the Admin plugin for ChatGPT Work and Codex on 25 August 2026. Workspace admins can review activity and credits, manage members and groups (seats), inspect effective permissions, and adjust usage limits or spending requests inside one conversation. The plugin tools Admin Console read/write actions that the admin already has. It does not widen access.

📑Table of Contents
  1. Four admin jobs the Admin plugin can run in chat
  2. How it stays inside existing roles
  3. Setup, then Slack or Teams routing
  4. Conversation admin vs a dedicated console
  5. FAQ
  6. Key takeaways

Why this is an admin-side control surface

Daily operations around seats, caps, and spend approvals often bounce across separate console screens. The plugin puts that work in chat. It is an admin-side control surface, not a substitute for consumer plan limits.


A practical order before you install

A practical order is:

  1. Enable in workspace settings
  2. Install from the Plugins directory
  3. Start with read-only usage checks
  4. Require pre-apply review for high-impact writes

Four admin jobs the Admin plugin can run in chat

What the four jobs cover

It does not create a new control plane. Instead, it maps existing ChatGPT Work and Codex admin tasks into a single conversation. OpenAI’s launch list includes four jobs.

  1. Adoption and usage: Review Work and Codex activity and credits, and find members or groups near their limits.
  2. Members and groups: Add or remove people, handle onboarding and offboarding, and update groups. Seat changes live here.
  3. Access and permissions: Inspect effective permissions, diagnose access failures, and control feature or model access by role or group.
  4. Usage limits and spending requests: Adjust limits for a member, group, or workspace, then approve or deny spend against current usage.

Demo: question to follow-up action

9to5Mac described a demo in which an admin asked ChatGPT Work about 30-day adoption and credit changes, built a chart, handled approvals, and shared a presentation to Slack. The point is the chain from question to confirmation to a follow-up action. For product context around Work itself, see What ChatGPT Work changes in long-running Codex desktop use.

Source:


How it stays inside existing roles

Existing role boundary

The plugin does not grant broader privileges. It maps each request to a supported read or write action inside the admin’s current role and policies, then returns a structured result. GadgetBond describes it as a conversational front door to existing controls, not a new privilege layer.


Pre-apply review

High-impact actions receive review before they take effect. Bulk seat changes, model-access changes, and workspace-wide limit edits all require that review step. iGeeksBlog also pairs structured results with pre-apply review.


The 45% internal figure

OpenAI’s internal IT note says deployed Work-agent workflows resolved about 45% of ticket volume.

How to read that number:

  • It is OpenAI’s own illustration, not an independent benchmark and not a target for your workspace.
  • GadgetBond treats it the same way.
  • IT Brief New Zealand (27 August 2026) quotes Kunal Malik, OpenAI’s Head of Global IT: the value is not only faster reporting, but turning a question into the next action—effective-permission checks, group updates, limit changes, or spend review.

Missing audit controls in the initial release

Pondero notes that IP allowlists and SSO event-log access are absent from the initial release. The official announcement does not list those controls. Regulated teams should keep a dedicated console available until they can verify audit coverage themselves.

Source:


Setup, then Slack or Teams routing

Enable and install

Setup follows the plugin directory, not a separate admin product.

  1. Enable plugins in ChatGPT workspace settings.
  2. Install from the Plugins directory in ChatGPT Work on web or desktop.
  3. Start with read-only checks, such as 30-day adoption and credits. Use pre-apply review for the first writes—one group limit change or one spending request.

Help Center constraints

OpenAI Help Center (“Plugins in ChatGPT and Codex”) says the App directory moved to the Plugin directory on 9 July 2026.

Installation and invocation still require more than simple directory visibility.

  • The directory is visible across ChatGPT plans, but install and invoke still depend on plan, workspace settings, role, supported surface, region, and included apps.
  • Enterprise and Edu disable plugins by default; Business enables them by default.
  • A greyed-out Connect control usually points to region, workspace policy, or plan.
  • “Disabled by admin” means an admin must enable the app.
  • Codex directory refreshes can take up to about six hours; restart or refresh plugin data if the listing lags.

Slack or Teams routing

Pending usage requests can route to approvers in Slack or Microsoft Teams. Qualifying feature-access requests can be auto-granted, with exceptions sent to a human. That routing is optional. If your existing approval workflow already lives in chat, the feature is useful; if it lives in tickets, conversation-side pre-apply review may be sufficient.


