Setting up your ChatGPT Business account
A step-by-step guide for small law firms.
You bought ChatGPT Business, or you're about to. This guide walks through every screen in Workspace settings that matters for a law firm, in the order the console shows them, with my recommendation for each setting. No technical background required. Plan on about an hour for a clean first setup, plus a few minutes per person for the apps.
ChatGPT Business is the plan OpenAI called ChatGPT Team until August 2025. I built this guide on September 28, 2026 by walking through a live Business workspace screen by screen, because the console no longer matches parts of OpenAI's own help articles. Everything I describe from the console is what I observed on September 28, 2026 in the Business workspace I reviewed. OpenAI rolls changes out gradually, so yours may not match exactly. Where a claim rests on OpenAI's documentation instead, I link to the source next to it. If your firm also uses Claude, I wrote the same walkthrough for Claude Team. The two products make different choices about privacy and sharing, and I point out where that matters.
A note before you start: the person doing the setup should be a workspace Owner. Whoever signed up for the plan is the first Owner. Only an Owner can change roles and seat types, buy seats, and manage identity settings. If that isn't you, find that person before going further.
Five things that surprise law firms
- In a shared project, everyone reads everyone's chats. Every member of a shared project can see every conversation in it and download every file. Claude works the other way.
- The firm can't turn memory off for everyone. In the workspace I reviewed, the firm-wide switch was locked for Enterprise. Each member can manage their own memory, but that's an individual choice, not a firm policy you can enforce. Project-only memory is your main wall between matters (Part 7).
- Several controls are locked. Sharing, memory, web search, code execution, and some Codex settings show in the console but can only be changed on Enterprise.
- The firm has no central way to retrieve chats. Business has no data export, no Compliance API, and no audit log of conversations. Chat retention shows as Infinite, with a note to contact support to change it.
- Every app in OpenAI's directory starts enabled. The Apps page counts them in the thousands. Plan to trim the list.
Settings at a glance
Every setting in this guide, grouped the way Workspace settings groups them, with my call. "On" means turn it on or leave it on. "Off" means turn it off or leave it off. "Your call" means it depends on your firm. "Locked" means the switch shows but Business can't change it.
| Setting | Where | My call |
|---|---|---|
| General | ||
| Workspace name and logo | Branding | On set both |
| Enable task insights | Analytics and reporting | Your call |
| OpenAI-created impact surveys | Analytics and reporting | Off |
| Include user identifiers in impact survey exports | Analytics and reporting | Off |
| Plugin permissions | Workspace policies | Allow read actions |
| Allow response feedback (thumbs) | Workspace policies | Off |
| Chat retention policy | Workspace policies | Ask support for a period |
| Permissions and roles (also listed under General) | ||
| Allow members to use dots | dots | Your call |
| Personal access tokens | Access tokens | Off |
| Access token expiration limit | Access tokens | Set a limit |
| Use Codex and Work locally | Codex and Work Local | Your call pilot first |
| Enable Computer History | Codex and Work Local | Off |
| Discover and control devices remotely | Codex and Work Local | Off |
| Device code sign-in (Codex and Office add-ins) | Codex and Work Local | Off unless sign-in needs it |
| ChatGPT record | Record | Your call consent rule first |
| Reference past notes and transcripts | Record | Off |
| Enable skills | Skills | On |
| Deploy or publish with Sites | Sites | Off unless you have a use |
| Enable agents | Workspace agents | On |
| Codex referrals | Codex referrals | Off |
| Sharing, memory, web search, code execution, Codex Cloud | Various | Locked on Business |
| Identity and access | ||
| Verified domains and SSO | Cloud Console | On |
| Automatic account creation | User Provisioning | Off |
| Allow external domain invites | User Provisioning | Off unless you use contractors |
| Enable workspace discovery | User Provisioning | Off |
| Billing | ||
| Default seat type | Seat preferences | Standard |
| Auto-approve join requests | Seat preferences | Off |
| Monthly usage limits | Billing | Set per seat type |
| Automatic reload | Credits balance | Your call after limits |
| Plugins | ||
| Configure Microsoft permissions | Plugins | Complete it or disable the Microsoft apps |
| Third-party plugins you don't use | Plugins | Off |
| Apps you don't use | Apps | Off |
| Marketplaces | Marketplaces | Only what you trust |
| GPTs | ||
| Third-party GPTs | GPTs | Restrict |
| Allow all domains for GPT actions | GPTs | Off |
| Migrate GPTs you use | GPTs | Before the date in your workspace notice |
| No switch: plan and train | ||
| Project-only memory for every client project | Each project | On |
| Delete shared links when done | Each user | Train people |
| Temporary chat, set to Unpersonalized, for one-off client questions | Each user | On |
Part 1: Confirm your foundation
Step 1.1: Know which workspace you're in
ChatGPT keeps a personal workspace and the firm's Business workspace separate, even when they use the same email address. Anyone who already had ChatGPT Plus or Pro keeps that personal workspace unless they choose to merge it.
