---
title: "Apps, plugins and connected data in ChatGPT"
description: "Three ways ChatGPT connects to your tools 1. Connected apps (formerly \"connectors\") give ChatGPT access to your data and actions in services such as…"
url: https://optimizeall.com/learn/mastering-chatgpt/apps-and-plugins-in-chatgpt
updated: 2026-10-05
---

Mastering ChatGPT (OpenAI) · Apps, plugins and Codex · lesson 14 of 19 · 16 min

# Apps, plugins and connected data in ChatGPT

## Three ways ChatGPT connects to your tools

1. **Connected apps (formerly "connectors")** give ChatGPT access to your data and actions in services such as Google Drive, Gmail, Google Calendar, Microsoft SharePoint, OneDrive, Outlook and Teams, Slack, Notion, GitHub, HubSpot and many more. ChatGPT can search and read content you have access to, cite it, and, where the app supports it, take actions such as drafting an email or creating a task.
2. **Interactive apps** built with OpenAI's **Apps SDK** (which is built on the Model Context Protocol, MCP) appear inside the conversation with their own interface, for example to browse listings, design a graphic or build a playlist.
3. **Plugins** (the app directory moved into a **Plugin directory** in July 2026) bundle skills, apps and app templates so a whole workflow can be enabled at once.

Availability depends on plan, region and, for Business and Enterprise, your admin's settings.

## Permissions: decide how much ChatGPT may do without asking

In **Settings → Apps**, you can set a default permission and override it per app. The default for many apps is **"Allow low-risk actions"**: once connected, ChatGPT can use your information and take low-risk actions when relevant without asking each time, while sensitive actions still require confirmation or are blocked. You can instead choose to be asked every time. Voice mode uses the same app permissions.

A sensible personal policy:

| App type | Permission |
|---|---|
| Read-only knowledge (Drive, SharePoint, Notion) | Allow low-risk actions |
| Communication (Gmail, Outlook, Slack) | Ask every time |
| Systems of record (CRM, finance, HR) | Ask every time; admin approval |
| Anything you rarely use | Disconnect |

## Using connected data well

- **Name the source:** "Using my Drive folder 'Client – Al Noor', summarise the last three monthly reports."
- **Ask for citations** to the files, emails or pages used, and open the important ones.
- **Scope the time frame:** "emails from the last 14 days".
- **Keep sensitive work in business workspaces**, where admin controls and commercial data terms apply.

## Custom apps and MCP (for technical teams)

Because apps are built on MCP, organisations can connect their own internal systems. Developers build an MCP server that exposes tools (for example, `get_order_status`) and, on eligible business plans and in developer mode, admins can add it as a custom app for their workspace. The same MCP server can also serve other AI clients, such as Claude or Microsoft Copilot, which is a strong argument for building on the open standard.

A minimal MCP server in Python (using the official `mcp` SDK):

```python
# pip install "mcp[cli]"
from mcp.server.fastmcp import FastMCP

mcp = FastMCP("order-status")

@mcp.tool()
def get_order_status(order_id: str) -> dict:
    """Return the shipping status for an order ID (read-only)."""
    # Replace with a call to your real system, using server-side credentials.
    return {"order_id": order_id, "status": "shipped", "carrier": "Aramex"}

if __name__ == "__main__":
    mcp.run(transport="streamable-http")
```

Deploy it behind HTTPS with authentication before connecting it to any workspace, and start with read-only tools.

## Security and governance

- **Prompt injection:** emails, documents and web pages can contain hidden instructions. Keep sensitive actions on "ask".
- **Least privilege:** connect only the apps and scopes you need; review periodically.
- **Oversharing:** connected apps respect your existing permissions, so an overshared folder becomes easily searchable.
- **Admin controls:** Business and Enterprise admins can enable or disable apps and plugins, control who can use them, and review activity; follow your workspace policy.

