Back to blog

OpenAI Admin Console: governing ChatGPT Work, Codex, and agents

Article created on 31 August 2026 · Publications analyzed: OpenAI Enterprise release notes from 20, 27, and 28 August 2026 · Source: OpenAI Help Center

OpenAI's August 2026 Enterprise release notes add several administration controls: workspace-scoped Admin keys, APIs for invitations and members, centralized identity management in Admin Console, RBAC, analytics, Work/Codex cost data, and GitHub-synced plugin marketplaces. For Belgian and French companies, the signal is clear: enterprise AI now has to be operated as a governed platform, not as a loose collection of individual assistants.

1. What is officially announced

OpenAI says workspace owners and admins can use workspace-scoped administration APIs to automate invitation and member management. Admin keys are created in Admin Console, inherit the relevant role permissions, and do not grant access to model inference.

The same set of updates also expands centralized management for users, groups, roles, permissions, and settings. Model controls can be managed at workspace and role level. Audit events, analytics, usage limits, Work/Codex cost data, and plugin catalogs are gradually becoming objects administrators can govern.

2. What this changes for Belgian and French companies

For an SME, the priority is to keep administration simple: a few roles, business-aligned groups, usage limits, and a monthly access review. For mid-market and large organizations, the value is more structural: connect SCIM, groups, RBAC, costs, logs, and plugin catalogs to governance that distinguishes office use, agents, Codex, sensitive workflows, and business integrations.

Public administrations and regulated sectors gain a useful evidence path: who had access, with which role, to which model, plugin, budget, and workspace. This granularity becomes essential when ChatGPT Work, Codex, or agents connect to contract, HR, finance, support, CRM, Odoo, or document data.

3. Underside analysis: from user access to AI operations

The important shift is not only functional. It moves AI governance toward operating objects: keys, roles, logs, budgets, catalogs, plugins, scheduled tasks, and workspaces. This is the same movement seen in RAG, MCP, and Odoo architectures: value depends less on the isolated model than on the full chain connecting identity, data, tools, and actions.

For a sovereign AI strategy, these controls have to be combined with local, cloud, or hybrid deployment choices. European hosting is not enough if roles are too broad, plugins are not inventoried, or logs cannot explain an action. Conversely, a cloud platform can be integrated more responsibly when data flows, rights, costs, revocation, and evidence are documented.

In an Apple Enterprise context, Codex and Work also add an endpoint dimension: files, conversations, applications, history, plugins, and managed devices need to be handled together. AI governance is becoming an extension of IT, security, and business governance.

4. Operational recommendation

Before expanding adoption, CIOs should build a "population x tool x data x action" matrix: which groups can access ChatGPT Work, Codex, models, plugins, scheduled tasks, Admin APIs, and analytics; which actions are only recommended versus actually executed; which logs are retained; which alerts are escalated; and who can suspend a scope during an incident.

For Odoo workflows, that matrix must go down to process level: CRM, purchasing, invoicing, support, HR, documents, projects, and BI do not carry the same risks. An agent connected to Odoo or document RAG needs an owner, least-privilege permissions, a budget limit, test evidence, and a withdrawal procedure.

Concrete priority: treat ChatGPT Enterprise, Work, and Codex as an AI operating platform, with RBAC, Admin keys, logs, budgets, plugin catalogs, and workflow mapping before any sensitive automation is expanded.

Frame AI governance

Read the official release notes

Read the official Admin keys documentation