Related quota split

Quota split between ChatGPT and Codex is covered separately in How to split ChatGPT and Codex quotas for GitHub delegation.

Source:


Conversation admin vs a dedicated console

Conversation vs dedicated console

The conversation surface brings analysis, permissions, and spending together into one chat. Pondero contrasts this approach with Claude Enterprise and Gemini Enterprise Agent Platform, which maintain dedicated management consoles. Conversation is faster for same-day seat, limit, and spend work. It becomes the weaker surface if you need IP allowlists or SSO event logs immediately.


Comparison table

Dimension Admin plugin (Work / Codex) Dedicated admin console
Surface Question → confirm → action in one chat Analytics, access, and billing often split across screens
Permissions Stays inside existing roles; no extra privilege Follows the console permission model
Audit Structured results plus pre-apply review IP allowlists / SSO logs may be stronger on the console
Best fit Same-day seats, limits, and spend requests Regulated audit, network controls, SSO event review

Source:


Four go/no-go checks

Decide go/no-go with four checks.

  1. Does the operator already have Admin Console-equivalent rights? If not, chat cannot write either.
  2. Do spend or feature-access approvals need Slack or Teams? If yes, configure routing; if not, pre-apply review in chat may be enough.
  3. Do you need IP allowlists or SSO event logs in the conversation surface? Do not expect that in the initial release.
  4. On Enterprise or Edu, did you explicitly enable plugins? Visibility in the directory does not mean invoke is allowed.

Same-day checklist

Checklist:

  • Confirm 30-day adoption and credits with a read-only prompt
  • Run one low-risk write with pre-apply review
  • Configure Slack / Teams routing only if spend requests need it
  • Define auto-grant conditions and the human-exception path
  • Keep the dedicated console when audit requirements exceed chat

If you need to share reasoning on a PR, that is a different surface: Shared threads for Codex / ChatGPT Work. The plugin changes settings. Shared threads share a read-only snapshot of thinking.


FAQ

Privilege and install

Q. Does the Admin plugin widen admin privileges?

No. It maps requests to supported read/write actions inside existing roles and policies. OpenAI says it does not grant broader access.

Q. Where do I install it?

Enable it in workspace settings, then install from the Plugins directory in ChatGPT Work (web or desktop). Enterprise and Edu may keep plugins disabled by default. Check Help Center constraints first.


Codex-only teams, the 45% figure, and Slack

Q. Can Codex-only teams install it?

The announcement covers ChatGPT Work and Codex. The install path is the Plugins directory in ChatGPT Work. Codex directory updates can take up to about six hours.

Q. Should we treat 45% as a target?

No. That is OpenAI IT’s internal claim, not a guarantee for other workspaces. Judge the plugin on whether it turns a question into the next admin action.

Q. Is Slack or Teams required?

No. Routing pending usage requests to existing chat is an optional automation. Email or ticket approval can stay; use pre-apply review in the conversation instead.


Key takeaways

The Admin plugin brings ChatGPT Work and Codex seat, limit, and permission tasks into a single conversation. It is not a new privilege layer. It surfaces existing read/write rights and can pause high-impact changes for review.

Next actions

Do this next:

  1. Enable plugins in Workspace settings
  2. Install from the ChatGPT Work Plugins directory
  3. Confirm usage and credits with a read-only prompt
  4. Start writes with pre-apply review on a low-risk change
  5. Keep a dedicated console if IP allowlists, SSO logs, or other audit controls are missing from chat

How to use the 45% figure

Treat the 45% ticket figure as OpenAI’s internal example. Your go/no-go should follow existing permissions, approval routing, audit needs, and whether Enterprise or Edu has plugins enabled.

Related articles:

krona23

Author

krona23

Over 20 years in the IT industry, serving as Division Head and CTO at multiple companies running large-scale web services in Japan. Experienced across Windows, iOS, Android, and web development. Currently focused on AI-native transformation. At DevGENT, sharing practical guides on AI code editors, automation tools, and LLMs in three languages.

DevGENT about →

Leave a Reply

Trending

Discover more from DevGENT

Subscribe now to keep reading and get access to the full archive.

Continue reading