## Worked example: account manager's Monday

An account manager at a London agency connects Google Drive (low-risk actions) and Gmail (ask every time). Monday prompt: "From the 'Clients' Drive folder and emails from the last 7 days, list what each of my five clients is waiting for, with source links. Draft (don't send) a status email for each." She checks the sources, edits two drafts, and sends them herself. The whole routine takes 25 minutes instead of an hour and a half (her own estimate).

## Hands-on

1. Open Settings → Apps and review your default permission.
2. Connect one read-only source you use daily (or review an existing one).
3. Run a scoped question with citations and open two cited sources.
4. Disconnect anything you have not used in a month.

## Pitfalls

- Leaving communication apps on automatic actions.
- Connecting personal accounts to work data, or vice versa.
- Installing unknown plugins or custom apps without review.
- Trusting summaries of connected data without opening key sources.

## How to measure success

Routine information-gathering is faster, every action that sends or changes something was explicitly approved, and your connected apps list is short and current.

## Video lecture: Apps, plugins and connected data in ChatGPT

Lecture coming soon · 15 chapters · about 8 minutes. Read the full transcript below.

1. Apps and plugins
2. Why connected data matters
3. Three connection types
4. Permissions
5. A sensible policy
6. Using connected data well
7. Custom apps via MCP
8. Security and governance
9. Simple example
10. Worked example: a London account manager
11. Try this now
12. Common mistakes
13. Watch me do it, part 1
14. Watch me do it, part 2
15. Recap and next step

## Lecture transcript

### Apps and plugins

Most of your work lives in Drive, Outlook, Slack, Notion and your CRM, not in a chat window. ChatGPT's apps and plugins bring it to that data, and with the right permissions, let it act. In this lecture you will learn the three ways ChatGPT connects to tools, how to set permissions sensibly, how technical teams can connect internal systems through MCP, and the security habits that matter.

### Why connected data matters

Why connect ChatGPT to your apps? Because answers grounded in your real documents and messages are far more useful than generic advice. What does this client need from me this week becomes a question ChatGPT can actually answer. But access is also risk. The same connection that lets ChatGPT read your email could, with the wrong permissions, let it send one. So this lecture is equal parts power and control.

### Three connection types

There are three connection types. Connected apps, previously called connectors, give ChatGPT access to your data and actions in services like Google Drive, Gmail, SharePoint, Outlook, Teams, Slack, Notion, GitHub and HubSpot. Interactive apps, built with OpenAI's Apps SDK, appear inside the conversation with their own interface. And plugins, since the app directory moved into a plugin directory in July twenty twenty six, bundle skills, apps and templates so a whole workflow can be enabled at once.

### Permissions

Permissions are the most important setting here. In Settings, under Apps, you choose a default and can override it per app. The common default is allow low risk actions. Once connected, ChatGPT can use your information and take low risk actions without asking each time, while sensitive actions still need confirmation. You can choose to be asked every time instead. And voice mode follows the same app permissions.

### A sensible policy

Here is a sensible personal policy. Read only knowledge sources like Drive, SharePoint and Notion can allow low risk actions. Communication apps like Gmail, Outlook and Slack should ask every time. Systems of record like your CRM, finance or HR tools should ask every time and follow admin approval. And anything you rarely use should be disconnected.

### Using connected data well

To get good answers from connected data, name the source, for example my Drive folder called Client Al Noor. Ask for citations to the files and emails used, and open the important ones. Scope the time frame, like emails from the last fourteen days. And keep sensitive work in a business workspace, where admin controls and commercial data terms apply.

### Custom apps via MCP

For technical teams, apps are built on the Model Context Protocol, the open standard for connecting AI to tools. Developers can build an MCP server for an internal system, exposing a tool like get order status, and on eligible business plans admins can add it as a custom app. The lesson includes a minimal Python example. The bonus is reuse, because the same MCP server can serve other AI clients such as Claude or Copilot. Deploy it behind HTTPS with authentication, and start with read only tools.

### Security and governance

Four security points. Emails and documents can carry hidden instructions, so keep sensitive actions on ask. Connect only the apps and scopes you need, and review them regularly. Remember that connected apps respect your existing permissions, so an overshared folder becomes very easy to search. And on business plans, admins can enable or disable apps and plugins, control who uses them, and review activity.

