Your Company Rolled Out ChatGPT Enterprise. Now Make Your Data Estate Agentic & Autonomous with Data Workers
A guide for heads of data whose company bought ChatGPT Enterprise: the Data agent puts your warehouse in every seat, and Data Workers keeps the data and definitions under those answers right.
ChatGPT Enterprise is where everyone asks. Data Workers is the agentic data platform that keeps the data and definitions under those answers right, and fixes them when they aren't. This guide is for the leader who owns the data estate in a company that just put ChatGPT in every seat.
The rollout went well. IT owns Workspace settings, a short list of apps is enabled under Admin > Plugins, custom roles decide who sees what, and the Compliance API streams conversations to security. Then on September 10, 2026 OpenAI launched the Data agent in ChatGPT Work. Now any employee can type @Data, ask why pipeline moved, and get an answer drawn from Snowflake, Databricks or BigQuery, with business context read from your semantic layer and a dashboard published to the team.
That is a real step forward, and it changes your team's week. A sales leader and a finance analyst ask the same question and find different tables. A chart looks wrong, and the follow-up lands in your Slack, because nobody can fix a dbt model from a chat. An access request typed into ChatGPT becomes a ticket. Every good answer that needs something changed ends in your queue.
Your data platform has a control-plane problem, and the control plane is your team. People are the connective tissue between ChatGPT and Snowflake, dbt, Airflow and Tableau, carrying context from one to the next by hand. The expensive part isn't knowing what needs doing. It's the doing: the changing, the checking and the fixing.
What ChatGPT Enterprise solved, and what it didn't
ChatGPT Enterprise solved the front door. Every employee has a capable analyst that queries the warehouse, explains what changed and builds dashboards in the BI tools you already own. Its admin model is careful: queries run with the connected account's table, row and column permissions, admins enable each app's read and write actions separately, and by default ChatGPT asks for confirmation before any write. Business data isn't used for training by default.
OpenAI was also candid about what made the Data agent work inside its own company. Its data team created shared business definitions, set access rules and put safeguards in place for sensitive data. The Data agent reads definitions; somebody has to keep them true. It answers from the tables it is given; somebody has to keep those tables right overnight. That work still sits with your team, and it is the job Data Workers does.
ChatGPT Enterprise is where your people ask and analyse. Data Workers is the agentic data platform that runs your whole data estate and keeps every answer standing on correct data.
Or, in one sentence for your team: we keep ChatGPT exactly as it is, and put one crew under it that keeps definitions governed, catches breaks before anyone asks, and fixes data behind an approval.
What goes on autopilot
Each of these is a queue your data team runs by hand today, and many of them now start with a question someone asked ChatGPT.

None of this requires replacing anything. Data Workers connects to ChatGPT as one custom app your admins publish and govern, works inside the tools you already run, and leaves an auditable record of every change. Your data stays in your infrastructure.
What changes for your organization

- •Your data team stops being the human control plane. The questions that used to end in a ticket end in a governed answer, or in a proposed fix one person approves.
- •ChatGPT answers agree with each other. Every seat reads the same governed definitions, owners and lineage, so the forecast call and the board deck show the same number.
- •The data is right before anyone asks. Schema changes, failed loads and quality breaks are caught and fixed overnight, so the first
@Dataquestion of the morning lands on correct tables. - •Spend stays in check as self-serve grows. More questions mean more queries. Snowflake credits are traced to the query and dbt model behind them, and the fix goes to the owner drafted.
- •Audits get the other half. ChatGPT's Compliance API holds the conversation. Every data change adds who or what made it, why, what it touched and how to undo it.
- •Engineers keep their tools. Analytics engineers review and approve where they already work, including Codex inside the same ChatGPT Enterprise workspace.
One incident, start to finish
This is an illustration, not a customer case.
- •Sales ops splits the EMEA region in Salesforce into North and South at 1 a.m., and Fivetran syncs the new values into Snowflake.
- •The nightly Airflow DAG run succeeds, but the dbt pipeline model doesn't know the new values, so those deals land with no region.
- •At 8 a.m. the VP of Sales asks ChatGPT why EMEA pipeline fell this week, and the Data agent reports the drop the table shows.
- •The answer is faithful to the data, and the fix lives in a dbt repo, an orchestrator and a dashboard.
Today that's a morning of Slack threads and a forecast call built on the wrong number. With Data Workers, the break is caught at 2 a.m. and traced to the picklist change. When the VP asks, ChatGPT answers with the cause and the open incident. The dbt fix arrives with its blast radius after ChatGPT confirms the write, an analytics engineer approves it, the DAG reruns, totals are checked against Salesforce, and the dashboard is right before 10 a.m. ChatGPT asked the right question. Data Workers fixed the cause and brought the receipt.
You choose how far and how fast
Our thesis is that data teams will climb from people working alongside an assistant, to people governing a team of agents, to a largely self-running agentic enterprise. You choose the altitude, one area at a time.