- Sign in at chatgpt.com
- On the web, click your name or profile icon; on mobile, open the sidebar
- Pick the firm's workspace from the workspace switcher
- Confirm the firm's name shows at the top of the menu
Why this matters: a personal account runs under OpenAI's consumer terms, where chats can be used to train OpenAI's models unless the user opts out. The Business workspace runs under OpenAI's business terms, and OpenAI doesn't train on it by default. Client work belongs in the firm's workspace every time.
Step 1.2: Decide what happens to personal accounts
When someone accepts an invitation, ChatGPT offers two paths: keep the personal workspace separate, or merge it into the firm's. Merging copies the person's chats, projects, custom GPTs, Library files, saved memories, and custom instructions into the firm's workspace, deactivates the personal one, and cancels a personal subscription bought on the web. There is no undo, and the firm can't force either choice.
My recommendation: keep personal workspaces separate by default. Merge only when someone has been doing firm work in a personal account and the firm wants that history under its terms. Tell people about the choice before the invitation arrives.
Step 1.3: Find Workspace settings
Click your name or profile icon, then Workspace settings. The left sidebar is the map for the rest of this guide:
- Access: General, Members, Groups, Permissions & roles, Identity & access, Access tokens, Trusted Access
- Billing: Billing
- Plugins: Plugins, Apps, Skills, Marketplaces
- Features: GPTs, plus links out to Sites, Agents, and Codex
- Analytics: Workspace analytics
Some switches appear faded. Those are locked on Business; the console labels their sections "Enterprise" with a Contact sales button. They still tell you what's happening in your workspace, so read them.
Part 2: Privacy and confidentiality (do this first)
This is the most important part for a law firm. Your duty of confidentiality under ABA Model Rule 1.6, and your state's version of it, doesn't pause because you're using AI. ABA Formal Opinion 512 (July 2024) is the starting point for the ethics analysis, and many state bars have issued their own guidance since. Get this part right before anyone touches a client matter.
Step 2.1: Know which terms govern the workspace
- OpenAI doesn't train its models on your workspace's data by default.
- Data is encrypted at rest (AES-256) and in transit (TLS 1.2 or higher).
- ChatGPT Business has completed a SOC 2 Type 2 audit. The report is on OpenAI's trust portal.
- A Data Processing Addendum is available for Business. Sign it; it's the document your clients' outside counsel guidelines will ask about.
One gap to know: OpenAI's compliance page lists ISO 27001 and ISO 27701 certification for ChatGPT Enterprise but not for Business. If a client's guidelines require ISO-certified vendors, that's an Enterprise conversation.
Step 2.2: Understand what the firm can and can't see
This is the biggest difference from Claude Team, and it cuts both ways.
- Owners and Admins can't read members' private chats.
- Workspace analytics shows activity counts, credits, and seat types, not what anyone typed.
- Business has no data export, no Compliance API, and no conversation audit log. Those are Enterprise features.
For your lawyers, that's real privacy from the firm. For the firm, it means Business lacks the centralized export and compliance tools you'd reach for in a litigation hold, an internal investigation, or a departure. Other routes still exist (the lawyer's own cooperation, work product saved to your document management system), but they aren't the same as an administrative export. Set up a counsel-directed preservation process before anyone uses ChatGPT on client work, and don't assume that removing a member either deletes or collects their work: OpenAI says a removed member's chats are kept and come back if they're re-added. If central retrieval matters to you, price out ChatGPT Enterprise before you commit.
Step 2.3: Set sensible data minimization rules
- Minimize regulated identifiers. Leave out Social Security numbers, financial account numbers, medical record identifiers, and other regulated data unless the task needs them and your client agreements permit it. Often a redacted version is enough.
- Be careful about pairing identity with strategy. In ChatGPT, every member of a shared project reads every chat. Don't put client names next to candid strategy in a shared project unless everyone in it belongs on the matter.
