ChatGPT logoChatGPTby OpenAI
Govern · ChatGPT

ChatGPT, governed at the paste and at the gateway.

ChatGPT Enterprise connects to Drive, SharePoint, GitHub and Slack, browses the web in agent mode, and runs custom GPTs with actions against your APIs. BrowserShield stops company data at the paste. The gateway decides every GPT action that reaches your systems. Your people keep ChatGPT.

Enforced on the browserBrowserShieldearly accessCompany data stopped at the paste. Employees keep their tools. Only the leak stops.
0
sensitive pastes through, at the paste
<30ms
per-action verdict at the gateway
1:1
a named person behind every governed action
1
policy across every ChatGPT account in use

How Agen governs ChatGPT

  • BrowserShield recognises API keys, credentials and sensitive data as they are pasted or uploaded into ChatGPT and blocks the paste. The rest of the session continues, and the person sees why.
  • Every ChatGPT surface in use, the enterprise workspace, personal accounts and custom GPTs, becomes visible in the Agen.co console with the person behind each one, before any of it is in an incident report.
  • Custom GPT actions, MCP connectors and agent tasks that reach your systems go through the gateway, where every call is decided in-line against the identity behind it, in under 30ms.
  • A custom GPT that acts on your systems gets a named owner. Above-policy actions pause for that owner, and the record shows who decided.
  • Workspace admin controls, SSO and the Compliance API stay as configured. Agen adds the verdict at the paste and at the gateway, and the record of both.
What ChatGPT reaches

A chat window with your company's documents behind it.

In an enterprise workspace, ChatGPT is connected to the systems your people already sign in to. These are the things it can reach.

Connectors
Google Drive, SharePoint, OneDrive, GitHub, Slack, Dropbox and more, searched and read inside OpenAI's cloud with the connecting user's permissions.
Agent mode
Browses websites, fills forms and completes tasks in a hosted browser, including on sites where the user is signed in.
Custom GPTs with actions
Calls external APIs defined by whoever built the GPT, with whatever credentials were configured in it.
Deep research
Runs long, multi-source research across connected data and the web, and writes the results into the conversation.
Uploads and pastes
Anything a person pastes or uploads becomes model context: contracts, customer records, source code, keys.
Codex and canvas
Delegates coding tasks to repositories and edits documents and code in place.
Where the native controls stop

Admin controls govern the workspace. Not the paste, and not the action.

ChatGPT Enterprise ships real admin tooling, and it should stay on. It cannot see what a person pastes, and it cannot judge what a GPT action does to your systems.

01

The paste is the leak

Company data pasted into any AI tool leaves no trace in any log. Workspace policy sees a seat, not a paste. Blocking chatgpt.com at the proxy moves the paste to a phone.

visibility at the pastenone
02

Personal accounts and custom GPTs nobody catalogued

The workspace is the governed account. The personal account on the same laptop, and the GPT a team built with an API key inside it, are not on any list.

accounts in useunknown
03

Actions run as the person, with no per-action owner

A custom GPT action or an agent-mode task acts on the user's sessions and credentials. The workspace log shows a user and a conversation, not who is accountable for the action.

accountable owner per actionnone
04

The Compliance API records conversations, not verdicts

You can export what was said. You cannot show an auditor which pastes were stopped, which actions were judged, against which policy, and what was decided.

per-action verdict lognone
How Agen governs it

Stop the leak in the browser. Decide the action at the gateway.

The gateway decides. Shield enforces where the gateway cannot see. For ChatGPT that means BrowserShield at the paste, and the gateway on every GPT action that reaches your systems.

01 · Discover
See every ChatGPT in use
BrowserShield surfaces every workspace, personal account and custom GPT your people actually use, with the person behind each one.
02 · Identify
Tie each paste and action to a person
Pastes resolve to the person from your IdP. A custom GPT or agent that acts on your systems becomes a governed principal with a named owner.
03 · Govern
Block the paste, judge the action
Keys and sensitive data are stopped at the paste. GPT actions, MCP connectors and agent tasks reaching your systems are decided at the gateway per action, in under 30ms.
04 · Evidence
Record the chain
Every stopped paste and every gateway verdict logged with person, target and decision. Exported to your SIEM. Produced at action time.
Shield

The gateway decides. Shield enforces where the gateway cannot see.

