OpenAI announced the Admin plugin for ChatGPT Work and Codex on 25 August 2026. Workspace admins can review activity and credits, manage members and groups (seats), inspect effective permissions, and adjust usage limits or spending requests inside one conversation. The plugin tools Admin Console read/write actions that the admin already has. It does not widen access.
📑Table of Contents
Why this is an admin-side control surface
Daily operations around seats, caps, and spend approvals often bounce across separate console screens. The plugin puts that work in chat. It is an admin-side control surface, not a substitute for consumer plan limits.
A practical order before you install
A practical order is:
- Enable in workspace settings
- Install from the Plugins directory
- Start with read-only usage checks
- Require pre-apply review for high-impact writes
Four admin jobs the Admin plugin can run in chat
What the four jobs cover
It does not create a new control plane. Instead, it maps existing ChatGPT Work and Codex admin tasks into a single conversation. OpenAI’s launch list includes four jobs.
- Adoption and usage: Review Work and Codex activity and credits, and find members or groups near their limits.
- Members and groups: Add or remove people, handle onboarding and offboarding, and update groups. Seat changes live here.
- Access and permissions: Inspect effective permissions, diagnose access failures, and control feature or model access by role or group.
- Usage limits and spending requests: Adjust limits for a member, group, or workspace, then approve or deny spend against current usage.
Demo: question to follow-up action
9to5Mac described a demo in which an admin asked ChatGPT Work about 30-day adoption and credit changes, built a chart, handled approvals, and shared a presentation to Slack. The point is the chain from question to confirmation to a follow-up action. For product context around Work itself, see What ChatGPT Work changes in long-running Codex desktop use.
Source:
- OpenAI, “Introducing the Admin plugin for ChatGPT Work and Codex” (August 2026)
- 9to5Mac (August 2026)
How it stays inside existing roles
Existing role boundary
The plugin does not grant broader privileges. It maps each request to a supported read or write action inside the admin’s current role and policies, then returns a structured result. GadgetBond describes it as a conversational front door to existing controls, not a new privilege layer.
Pre-apply review
High-impact actions receive review before they take effect. Bulk seat changes, model-access changes, and workspace-wide limit edits all require that review step. iGeeksBlog also pairs structured results with pre-apply review.
The 45% internal figure
OpenAI’s internal IT note says deployed Work-agent workflows resolved about 45% of ticket volume.
How to read that number:
- It is OpenAI’s own illustration, not an independent benchmark and not a target for your workspace.
- GadgetBond treats it the same way.
- IT Brief New Zealand (27 August 2026) quotes Kunal Malik, OpenAI’s Head of Global IT: the value is not only faster reporting, but turning a question into the next action—effective-permission checks, group updates, limit changes, or spend review.
Missing audit controls in the initial release
Pondero notes that IP allowlists and SSO event-log access are absent from the initial release. The official announcement does not list those controls. Regulated teams should keep a dedicated console available until they can verify audit coverage themselves.
Source:
- OpenAI blog
- GadgetBond
- iGeeksBlog
- Pondero (August 2026)
Setup, then Slack or Teams routing
Enable and install
Setup follows the plugin directory, not a separate admin product.
- Enable plugins in ChatGPT workspace settings.
- Install from the Plugins directory in ChatGPT Work on web or desktop.
- Start with read-only checks, such as 30-day adoption and credits. Use pre-apply review for the first writes—one group limit change or one spending request.
Help Center constraints
OpenAI Help Center (“Plugins in ChatGPT and Codex”) says the App directory moved to the Plugin directory on 9 July 2026.
Installation and invocation still require more than simple directory visibility.
- The directory is visible across ChatGPT plans, but install and invoke still depend on plan, workspace settings, role, supported surface, region, and included apps.
- Enterprise and Edu disable plugins by default; Business enables them by default.
- A greyed-out Connect control usually points to region, workspace policy, or plan.
- “Disabled by admin” means an admin must enable the app.
- Codex directory refreshes can take up to about six hours; restart or refresh plugin data if the listing lags.