- Treat ChatGPT inputs like vendor inputs. Anything typed or uploaded is subject to your engagement letter, your privacy policy, and your AI use disclosure. Confirm your engagement letters and outside counsel guidelines permit AI assistance.
Step 2.4: Manage retention
The console shows Chat retention policy set to Infinite, with a note to contact support to change it. OpenAI's help center treats custom retention as an Enterprise feature, so the answer may be no, but the screen invites the question. If your records policy wants chats gone after a set time, ask OpenAI support in writing.
- Until then, chats stay until the user deletes them. Archiving doesn't delete.
- A deleted chat is removed from OpenAI's systems within 30 days unless OpenAI must keep it for legal or security reasons. Nobody can restore it.
- Deleting a chat doesn't delete the files it put in the Library. Delete those separately.
- Temporary chats aren't saved to history and don't create new memories, but OpenAI may keep a copy for up to 30 days for safety. For a one-off client question, choose Temporary, then Unpersonalized before sending the first message. A Personalized temporary chat can still use existing memories and plugins. Unpersonalized also drops custom instructions, so include any drafting instructions yourself. Saving a temporary chat turns it into a regular chat under your normal settings.
- When you remove a member, their chats and files are kept and come back if you re-add them. Their projects and GPTs move to a workspace Owner, but the conversations inside don't.
Write a deletion rule before rollout that fits your records policy and any litigation holds. For example: delete chats that contain client confidences once the work product is saved to the document management system.
Step 2.5: Turn off response feedback
The thumbs-up and thumbs-down buttons send feedback to OpenAI, and OpenAI's enterprise privacy page says data you explicitly share through feedback may be used to train its models. A frustrated associate who rates a bad draft about a real client matter may be sending that conversation along with the rating. Business has a switch for this: turn off Allow response feedback, and have people tell the firm's AI champion instead.
Step 2.6: PHI and HIPAA
ChatGPT Business isn't eligible for a Business Associate Agreement. Holding medical records doesn't by itself make a firm a HIPAA business associate; that depends on whose records they are and for whom you're working. A firm that represents a health plan or provider may be one. Other firms handle medical records in personal injury, workers' compensation, med-mal, disability, and elder law matters without being business associates, but still owe confidentiality. Have counsel determine the firm's role. My conservative recommendation is a firm policy that keeps medical records out of Business unless counsel has cleared a specific use.
Step 2.7: Know where your data is stored
By default, Business data is stored in the United States. OpenAI is rolling out data residency for Business gradually, chosen at checkout. Even with a region outside the US, OpenAI keeps a copy of prompts and responses in the US for a limited time for safety monitoring.
Step 2.8: Decide what clients need to know
ABA Formal Opinion 512 says a lawyer may need a client's informed consent before putting information about the representation into an AI tool, and that boilerplate in an engagement letter isn't enough when consent is required. Decide, for each tool and each kind of use, whether consent is needed, and get it specifically when it is. Check your state bar's guidance too, and any outside counsel guidelines that restrict AI use.
Part 3: Four firm decisions before you invite anyone
- What data may go into ChatGPT? Pleadings? Discovery? Medical records? Privileged communications? Write it as a one-page firm policy.
- Who may create shared projects, and who decides who's in them? Adding someone to a shared project shows them every chat in it. Treat project membership like an ethical wall, because it works like one.
- What may ChatGPT do on its own? ChatGPT can now send email and Teams messages, create and edit files in SharePoint and Google Drive, run tasks on a schedule, and work with files on a lawyer's computer. Decide whether that's allowed, and whether a person approves every change.
- What must be verified before output leaves the firm? Part 9 gives you a starting protocol. Courts have sanctioned lawyers for unverified AI output.
Get the four answers signed off by the partners before you send a single invitation.
Part 4: Identity, members, and billing
Step 4.1: Verify your domain and set up single sign-on
Start in Identity & access. OpenAI documents two arrangements: in some Business workspaces, the domain and single sign-on settings are editable right there; in others they're read-only and link to OpenAI's Cloud Console, where a global administrator manages a shared connection. In the workspace I reviewed, both Verified Domains and single sign-on pointed to Cloud Console. Either way, you add a DNS record to prove you own your domain and connect your identity provider (Microsoft Entra ID, Google Workspace, Okta, and others). If you're sent to Cloud Console, don't create a second connection.
