New compliance and administrative tools for ChatGPT Enterprise
OpenAI
OpenAI just gave ChatGPT Enterprise a compliance toolkit. Think SCIM user management, API hooks for compliance teams, and tighter controls on custom GPTs.
Based on reporting by OpenAI — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
OpenAI is making a pitch to the people who actually sign enterprise software contracts: the compliance officers, the IT admins, the ones who lose sleep over data governance audits. The company rolled out a set of new administrative features for ChatGPT Enterprise built around three things — compliance API integrations, SCIM support, and expanded controls over how GPTs get used inside an organization.
SCIM is the boring but essential part. It stands for System for Cross-domain Identity Management, and it's the protocol that lets IT departments automatically provision and deprovision user accounts across dozens of tools without manually clicking through admin panels. Add ChatGPT to that automated pipeline and a new hire gets access the moment they're added to the company directory, while someone who leaves loses it just as fast. That sounds unglamorous until you consider how many security incidents trace back to an ex-employee still holding valid credentials months after they walked out the door.
The compliance API piece is aimed squarely at the audit-and-legal crowd. Enterprises running formal compliance programs — think SOC 2, HIPAA, or internal data retention policies — need to pull usage logs, monitor data flows, and prove to regulators or auditors that nothing weird happened. Giving them API access to that information means compliance teams don't have to beg engineering for exports or trust a dashboard screenshot; they can plug ChatGPT activity straight into whatever governance system they already run.
Then there's the GPT controls, which address a headache anyone managing a large ChatGPT rollout will recognize: employees building custom GPTs that quietly access sensitive data or get shared outside their intended team. Tighter administrative oversight here lets an organization decide who can build, publish, or use internal GPTs, closing off a shadow-IT problem before it becomes one.
None of this is flashy. There's no new model, no benchmark chart, no demo video. But it signals where OpenAI thinks its enterprise revenue actually grows from here — not from smarter answers, but from convincing a Fortune 500 security team that ChatGPT can behave like any other piece of sanctioned corporate software.
My take — AI-written commentary, not fact-checked reporting
This is OpenAI quietly admitting that enterprise sales aren't won by GPT-5 headlines, they're won by SCIM tickets and audit logs, the same unglamorous stuff that made Okta and Workday billion-dollar companies. I'd rather see this kind of governance investment than another capability demo, because the actual risk in most companies isn't rogue superintelligence, it's an intern's custom GPT leaking a spreadsheet nobody meant to share.
Read more about this at: OpenAI