You're on ChatGPT Enterprise: Connect Data Workers Over MCP So Every Answer Comes From Governed Data
Already on ChatGPT Enterprise? Publish Data Workers as a custom MCP app so ChatGPT answers from governed context and fixes data through approvals and receipts.
Your company bought ChatGPT Enterprise, and the workspace is busy. IT owns Workspace settings, a short list of plugins and apps is enabled under Admin > Plugins, custom roles decide who sees what, and the Compliance API makes conversations available for audit. Since September 10 the Data agent in ChatGPT Work has put your warehouse one @Data mention away from every seat: sales leaders ask why pipeline moved, finance asks for a variance readout, and ChatGPT queries Snowflake or Databricks, reads your semantic layer and builds a dashboard you can publish with ChatGPT Sites. ChatGPT Enterprise is where everyone asks. Data Workers is the data team's crew under the answer: connected as a custom MCP app, it answers from one governed context graph and does the real data work (fix, rerun, verify) through ChatGPT's own confirmation prompt, a named approver and a receipt.
OpenAI's Data agent launch post credits its own data team with making the agent work internally, by creating shared business definitions, setting access rules and putting safeguards in place for sensitive data. That is the job this guide is about. Data Workers is the agentic data platform that does that work for your data team, across every system, on top of the ChatGPT rollout you already have.
Key takeaways
- •ChatGPT Enterprise keeps its job. Seats, Workspace settings, RBAC, the Data agent and the Compliance API stay as they are. Data Workers plugs in as one more app your admins publish and govern.
- •Answers come from governed context. ChatGPT reads metric definitions, lineage, owners, freshness and open incidents from one context graph, so sales and finance get the same number for the same question, and breaks are fixed overnight before anyone asks.
- •Fixes run through two locks. ChatGPT asks before write actions, and Data Workers routes each change to a named approver in Spellbook with its blast radius. Every change is reversible and leaves a receipt.
- •Setup is a short admin task. Create a custom app with the Data Workers MCP endpoint, sign in through your own identity provider, enable read actions, publish to the data team's role, and add write actions one domain at a time.
- •Start with a pilot. Read-only first, then one write class in one domain, on the ladder from L0 manual to L4 autonomous.
ChatGPT Enterprise is where everyone asks. Data Workers is the data team's crew under the answer.
ChatGPT Enterprise has become the front door for data questions. The Data agent (listed as the Data plugin) connects to Amazon Redshift, ClickHouse, Databricks, Google BigQuery, MongoDB, Snowflake, Datadog and more, uses business context from semantic layers, dbt, Snowflake Horizon, Databricks Genie Ontology and BI dashboards, and works with dashboards in Tableau, Power BI, Sigma, ThoughtSpot, Omni and Oracle BI. Queries run with the connected account's table, row and column permissions. That is a strong analysis surface, and it raises the stakes on the data underneath: when the number in Snowflake is wrong, every seat sees the wrong number at once.
Here is a Monday morning with Data Workers connected. This is an illustration, not a customer case.
| Time | System | What happens |
|---|---|---|
| 01:10 | Salesforce | A sales ops admin splits the EMEA region picklist value into EMEA North and EMEA South |
| 01:30 | Fivetran | The sync lands the new picklist values in Snowflake |
| 02:00 | Airflow + dbt | The nightly DAG run succeeds; fct_pipeline maps regions from an accepted list, so the new values land as null |
| 02:20 | Data Workers | The null-rate check on fct_pipeline.region fails; Data Workers traces it through lineage to the picklist change and opens an incident |
| 08:05 | ChatGPT Enterprise | The VP of Sales asks ChatGPT, with the Data Workers app selected, why EMEA pipeline fell 18% this week |
| 08:06 | Data Workers | The answer comes back from governed context: EMEA pipeline is flat; 14% of opportunities lost their region at 02:00; here is the open incident, the definition used and the owner |
| 08:09 | ChatGPT Enterprise | The VP asks for the fix; ChatGPT shows the tool input and asks to confirm the write action |
| 08:10 | Data Workers | Data Workers proposes a dbt diff mapping both new values to EMEA, with its blast radius: three models and two Tableau dashboards |
| 08:40 | Spellbook | The analytics engineer who owns the model reviews the diff and approves; dbt CI passes |
| 08:45 | Airflow | Data Workers reruns the DAG for the affected partitions |
| 09:05 | Snowflake | The null check passes with zero null regions; EMEA totals are back on their baseline |
| 09:10 | Tableau | The pipeline dashboard refreshes before the 10:00 forecast call; ChatGPT's next answer cites the receipt |

ChatGPT did its job: it read the table it was given, and the table really did show a drop. What changed is that the data team's crew was already on the break at 02:20, and the fix went through the same chat the question came from, with one confirmation, one approval and one receipt.
