Skip to content
Pylon Digital

AI security & privacy · Guide

How to set up ChatGPT Business securely for a professional firm

To set up ChatGPT Business securely, verify your email domain, connect single sign-on with MFA, control who can join, switch off unapproved apps and third-party GPTs, set memory and record-keeping rules, and train staff against a written policy. This checklist is for practice managers at Australian law and accounting firms, current as at September 2026.

Published
Last reviewed
Reading time
7 min read

What does a secure ChatGPT Business setup involve?

A secure setup controls three things: who can get into the workspace, what the workspace can reach, and what staff are allowed to put into it. OpenAI’s defaults handle part of this. The rest is configuration and policy, and it is easy to skip when a partner simply buys seats on a credit card.

Some context first. OpenAI renamed ChatGPT Team to ChatGPT Business on 29 August 2025, with no change to features or contracts. OpenAI’s enterprise privacy commitments say it does not train its models on ChatGPT Business data by default, and its help centre says business data is encrypted in transit and at rest. Those defaults are sound. Other defaults, such as workspace discovery and apps, are switched on, and a law or accounting firm should decide deliberately whether to keep them. Everything below is as at September 2026. OpenAI changes its admin settings often, so check each step against the linked help article when you do it.

What should you decide before you buy?

Decide three things before checkout: where the workspace stores data, who the owners are, and which client information is allowed in. The first is set at purchase, and the other two shape every setting that follows.

  • Storage region. OpenAI is rolling out a storage-region choice at ChatGPT Business checkout. It is not yet available to every customer, and it covers where data is stored at rest, not where responses are generated. If you choose a region outside the United States, OpenAI still keeps a copy of every prompt and response in the US for a limited time for safety and abuse monitoring. Record which regions you were offered and what you chose. Our guide to where ChatGPT stores your data goes into the detail.
  • Owners. A Business workspace needs at least two paid seats and has four roles: owner, admin, analytics viewer and member. Owners control billing, identity settings and roles. Name two owners, usually the practice manager and a partner, so the firm is never locked out when one person leaves. Give the admin role to whoever handles day-to-day onboarding; everyone else is a member.
  • Data rules. Agree in writing which kinds of information may go into the workspace. That decision becomes the core of your AI acceptable use policy.

What are the setup steps, in order?

Work through these twelve steps in order, because several depend on the one before. A practice manager can do most of them, with your IT provider handling DNS and your identity provider.

  1. Verify your email domain. An owner adds the firm’s email domain under Identity & access in workspace settings, then publishes the DNS TXT record OpenAI provides. OpenAI’s domain verification guide notes that propagation can take up to 24 hours and that each exact email domain needs its own verification. A firm that kept a second domain after a merger must verify both.
  2. Connect single sign-on. SSO is included in ChatGPT Business. Connect it to the identity provider you already use, which for most firms is Microsoft Entra ID (Microsoft 365) or Google Workspace, using SAML or OIDC as set out in OpenAI’s SSO guide for Business. Staff then sign in with their work account, and disabling that account stops new sign-ins.
  3. Make SSO required. Once SSO works for a test user, set it to required, so people on your verified domain can only sign in to the workspace through your identity provider rather than with a separate password.
  4. Enforce multi-factor authentication. With SSO in place, MFA is enforced by your identity provider, so require it there; in Microsoft Entra ID that means Conditional Access or security defaults. For any account that does not sign in through SSO, turn on ChatGPT’s own MFA under Settings, then Security and login.
  5. Decide who can join. Workspace discovery is on by default in ChatGPT Business: anyone who signs up with your verified domain can see the workspace and ask to join. Either require admin approval for join requests or turn discovery off and invite people yourself from the Members page.
  6. Put joiners and leavers on the HR checklist. A standalone Business workspace does not include SCIM, so ChatGPT does not add or remove people when your directory changes. Removing a leaver’s seat is a manual step. When you do, their projects and GPTs pass to a workspace owner, while their chats and files are kept (OpenAI says indefinitely, for Business) but are not visible to the owner. Decide what the firm’s own records need before the person leaves.
  7. Confirm data sharing is off. OpenAI excludes Business data from model training unless the organisation opts in. It also notes that data explicitly shared through opt-in feedback mechanisms may be used to improve its models, so your policy should say whether staff may send feedback on chats.
  8. Switch off apps you have not approved. Apps, which OpenAI called connectors until December 2025, let ChatGPT search and act in systems such as SharePoint, Outlook and Google Drive. OpenAI’s admin controls for apps say apps are enabled by default in Business workspaces. Disable every app you have not reviewed, then enable approved ones individually, limited to read actions where the action controls allow it.
  9. Set rules for GPTs and sharing. Custom GPTs are a good home for a shared prompt library, such as an engagement-letter checker or the firm’s standard email tone. In workspace settings, decide who can create GPTs, how widely they can be shared, and whether staff may use third-party GPTs; for most firms, third-party GPTs should be off or owner-approved only. Shared chat links only open for members of your workspace.
  10. Decide on memory. Memory lets ChatGPT carry details from one chat into later ones, which is convenient but can bring one client’s details into another client’s work. Workspace owners can turn memory off for the whole workspace; OpenAI notes this deletes members’ existing saved memories.
  11. Set record-keeping rules. Chats stay in a member’s history until they delete them or a workspace retention policy removes them. Deleted chats are scheduled for permanent deletion within 30 days unless OpenAI must keep them longer for security or legal reasons (chat and file retention). ChatGPT is not your document management system: final advice, file notes and workpapers belong in LEAP, Actionstep, Xero Practice Manager or wherever your matter and job records live.
  12. Publish the policy and onboard staff. Run a short session showing the approved workspace, the data rules and a few worked prompts for real tasks. If the approved tool is harder to use than a personal account, staff will drift back to the personal account.

