ChatGPT in Slack and Teams: Who Can See the Answer?
Caitlin Price
When you ask @ChatGPT a question in a shared Slack or Microsoft Teams conversation, the people in that conversation can see its reply. The account supplying the answer may have different access from those people. Before legal approves a rollout, check both the connected account's permissions and the audience receiving the response.
For example, a sales channel may be an appropriate place to explain your standard payment terms. A summary drawn from a restricted settlement memo needs a different audience, even if the system can retrieve that memo. A source link that some participants cannot open does not resolve what the answer itself reveals.
GC AI is our enterprise legal AI platform, trusted by 2,200+ legal teams. Teams at Vercel, Arc’teryx, and Riot Games use GC AI. Our co-founder and CEO, Cecilia Ziniti, previously served as general counsel at Anki, Bloomtech, and Replit and worked in-house at Amazon and Cruise. Her experience shaped a product for the practical demands of advising a business: understanding company context, checking the underlying material, and giving colleagues an answer they can act on.
That is the job here. Counsel needs to turn account settings and test results into a decision about what the business can safely share. Our Agent Connectors bring information from connected work apps into GC AI, where the lawyer can analyze it, prepare a response, and review the destination before sending. The sections below show how to assess the shared ChatGPT setup and use GC AI to prepare that legal review.
Identify Which ChatGPT Integration You Are Approving
“ChatGPT in Teams” can describe different arrangements. Ask the implementation owner to name the app, where employees will use it, and how it connects to company information.
| Arrangement | What Legal Should Check |
|---|---|
| @ChatGPT inside Slack or Microsoft Teams | The organization's messaging setup, company connections, and conversation audience. |
| Slack or Teams connected as an app inside ChatGPT | The connected user's source access, enabled actions, and any separate administrator-managed sync. |
| Microsoft 365 Copilot or another vendor's bot | That product's documentation and settings. Its controls need their own review. |
OpenAI describes the messaging integration and connected apps as separate setups. Approval of one does not establish the configuration of the other. An older Slack sidebar installation also needs a fresh review when the organization upgrades.
Start With the Account Behind the Answer
For company connections, OpenAI's enterprise deployment guide describes @ChatGPT as a separate service account. Its access can differ from the permissions of people participating in a conversation. It does not automatically inherit each person's private files or channels.
Ask IT to show which account connects each source and which resources that account can reach. “Employees already have access to Slack” does not answer whether the shared assistant can retrieve a restricted drive folder.
Personal app connections follow a different path. OpenAI says a user must authorize those connections separately, and that authorization does not let other participants use the person's connected apps. It also says a direct message with @ChatGPT does not switch the assistant into the employee's personal ChatGPT account. The current usage documentation explains these distinctions.
Ask the administrator to demonstrate which connection supplied a test answer. A screenshot of the app's name is insufficient evidence of the account and permissions behind it.
Check Slack and Teams Separately
In Slack, restricting @ChatGPT to selected channels does not also restrict direct-message access, according to OpenAI's deployment guide. Include a DM test in the approval scope. A pilot described as “one legal channel” needs to account for the other available entry points.
For Teams, OpenAI's setup instructions direct administrators to install the app for the intended users or groups and test personal chat and file access separately. Record the conversation types your deployment supports; a successful Slack channel test says nothing about a Teams group chat.
There is also a broader configuration change to review. OpenAI says enabling a workspace connection for @ChatGPT turns on team/service-account access and sets the connection to All roles. Turning that option off does not automatically undo the other grants. Have the administrator capture those settings before enabling the connection and identify what must change to roll back the pilot.
For each messaging environment, ask the owner to document who can install or invoke the app, where it can respond, and who maintains its connected accounts. Instructions telling the assistant to avoid sensitive material cannot replace access controls.
Test the Reply and the File With Two People
Use harmless test material before connecting a sensitive repository. Run the proposed acceptance test below with IT and record the results for your deployment.
Have IT create an approved policy with a distinctive test sentence and a separate restricted document containing a different harmless sentence. Use one participant with source access and another without it. Give both access to the conversation being tested.
- Ask for the approved policy by name and by link: Record the connection used and inspect the response for the expected source.
- Ask for the restricted test document from each identity: Check whether either the answer or its citations reveal material outside the intended approval scope.
- Generate a test file: Have the second participant inspect the reply and attempt to open the file independently.
- Repeat the relevant tests in the permitted Slack channels, direct messages, and supported Teams conversations: Record an unsupported surface as out of scope.
- Remove test access and repeat the affected checks: Record when the change takes effect and what remains visible in earlier messages.
OpenAI distinguishes the audience for a reply from access to a generated file. Seeing a file's link does not necessarily mean a participant can open the file. Check the text posted alongside it as carefully as the file permissions.
Keep the results in the approval record, together with the source account, approved resource scope, permitted conversation types, test identities, settings screenshots, and named owner. If a test exposes the restricted sentence to an unintended reader, narrow the account's access or the rollout audience and rerun it.
Use GC AI to Prepare Legal's Review and Approved Response
In GC AI, you work from the documents, instructions, and company context relevant to the question. Our Projects bring related chats and files together, so a follow-up question can use the matter's existing material. Agent Connectors let you retrieve context from supported work apps and prepare actions from the chat, subject to organization policies and tool permissions.
For this assessment, the inputs are the approved pilot scope, configuration evidence, and harmless test results. The output is a source-backed review memo and a separate business-facing response. Counsel decides which conclusions and details belong in each. GC AI helps assemble and analyze the evidence; it does not establish that an administrator's configuration works without the tests.
Start with a Private Project and invite the people handling the assessment. Our Projects documentation explains that invited members can view project chats and linked files; inviting someone to a Private Project also grants read access to linked files and folders. Choose those materials deliberately.
Upload the configuration export, permission screenshots, and test results. Ask GC AI:
Compare these settings and test results with our approved pilot scope. For each connected account, identify the source resources it can access, the people who can receive its responses, and any mismatch. Cite the supporting file and section. Mark missing evidence as unresolved. Draft a short recommendation for Legal and IT; do not send it.
Counsel and IT can then verify the cited evidence and resolve the gaps before approving access.
Our documentation explains the controls for the next step. Each member connects their own accounts, existing app permissions apply, and organizations can set connector policies. Read operations default to Always allow; write and delete operations default to Needs approval. Members can change individual tool permissions, so check the settings in use.
For the pilot, keep the relevant Slack or Teams send action on Needs approval. Review the exact message and destination before authorizing it. A business channel might receive the approved policy answer and its source, while the assessment remains with the project members.