Do it. A verified domain unlocks the rest of the page, and single sign-on lets your identity provider enforce multi-factor authentication and cut off a departing lawyer. ChatGPT can't enforce multi-factor authentication for the workspace on its own. Before you require SSO, test sign-in in a private browser window, keep an administrator session signed in while you switch it on, and write down your recovery route, including how to reach OpenAI Support. Two Owners help with continuity, but they won't save you if both sign in through the same broken identity provider. Business doesn't include SCIM directory syncing, so adding and removing people stays manual.
The page also offers an organization slug, a permanent short name drawn from your verified domain that's used for Sites and workspace email. It can't be changed once saved, so pick it deliberately, or skip it; your default addresses keep working.
Step 4.2: Close the side doors
- Automatic Account Creation: Off. Anyone who signs in with a firm email would get a workspace account with no invitation. Needs a verified domain.
- Allow External Domain Invites: Off unless you work with contract attorneys at other domains. It only affects new invitations. Needs a verified domain.
- Enable workspace discovery: Off. Lets people with your email domain find the workspace and ask to join. A small firm invites people itself.
- Auto-approve join requests (now under Billing): Off. It approves join requests automatically and lets invited people in even when the workspace is full, billing you immediately for the extra seats.
Step 4.3: Invite members, and know the rule you can't enforce
- Go to Members
- Click Invite member
- Enter email addresses and choose the role and seat type
- Send the invitations
The Members page shows your Standard and Premium seats with assigned and available counts, plus Users, Pending invites, and Pending requests tabs. An invitation doesn't reserve a seat; the check happens when the person accepts. And by OpenAI's own account, members can invite other members on the default seat type, with no setting to stop it. Put "only the AI admin invites people" in your policy and check the member list monthly.
Groups lets you build named groups of members, which you can then use to share projects with a whole practice group at once.
Step 4.4: Choose Standard or Premium seats
- Standard: $25 per user per month, or $20 billed annually. Includes ChatGPT, ChatGPT Work, and Codex with included usage limits.
- Premium: $125 per user per month, or $100 billed annually. About five times the usage of Standard, with no five-hour usage window and far more access to the top models.
Those are OpenAI's published US prices, and they change. The plan needs at least two paid seats. Billing shows the plan with a Manage seats button and an offer to switch to annual billing and save 20 percent. Under Seat preferences, leave the default seat type at Standard. Start everyone on Standard and move someone to Premium when they hit limits week after week. Removing a member doesn't reduce what you pay; reduce seats with Manage seats.
Step 4.5: Set usage limits before you buy credits
Each seat includes a usage allowance. When someone runs out, work can continue on workspace credits if you've bought them. ChatGPT Work, Codex, the Office add-ins, and agents all draw on the same pool. The Billing page has:
- Credits balance: Add credits, and Automatic reload, which tops up when the balance runs low, up to a monthly limit you set.
- Usage alerts: set them.
- Monthly usage limits: a default spend allocation for Standard seats and for Premium seats, plus per-user overrides. Set these first.
- Wallet balance: for redeemed gift cards.
Step 4.6: Assign roles
- Owner: everything, including billing, identity, roles, and seat types. You can have more than one.
- Admin: members, groups, workspace settings, apps, and spending limits.
- Analytics Viewer: a member who can also see workspace analytics.
- Member: uses ChatGPT, with no admin access.
Two Owners (for example the managing partner and the firm administrator), one Admin, an Analytics Viewer for whoever runs the 30-day review, and everyone else a Member. Permissions & roles only has a Workspace tab on Business, so every switch applies to everyone. That's why several recommendations below say "pilot first."
Step 4.7: Access tokens and Trusted Access
Access tokens lets people create tokens for programmatic use of ChatGPT and Codex. Most firms need none; keep personal access tokens off (Step 5.3). Trusted Access is where a firm verifies its business (through OpenAI's identity partner, Persona) and applies for specialized access programs. Skip it unless OpenAI or a vendor has pointed you to a specific program.
Step 4.8: Run a pilot before firm-wide rollout
Before you invite everyone, invite one attorney and one staff member as a pilot pair. Have them sign in, install the desktop app and the Office add-in, connect Microsoft 365 or Google, create a matter project with project-only memory, and ask a real but non-sensitive question. This catches problems, such as a Microsoft 365 tenant that blocks the add-in, before you debug them across the firm.
