Bunny Honey ClubBunny Honey/blog
Work with us
← back to indexblog / ai / chatgpt-team-tasks-shared-connections-small-business
● AI

ChatGPT Team Tasks: Whose Login Does the Task Use?

ChatGPT Business now runs shared recurring tasks under a team account. Before you build one, read what OpenAI says the task can reach.

AH
Arthur HofFounder, Bunny Honey Club AI
publishedOct 06, 2026
read7 min
ChatGPT Team Tasks: Whose Login Does the Task Use?

On September 29, OpenAI let a whole ChatGPT team share one scheduled robot. It runs in the cloud, it never sleeps, and it uses a login that nobody in the room personally owns. That sounds like a convenience. It is also the first time a recu

On September 29, OpenAI let a whole ChatGPT team share one scheduled robot. It runs in the cloud, it never sleeps, and it uses a login that nobody in the room personally owns.

That sounds like a convenience. It is also the first time a recurring ChatGPT job has had a shared set of keys, so it is worth asking whose keys.

Team tasks are shared recurring jobs with a shared set of keys

OpenAI's Business release notes for September 29 describe team tasks like this: recurring work you run on a schedule or a supported trigger, using approved company tools, that authorized teammates can review and update together. The example is a weekly project update posted to an approved Slack channel, with progress, blockers and next steps.

The same day brought three neighbours. Teams you can add colleagues to, shared Pages and Spaces, and @ChatGPT inside Slack and Microsoft Teams. Together they turn ChatGPT from a tool each person opens into a workspace the team shares.

OpenAI's own examples in the team tasks help article are modest. A daily customer-change digest. A meeting briefing from selected documents. A recurring research brief. None of them move money.

Good. Start there. But notice the design choice underneath, because it decides how this goes wrong.

1service account per team, which runs its tasks in the cloud (OpenAI)
0owner approvals needed to join a team through its link (OpenAI)
0automatic syncing of team membership with groups or Slack channels (OpenAI)
$20-25per user per month for a Business Standard seat, annual or monthly (OpenAI)

The task runs as the team, not as you

When you ask ChatGPT something in your own chat, it uses your connected accounts. Team tasks do not.

OpenAI says team tasks "run in the cloud under the team's service account, using the task's saved instructions and the connections configured for the team." Creating one does not put it in your personal account. And the team does not inherit your saved memories, Custom Instructions or chat history, so the task only knows what its saved instructions say.

Here is the line that matters.

Each connection uses a designated account. That account's permissions determine which data and actions are available.

— OpenAI Help Center, Creating and managing team tasks in ChatGPT

Read that as a business owner. The task has no judgment about what it should touch. It has a login, and it can do whatever that login can do.

If the designated Gmail account is yours, the task can read what you can read. If the designated Slack account can post in every channel, the task can post in every channel. OpenAI's help page does not say which account supplies the identity for a given connection, and it does not say how a run is attributed in an app's audit log. Those are the two questions I would ask before anything else.

Who sets this up is split three ways. Workspace admins configure the connections and decide who can use them. The team owner picks which of those connections the team gets. Team members, within their permissions, then run and edit the tasks. That is sensible on paper. In a ten-person company it usually collapses into one person doing all three.

We covered the same shape of problem when Meta's Muse for Small Business launched with a dozen connectors. Different vendor, same lesson: the connector is the permission, and the permission is the risk.

Anyone in the workspace can join the team

This is the part I would not skip.

OpenAI's Teams in ChatGPT article says other members of the same workspace can join a team by opening its link, and that joining "doesn't require a separate approval from the team owner." Team members can invite coworkers and remove anyone who is not the owner. They can view, run, edit, pause, resume or delete tasks according to each action's permissions. They can also review runs completed before they joined.

And the article says team membership does not sync from workspace groups or from Slack or Microsoft Teams channels. You add and remove people by hand.

In a six-person plumbing company where everyone is trusted, this is a feature. Fewer clicks, fewer "can you add me" messages.

