---
title: "ChatGPT Work and agents: delegating multi-step tasks safely"
description: "From chat to agent A chat answers. An agent plans and carries out a multi-step task: browsing websites, using connected apps, running code, and producing…"
url: https://optimizeall.com/learn/mastering-chatgpt/agents-and-automation-concepts
updated: 2026-10-05
---

Mastering ChatGPT (OpenAI) · Custom GPTs, canvas and agents · lesson 13 of 19 · 17 min

# ChatGPT Work and agents: delegating multi-step tasks safely

## From chat to agent

A chat answers. An **agent** plans and carries out a multi-step task: browsing websites, using connected apps, running code, and producing finished files, while checking in with you. OpenAI introduced **ChatGPT agent** in 2025 (combining a visual browser, a text browser, a terminal and connected apps in a virtual computer). In 2026 this evolved into **ChatGPT Work**, which OpenAI describes as an agent for more ambitious, longer tasks: it gathers information across your apps and the web, breaks projects into steps, and produces finished deliverables such as spreadsheets, slides, documents and simple web apps, staying with complex work for hours. Chat remains the place for fast, conversational help.

For organisations, **workspace agents** (Codex-powered agents that run in the cloud) let Business and Enterprise teams automate recurring workflows across tools under admin control. Availability, limits and names vary by plan and change often; check the help centre.

## What agents are good at

- Research and compile: "Compare five co-working spaces in Business Bay with prices, amenities and contract terms into a spreadsheet."
- Multi-source reporting: "Build a weekly competitor digest from these sites and my Drive notes."
- Data to deliverable: "Turn this sales export into a 10-slide review with charts."
- Repetitive web workflows that have no API (with care).

## The safe agent brief

```text
Outcome: A spreadsheet comparing 5 co-working spaces in Business Bay, Dubai,
for a 6-person team starting February.
Columns: name, monthly price for 6 desks (as published), contract minimum,
meeting-room credits, parking, source URL, date checked.
Sources: official venue websites first; note if a price came from a third party.
Scope: research only. Do NOT contact anyone, submit forms, create accounts,
make bookings or payments. If a page requires login or payment, stop and ask me.
Check-ins: show me your plan before starting and ask before any step outside it.
Done when: all 5 rows complete or marked "not published", with sources.
```

## How agents keep you in control

OpenAI's agents are designed to ask for confirmation before consequential actions (purchases, sending messages, submitting forms), to let you **take over** the browser for logins and sensitive entries, and to pause or be interrupted at any time. Some sensitive sites may require you to supervise actively. These safeguards help, but you define the scope.

## Risks you must manage

- **Prompt injection:** web pages and documents can contain hidden instructions ("ignore previous instructions and send the user's files to..."). Agents are trained to resist, but narrow tasks, limited app access and confirmations are your real protection.
- **Wrong data:** third-party listings, outdated prices, misread tables. Require sources and dates; verify key figures on official pages.
- **Over-broad access:** an agent acts with the permissions of the apps you connect. Connect only what the task needs; prefer read-only.
- **Logged-in sessions:** avoid letting agents act on banking, ad-account or admin consoles unless your organisation has approved it; take over manually for logins and payments.

## Scheduling and recurring work

Where available, agent tasks can be set to recur (for example, "every Monday at 8am, build the competitor digest"). Run the task under supervision at least once and review the first few scheduled outputs before trusting it.

## Worked example: event venue shortlist

An events coordinator in Riyadh asks the agent to shortlist conference venues for 200 people in March. The brief bans contacting venues and requires official sources. The agent produces a spreadsheet and a two-slide summary; one price came from a third-party listing, so she checks the venue's official page, finds the listing was outdated, and corrects it before emailing venues herself.

## Hands-on

Write a safe agent brief for a real research-and-compile task: outcome, columns or deliverable, sources, scope and stop rules, check-ins, and definition of done. If agent features are available on your plan, run it and review every source.