What should staff never put into ChatGPT Business?

That is the firm’s decision, but it should be explicit and conservative. The OAIC’s guidance on privacy and commercially available AI products recommends, as best practice, that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots, and expects due diligence before any AI product is used with personal information. For law practices, the December 2024 statement on the use of AI in Australian legal practice from the Victorian, NSW and WA legal regulators says lawyers cannot safely enter confidential, sensitive or privileged client information into public AI chatbots such as ChatGPT, and that commercial tools need their contractual terms reviewed carefully first.

A workable starting point:

InformationDefault rule
Public information, firm templates, marketing copyAllowed
Internal firm information with no client identifiersAllowed
De-identified client scenariosAllowed, with care
Named client matters, files and correspondenceOnly if partners approve it after reviewing OpenAI’s terms
Tax file numbers, health information, trust account records, material under suppression ordersNever

Example: a 25-person accounting firm on Microsoft 365

Illustrative scenario: a 25-person accounting firm finds that staff are drafting client emails in personal ChatGPT accounts. The practice manager buys ChatGPT Business, names herself and the IT partner as owners, verifies the firm’s domain and connects Microsoft Entra ID, so staff sign in with their existing Microsoft 365 accounts and MFA. Workspace discovery is set to require approval. All apps are disabled at launch, and the SharePoint app is enabled later, read-only, after a test. One shared GPT holds the firm’s email templates and tone. Third-party GPTs and memory are off. The policy bans tax file numbers and bank details outright, and the firm’s leaver checklist now includes removing the ChatGPT seat.

When is ChatGPT Business not enough?

ChatGPT Business suits drafting, summarising and research on information the firm is comfortable sending to OpenAI. It falls short when the firm needs automated provisioning, needs to choose where client data is stored and processed, or cannot put client data into a public tool at all.

Who can set this up for you?

Pylon Digital’s AI Setup service works through this checklist with you: single sign-on, admin controls, training opt-outs, apps, a prompt library, the usage policy and staff onboarding. It is a fixed-fee project with optional monthly admin, and it starts with a free 45-minute discovery call.

This is general information, not legal advice.

Questions

Frequently asked questions

Is ChatGPT Business the same as ChatGPT Team?

Yes. OpenAI renamed ChatGPT Team to ChatGPT Business on 29 August 2025. It was a name change only: features, pricing, limits and existing contracts stayed the same, and workspaces did not need to be migrated. Older guides that mention ChatGPT Team still broadly apply, but check each setting against OpenAI's current help centre, because the admin controls change often.

Does OpenAI train its models on ChatGPT Business data?

Not by default. OpenAI states that it does not use ChatGPT Business inputs or outputs to train or improve its models unless the organisation explicitly opts in, for example through feedback mechanisms. That is a real advantage over personal accounts, but it does not decide where your data is stored, how long chats are kept or who in the firm can see them.

Can ChatGPT Business keep our data in Australia?

Not reliably, as at September 2026. OpenAI is rolling out a storage-region choice at ChatGPT Business checkout, but it is not yet available to every customer, it covers data at rest only, and with a non-US region a copy of prompts and responses is still kept in the United States for a limited time for safety monitoring. Check the regions offered before you buy.

Can we get zero data retention on ChatGPT Business?

No. Zero data retention is an arrangement OpenAI offers to eligible customers of its API platform, with OpenAI's prior approval. It is not a setting in the ChatGPT Business workspace. If a use case genuinely needs zero retention, it usually means building on the API or on a private AI service rather than giving staff a chat workspace.

What happens to a leaver's chats in ChatGPT Business?

They are kept but stay private. OpenAI says a Business workspace retains a removed member's chats and files indefinitely and restores them if the person is re-added. Their projects and GPTs pass to a workspace owner, but their conversations are not transferred and the owner cannot see them. With no SCIM in standalone Business, removal is a manual offboarding step.

How long does a secure ChatGPT Business setup take?

The settings themselves are quick. The slow parts are DNS verification of your domain, which OpenAI says can take up to 24 hours to propagate, and agreeing the data rules with partners. Pylon Digital's AI Setup is scoped as a fixed-fee project, with the timeline set out in the proposal after the discovery call.

Secure by design. Set up correctly. Fully managed.

Talk to us before you commit to anything

Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.

Book a free 45-minute discovery call