Service eligibility and regional restrictions
PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.
Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.
Key Takeaways
- Data agent can connect enterprise data in ChatGPT Work, investigate changes, generate interactive dashboards, and prepare follow-up actions through approved tools.
- Data plugin availability, enablement of the relevant data-source plugin, and authorization of the underlying app are three separate requirements. Successful installation does not prove the target data is readable.
- Administrators can control plugins by role or group. Queries remain subject to the connected account's existing table, row, and column permissions.
- First establish a semantic layer for metric definitions, calculation conventions, data relationships, and trusted reports. Then validate the evidence chain with synthetic or low-sensitivity data.
- When publishing to Sites, data used in the analysis is copied to the published site. Review the audience and data permissions before publication.
- PRODUCT_FIT=CONDITIONAL_NETWORK_ONLY: fixed egress cannot grant plugin, app, or data permissions. Compare network paths only with evidence of DNS, TLS, 407, or connection-timeout problems.
What changed: Data agent launched, but tenant availability cannot be inferred from the announcement
OpenAI released ChatGPT Work Data agent on September 10, 2026. It can connect approved enterprise data, investigate metric changes, show evidence behind each finding, and turn analysis into interactive dashboards that can be edited, shared, and refreshed. With approval, it can also send results or perform actions through connected tools.
The public page lists sources including Amazon Redshift, Datadog, Google BigQuery, ClickHouse, Databricks, MongoDB, Snowflake, Google Drive, and SharePoint, and supports collaboration with BI tools such as Power BI, Tableau, and Sigma. However, the announcement does not specify every plan, Region, connector, usage limit, standalone price, or tenant rollout completion rate. Verify the actual account state in the real workspace.
Separate three requirements: the Data plugin, data-source plugin, and underlying app
Before starting, confirm that the Data plugin is available in the target ChatGPT Work workspace. Administrators can inspect installation policy under Workspace settings > Plugins, make it available or preinstalled, and control access by role or group. An ordinary user seeing the plugin directory does not establish that administrator policy permits use.
Reading a particular service also requires enabling the corresponding data-source plugin and its included app and completing the provider-account connection. Installation of the Data plugin, enablement of the data-source plugin, and authorization of the underlying app are independent states. A missing layer should be handled as a permission or configuration issue before blaming networking.
Document the semantic layer and least-privilege checklist before the pilot
For the first use case, record the business question, data owner, connected identity, permitted datasets, table/row/column permissions, retention period, and approver. Queries inherit the connected account's existing permissions. Use a dedicated least-privilege identity rather than sharing a highly privileged personal account across the team.
Also prepare authoritative metric definitions, time windows, filters, custom calculations, and data relationships. OpenAI calls these business definitions a semantic layer. Without consistent definitions, a successful connection may still produce answers that conflict with existing reports. Start with a metric that can be manually recalculated against a trusted report.
Use low-sensitivity data to validate sources, definitions, and evidence
In a nonproduction space, use synthetic or low-sensitivity data and explicitly specify the source, metric, time period, and comparison baseline. Ask Data agent to show the data, filters, definitions, and evidence used, then compare each item with an approved report. Do not accept conclusions merely because the dashboard looks plausible.
At minimum, test normal queries, unauthorized datasets, row/column restrictions, expired credentials, empty results, and conflicting definitions. If the connection works but data is missing, first verify direct access in the provider's service with the same connected account. A successful connection does not create additional data permissions.
Publishing and sharing: address copied data and audience boundaries first
Data agent can turn analysis into dashboards and publish them to workspace members after OpenAI Sites is installed. The official help page explicitly warns that data used in the analysis is copied to the published site. The publisher must therefore review chart details, filters, hidden fields, export capabilities, and the sharing audience.
Make the pre-publication checks a fixed gate: data-owner approval, an audience consistent with original permissions, sensitive fields removed, a clear metric time period, an identified refresh owner, and a test with an unauthorized account confirming that the content is invisible. Stop publication if permissions are broadened, the copied-data scope is unclear, or the revocation path has not been verified.
Actions, automation, and rollback: accepted analysis does not authorize execution
Sharing through Slack, email, or other connected tools, and taking actions in external systems, still depends on tool capabilities, account permissions, workspace settings, and specific approval. Separate analysis from action first: default to read-only, show the destination and content, require human confirmation, and retain the time, operator, inputs, outputs, and approval record for every external write.
If analysis is wrong, permissions are unclear, data drifts, audit records are insufficient, or costs are not visible, stop actions and automatic refreshes, disable the relevant connection or plugin, and restore the existing BI/query workflow with human approval. Do not delete original reports or make Data agent the only business-continuity path.
Network boundaries: gather evidence by layer when a connector fails
An invisible plugin, disabled administrator setting, unconfigured included app, missing table/row/column permissions on the source account, conflicting metric definitions, or an action awaiting approval is not an IP problem. Fixed egress cannot grant Data agent access, expand source permissions, or correct business definitions.
Only after plugins and permissions are confirmed should network comparisons be considered for DNS failures, TLS handshake errors, proxy 407 responses, connection timeouts, or stable differences reproduced with the same account and configuration across egress paths. Use the proxy connection troubleshooting checklist to record network-layer evidence. If data remains missing after connectivity recovers, return to plugins, apps, permissions, and the semantic layer.
Sources
Frequently Asked Questions
What can ChatGPT Work Data agent do?
It can use approved enterprise data to investigate business questions, show evidence, generate interactive dashboards, and prepare sharing or follow-up actions when tools and approvals permit. Actual capabilities depend on the workspace, connectors, and account permissions.
Why can it still not read data after the Data plugin is installed?
The Data plugin, corresponding data-source plugin, and included app authorization are three independent requirements. Also confirm that the expected account is connected and can directly access the target data in the provider's service.
Does Data agent bypass warehouse row and column permissions?
No. OpenAI says queries inherit the connected account's existing permissions, including table, row, and column restrictions. The connected identity should therefore still follow least privilege.
How can I reduce the risk of incorrect Data agent analysis?
Establish an authoritative semantic layer, specify sources, metrics, time periods, and filters, require evidence, and manually recalculate against trusted reports. Do not share or execute actions while conflicting definitions remain unresolved.
What should I check when publishing a Data agent dashboard?
The official help page warns that analysis data is copied to the published site. Before publication, inspect sensitive fields, audience, export capabilities, and revocation paths, and verify isolation using an unauthorized account.
Can changing to a fixed IP fix an invisible Data plugin or denied access?
No. Fixed egress cannot change plugin installation policy, included app configuration, or data permissions. Network comparisons are meaningful only with evidence of DNS, TLS, proxy 407, connection timeouts, or reproducible path differences.