The climb has five levels: L0 manual, L1 observe, L2 propose, L3 act reversibly, L4 autonomous. Every area starts at L1, with agents watching and explaining. At L2 they propose changes your team approves. At L3 they make reversible changes on their own and leave a receipt. Only areas that have earned it reach L4, and any area can be dialled back. Two locks hold at every level: ChatGPT's Action control and confirmation prompt decide whether ChatGPT may call a tool, and the per-domain guardrail decides whether the change may run. No agent approves its own work.
Why doesn't ChatGPT do this itself?
Focus and risk. OpenAI built a general assistant for every team in the company, and it made sensible choices for that job. ChatGPT is the client. The systems behind it belong to other vendors and to your data team. OpenAI's own apps are search-only, its documentation puts responsibility for what a custom app does on the admins who publish it, and its rollout guidance says to start with read actions and document a recovery path before enabling writes.
That is the right design for a product sold to every department. Changing production data across Snowflake, dbt, Airflow and Fivetran is a different product. It needs to know which models, dashboards and consumers a change touches before it runs, approvals routed to the people who own each model, rollback, verification against the source and a receipt an auditor can read. It also carries responsibility for changes inside systems OpenAI doesn't run. ChatGPT ships the gate. Data Workers is the product on the other side of it.
How it fits with ChatGPT Enterprise
- •Your admins stay in charge of ChatGPT. Data Workers is published as one custom app, read actions first, to the roles you choose. New tools appear only after an admin reviews and enables them. Custom MCP apps with write actions are rolling out in beta to ChatGPT Business, Enterprise and Edu, and Data Workers is built for that path.
- •Your warehouse permissions stay the lock. Every change goes through the grants you give Data Workers. There's never a second permission system.
- •The Data agent keeps its job. People keep asking
@Dataand building dashboards. Data Workers keeps the definitions and tables it reads correct and current. - •Private networks stay private. A deployment inside your network reaches ChatGPT through OpenAI's Secure MCP Tunnel, with no inbound ports.
- •Nothing is migrated. Data Workers stores metadata and scrubbed facts about your data, not your tables.
The practitioner version, with the admin steps and a request run end to end from L0 to L4, is You're on ChatGPT Enterprise. The wider view across assistants is Your company just rolled out AI assistants. Now what?
When you don't need Data Workers
- •Your people use ChatGPT for writing, research and code, and rarely ask it about company numbers.
- •Your estate is one warehouse with no dbt, orchestration or BI layer in the critical path.
- •Your data team isn't the bottleneck.
If all three are true, keep your budget. If any of them isn't, the rest of this guide is about you.
The case for your CFO
The outcome. The company already pays for ChatGPT Enterprise seats, and the Data agent put the warehouse in front of every one of them. With Data Workers underneath, those seats answer from governed definitions and correct tables, so revenue, pipeline and cost figures are right before finance and the board read them.
The risk story. Agents start by watching. Each area earns the right to propose, then to make reversible changes, on its own record. ChatGPT's Action control and confirmation sit in front of every write, the per-domain guardrail sits behind, and anything irreversible needs a named person's approval. Every receipt records who or what acted, why, what it touched and how to undo it. There is zero migration. Our safety guide and security and deployment guide go deeper.
Why now. Self-serve analysis is live across the company, so a wrong number no longer reaches one analyst; it reaches every seat that asks. The choice is one governed app for the whole workspace or each team wiring its own, which is the trade-off in build it ourselves with Claude Code and MCP servers.
The first win. A read-only Data Workers app for the data team that answers "why does this number look wrong?" with lineage, owner, definition and open incidents, followed by one write class in one domain.
What stays the same. ChatGPT seats, Workspace settings, the Compliance API, your warehouse permissions, your dbt review process and your dashboards. The path is a pilot, and the pilot is credited in full against the first year. The ROI guide shows how to size it.
The sentence to repeat upstairs: we already gave everyone ChatGPT; Data Workers makes sure what it tells them is right, and fixes the data when it isn't, with an approval and a receipt.
Where to start
Pick one domain where @Data questions already hit the warehouse, such as sales pipeline or revenue. Most teams start with "where does this number come from?" answered from governed lineage, then overnight fixes to failed loads in that domain made reversibly.
Start with a pilot. A forward-deployed engineer connects your estate and runs the first areas alongside your team, so you see results on your own data before you commit. See pricing for how the pilot works.
If your architects want the detail, send them You're on ChatGPT Enterprise. The four products that do the work: Data Context Wizard keeps one governed graph of definitions, owners and lineage across your warehouse, dbt, orchestration and BI; the Data-Agents Swarm makes the changes; the Autonomous Data-Conductor runs each fix from detection to a verified result; and Spellbook Data Catalog (in preview) is where your team approves, audits and rolls back. The thinking behind them is in our thesis.
Sources
- •OpenAI, ChatGPT Enterprise product page, checked Oct 2, 2026: https://chatgpt.com/business/enterprise/
- •OpenAI, "Now everyone can put data to work" (Data agent launch, Sept 10, 2026), checked Oct 2, 2026: https://openai.com/index/put-data-to-work/
- •OpenAI Help Center, Using the Data plugin in ChatGPT Work and Codex, checked Oct 2, 2026: https://help.openai.com/en/articles/20001518-using-the-data-plugin-in-chatgpt-work-and-codex
- •OpenAI Help Center, Developer mode and MCP apps in ChatGPT, checked Oct 2, 2026: https://help.openai.com/en/articles/12584461-developer-mode-and-mcp-apps-in-chatgpt
- •OpenAI Help Center, Admin controls, security, and compliance for plugins and apps, checked Oct 2, 2026: https://help.openai.com/en/articles/11509118-admin-controls-security-and-compliance-for-plugins-and-apps
- •OpenAI, Plugin controls for Business and Enterprise, checked Oct 2, 2026: https://learn.chatgpt.com/docs/enterprise/apps-and-connectors
- •OpenAI developer docs, Secure MCP Tunnel, checked Oct 2, 2026: https://developers.openai.com/api/docs/guides/secure-mcp-tunnels
- •OpenAI, Compliance API and audit events, checked Oct 2, 2026: https://learn.chatgpt.com/docs/enterprise/compliance-api