ChatGPT (OpenAI)
What ChatGPT’s own help pages, docs and terms said on 1 October 2026, by the same six questions we ask of every agent. We didn’t test it for this page. “Not documented” means we didn’t find it on the vendor’s pages; it doesn’t mean the feature is missing.
Assistant
- Can you limit it?
- Four levels per app
- Does it ask first?
- Before hard-to-reverse acts; "Allow all actions" removes it
- Can you stop it?
- Stop or disconnect
- Is there a record someone outside can check?
- Not documented
- What about sub-agents?
- Not documented
- Can you test it yourself?
- Custom MCP on Business, Enterprise, Edu
What the vendor’s pages say
Each connected app has four permission levels, from "Always ask" to "Allow all actions", which OpenAI says "carries elevated risk". The cloud browser is "designed to request confirmation" before bookings, payments and other hard-to-reverse actions, and you can stop a task. Changing a permission "does not disconnect the app or revoke access"; disconnecting does. On Enterprise, "All app calls are logged" in OpenAI's Compliance Logs. Full custom MCP, including write actions, is in beta for Business, Enterprise and Edu. "ChatGPT agent is no longer available"; its successor is ChatGPT Work.
Every statement above was checked on the vendor’s own page on 1 October 2026; each links to its source.
Run this test on yours
Delegus Check gives your agent a permission and a one-hour test server, then shows every action it tries and what was refused. It works today with agents that accept a custom MCP server, including Claude on any plan.
Corrections
Vendors and readers: if anything here is out of date, write to hello@delegus.ai and we’ll fix it. Each change is listed here with its date.
- 1 October 2026: first published. All vendor statements checked that day.