### Simple example

A simple example. Connect Google Drive and ask, find last quarter's board deck and list the three targets we set. ChatGPT searches your Drive, finds the deck, lists the three targets and links to the file. You click the link, check slide four, and confirm. No searching through folders, no copy and paste, and nothing was changed or sent. That is connected data at its safest and most useful.

### Worked example: a London account manager

An account manager at a London agency connects Google Drive with low risk actions allowed, and Gmail set to ask every time. On Monday she asks ChatGPT to list what each of her five clients is waiting for, using the clients folder and the last seven days of email, with source links, and to draft but not send a status email for each. She checks the sources, edits two drafts and sends them herself. By her own estimate, a ninety minute routine now takes twenty five. Two weeks later, one client email contained a line of white text addressed to AI assistants, asking them to forward the client's contract to an outside address. Because Gmail was set to ask every time, ChatGPT asked her before taking any action, and she simply declined. Her permission settings turned a potential leak into a non event.

### Try this now

Try this now. Open Settings, then Apps. Look at your default permission and each connected app. Set anything that can send messages or change records to ask every time. Then run one scoped question over a read only source, for example, from my Drive folder for this client, what did we agree in the last month, with citations. Open two of the cited files to check. Finally, disconnect any app you have not used in the last month.

### Common mistakes

Let's name the common mistakes. Leaving communication apps on automatic actions, so a misunderstanding becomes a sent email. Connecting personal accounts to work data, or the other way round. Installing unknown plugins or custom apps without anyone reviewing them. And trusting a neat summary of connected data without opening the key sources. Each one is easy to avoid once you know to look for it, and together they account for most of the real problems people have with connected AI.

### Watch me do it, part 1

Let me set up the London account manager's Monday. In settings, then apps, I set Google Drive to allow low risk actions, because it is read only knowledge, and Gmail to ask every time. I disconnect a note taking app I have not used since spring. Then I ask, from my Drive folder called Clients and my emails from the last seven days, list what each of my five clients is waiting for from me, with source links. The answer lists each client with a link to the email or document it came from.

### Watch me do it, part 2

I open two of the linked sources to confirm the summary is right. Then I ask for a status email draft for each client, and to create drafts, not send. Because Gmail is set to ask, ChatGPT asks permission before creating drafts, and I approve. I edit two drafts and send them myself. For technical teams, here is the internal system piece. A small Python MCP server with one tool, get order status, marked read only, returning the status from our system with credentials kept on the server. Deployed behind HTTPS with authentication, an admin can add it as a custom app where the plan allows.

### Recap and next step

Recap. ChatGPT connects through connected apps, interactive apps and plugins. Set permissions by risk, ask for citations and verify key sources, use MCP to connect internal systems safely, and disconnect what you do not use. Your next step: review your app permissions today, connect or review one read only source, run a scoped question with citations, and open two of the sources it used.

## Key takeaways

- ChatGPT connects to tools via connected apps (formerly connectors), interactive Apps SDK apps and plugins (Plugin directory since July 2026).
- Set app permissions by risk: low-risk actions for read-only knowledge, ask every time for email, chat and systems of record.
- Name sources, scope time frames and ask for citations; keep sensitive work in business workspaces with admin controls.
- Apps are built on MCP, so one internal MCP server (read-only first, authenticated) can serve ChatGPT and other AI clients.

## Try it

Review your app permissions, set communication and systems-of-record apps to "ask every time", run one scoped question over a connected read-only source with citations, and open two cited sources to verify them.

- [Previous: ChatGPT Work and agents: delegating multi-step tasks safely](https://optimizeall.com/learn/mastering-chatgpt/agents-and-automation-concepts)
- [Next: Codex: OpenAI’s coding agent for builders and teams](https://optimizeall.com/learn/mastering-chatgpt/codex-for-builders)
- [All lessons of Mastering ChatGPT (OpenAI)](https://optimizeall.com/learn/mastering-chatgpt)