| Job | What ChatGPT Enterprise does | What Data Workers does |
|---|---|---|
| The question | Takes it in plain language from any seat | Supplies the governed definition, lineage, owner and freshness behind the answer |
| The analysis | Queries the warehouse, explains what changed, builds and publishes dashboards | Makes sure the tables and metrics it reads are correct and current |
| The context | Reads business definitions from semantic layers, dbt and trusted dashboards | Keeps one context graph across every platform current, with provenance |
| The break | Reports what the data says | Detects the break, traces the cause across Salesforce, Fivetran, dbt and Snowflake |
| The fix | Asks the user to confirm the write action | Proposes the change with its blast radius, routes it to a named approver, applies it reversibly |
| The proof | Logs the conversation and app requests to the Compliance API | Verifies downstream with checks and baselines on the changed tables and writes a receipt for the change |
| Access | Enforces RBAC on apps and actions in the workspace | Proposes and applies grants on the data platforms by policy |
Why doesn't ChatGPT Enterprise just do this itself?
Because OpenAI built a general assistant for every team in the company, and it made sensible choices for that job. ChatGPT is the client. The systems behind it belong to other vendors and to your data team, and OpenAI's own documentation puts the responsibility for what an app does on the people who publish it: admins are "responsible for verifying the MCP server and app are safe and appropriate" before publishing, OpenAI-built apps are search-only, and the rollout guidance says to start with read actions and, before enabling writes, document "external effects and a recovery path".
That is the right design for a product sold to every department. Writing to production data across Snowflake, dbt, Airflow and Fivetran is a different product category. It needs blast-radius scoping across systems ChatGPT doesn't run, approvals routed to the people who own each model, rollback for every change class, receipts that tie a change to its cause, and liability for what happens inside tools OpenAI doesn't own. ChatGPT gives you the gate: Action control, App permissions, risk warnings and a confirmation before writes. Data Workers is the trusted app on the other side of that gate: it knows what the write will touch and how to undo it, so ChatGPT can stay a fast, general front door.
Every tool owns a slice. Data Workers covers the whole lifecycle
ChatGPT Enterprise owns one slice of the data lifecycle, and owns it well: answering questions and analysing data for every employee. Each point tool adds another console, contract and handoff. Data Workers covers the whole lifecycle with one context, one approval flow and one audit trail, and builds on ChatGPT where your people already work.

