Imagine an ordinary Monday chat. You ask ChatGPT to tidy tomorrow's meeting agenda, and it points out that a launch date in a connected project file no longer matches the date in your draft. You never named that file. You did not even ask it to search the project folder.
That can feel wonderfully helpful for about three seconds. Then someone asks the more important question: why could it see that file, and what else could it bring into a conversation without being named?
This is the real small-team test for ChatGPT apps with sync. The interesting feature is not the connect button. It is what happens when connected information becomes easy enough to surface that a suggestion feels almost unprompted.
As of August 26, 2026, OpenAI says synced app data can help ChatGPT offer relevant suggestions, and that ChatGPT may automatically decide when to use an app with sync. The Learn documentation adds the mechanism: selected connected content can be indexed in advance. None of that means ChatGPT has become an all-seeing monitor that watches every file live, sends its own alerts or acts outside the chat whenever it feels like it.
What “proactive” means here—and what it doesn't
OpenAI's current Learn documentation draws a clear line between non-synced and synced connections. With a non-synced app, ChatGPT retrieves information when a chat or research task uses the connection, and that content is not indexed in advance. With a synced app, selected connected content is indexed ahead of time.
The documentation establishes two things: ChatGPT may automatically choose a synced app while answering a question, and synced data may contribute to helpful suggestions. It does not promise that an unrelated chat will surface an unmentioned file, nor does it define proactive suggestions as autonomous monitoring.
That distinction matters. If ChatGPT mentions the launch date from the opening example, it does not prove that it has been watching the project all weekend. It may simply mean the relevant content was already in the synced index when the Monday conversation began. OpenAI also warns that changes to source content or permissions can take time to appear, so “synced” should not be read as “instant.”
Keep these five things separate:
| What happened | What it actually tells you | What it does not prove | | --- | --- | --- | | A plugin was installed | Its bundled skills or connectors can become available in new chats | The user can already read the connected service | | A connected account was authorized | ChatGPT can use that identity within its granted scope | Every employee sees the same records | | Sync was enabled | Selected connected content can be indexed in advance | Every file is indexed or every change is immediate | | Read or write actions were allowed | The connector may search, retrieve or act within those controls | It can exceed the source account's permissions | | Memory was enabled | Useful context from earlier work may carry into later chats | The app connection and memory are the same store |
The first surprise is usually an identity surprise
When an answer contains unexpected work information, start with the signed-in identity. OpenAI describes plugin availability, app access, action permissions and service authorization as separate layers. Making a plugin available does not grant access to a drive, channel or record. The connected account still decides what the app can reach.
That sounds reassuring until a team connects a broad shared account instead of each person's normal work account. A shared connection may have access that the person asking the question does not. The answer can be technically authorized and still be a terrible surprise.
Before inviting the rest of the company, be able to answer four plain questions:
- Which account is connected: the employee's own account, a shared account or a dedicated integration identity?
- Which folders, channels, records or workspaces can that account already open?
- Is the app limited to reading, or can it create, change or send something?
- When will ChatGPT ask before using the app or taking an action?
OpenAI's admin documentation says app permissions determine when ChatGPT asks, while action controls can limit a connector to read-only work or an approved set of actions. Those are useful controls, but neither one repairs an overpowered account at the source. If the connected identity can read the executive drive, “read-only” still means it can read the executive drive.
Memory is a different kind of remembering
Sync and memory can both make an answer feel as though ChatGPT knew something before you asked. They get there by different paths.
A synced app makes selected information from a connected system available in advance. Memory carries useful context from earlier work into future conversations when the relevant memory settings allow it. A detail may also remain in an old conversation, a project file or another saved location.
That is why disconnecting an app is not a universal eraser. OpenAI's cloud-security documentation says disconnecting an app does not automatically remove information already saved in a conversation, generated file or record with its own retention policy. It also says deleting a conversation, removing a saved memory and disconnecting an app are separate actions.
For a small team, the useful rule is simple: access, chat history and memory need separate cleanup decisions. If someone connected the wrong folder, disconnect or narrow the app to stop future retrieval, then review conversations and saved material that may already contain the information. Review memory settings separately rather than assuming the disconnect handled them.
Give five people a boring little test folder
The safest useful trial is deliberately uneventful. Choose five people who already share one real task—perhaps preparing a weekly project update—and give the app read-only access to a temporary folder made for the trial.
Put three invented documents in it:
- A current project note with a memorable date, owner and decision.
- An older note with a clearly stale date and “superseded” in the first line.
- A private control document that the pilot account is not allowed to open.
Do not seed the folder with customer records, HR material or anything you would hate to see quoted in the wrong meeting. Synthetic content makes a permission failure obvious without turning the test itself into an incident.
Now ask a short set of questions in new chats. Start with an explicit retrieval request: “What is the current launch date in the pilot folder, and which source says so?” Then make the wording less specific: “What should I fix before tomorrow's launch meeting?” Follow with an unrelated agenda-editing request and notice whether any connected detail appears without being named.
The aim is not to force a proactive suggestion. It is to see whether relevant connected information appears, whether the source is visible, whether the current note beats the stale one and whether the inaccessible control document stays inaccessible.
Have a second pilot user who lacks access to the current note ask the same questions. If both people receive the same answer, stop and inspect the connected identity and sharing rules. Do not explain it away as AI being clever.
Disconnect it before you trust the disconnect button
A connection should be tested in reverse while the stakes are still low. Disconnect the pilot app, start a new chat and repeat the retrieval questions. Check whether the app is unavailable and whether new source retrieval stops.
Then inspect the earlier chat separately. Its text may remain under the workspace's conversation-retention settings. If a useful detail was saved as memory, that follows separate memory controls. If the test produced a file or copied information into a project, that copy has its own home too.
This is not evidence that disconnect is broken. It is evidence that “disconnect the source” and “delete every copy” are different jobs. OpenAI's documentation says so explicitly, and a rollout owner should know which job the team actually needs.
Widen the trial only when the surprise is explainable
After a week, the five pilot users should be able to point to the source behind a connected answer, explain why their account could access it and tell the difference between sync, memory and an old chat. The admin should be able to remove the connection and name what remains.
If those answers are fuzzy, adding more folders will not make them clearer. Keep the app read-only, shrink the scope or turn sync off while the team fixes its source permissions.
If the pilot is boring in the best possible way—current sources win, private material stays private, and every unexpected suggestion has an understandable path—then add one more group or one more source. Leave write actions for a later decision. If the connected app will eventually feed a workspace agent, use the stricter internal-tool approval check before it can post, update or send anything.
The goal is not to prevent ChatGPT from ever surprising the team. A well-timed connection between two pieces of work is the reason to use sync at all. The goal is to make every surprise traceable to an account, a permission and a source you meant to connect.