Product1 distinct publisher2 min readUpdated
OpenAI's agent product pays off in proportion to the access it is given. That makes the rollout an access-control project, and the person holding the keys is usually a team lead.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
A harness, in the vocabulary of the engineers building these products, is the software wrapped around a model that decides what information it sees, what tools it can use, and how it presents answers back to you [6]. That is also a serviceable definition of an access policy. The open question for ChatGPT Work is who gets to write that policy, and on whose behalf.
The wager Andrew Ambrosino describes is coherent for someone whose job is testing this on himself: he accepts that a drafting agent may pull from a private DM, treats it as a personal hit he is willing to take, and reports it has not landed yet [5]. Copied into a team, the arithmetic changes owner. The messages an agent surfaces belong to colleagues, while the grant was made by whoever held the credentials [4]. Tibault Sottiaux, who runs core product work including Work, describes ChatGPT completing entire complicated tasks autonomously in a way that is "delightful and safe" [12]. In that sentence, "safe" is doing all of the load-bearing work, and none of the scoping.
The adoption spread in the OpenAI-backed study is usually read as a usability problem, and OpenAI reads it that way too: the tool was, in Ambrosino's words, actively hostile to the company's own comms and finance staff, and the team spent February onward making it general purpose [8]. The remaining distance between insiders and paying organisations is 81 percentage points, about 5.8 times the rate [13][14]. Now look at who the 98% are [7]. They are employed by the company receiving the data. Connecting a mailbox moves nothing across an organisational boundary for them. For an accountant or a doctor, the same click adds a counterparty.
Christian Catalini's warning on a16z's Time to Build blog is that if the labs cannot rapidly get hold of the key complementary assets needed to scale AI in the market, value accrues elsewhere [10]. In coding, that asset was the repository. Outside engineering, it is a pile of permission grants that belong to other people, and no amount of model quality wins one. Harvey in law and Clay in sales are chasing the same professional customers with a model-agnostic approach [11], which means they arrive at the identical consent screen with the identical problem.
What none of the reporting establishes is how ChatGPT Work behaves on partial access: whether a Slack connection scoped to three channels still completes multistep work, or only demonstrates it. That is the figure a team lead needs before signing, and it has not been published.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
An OpenAI-backed study found that in June, 98% of OpenAI employees were using Codex, but just 17% of organizational subscribers and less than 1% of individual subscribers were using the agentic coding tool.
Tibault Sottiaux, who leads OpenAI's core product work including Work, said ChatGPT "can actually do entire, very complicated tasks for you all autonomously in a way that is delightful and safe".
ChatGPT Work was released last month and is available on OpenAI's lowest subscription tier, for $20 a month; TechCrunch describes it as OpenAI's biggest bet.
ChatGPT Work is a modified version of OpenAI's Codex coding tool, meant to give non-engineers a tool that completes multistep projects on its own rather than only answering questions.
The product is intended to let white collar workers field AI agents, hooking LLMs up to the digital workflows used by accountants, investors, doctors and others whose day is dominated by their computer.
Andrew Ambrosino, lead engineer for OpenAI's desktop app, has given that app access to and control over his inbox, his Slack account, his phone, and apps including Notion and Figma.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-outlet vendor interviews with one secondhand number
Everything rests on one TechCrunch piece built from on-record interviews with two named OpenAI employees. That makes the product description, access footprint and leakage admission well attributed but wholly unverified externally. The one quantitative claim — the June Codex split — is attributed only to an unnamed 'OpenAI-backed study' with no methodology or link, and the a16z quote is commentary rather than measurement. No independent testing, no admin-side documentation, no competitor or customer response.
Near-total internally, negligible outside
The only measured adoption concerns Codex, the tool ChatGPT Work is derived from: 98% inside OpenAI versus 17% of organizational subscribers and under 1% of individual subscribers in June — an 81-point internal-to-external gap the article itself calls the company's central challenge. ChatGPT Work launched roughly a month before publication with no disclosed seats, usage or retention, so external adoption of the product in question is effectively unevidenced and the score reflects the weak external Codex baseline plus a bare release datapoint.
Autonomy and safety language outruns the data
Sottiaux's claim that ChatGPT can do 'entire, very complicated tasks for you all autonomously in a way that is delightful and safe' and the 'biggest bet' framing sit against under 1% individual and 17% organizational uptake of the predecessor tool, plus the desktop app lead's own concession that the agent may surface a private DM it should not share. The article deserves credit for placing the adoption gap and the leakage risk in plain view rather than suppressing them, which keeps the gap moderate rather than extreme; the overstatement is in the vendor quotes, not the reporting.
Vendor sources, vendor study, token-metered upside
Incentives are unusually legible. The article states that longer-running agents burn more tokens and are therefore more lucrative per user, so OpenAI's revenue rises with the breadth of access users grant. Both named sources are OpenAI employees promoting their own product, including one whose quote directly monetises the value framing ('of course I want to pay $20 bucks a month'). The adoption statistic comes from an OpenAI-backed study, and the analyst voice is a venture firm's own blog. No disinterested party appears in the cluster.
Directionally solid, numerically thin
The core structural read — that ChatGPT Work's value is proportional to the access granted, and that access decisions get made on colleagues' behalf — follows directly from quoted, on-record material and is unlikely to be overturned. Confidence is held down by the single-publisher cluster, the unlinked vendor-backed study behind the only percentages, and the total absence of post-launch data on Work or of administrator-side permission detail that would let an operator verify the risk surface.
build
Developer habit, priced at $965B: what Anthropic's run actually proves1 distinct publisher
leadership
Slack Code makes the chat window a coding surface, and a platform call for engineering leaders1 distinct publisher
build
Codex at OpenAI: stop polishing the prompt, start building the harness1 distinct publisher
invest
Northzone says the AI notetaker is dead. Its own portfolio is the tell1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026