| Stage | Data Workers | ChatGPT Enterprise | Why we scored it this way |
|---|---|---|---|
| Catalog & Context | 9 | 5 | The Data agent reads business context from semantic layers, dbt, Snowflake Horizon and Genie Ontology, and company knowledge searches connected apps. Data Workers builds and maintains one governed context graph across every platform. |
| Analytics & Insights | 8 | 9 | ChatGPT Enterprise's home stage: the Data agent (launched Sept 10, 2026) queries the warehouse, explains what changed and builds dashboards. Data Workers' Insights agent answers too, through governed metric definitions. |
| Data Quality | 8 | 2 | OpenAI's Data plugin guide asks users to check the source, filters and metric definition before relying on a result. Data Workers writes, runs and repairs the checks behind those results. |
| Observability & Incidents | 8.5 | 2 | ChatGPT can read an alert through a connected app. Data Workers detects the break, traces it across systems, fixes it and verifies the result. |
| Pipelines & Ingestion | 8.5 | 3 | Codex in ChatGPT Enterprise can write pipeline code for review. Data Workers builds, reruns and backfills pipelines behind approvals and verifies the output. |
| Schema & Migration | 8 | 3 | Codex can draft a migration in a pull request. Data Workers catches upstream schema changes in the dbt manifest and in review, assesses impact and drafts each migration with rollback SQL for the owner to apply. |
| Governance & Access | 8.5 | 6 | Strong over its own workspace: RBAC, Action control, App permissions, and queries that respect the connected account's table, row and column rules. Data Workers proposes and applies grants on your data platforms by policy. |
| Security & Privacy | 8 | 6 | Strong for its own content: no training on business data by default, encryption in transit and at rest, and the Compliance API. Data Workers flags sensitive column names in pull request review and proposes masking for the owner. |
| Cost / FinOps | 8 | 2 | ChatGPT Enterprise reports its own workspace usage and credits. Data Workers traces Snowflake credits to the dbt model behind them and drafts the fix for its owner. |
| MLOps & Models | 7.5 | 3 | ChatGPT Enterprise runs OpenAI's models; training and monitoring your own models is a different job. Data Workers keeps the data under your models healthy and connects to MLflow and W&B. |
How ChatGPT Enterprise and Data Workers work together
ChatGPT stays on top, where people ask, analyse and confirm. Spellbook Data Catalog (in preview) is where the data team looks: each proposed change, who approved it, what it touched and how to roll it back. Between them run four layers: Context Wizard keeps one governed context graph, the Data-Agents Swarm does the work with more than 20 specialist agents, the Autonomous Data-Conductor runs each fix end to end (detect, diagnose, fix, review, verify, remember), and per-domain guardrails hold approvals, receipts and rollback.

Setup in ChatGPT Enterprise. Every Data Workers agent is an MCP server, and the same tools are served over Streamable HTTP for remote clients like ChatGPT. ChatGPT connects to remote MCP servers, so a deployment inside your network reaches it through OpenAI's Secure MCP Tunnel, an outbound-only client that needs no inbound firewall ports. Full MCP support, including write actions, is rolling out in beta to ChatGPT Business, Enterprise and Edu on the web.
Sign-in runs through your own identity provider, such as Okta or Microsoft Entra ID. ChatGPT supports OAuth for custom apps; your provider is the authorization server, and Data Workers' remote endpoint runs in OAuth mode, verifying every access token's signature, issuer and audience against your provider's published keys. Users sign in with the identity they already have, and tokens refresh at your provider. The admin steps, using OpenAI's names this month:
- •In Workspace settings > Permissions & roles > Connected Data, grant developer mode to the admins or data platform engineers who will build the app.
- •In your identity provider, register ChatGPT as an OAuth client for the Data Workers endpoint and turn on refresh tokens (
offline_access) so the connection doesn't lapse. - •In Workspace settings > Apps, choose Create, enter the Data Workers endpoint, pick OAuth, complete the sign-in prompt and select Scan Tools.
- •Test the draft app in a chat: ask a read question, then try one write tool and watch ChatGPT ask for confirmation.
- •Publish. In Configure Actions, enable read actions only; in Configure Access, choose the data team's group. In Action control, set New actions to Disable new actions, and later enable one write class for one domain.
Example: ChatGPT Enterprise custom app for Data Workers
Name: Data Workers
MCP server URL: https://<your-data-workers-host>/mcp (Streamable HTTP)
Authentication: OAuth through your IdP (Okta, Entra ID); offline_access on
Token check: Data Workers verifies IdP-signed tokens (issuer, audience, keys)
Private network: Secure MCP Tunnel; tunnel-client runs inside your VPC
Actions: read actions on publish; one write class per domain later
Access: custom role "Data team", then wider roles for readOnce published, ChatGPT uses a frozen snapshot of the app's tools. When Data Workers adds capabilities, your admin selects Refresh, reviews the diff and enables the new actions on purpose, so the tools ChatGPT can call change only when someone decides they should.
One request end to end, L0 to L4. The autonomy ladder is set per domain, and it maps directly onto ChatGPT's own controls.

- •L0 manual. ChatGPT drafts SQL or a dbt change; your team runs and reviews everything by hand.
