Understand the current tools before selecting a workflow
ChatGPT Work handles longer tasks and finished deliverables, while Chat remains the conversational experience and Codex focuses on software development. On desktop, select ChatGPT in the top-left menu, then choose Work. Web and mobile also offer Work for eligible accounts.1 Start with a written outcome and approved source material. Review the resulting document or spreadsheet as a business deliverable.
OpenAI's older ChatGPT agent article now begins with a notice that agent is unavailable and directs users to Work, although it retains earlier agent-mode instructions further down the page.13 Use the current Work documentation and the controls visible in your account when planning a deployment. Avoid promising a menu or allowance from a screenshot that no longer matches your team's interface.
For shared repeat work, workspace agents combine instructions with selected tools and files, and can be shared, scheduled or triggered through an API.2 A skill supplies a reusable process, including instructions and supporting resources; a plugin can package skills and connected apps.4,5 Choose the smallest arrangement that delivers the result. You can practise a procedure manually before adding a trigger.
Choose an output that is easy to inspect
Good starting tasks have a controlled source, clear acceptance criteria and an owner available to resolve exceptions. Examples include an internal supplier comparison, a draft enquiry brief or a summary of approved project updates. Define what completion means: the document includes source links, states missing information and waits for the responsible person to approve the next action.
In a hypothetical Wellington consultancy, a weekly briefing gathers progress from an authorised project folder and drafts an internal update. The project lead checks commitments against the original notes. In a hypothetical Tauranga wholesaler, an enquiry workflow proposes a reply from the current product specification. The sales manager approves wording and availability. Neither example implies results achieved for an actual client.
Keep payroll changes, employment outcomes, customer refunds and safety decisions outside a first unattended workflow. That is a recommended design boundary for this guide. Automation becomes harder to inspect when the same run reads uncertain material, interprets policy and changes records. Divide those steps so the person reviewing the interpretation can still stop the proposed action.
- State the input source and who maintains it.
- Define a deliverable with visible evidence and unresolved questions.
- Choose the person who can approve the business action.
- Specify an exception route when the source is missing or contradictory.
Package a repeat procedure with a skill or plugin
Eligible users find skills through Plugins in the sidebar, then the Skills tab in the directory. Create with chat, Create with editor and file upload are supported options, subject to workspace availability.5 For an internal brief, include the purpose, output headings, accepted source types and conditions that require referral. Give the workflow a business owner who can approve changes to those instructions.
Review a plugin's included apps before installing it. Installation may start app setup, but does not replace provider authorisation or grant extra access. You can invoke an available plugin with an @ mention.4 Ask the administrator to approve the connection used for the trial. Keep a practice copy of the reference material so testing cannot affect current customer work.
Existing custom GPT workflows need migration planning. OpenAI's migration FAQ says that creators can use Migrate to plugin from My GPTs when the option becomes available, but custom actions do not transfer automatically.6 The published retirement date is 11 December 2026, with an approved deferral for qualifying Enterprise workspaces; follow your account's notice.6 Save familiar evaluation prompts and compare the replacement's output. Check sharing and app access before switching staff to it. Treat rebuilding an integration as separate work with its own acceptance check.
Build and test a workspace agent before sharing
Open Agents in the sidebar, select Create and describe the job. Review the proposed plan, choose Build this agent, then configure the builder. Preview lets you test before selecting Create.2 Draft the business instructions yourself before accepting generated configuration. The builder's suggested tools are a proposal for you to assess.
Test normal requests alongside missing records, conflicting documents and an instruction that asks for an unapproved action. Record the expected response before each test. If the agent has insufficient evidence, it should report the gap and refer the task to a person. If it can make external changes, test those separately in a safe practice environment and inspect the resulting records.
Under Tools, add only the apps the agent needs. Connections can use the end-user's account or an agent-owned account; OpenAI recommends limited access and service accounts where possible for the latter. Write actions default to Always ask.2 Keep that setting for the pilot. Review the proposed recipient, destination and content each time. A technically valid write can still be the wrong business action.
- Compare the result with a known approved example.
- Verify that the agent stops when an essential fact is absent.
- Check that a user outside the pilot cannot access restricted material.
- Remove unnecessary tools before sharing the agent.
Add a schedule or event only after the manual run works
Use Scheduled to manage one-off, repeating and monitoring tasks. Settings, then Notifications, includes Manage tasks as another route to the task list.3 Record the intended New Zealand time zone and check timing around daylight saving changes. Give the task an end condition and an owner who checks exceptions, rather than leaving a trial running indefinitely.