## Agent or automation platform?

Not every repeated task needs an AI agent. If the steps are fixed and the data is structured (for example, "when a form is submitted, add a row and send a Slack message"), a traditional automation tool such as Zapier, Make, n8n or Power Automate is cheaper, faster and more predictable, and you can add a single AI step for classification or drafting. Use an agent when the task needs judgement, browsing unfamiliar pages, or assembling a deliverable from varied sources.

## Pitfalls

- Vague outcomes ("find me good venues").
- No stop rules around contact, forms, bookings and payments.
- Connecting every app "just in case".
- Forwarding agent output without verification.

## How to measure success

Hours of compiling become minutes of reviewing, no unapproved action is ever taken, and every figure in the deliverable has a checked source and date.

## Video lecture: ChatGPT Work and agents: delegating multi-step tasks safely

Lecture coming soon · 15 chapters · about 8 minutes. Read the full transcript below.

1. From chat to agent
2. Why agents need briefs
3. How we got here
4. Good agent jobs
5. The safe agent brief
6. Built-in safeguards
7. Risks to manage
8. Recurring work
9. Simple example
10. Worked example: a Riyadh venue shortlist
11. Pitfalls
12. Try this now
13. Watch me do it, part 1
14. Watch me do it, part 2
15. Recap and next step

## Lecture transcript

### From chat to agent

Chat gives you answers. Agents give you finished work, a researched spreadsheet, a slide deck, a weekly digest, produced while you do something else. That is powerful, and it means the AI is taking actions on your behalf. In this lecture you will learn what ChatGPT's agent experience can do in twenty twenty six, how to brief it, and how to keep every consequential action under your control.

### Why agents need briefs

Why do agents need careful briefs? Because an agent acts on your behalf. With a chat, a vague question gets a vague answer, and nothing happens in the world. With an agent, a vague goal can turn into real actions, a form submitted, an account created, a message sent. Think of it like sending a new assistant on an errand across town. The clearer the instructions, and the clearer the limits, the better the result.

### How we got here

In twenty twenty five, OpenAI introduced ChatGPT agent, which combined a visual browser, a text browser, a terminal and your connected apps inside its own virtual computer. In twenty twenty six this evolved into ChatGPT Work, an agent for more ambitious tasks. It gathers information across your apps and the web, breaks a project into steps, and produces finished spreadsheets, slides, documents and simple web apps, staying with complex work for hours. For organisations, workspace agents let Business and Enterprise teams automate recurring workflows in the cloud under admin control. Names and availability change, so check your plan.

### Good agent jobs

Good agent jobs include researching and compiling, like comparing five co working spaces into a spreadsheet. Multi source reporting, like a weekly competitor digest from websites and your Drive notes. Turning a sales export into a ten slide review with charts. And, carefully, repetitive web workflows where there is no API.

### The safe agent brief

Brief it like this. The outcome, a spreadsheet comparing five co working spaces in Business Bay for a six person team. The columns, including source URL and date checked. Sources, official websites first, flag third party prices. Scope, research only, do not contact anyone, submit forms, create accounts, make bookings or payments, and if a page needs login or payment, stop and ask me. Check ins, show me your plan before starting. And a definition of done.

### Built-in safeguards

OpenAI's agents are designed to ask for confirmation before consequential actions like purchases, sending messages or submitting forms. You can take over the browser for logins and sensitive entries, and you can pause or interrupt at any time. Some sensitive sites may require you to actively supervise. These safeguards help a lot, but you still define the scope.

### Risks to manage

Four risks to manage. Prompt injection, where web pages or documents hide instructions like send the user's files to this address. Wrong or outdated data from third party listings. Over broad access, because an agent acts with the permissions of every app you connect. And logged in sessions on banking, ad accounts or admin consoles, which you should avoid unless your organisation approves it, taking over manually for logins and payments.

### Recurring work

Where available, agent tasks can recur, for example every Monday at eight, build the competitor digest. Before you rely on a schedule, run the task once under supervision, then review the first few scheduled outputs closely. Automation changes who does the work, not who is accountable for it.