- •L1 observe. Read actions only. Ask "why did EMEA pipeline drop?" and Data Workers resolves the metric definition, walks lineage, checks load lag against its baseline and lists open incidents. Set App permissions to Allow read actions so reads don't prompt every time.
- •L2 propose. Enable the proposal tools. Ask for the fix, confirm the write in ChatGPT, and Data Workers proposes a dbt diff with its blast radius. Nothing reaches production until the owner approves in Spellbook and CI passes.
- •L3 act reversibly. For change classes with a proven record, such as reruns and backfills of failed partitions, Data Workers applies the change after confirmation, re-runs the checks on the changed tables, with the undo recorded before it runs.
- •L4 autonomous. For a scoped domain like freshness failures in the sales marts, Data Workers fixes overnight without waiting for a question, and ChatGPT's morning answers can cite the receipt.
Each step up is a per-domain decision backed by receipts, and you can step back down any time. For the safety model, read is it safe to let AI agents change production data, and for where data and credentials live, read where does our data go.
The same Data Workers server serves other assistants and coding agents, so there is no second integration when engineering works in Codex or another team uses Claude. See you're on Codex, you're on Claude, you're on Microsoft 365 Copilot and the hub, AI assistants are rolled out, now what. For the warehouse and modelling side, read Data Workers on Snowflake and Data Workers + dbt.
What changes for your team
ChatGPT Enterprise gave every employee an analyst. Data Workers gives the data team a crew, so questions from every seat don't turn into a queue of "is this number right?" tickets.

- •Incidents. Breaks are traced, fixed and verified overnight, so the first person to ask ChatGPT in the morning gets the right number.
- •Data quality. Every break that reached a ChatGPT answer becomes a check or a dbt test, so the same failure is caught upstream next time.
- •Cloud spend. Snowflake credits are traced to the query and dbt model behind them, and each fix goes to its owner drafted.
- •Access. "Can I see the margin table?" typed into ChatGPT becomes a time-boxed grant proposal to the data owner, with the policy that justifies it.
- •Audits. ChatGPT's Compliance API holds the conversation. Data Workers holds the other half: who changed what in the data, why, and how to undo it.
- •Migrations. Platform moves run in approved, parity-checked waves while ChatGPT answers keep working against the same governed definitions.
Analytics engineers stop answering the same reconciliation question in five Slack threads and spend the week on models and definitions only they can write.
Keep ChatGPT Enterprise, or consolidate?
Keep ChatGPT Enterprise if you love it; Data Workers works with it from day one. Many teams consolidate once Data Workers runs that slice too.
For most companies the right answer is to keep it: it is where your people already work, the Data agent is a strong analysis surface, and your admin model is in place. Data Workers adds the slice ChatGPT leaves to the server it calls: governed context, quality, incident repair, change control and evidence across the estate. Where teams consolidate, it is usually a duplicate data assistant or a separate data-quality and observability stack, now that Data Workers runs those jobs and answers through ChatGPT anyway. If you are weighing building this layer yourself, read build it ourselves with Claude Code and MCP servers: the MCP endpoint is the easy part; the context graph, approvals and rollback are where the work is.
The case for your CFO
The outcome: the company already pays for ChatGPT Enterprise seats, and Data Workers makes the answers those seats give about the business correct, current and auditable. Every decision made from a ChatGPT dashboard rests on the data under it.
The risk story has two locks. ChatGPT's admins decide which Data Workers actions exist (Action control) and when ChatGPT asks first (App permissions). Data Workers sets autonomy per domain from L0 manual to L4 autonomous, routes each change to a named approver, applies it reversibly, verifies it downstream and writes a receipt: who approved it, what it touched, how to undo it. There is zero migration: your warehouse, dbt project, orchestration and BI stay where they are.
Why now: the Data agent put self-serve analysis in front of every employee, so a wrong number no longer reaches one analyst; it reaches every seat that asks. The first win is a read-only app for the data team that answers "why does this number look wrong?" with lineage, owner, definition and open incidents, then one write class in one domain. What stays the same: ChatGPT seats, the admin console, the Compliance API, warehouse permissions and your dbt review process. For the numbers, see the ROI of agentic data operations, and for a version written for the data leader, the ChatGPT Enterprise data leaders guide.