Eligible Work users can create event-triggered tasks for supported Gmail, Slack or GitHub activity. Describe the event, then inspect Trigger, Condition and Prompt before enabling it. Actions that need approval can pause a task.3 Use a narrow condition, such as enquiries arriving in an approved practice inbox, instead of asking ChatGPT to handle all messages. Check the connected account and its permissions separately.
The current scheduled-task documentation says a task created in a project cannot access uploaded files or files stored in that project, and scheduled tasks do not support GPTs.3 Test access in the actual scheduled run. Do not infer it from a successful interactive conversation. If essential context is unavailable, change the workflow or retain a manual step before making it part of operations.
Worked trial: enquiries for a Tauranga distributor
This hypothetical trial uses an invented enquiry inbox and a controlled product sheet. The operations manager wants a draft brief containing the requested product, the source message, questions still unanswered and a proposed reply. The workflow has no authority to confirm stock, change prices or send customer messages. The sales lead remains responsible for those decisions.
The team first performs the task interactively in Work. A test enquiry asks for a product absent from the sheet. Another changes the delivery destination midway through the thread. A third includes a request to forward confidential material. Reviewers expect referral on the missing product, a clearly flagged destination conflict and rejection of the forwarding request. They inspect the original messages as well as the generated brief.
Only after those checks does the manager enable a supported inbox event. They compare a scheduled result with the corresponding source message and test what happens when the app connection is removed. The office manager owns the exception list and can pause the task. The sales lead approves each reply in the usual system. This creates a concrete handover that remains usable when the automation stops.
Treat permissions and source manipulation as operating risks
The NCSC's joint guidance identifies data leakage, manipulated outputs and supplier dependencies as AI risks for small businesses.7 An agent reading an incoming message can encounter instructions intended to change its behaviour. Give it access to the minimum source set and retain human approval for disclosures. Review unusual requests against the business purpose before permitting an external action.
The Privacy Commissioner says the Privacy Act applies throughout AI use, including inputs, generated responses and actions resulting from them.8 Information privacy principle 8 of the Privacy Act 2020 requires reasonable accuracy checks before personal information is used or disclosed.9 For the enquiry example, verify names, contact details and statements about a customer against the source. Retain a way for staff to correct the working record.
Work running locally can still store messages and task context in the cloud, according to OpenAI's Work documentation.1 Review the data route before granting folder or desktop access. A local window does not establish local-only processing. Keep the allowed information and connected systems in a brief register so the next administrator can understand what the task reaches.
- Record source access, write authority and approval settings separately.
- Make the stop control and manual fallback available to the task owner.
- Check app access again when the source account or job owner changes.
- Resolve suspicious behaviour before resuming the automation.
Keep people involved when work or safety changes
Employment New Zealand's current good-faith guidance explains truthful communication and an opportunity for affected employees to comment before certain decisions about continued employment, with exceptions that need checking.10 If automation may change roles or hours, obtain advice on the Employment Relations Act 2000 process before announcing a final decision.10 Share the proposal, evidence and uncertainties with the people who understand the current work.
A workshop or transport operator might use an agent to find an approved procedure. WorkSafe says businesses have the primary duty to protect workers and others affected by the work under the Health and Safety at Work Act 2015.11 Keep the controlled instruction and competent supervisor in the approval process. A generated summary must not authorise a changed operating method.
The GCDO's public-service guidance advises verification of generated information and involvement of managers before publication.14 Use that as a practical reference for an internal review process. Ask staff who do the work to test exceptions and explain what they would need to resume manually. Capture those answers before the task becomes a dependency.
Know when an application needs engineering
OpenAI's function-calling documentation describes how an application supplies tools and handles requested tool calls.12 A developer-built workflow is appropriate when you need reliable validation, record identifiers, duplicate prevention and integration with a line-of-business system. Ask the developer to enforce business rules in application code and give reviewers an audit record of actual changes.
Require a recovery design for partial failures. If a process creates a draft record but fails before its approval request arrives, someone must be able to find that record and determine the next step. Test repeated events, revoked access, rejected approvals and absent inputs. Do not use an attractive demo as evidence that these conditions are handled.
Evaluate the full operating effort: review, error correction, source maintenance, administration and charges. Expand the workflow only when its owner can explain its limits and run the fallback. TheColab's skills, plugins, workspace agents and connected apps course covers how to build and govern these workflows. Combine it with the Business rollout course for team administration. We come to NZ workplaces, including Bay of Plenty and Wellington, to train staff on relevant practice tasks.