Test that the restrictions hold, not just that things work. Using made-up matter data, confirm that:
- a colleague who isn't in a project can't see its chats or files
- a project set to project-only memory doesn't draw on chats outside it
- an app write action (sending an email, editing a file) asks for approval or is blocked
- a search stays within the sources you pointed it at
- removing a test member actually ends their access
Write down the date, who tested, what you expected, and what happened. That record is what you show a client who asks how the firm controls AI.
Part 5: General and permissions
The General page carries most of the workspace's switches under Workspace policies. Permissions & roles shows the same switches grouped by feature, with a search box. Change them in either place.
Step 5.1: Branding and analytics
- Workspace name and Logo: set both, so people know at a glance they're in the firm's workspace.
- Workspace IDs: your organization and workspace identifiers. You'll need them only for support.
- Enable task insights: Your call. Turns on message classification for the workspace, which feeds analytics about what kinds of tasks people use ChatGPT for.
- Enable OpenAI-created impact surveys: Off, along with Include user identifiers in impact survey exports. Surveys about how AI affects people's work are useful, but tie names to answers only with a reason.
There's no workspace-wide instructions field on Business. Put your firm's standing instructions in each project's instructions, and give everyone the same text to paste into Settings > Personalization > Custom instructions:
You are working for [Firm Name], a [practice area] law firm. Treat all uploaded documents and conversation content as confidential client information. When answering legal questions, cite primary sources (statutes, cases, court rules) rather than secondary commentary, and say plainly when you can't find authority. Flag any sentence where you are inferring rather than working from a cited source. Produce drafts for an attorney to review, not advice to a client.
Step 5.2: Plugin permissions
This decides when ChatGPT has to ask before a plugin or app takes action in Outlook, SharePoint, Google Drive, and the rest. The options run from asking before anything, to reading without asking but asking before any change, to letting some changes through without asking. Choose the read-only option. Searching a mailbox is the point of connecting it; sending, editing, moving, or sharing should wait for a person to click Allow.
Step 5.3: Access tokens
- Allow users to create personal access tokens: Off. Tokens let software act as a person in ChatGPT without signing in. No lawyer needs one.
- Access token expiration limit: set a limit such as 90 days rather than No limit, so any token that does get created expires.
Step 5.4: Codex and Work on the desktop
ChatGPT Work is the mode for longer, multi-step jobs that end in a finished document, spreadsheet, presentation, or report. It replaced agent mode. On the web it runs in the cloud; on the desktop it can also work with files and apps on your computer. Codex is OpenAI's coding agent.
- Allow members to use Codex and Work Locally: Your call. Covers Codex and Work in the command line, code editors, and the desktop app. It lets ChatGPT read and write files on a lawyer's computer. Have your champion try it first, then decide for everyone.
- Enable Computer History: Off. Records clicks, typing, and app switches on a Mac so ChatGPT can remember what you worked on.
- Allow members to discover and control devices remotely: Off. Lets people steer Codex on their computer from a phone.
- Enable device code sign-in for Codex, Excel, PowerPoint, and Word: Off unless someone can't sign in to the Office add-in without it. The console itself warns that device codes can be phished.
- Allow members to send Codex referrals: Off. Nobody at a law firm needs to invite outsiders to try Codex.
On Business, Codex Cloud, Codex internet access for cloud tasks, Codex Security, and code edits on the Mac app show as locked on. If nobody at the firm builds tools, the local switch above is your only lever; tell people Codex isn't part of the firm's approved toolset.
Step 5.5: Record
Record transcribes and summarizes meetings and calls in the Mac desktop app. The console says recordings are used only for transcription and not stored by OpenAI; the transcript and notes stay with the chat.
- Allow members to use ChatGPT record: the legal issue is consent. California and several other states require everyone's consent to record a conversation. Write the consent rule first (announce it, get agreement, never on a client call without the client's consent), then turn it on.
- Allow ChatGPT to reference past notes and transcripts: Off. It lets ChatGPT draw on earlier meeting transcripts in later conversations, which is how one client's call surfaces in another client's work.
Step 5.6: Skills, Sites, agents, and dots
- Enable skills: On. Skills are reusable instructions people create for repeatable tasks. Review them on the Skills page (Step 6.3).
- Allow members to deploy or publish with Sites: Off unless you have a use. Sites builds and hosts small websites and apps. Turning it on accepts OpenAI's Sites terms and makes the firm responsible for what gets published, and this one switch covers both creating and publishing.