For ChatGPT the leak is the paste, so BrowserShield does the work. AgenShield covers the ChatGPT desktop app and Codex on managed devices with the same policy.

AS
On the device
AgenShield

Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.

AgenShield · ChatGPT desktop · mbp-221blocked
Actionupload · customer-export.csv
Stoppedon device, before execution
Verdict27ms · logged
AgenShield in depth →
BS
In the browser
BrowserShield early access
Primary for ChatGPT

Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.

BrowserShield · chatgpt.compaste blocked
Detectedcompany API key in paste
Everything elseflows normally
Verdictlogged · same audit chain
Join the early-access program →
Same policy · same identity · same verdictShield overviewHow the gateway decides
Governed actions

What ChatGPT asks to do, and what policy says.

Illustrative verdicts for common ChatGPT actions under a typical policy. Paste rows are BrowserShield. Action rows are the gateway.

Typical per-action verdicts for ChatGPT
ChatGPT actionVerdictWhy
Ask a question with no company data in the promptallowNothing sensitive in the paste. The tool in use is recorded, the person keeps working.
Paste an API key or access token into a promptdenyRecognised at the paste and blocked before it leaves the tab. The person sees why.
Upload a customer export containing personal datadenyRecognised at the upload and blocked. The person is pointed to a governed path.
Use a personal ChatGPT account with company datadenyOutside the governed workspace. Blocked at the paste, the person is pointed to the enterprise account.
Custom GPT action reads an internal API through the gatewayallowScoped to the GPT's grant and the person behind it. Logged, not interrupted.
Custom GPT action writes to a production systemstep-upThe GPT's named owner confirms from their phone. Approved, policy remembers.
MCP connector queries a customer databasemaskThe query runs. Personal data is masked at the gateway before it enters the model context.
Agent task calls an MCP server not on the approved listhuman-in-the-loopA new door. The owner reviews it once, then policy remembers the answer.

Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.

Book a demo

See ChatGPT governed, live.

Thirty minutes on the way your teams already use ChatGPT. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.

length30 minutes
formatlive, on your ChatGPT setup
you seeevery action decided at runtime
Watch it happen

An API key heads for ChatGPT. It never leaves the tab.

A RevOps analyst pastes a block of config into chatgpt.com to ask a question. BrowserShield recognises a company API key in the paste and blocks it. The rest of the session continues.

blocked at the paste · live product scene
From connect to governing

ChatGPT does not change. Neither does your workspace.

Your admin settings, SSO and connectors stay exactly as they are.

Day 1
Connect the gateway and your IdP
GPT actions and MCP connectors that reach your systems route through the gateway. Every action resolves to a person through Okta, Entra or any OIDC provider.
Day 1
Join BrowserShield early access
BrowserShield is running with design partners now. It deploys to managed browsers through the MDM you already have.
Week 1
Run observe-only
See which accounts, GPTs and connectors are actually in use across the company, including the personal accounts, before enforcing anything.
Week 2
Turn on the policies that matter
Start with secrets at the paste, personal accounts and production writes. People only notice the crossing action.
The platform

Discover, Govern, Shield. One policy plane.

The same three capabilities govern ChatGPT and every other agent you run, internal and external.

Expand a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

FAQ

Questions, answered.

Does Agen replace ChatGPT Enterprise admin controls?
No. Keep SSO, workspace policies and the Compliance API. They govern the workspace. Agen stops the leak at the paste, decides GPT actions at the gateway, and records both.
Does this block people from using ChatGPT?
No. Guardrails, not blanket blocks. People keep using ChatGPT. Only the leaking paste or out-of-policy action stops, and the person sees why.
Can Agen govern ChatGPT's built-in connectors to Drive or SharePoint?
Those reads happen inside OpenAI's cloud between OpenAI and the source, so no browser or gateway sits in that path. Agen surfaces which connectors are attached and to whom. Per-action verdicts apply at the paste and to every action that reaches your systems through the gateway.
How are custom GPT actions governed?
An action that reaches your systems is decided at the gateway, tied to the GPT's named owner. A GPT without an owner is surfaced by discovery so one can be assigned.
Is BrowserShield generally available?
Early access. It is running with closed-beta design partners today. Ask about joining the program.

Govern ChatGPT without taking it away.

Company data stopped at the paste, GPT actions decided at the gateway, a named person behind every one.