Slack or Teams routing
Pending usage requests can route to approvers in Slack or Microsoft Teams. Qualifying feature-access requests can be auto-granted, with exceptions sent to a human. That routing is optional. If your existing approval workflow already lives in chat, the feature is useful; if it lives in tickets, conversation-side pre-apply review may be sufficient.
Related quota split
Quota split between ChatGPT and Codex is covered separately in How to split ChatGPT and Codex quotas for GitHub delegation.
Source:
- OpenAI blog
- OpenAI Help Center, “Plugins in ChatGPT and Codex” (as of August 2026)
Conversation admin vs a dedicated console
Conversation vs dedicated console
The conversation surface brings analysis, permissions, and spending together into one chat. Pondero contrasts this approach with Claude Enterprise and Gemini Enterprise Agent Platform, which maintain dedicated management consoles. Conversation is faster for same-day seat, limit, and spend work. It becomes the weaker surface if you need IP allowlists or SSO event logs immediately.
Comparison table
| Dimension | Admin plugin (Work / Codex) | Dedicated admin console |
|---|---|---|
| Surface | Question → confirm → action in one chat | Analytics, access, and billing often split across screens |
| Permissions | Stays inside existing roles; no extra privilege | Follows the console permission model |
| Audit | Structured results plus pre-apply review | IP allowlists / SSO logs may be stronger on the console |
| Best fit | Same-day seats, limits, and spend requests | Regulated audit, network controls, SSO event review |
Source:
- OpenAI blog
- Pondero (August 2026)
Four go/no-go checks
Decide go/no-go with four checks.
- Does the operator already have Admin Console-equivalent rights? If not, chat cannot write either.
- Do spend or feature-access approvals need Slack or Teams? If yes, configure routing; if not, pre-apply review in chat may be enough.
- Do you need IP allowlists or SSO event logs in the conversation surface? Do not expect that in the initial release.
- On Enterprise or Edu, did you explicitly enable plugins? Visibility in the directory does not mean invoke is allowed.
Same-day checklist
Checklist:
- Confirm 30-day adoption and credits with a read-only prompt
- Run one low-risk write with pre-apply review
- Configure Slack / Teams routing only if spend requests need it
- Define auto-grant conditions and the human-exception path
- Keep the dedicated console when audit requirements exceed chat
If you need to share reasoning on a PR, that is a different surface: Shared threads for Codex / ChatGPT Work. The plugin changes settings. Shared threads share a read-only snapshot of thinking.
FAQ
Privilege and install
Codex-only teams, the 45% figure, and Slack
Key takeaways
The Admin plugin brings ChatGPT Work and Codex seat, limit, and permission tasks into a single conversation. It is not a new privilege layer. It surfaces existing read/write rights and can pause high-impact changes for review.
Next actions
Do this next:
- Enable plugins in Workspace settings
- Install from the ChatGPT Work Plugins directory
- Confirm usage and credits with a read-only prompt
- Start writes with pre-apply review on a low-risk change
- Keep a dedicated console if IP allowlists, SSO logs, or other audit controls are missing from chat
How to use the 45% figure
Treat the 45% ticket figure as OpenAI’s internal example. Your go/no-go should follow existing permissions, approval routing, audit needs, and whether Enterprise or Edu has plugins enabled.
Related articles:
Author
krona23
Over 20 years in the IT industry, serving as Division Head and CTO at multiple companies running large-scale web services in Japan. Experienced across Windows, iOS, Android, and web development. Currently focused on AI-native transformation. At DevGENT, sharing practical guides on AI code editors, automation tools, and LLMs in three languages.
🔥 Most Popular
- Claude Pricing: Free, Pro, Max & Team Plans Compared (August 2026)
- Claude Desktop Won't Install? Windows & Mac Fixes That Worked (2026)
- AI Code Editor Comparison 2026: 6 Tools Tested, Why I Use Zed + Claude Code
- Claude Cowork Automation — 5 Real Use Cases (2026)
- Cursor Pricing 2026: Plans & Real Costs After 3 Years of Pro












Leave a Reply