- Enable agents: On. Lets members browse and run workspace agents, reusable assistants someone builds once. Manage them from the Agents link in the sidebar.
- Allow members to use dots: Your call. A newer feature with its own switch; try it with your champion before deciding.
Step 5.7: What's locked on Business
These switches appear in the console, but their sections are marked Enterprise. Know what they're set to, because you can't change them:
- Sharing: chats, canvases, and projects can be shared with workspace members only. Shared links can't be turned off, so tell people to delete them when they're done (Settings > Data controls > Shared links > Manage).
- Memory: on for the workspace, and administrators can't turn it off firm-wide. Members can still manage their own memory, but you can't enforce their choices. Improved memory is off. Part 7 explains how to contain it.
- Web search: on. It may send search queries and general location information to Bing, not linked to user accounts.
- Code execution and code network access in canvas and code blocks: on.
- Screen and video sharing in Voice: on.
- Apple Intelligence linking: on.
Part 6: Plugins, apps, skills, and GPTs
Step 6.1: Plugins
A plugin bundles skills, app connections, and templates. The Plugins page has a Public tab (OpenAI's catalog) and a tab for your own workspace's plugins, with each plugin's installation policy (Available means members may install it) and whether it's enabled.
- Configure Microsoft permissions: if the banner at the top says it needs attention, either have your Microsoft 365 administrator approve the permissions for Outlook Email, Outlook Calendar, SharePoint, and Teams, or disable those apps. A half-approved connection helps nobody.
- Review the list: many third-party plugins arrive enabled, including ones that act on a computer or pull data from the web. Disable everything the firm doesn't use, keep the Microsoft or Google set your firm runs, and add the legal plugins you license (the catalog includes iManage, NetDocuments, Clio, and others).
- Manage access controls who can use plugins; Add brings in your own.
Step 6.2: Apps
The Apps page has Enabled, Directory, and Drafts tabs. On Business, apps in OpenAI's directory start enabled, so the Enabled count runs into the thousands, from coffee ordering to astrology. Each person still has to connect an app before it can see their data, but a firm doesn't need thousands of doors. Use the checkboxes to disable apps in bulk and keep the short list you actually use.
For the apps you keep, open each one and review its actions. Every app has read actions (search, open, summarize) and write actions (send, create, edit, share). Keep write actions off during the pilot, then turn on only the ones your lawyers need. Where an app offers it, limit connections to your firm's email domain so nobody connects a personal account. Create builds a custom app; leave that to a vetted internal system.
Step 6.3: Skills and Marketplaces
The Skills page lists every workspace skill with its owner, access (for example, invite only), users, and how often it ran in the last 30 days. You can update access, transfer ownership, and delete skills that shouldn't be available. Review it monthly. Marketplaces lets you add plugin collections from outside sources; add only ones you trust.
Step 6.4: GPTs are retiring
In the workspace I reviewed, the GPTs page opened with a banner saying GPTs will be retired on December 11, 2026, and that to keep using one you have to migrate it to a plugin by then. OpenAI's public documentation names that date for Enterprise workspaces and says other plans are expected to follow the same timeline. Check the notice in your own workspace, and migrate and test the workflows you depend on before its stated deadline. Tabs show your workspace's GPTs, migrated ones, and unassigned ones left behind by people who left.
- Third-party: controls whether members can use GPTs created outside your workspace. Restrict it rather than allowing all.
- GPT actions: uncheck Allow all domains for GPT actions and list only domains you approve, so a GPT can't call any website on the internet.
- Sharing and Apps in GPTs are locked on Business.
Don't build new GPTs. List the ones people use, migrate those, and let the rest go.
Step 6.5: The Office add-ins
OpenAI ships one Microsoft add-in that works in Excel, Word, and PowerPoint, plus a Google Sheets add-on. There's no Outlook add-in; Outlook works through the Outlook apps inside ChatGPT. Your Microsoft 365 administrator has to allow the add-in, or deploy it from the Microsoft 365 admin center. Tell users three things: add-in conversations are separate from ChatGPT history, memory doesn't carry into them, and the add-in can make edits you didn't intend, so work on a copy until you trust it.
Part 7: Projects and memory
Projects are the most useful feature for a law firm on Business, and the place where most confidentiality mistakes happen. Because the firm can't switch memory off for everyone, the project memory setting is your main wall between matters. It's a wall around memory, though, not around everything, as Step 7.3 explains.
