The paste is the leak
Company data pasted into any AI tool leaves no trace in any log. Workspace policy sees a seat, not a paste. Blocking chatgpt.com at the proxy moves the paste to a phone.
ChatGPT Enterprise connects to Drive, SharePoint, GitHub and Slack, browses the web in agent mode, and runs custom GPTs with actions against your APIs. BrowserShield stops company data at the paste. The gateway decides every GPT action that reaches your systems. Your people keep ChatGPT.

In an enterprise workspace, ChatGPT is connected to the systems your people already sign in to. These are the things it can reach.
ChatGPT Enterprise ships real admin tooling, and it should stay on. It cannot see what a person pastes, and it cannot judge what a GPT action does to your systems.
Company data pasted into any AI tool leaves no trace in any log. Workspace policy sees a seat, not a paste. Blocking chatgpt.com at the proxy moves the paste to a phone.
The workspace is the governed account. The personal account on the same laptop, and the GPT a team built with an API key inside it, are not on any list.
A custom GPT action or an agent-mode task acts on the user's sessions and credentials. The workspace log shows a user and a conversation, not who is accountable for the action.
You can export what was said. You cannot show an auditor which pastes were stopped, which actions were judged, against which policy, and what was decided.
The gateway decides. Shield enforces where the gateway cannot see. For ChatGPT that means BrowserShield at the paste, and the gateway on every GPT action that reaches your systems.
For ChatGPT the leak is the paste, so BrowserShield does the work. AgenShield covers the ChatGPT desktop app and Codex on managed devices with the same policy.
Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.
Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.
Illustrative verdicts for common ChatGPT actions under a typical policy. Paste rows are BrowserShield. Action rows are the gateway.
| ChatGPT action | Verdict | Why |
|---|---|---|
| Ask a question with no company data in the prompt | allow | Nothing sensitive in the paste. The tool in use is recorded, the person keeps working. |
| Paste an API key or access token into a prompt | deny | Recognised at the paste and blocked before it leaves the tab. The person sees why. |
| Upload a customer export containing personal data | deny | Recognised at the upload and blocked. The person is pointed to a governed path. |
| Use a personal ChatGPT account with company data | deny | Outside the governed workspace. Blocked at the paste, the person is pointed to the enterprise account. |
| Custom GPT action reads an internal API through the gateway | allow | Scoped to the GPT's grant and the person behind it. Logged, not interrupted. |
| Custom GPT action writes to a production system | step-up | The GPT's named owner confirms from their phone. Approved, policy remembers. |
| MCP connector queries a customer database | mask | The query runs. Personal data is masked at the gateway before it enters the model context. |
| Agent task calls an MCP server not on the approved list | human-in-the-loop | A new door. The owner reviews it once, then policy remembers the answer. |
Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.
Thirty minutes on the way your teams already use ChatGPT. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.
A RevOps analyst pastes a block of config into chatgpt.com to ask a question. BrowserShield recognises a company API key in the paste and blocks it. The rest of the session continues.
Your admin settings, SSO and connectors stay exactly as they are.
The same three capabilities govern ChatGPT and every other agent you run, internal and external.
Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.
Company data stopped at the paste, GPT actions decided at the gateway, a named person behind every one.