ChatGPT Team, a self-serve subscription plan designed for organizations and businesses wishing to adopt ChatGPT for use among their teams! - OpenAI Support Bot
We are a smaller company with slightly less than 100 members. We have been trying to get in touch with OpenAI about Enterprise since September but have not received any response. Since October, we have been reimbursing employees’ ChatGPT Plus subscriptions. We have been huge proponents and users of OpenAI’s services at our organization.
When the ChatGPT Team subscription launched, we felt seen. Finally, we could get our employees into a safe space where conversations were not used for training, and Custom GPTs could be private to our organization and finally be useful because they could contain company information that couldn’t be extracted by malicious actors who found the links.
This was the Enterprise experience we were waiting for. Due to our size, this is the only Enterprise option that we have, and I imagine we are not the only organization in this class.
After paying for the first 40 seats at the annual rate, we discovered that all members can invite an arbitrary number of new members. Not only this, but any member can obligate the Team to pay for more seats, pro-rated, and neither Admins nor Owners can prevent this. These costs appear to not be easily refundable.
I’m sorry for the strength of my language, but this is completely absurd.
There are two major security and billing issues with this:
- Malicious actors are provided an unauthorized access vector to Custom GPT knowledge via every member.
- Malicious or non-malicious actors can generate unauthorized billing costs by inviting new members, even outside the range of baseline seats.
These vulnerabilities are incredibly easy to abuse and impossible to protect against. Adding new members can even be accomplished via CSV.
Because ChatGPT Team is the only option available for our organization, there needs to be some form of invitation control. This design choice is so unexpected for a company like OpenAI. No organization our size can ethically use this product without this feature.
One hundred members is too large a group to be able to fully trust every member with security and billing repercussions.
I’ll repeat: ChatGPT Team needs some form, any form, of invitation control.