Step 7.1: One matter, one project, project-only memory
- In the sidebar, click New project and give it the matter name
- Open the project's menu (the three dots), then Project settings
- Under Memory, choose Project-only memory and save
- Only then add the matter's files and the instructions ChatGPT should follow
- Project-only memory: chats in the project use only conversations from the same project and ignore saved memories. Nothing outside the project can reach in.
- Default memory: chats in the project can draw on conversations outside it, and chats outside can draw on this one. That's how one client's facts surface in another client's draft.
Set project-only memory before any client information goes in. There's no setting to make every project project-only, so it's a habit you build and check. You can change an existing unshared project, but OpenAI says the change can take a few hours to apply, so don't use the project for sensitive work until you've confirmed it took. Shared projects are switched to project-only automatically and can't be switched back. The trade-off: ChatGPT Work isn't available in a project-only project.
One prerequisite matters here. Project-only memory needs memory turned on in each person's own settings, including Reference saved memories and Reference chat history under Settings > Personalization > Memory. If someone turns those off, check whether their projects still offer project-only memory before relying on it.
Step 7.2: Keep client work out of loose chats
With memory on, a chat outside any project can reference your other chats. The firm rule: client work happens in a project-only project, or in a Temporary chat set to Unpersonalized for a one-off question (Step 2.4). Loose chats are for general questions.
Each person can manage their own memory, but that's an individual choice rather than a firm control, and turning off one switch, such as Reference chat history, doesn't clear saved memories. Because the personal switches also feed project-only memory, I'd leave them on and rely on the project rule, rather than asking lawyers to turn them off.
Step 7.3: Know what a project doesn't wall off
A member of a shared project sees every chat in it with each author's name, every file (which they can download), and the member list with email addresses. Share client projects by name, never by link, and treat the member list as an ethical wall: check it against the matter team every month. ChatGPT knows nothing about your conflicts system.
And project memory settings don't narrow what a connected app can reach. From inside any project, the Outlook, SharePoint, or Google Drive app can still pull any other matter the lawyer can open in that system, and a read-only search can bring that material into an answer someone then shares. Instructions to keep matters separate aren't access controls. Point each task at the sources it needs, and check which matter the answer drew on before sharing it.
Step 7.4: Clean up what ChatGPT remembers, and how it reads files
To remove something ChatGPT learned from a client chat, delete the saved memory (Settings > Personalization > Memory > Manage), delete the chat, and delete any files it left in the Library. And know that on Business, when ChatGPT retrieves from uploaded documents it works from the extracted text and discards images inside them (visual reading of PDF pages is an Enterprise feature), so a scanned exhibit with no text layer can come through blank. Run scanned PDFs through OCR first.
Step 7.5: Suggested starter projects
- Firm Style and Templates: shared with the firm (or a Group), Chat access for most. Templates, citation conventions, the style guide. No client material.
- Practice Area Reference: shared with the practice group. Statutes, key cases, local rules.
- Client Intake Helper: private or shared with intake staff. Project-only memory.
- One project per active matter: project-only memory, shared by name with the matter team only.
Part 8: Install the apps
- Desktop: download from chatgpt.com/download (Mac or Windows), sign in with your firm email, and select the firm's workspace. The desktop app combines Chat, Work, and Codex.
- Mobile: install ChatGPT from the App Store or Google Play and pick the firm's workspace from the sidebar.
- Office: in Word, Excel, or PowerPoint, go to Home > Add-ins, search for ChatGPT (publisher: OpenAI), and sign in to the firm's workspace.
Voice and dictation capture more than people intend; treat the phone like any recording device around clients and opposing counsel.
Part 9: Verification protocol before anyone uses ChatGPT on live matters
ChatGPT output is never final legal work product. Before any AI-assisted material is filed with a court, sent to a client, served on opposing counsel, or shared with a third party, an attorney must independently verify it. The duties of competence (ABA Model Rule 1.1) and candor (Rule 3.3) belong to the lawyer, not to the tool.
- Citations: confirm every case, statute, regulation, and rule against the primary authority.
- Quotations: verify quoted language against the original source.
- Research reports: open the sources behind deep research and search answers and confirm they say what ChatGPT says they say.
- Procedural rules and deadlines: confirm them in the jurisdiction's current rules.
- Calculations: independently recompute damages, dates, interest, and fees.
