Environment
- Surface: ChatGPT Projects
- Connected apps involved: Google Drive and Gmail
- Plans/workspaces observed: multiple ChatGPT Projects, including environments where the same connected Google account is available
- Issue type: Project isolation / connected-app authorization scope
What I observed
I have observed a practical isolation issue across separate ChatGPT Projects when the same connected Google account is available.
The important distinction is that this is NOT proven hidden-memory leakage.
In my testing:
- A chat in one ChatGPT Project could not directly access another Project’s hidden chat memory or internal context.
- However, because the same Google Drive connection was available, that chat could search for documents and communications belonging to another Project.
- It located governance documents and communication mailboxes from that other Project.
- It was also able to write communication artifacts into those Google Drive locations.
- The crossover therefore occurred through the shared connected Google Drive data plane, not through hidden ChatGPT memory.
Why this matters
The practical result is that Project-only memory can isolate conversation/history context while a broadly authorized Google Drive or Gmail connection may still expose information from unrelated Projects if the connected Google identity itself has access to that information.
From a user perspective, the net effect can resemble cross-project information or memory exposure even though the technical mechanism is external connected-app retrieval.
This means there appear to be two different boundaries:
- ChatGPT Project / memory boundary
- Connected Google account / provider authorization boundary
The first may isolate Project conversations and memory, while the second may remain much broader.
Expected behavior / product question
I would like clarification on whether connected-app access can also be isolated at the ChatGPT Project level.
Specifically:
-
Can Google Drive or Gmail access be restricted per ChatGPT Project?
-
Can one Project be limited to selected Google Drive folders, Shared Drives, Gmail labels, mailboxes, or specific connected accounts while another Project uses a different subset?
-
If multiple Google accounts are connected, can a specific Google account be bound or restricted to a specific ChatGPT Project?
-
For live Google Drive/Gmail app actions, is the effective information boundary always the connected Google account’s provider-side permissions rather than the ChatGPT Project boundary?
-
Are project-scoped connector identities, source restrictions, or connector policies available or planned?
-
What architecture does OpenAI recommend when customers require strong information isolation between ChatGPT Projects while still using connected apps?
-
Is the distinction between Project-only memory and connected-app scope documented clearly enough for users to understand that Project isolation may not constrain the scope of the connected provider account?
Security / governance concern
This is particularly important for large or sensitive projects.
For example, if Project A and Project B both use the same broadly authorized Google account, Project A may be able to retrieve Project B documents or communications from Google Drive or Gmail even though Project A cannot directly access Project B’s ChatGPT memory.
If write actions are enabled, the issue is broader than passive retrieval because one Project may also be able to write into durable storage used by another Project.
For environments requiring strict isolation, this could require compensating controls such as:
- separate provider identities;
- project-specific Shared Drives or folder ACLs;
- separate mailboxes;
- service identities;
- explicit cross-project authorization rules.
I would like to know whether OpenAI provides a native per-Project connector-scoping mechanism that should be used instead.
Scope clarification
This report is NOT alleging hidden-model-context leakage or hidden-memory leakage.
The observed mechanism is connected-app retrieval/write through shared provider authorization.
The concern is a possible mismatch between the isolation users may expect from ChatGPT Projects and the broader access scope of connected apps such as Google Drive and Gmail.
I have also reported this separately to OpenAI Support so that the product-boundary question can receive an official response.
I would be interested in hearing whether other users have observed the same behavior or have found a supported way to restrict connected-app access per ChatGPT Project.
Ernie Fedorowych
Senior Business Systems Analyst