It stops being a feature the day the workspace grows to include a part-timer, a freelancer on a company seat, or a former employee nobody removed. Because membership does not sync from anywhere, offboarding is a manual step in a place you may not think to look.

Triggers turn strangers into instructions

A schedule is predictable. A trigger is not.

OpenAI says tasks can respond to supported activity in connected apps, such as a new Gmail email or a Slack message. For a Slack trigger you choose the channel to monitor.

Think about what lands in a monitored mailbox. Customer emails. Supplier quotes. Contact-form submissions. Every one is text written by someone you do not control, handed to an agent that holds your keys.

I am not claiming OpenAI's task can be talked into misbehaving. I have not tested it, and OpenAI does not say. I am saying the usual rule from our Muse for Small Business post applies: an agent that reads outside text, holds private data and can send things out is three risky properties in one tool. A summary task that only reads and drafts is a very different animal from one that also posts or sends.

So match the trigger to the blast radius. A weekly digest from internal documents is low risk. "Reply to new customer emails" is not a first project.

Tasks fail quietly, and a clean run is not proof of anything

The help article is unusually frank here. It is worth reading as a list of ways your new automation can disappoint you.

  • An unattended run cannot finish a new app sign-in. If a connection expires, the task cannot log back in for you. You need a person to complete sign-in before the next run.
  • A Completed schedule does not mean a job succeeded. For a time-based schedule, Completed only means there are no future runs. Check the result, and check the destination.
  • Failed app actions are not necessarily retried. Some temporary errors are retried automatically. A failed action inside a run does not necessarily trigger a retry.
  • Reruns can repeat what already happened. OpenAI tells you to check what an earlier run did before rerunning a task that sends messages or changes files.
  • Pausing does not stop a run in progress. Check any active run separately.

None of these is a flaw. They are what any automation does when a token expires at 2 a.m. on a Tuesday.

They are also the difference between a task that works in the demo and one that works in March. We run into the same wall with any recurring job, in n8n or an AI agent: the build is a small part of it, and the monitoring is the job.

How we would set up a team task before trusting it

Disclosure: Bunny Honey Club builds automations for a living, so we have a stake in you hiring someone. Judge this list accordingly. It also happens to be the list we would follow ourselves.

  1. Give the task its own login. Create a dedicated account for the job instead of designating the owner's inbox. If the owner leaves, the task keeps working. If something goes wrong, the damage stops at that account's edge.
  2. Start read-only. Let it read documents and draft. Add posting and sending only after a month of clean runs.
  3. Name an owner and write down the connections. One person, one page, listing every connection the team has and which account sits behind it.
  4. Put a human gate on anything that spends or sends. Money, customer messages, file changes. The task drafts, a person approves. OpenAI's own safety design for its agents relies on approval for exactly this reason, which is the same argument we made about always-on ChatGPT dots.
  5. Keep client data out of the first project. If you are unsure which of your people are already pasting client details into the wrong plan, start with shadow AI and client data in ChatGPT.
  6. Review the member list monthly. Membership does not sync, so someone has to remove leavers. Put it in the calendar.
  7. Read the run history weekly. A task that "ran" is not a task that worked.

This is more setup than "type a prompt and hit schedule." That is the point. The prompt takes ten minutes. The login, the scope, the approval gate and the weekly look at the output are where the business risk lives.

Where we would use it: the Friday project digest, the Monday briefing, the weekly report that nobody wants to write. Where we would not, yet: anything that touches your books, your customers' inboxes or your ad account.

Where this fits next to what you may already have

ChatGPT's team tasks are one more way to run a recurring job inside a tool you already pay for. They sit alongside ChatGPT Work, which handles the one-person version, and dedicated automation platforms like n8n.

If your recurring job lives entirely inside ChatGPT and touches nothing sensitive, try it yourself. It is a perfectly good place to learn.

If the job touches money, customers or compliance, the shared-login question is the whole project, and that is what we build for people. Dedicated identities, narrow permissions, an approval step and a log you can read. See our automation work or tell us the job and we will tell you honestly whether it needs us.

— share
— keep reading

Three more from the log.