- Factual assertions: confirm every factual claim against the source documents.
- Actions taken: review anything ChatGPT sent, saved, or changed through an app.
- Privilege and confidentiality: confirm nothing privileged appears where it shouldn't.
- Court rules on AI: before filing, check the court's local rules and the judge's standing orders for AI disclosure or certification requirements.
Label AI-assisted work "DRAFT, AI-assisted, attorney review required" until an attorney signs off. If the firm wants a record of AI-assisted work, plan to keep it in your own systems, such as the document management system; Business has no central export to rely on.
Part 10: Roll out to your team
Step 10.1: A 30-minute orientation for every new user
- How to sign in to the firm's workspace, not a personal one
- What the firm can and can't see, and the confidentiality rules from Part 2
- Project-only memory for every matter, set before any client information goes in, and Temporary chat set to Unpersonalized for one-off questions
- Shared projects show every chat, so share by name and only with the matter team
- The verification protocol from Part 9
- Delete shared links when done, and read before you click Allow
Step 10.2: Designate an internal champion
Pick one person, ideally not a senior partner, who is the go-to for "how do I do X with ChatGPT" questions and who hears the feedback that used to go to the thumbs-down button.
Step 10.3: Schedule a 30-day review
- Seats and members. Rebalance Premium seats and look for anyone who joined outside your process.
- Shared projects. Read each member list against the matter team.
- Project memory. Spot-check that matter projects use project-only memory.
- Plugins, apps, and skills. New arrivals get switched on by default; trim them.
- Credits. Spending against your monthly limits.
- GPTs. Until the retirement date in your workspace notice, track which still need migrating.
Step 10.4: Write the offboarding and incident checklists
Neither of these is a single button in ChatGPT. They're firm procedures, and they belong on paper before you need them.
When someone leaves:
- Preserve what your records policy or a hold requires, with the person's help while they still have access, and hand off their projects, skills, agents, and scheduled tasks to a named colleague.
- Remove them from Members and from your identity provider, and have them (or IT) disconnect their connected apps and revoke any access tokens.
- Stop their scheduled tasks, and review their shared links and any files they kept on their own computer.
- Reduce paid seats separately with Manage seats; removing a person doesn't lower the bill.
When something goes wrong (a document uploaded to the wrong matter, a mistaken share, an action ChatGPT shouldn't have taken):
- Stop the workflow and restrict access: remove people from the project, delete the shared link, or disconnect the app.
- Tell the firm's designated contact, usually the general counsel or risk partner.
- Preserve the evidence. Don't reflexively delete the chat or file; counsel may need it to assess what happened and whether anyone must be notified.
Quick reference: where things live
| To do this | Go here (Workspace settings) |
|---|---|
| Name, logo, analytics settings, most policies | General |
| Invite members; see seats; pending invites and requests | Members |
| Build groups of members | Groups |
| The same policies, grouped by feature | Permissions & roles |
| Domains, SSO, discovery, automatic accounts | Identity & access (and Cloud Console) |
| Programmatic tokens | Access tokens |
| Seats, seat preferences, credits, limits, payment | Billing |
| Plugins and Microsoft permissions | Plugins |
| Enable or disable apps and their actions | Apps |
| Review workspace skills | Skills |
| Third-party GPTs, GPT actions, migration | GPTs |
| Usage | Workspace analytics |
| Set a project to project-only memory | Project menu > Project settings > Memory |
| Review or delete your memories | Settings > Personalization > Memory |
| Delete shared links | Settings > Data controls > Shared links > Manage |
| Download the desktop app | chatgpt.com/download |
Where to get help
- OpenAI Help Center: help.openai.com, especially the ChatGPT Business release notes. Expect the console to be a step ahead of it.
- OpenAI Status: status.openai.com
- OpenAI Trust Portal: trust.openai.com, for the SOC 2 report and security documentation
- OpenAI's enterprise privacy commitments: openai.com/enterprise-privacy
If your firm needs to export or audit conversations, turn memory off firm-wide, control sharing, sync your directory with SCIM, give different people different features, or sign a BAA, Business isn't enough. Talk to OpenAI about Enterprise.
Configuration is one piece of responsible AI use in a law firm. The bigger piece is judgment: deciding what goes into ChatGPT, who gets to see it, how to verify what comes out, and how to tell clients. The settings above give you the guardrails. Project-only memory and the verification protocol in Part 9 keep you out of trouble. The rest is on you and your team.