Build1 publisher2 min readPublished
ChatGPT Space lets Memory write personal context onto pages every viewer can read
OpenAI's Help Center says Memory in ChatGPT Space can write a user's personal context onto a shared page, where every viewer can read it. OpenAI's safeguard is a review before sharing, a check that runs once while collaborators' agents keep editing.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- OpenAI's Help Center article on Space, updated around October 2, 2026, says Space replaces Library as the home for files and pages in ChatGPT, while Projects stay as they are.
- Every collaborator on a page can have their own ChatGPT agent work on what is shared there.
- The owner's private chats and Memory stay private when a page is shared, and each collaborator uses their own ChatGPT.
- Personal accounts follow the agent user's training settings, while Business and Enterprise accounts are not trained on by default.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure Granting view access to a Space page also grants access to whatever any editor's Memory writes there later, content the page owner may never have read.
- decision Teams using Space have to decide whether one review at share time is enough, or whether pages with active agents need checking again while editing continues.
- exposure On a literal reading, a Business team's page content may be handled under a personal-account collaborator's training setting when that person's agent works on it.
OpenAI's privacy split covers the Memory store and stops at whatever Memory writes. A line Memory puts on a page becomes page content, readable by the page's viewers [4]. From then on it sits under the page's permissions, the same ones that govern files uploaded into it [6].
The safeguard OpenAI gives, according to a dev.to post summarising the Help Center article, is to review the page before you share it [5]. The check happens once, at the moment of sharing. After that, collaborators' agents keep editing, and context one person's Memory adds later is readable by viewers already on the page [1]. The summary does not describe an approval step for agent edits, a label on Memory-sourced text, or a per-page switch for Memory writes.
The post's author built a small model of the design in TypeScript. It runs with npx tsx space.ts on Node.js 18 or newer, with no API key and no real model [9]. "One honesty note: this is not how OpenAI built Space. It's my small model of the ideas in their Help Center," the author wrote [10]. In the model, agents inherit their human's grants. Every edit goes through the access list, bumps a revision and lands in an append-only log [11]. The revision number is how the model catches two agents writing the same section without a re-read [12].
In the demo, two agents work on the same page and run into a conflict, a stranger is refused, and a private Memory note leaks into a section other people can see [13]. The leak is its own event type, memory.leaked, logged beside edit.denied and conflict [14]. The author got this right. Because the log is append-only, a leak recorded as an event stays findable after the section is edited again [11].
Anthropic's Help Center, as cited in the post, says that starting October 6, 2026, Pro and Max plans will run new Cowork tasks in the cloud [8]. Settings > General loses its "Only on your computer" option, and sessions and files follow the account across desktop, web and mobile [8]. "Different products. Same direction," the author wrote [15].
What to watch
- Whether OpenAI adds a label, an approval step, or a per-page off switch for Memory-written text on shared Space pages.
- Whether the Help Center spells out which training setting applies when personal and Business accounts work on the same page.
- Whether Space exposes an edit history showing which collaborator's agent wrote each section.