The sentence to repeat upstairs: "We already gave everyone ChatGPT; Data Workers makes sure what it tells them is right, and fixes the data when it isn't, with an approval and a receipt."
Getting started
Start with a pilot. Pick one domain where ChatGPT questions already hit the warehouse, such as sales pipeline or revenue, publish the Data Workers app read-only to the data team's role, and run it for a few weeks before enabling the first write class. The pilot path and plans are on the pricing page, and the pilot is credited in full against the first year.
FAQ
Doesn't the ChatGPT Data agent already do this? The Data agent analyses data, builds dashboards and reads business definitions from your semantic layer and trusted sources. It works from the data and definitions it is given. Data Workers keeps those correct: it maintains the governed context, catches and fixes breaks, and verifies the result.
Is it safe to let ChatGPT trigger writes to our data platform? Writes pass two locks. In ChatGPT, admins enable each write action deliberately and ChatGPT asks for confirmation. In Data Workers, each change has a blast radius, a named approver in Spellbook, a rollback path and a receipt, with autonomy set per domain.
Whose credentials does Data Workers use? Users sign in through your identity provider, and Data Workers verifies each token before any tool runs. It then acts on the warehouse, dbt and orchestration with the credentials you configure per connection, scoped to each domain, and its guardrails decide what each agent may change. Warehouse permissions stay the system of record, by design.
Our warehouse is in a private network. How does ChatGPT reach Data Workers? Run Data Workers inside your network and connect it through OpenAI's Secure MCP Tunnel. The tunnel client opens an outbound HTTPS path to OpenAI, so the server needs no public endpoint or inbound firewall rule.
What shows up in the audit trail? Two complementary records. The Compliance API covers ChatGPT conversations, including those that use apps. Data Workers' receipts cover the change itself: the cause, the diff, the approver, the verification and the rollback path.
Does this replace our semantic layer or catalog? No. Your dbt Semantic Layer, Snowflake semantic views or catalog stay the source of definitions. Data Workers' Context Wizard reads them into one governed graph with lineage, quality and usage, and serves that graph to ChatGPT and every other assistant you use.
Sources
- •OpenAI, ChatGPT Enterprise product page, https://chatgpt.com/business/enterprise/ (checked Oct 2, 2026)
- •OpenAI, "Now everyone can put data to work" (Data agent launch, Sept 10, 2026), https://openai.com/index/put-data-to-work/ (checked Oct 2, 2026)
- •OpenAI Help Center, Using the Data plugin in ChatGPT Work and Codex, https://help.openai.com/en/articles/20001518-using-the-data-plugin-in-chatgpt-work-and-codex (checked Oct 2, 2026)
- •OpenAI Help Center, Developer mode and MCP apps in ChatGPT, https://help.openai.com/en/articles/12584461-developer-mode-and-mcp-apps-in-chatgpt (checked Oct 2, 2026)
- •OpenAI Help Center, Admin controls, security, and compliance for plugins and apps, https://help.openai.com/en/articles/11509118-admin-controls-security-and-compliance-for-plugins-and-apps (checked Oct 2, 2026)
- •OpenAI developer docs, ChatGPT developer mode, https://developers.openai.com/api/docs/guides/developer-mode (checked Oct 2, 2026)
- •OpenAI Apps SDK, Authentication, https://developers.openai.com/apps-sdk/build/auth (checked Oct 2, 2026)
- •OpenAI developer docs, Secure MCP Tunnel, https://developers.openai.com/api/docs/guides/secure-mcp-tunnels (checked Oct 2, 2026)
- •OpenAI, Plugin controls for Business and Enterprise, https://learn.chatgpt.com/docs/enterprise/apps-and-connectors (checked Oct 2, 2026)
- •OpenAI, Roles and workspace permissions, https://learn.chatgpt.com/docs/enterprise/roles-and-workspace-permissions (checked Oct 2, 2026)
- •OpenAI, Compliance API and audit events, https://learn.chatgpt.com/docs/enterprise/compliance-api (checked Oct 2, 2026)
- •Data Workers agent swarm repository: MCP servers, remote Streamable HTTP transport and its OAuth token verification, agents (checked Oct 2, 2026)