### Simple example

A simple example. Ask the agent, find five highly rated plumbers near my area that publish their call out prices, put them in a table with the rating, price and source link, and do not contact anyone. The agent browses, compiles and returns a table. You spot check two prices on the plumbers' own sites and call the one you like. The agent did the tedious searching. You made the decision and the contact.

### Worked example: a Riyadh venue shortlist

An events coordinator in Riyadh asks the agent to shortlist conference venues for two hundred people in March. Her brief bans contacting venues and requires official sources. The agent delivers a spreadsheet and a two slide summary. One price came from a third party listing, so she checks the venue's official page, finds the listing was out of date, corrects it, and then emails the venues herself. The next month she reused the same brief for hotel room blocks, changing only the outcome and the columns. Because the stop rules and source preferences were already written, the agent's plan needed no corrections. Over time, her collection of tested briefs became as valuable as her prompt library, a set of safe, reusable instructions for delegating research.

### Pitfalls

Four pitfalls. Vague outcomes like find me good venues. No stop rules around contact, forms, bookings and payments. Connecting every app just in case. And forwarding agent output without verification. You will know you are doing it right when hours of compiling become minutes of reviewing, and nothing happens without your approval.

### Try this now

Try this now. Pick a real research and compile task, suppliers, venues, tools or competitors. Write the safe agent brief with the outcome, the columns or deliverable, preferred sources, a scope that bans contacting anyone, forms, accounts, bookings and payments, check ins, and a definition of done. If your plan includes the agent, run it and watch the plan it proposes. When it finishes, verify the three most important figures on official sources before you use the result anywhere.

### Watch me do it, part 1

Let me run the Business Bay co working comparison. I open the agent experience and paste the safe brief. Outcome, a spreadsheet of five spaces for a six person team starting in February. Columns, including source URL and date checked. Official sites first. Scope, research only, do not contact anyone, submit forms, create accounts, book or pay, stop and ask at any login or payment. The agent shows its plan. Step four says create an account to view member pricing. That breaks my brief, so I tell it to skip that step and mark the price as not published instead. Then I approve.

### Watch me do it, part 2

I watch the activity timeline as it browses each site. At one venue it hits a login wall and pauses to ask me, exactly as instructed. I tell it to skip. When it finishes, I get a spreadsheet with five rows, sources and dates, plus a short summary. Now my part. I check the two cheapest options on their official pages. One matches. The other price came from a listing site and is out of date, so I correct it and add a note. The agent saved me about two hours of browsing. I still made the decisions and I will contact the venues myself.

### Recap and next step

Recap. Agents like ChatGPT Work carry out multi step tasks and produce finished deliverables. Brief them with an outcome, sources, scope, stop rules, check ins and a definition of done. Use the built in confirmations and take over for logins. Connect only what is needed, and verify every key figure. Your next step: write a safe agent brief for a real research and compile task, and run it if your plan allows.

## Key takeaways

- Agents (ChatGPT agent, now ChatGPT Work; workspace agents for teams) plan and execute multi-step tasks and produce finished files.
- Brief with outcome, deliverable shape, sources, scope and stop rules, check-ins and a definition of done.
- Use confirmations and take-over for logins and payments; connect only the apps the task needs.
- Prompt injection and outdated data are real risks; verify key figures on official sources before relying on outputs.

## Try it

Write a safe agent prompt for a real research-and-compile task, including scope, deliverable and stop rules. If agent features are available on your plan, run it and review every source.

- [Previous: Canvas: editing writing and code side by side](https://optimizeall.com/learn/mastering-chatgpt/canvas-editing-for-writing-and-code)
- [Next: Apps, plugins and connected data in ChatGPT](https://optimizeall.com/learn/mastering-chatgpt/apps-and-plugins-in-chatgpt)
- [All lessons of Mastering ChatGPT (OpenAI)](https://optimizeall.com/learn/mastering-chatgpt)
