Skip to content

The 6 ChatGPT Enterprise security checks Black Cat runs

Black Cat SSPM evaluates 6 security policies against your ChatGPT Enterprise configuration on every scan, classifies each finding by risk, and provides remediation steps. All of them are listed below.

How to connect ChatGPT Enterprise — what access Black Cat needs, and why.

Other checks (6)

severity: medium Disabled Member Present fix difficulty: easy #

Remove or fully deprovision disabled ChatGPT Enterprise members

  1. Open chatgpt.com/admin > Members
  2. Remove the disabled member, or complete deprovisioning in your IdP/SCIM source
  3. Confirm the member no longer appears in the workspace

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: low Non-SCIM-Managed User fix difficulty: medium #

Bring manually-added members under SCIM/IdP provisioning

  1. Configure SCIM provisioning from your IdP to ChatGPT Enterprise
  2. Re-provision the affected member through the IdP so they carry an externalId
  3. Remove any locally-created duplicate account

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

severity: medium GPT With Unreviewed Third-Party Actions fix difficulty: medium #

Review third-party actions on publicly shared custom GPTs

  1. Open chatgpt.com/admin > GPTs
  2. Review each third-party action's domain and requested scope on the GPT
  3. Remove unreviewed actions, or restrict the GPT's sharing to private/workspace

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Secret Detected In ChatGPT Conversation fix difficulty: medium #

Rotate the exposed credential, then remove the conversation from ChatGPT Enterprise

  1. Rotate the exposed credential immediately at its issuing provider
  2. Open chatgpt.com/admin
  3. Locate and remove the flagged conversation via the ChatGPT admin console

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: low Empty Group fix difficulty: easy #

Remove unused empty groups

  1. Open chatgpt.com/admin > Groups
  2. Delete the group if it is no longer needed, or assign members

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Workspace Allows Unapproved Connectors fix difficulty: medium #

Restrict the workspace to an approved connector allowlist

  1. Open chatgpt.com/admin > Settings > Connectors
  2. Disable "Allow unapproved connectors" for the workspace
  3. Add any connectors members need to the approved allowlist explicitly

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial