Connectors

ChatGPT Enterprise vs Team vs Free: what evidence can you actually get?

A clear look at what audit evidence each ChatGPT tier exposes, why Free, Plus and Team leave a gap, and the practical routes to close it.

5 June 2026 · 7 min read

If you run IT or compliance, "we use ChatGPT" is not an answer you can stand behind. The honest follow-up is: which tier, on whose accounts, and what record does it leave? Those answers vary enormously across OpenAI's plans, and the gap between them is exactly where governance falls down. This is a plain explainer of what evidence each tier actually exposes — and what to do about the tiers that expose almost nothing.

The dividing line is the Compliance API

OpenAI does provide a proper audit surface, but it lives on one side of a hard line. The Compliance API — the export and audit interface that exposes conversation logs, file events and admin actions — is available only on ChatGPT Enterprise (and the equivalent Edu plan).

That is the whole story in one sentence: an API that lets a third party pull a structured, complete record of usage exists for Enterprise and Edu, and does not exist for Team, Plus or Free. It is not a question of turning on a setting or paying a little more on a smaller plan. The data interface is simply not there below Enterprise.

So when someone says "we have ChatGPT for Business", the first thing to establish is whether that means Enterprise or Team. The names sound adjacent. The evidence they leave behind is not.

What each tier gives you

In plain terms:

  • Enterprise and Edu — the Compliance API is available. Conversation logs, file events and admin actions can be exported programmatically into your own records. This is the only tier with an audit-grade evidence interface.
  • Team — central billing and admin controls, but no Compliance API. You can see seats and broad workspace settings; you cannot pull conversation-level audit logs out through a supported interface.
  • Plus — an individual paid account. No admin surface, no export API, no central oversight.
  • Free — the same as Plus from a governance point of view: a personal account with nothing to query.
Team gives you an admin console. It does not give you an audit trail. Those are not the same thing, and treating them as equivalent is where a lot of firms quietly fail an audit.

The trap is that Team *feels* governed. It has a workspace, an owner and a billing relationship, so it is easy to assume the evidence is there. It is not. And Plus and Free accounts — including personal accounts staff use on the side — sit entirely outside anything you administer.

How Evaident closes the gap

The approach depends on the tier, because the available evidence does.

On Enterprise and Edu, Evaident connects through the Compliance API and pulls usage into one tamper-evident record, with optional billed costs alongside it. You are using the audit surface OpenAI exposes, consolidated into a record you control.

For Team, Plus, Free and personal accounts, there is no Compliance API to lean on, so the evidence has to come from somewhere you do control. There are two routes:

  • The Evaident Gateway — for API tools and in-house agents, on any tier. It captures usage in real time, can enforce policy, and records exact per-person token costs. If your people build on the API rather than the chat product, this is the cleanest source of truth.
  • A managed browser extension — captures ChatGPT, Claude and Gemini web use, including Free, Plus, Pro and personal accounts. This is detection and evidence, not blocking: it sees and records the use rather than preventing it. By default it captures metadata.

That metadata-by-default point matters. The standard posture is to record the *fact and shape* of use — who, when, which tool — without storing what was typed. If you need more, preview or full content capture is opt-in, and full verbatim transcripts require the Enhanced Content Capture add-on. You decide how deep the record goes; it is not all-or-nothing.

Where shadow AI logs fit — and where they stop

Many firms reach first for what they already have: firewall, secure web gateway or SIEM logs. These are genuinely useful for one job. They show that chatgpt.com is being reached, and by whom, which is how you discover usage you never sanctioned.

But there is a firm limit, and it is worth stating plainly. Those logs work by destination. They cannot see inside the encrypted (TLS) connection, so they never reveal prompt content. You learn that ChatGPT is in use and roughly by which user; you learn nothing about what was actually sent. For discovery that is fine. As an evidence base for how AI is being used, it stops well short.

So the layers stack like this: network logs tell you a tool is in use; the Gateway and the extension tell you how it is being used and at what cost; and on Enterprise, the Compliance API gives you OpenAI's own audit export. Each covers a different part of the picture.

The practical takeaway

Match the route to the tier, and be honest about the limits:

  • If you are on Enterprise or Edu, you have a real audit surface — connect to it and consolidate.
  • If you are on Team, Plus or Free, accept that there is no audit API and close the gap with the Gateway for API and agent use, and the managed extension for web use.
  • Use network logs to discover shadow usage, not to evidence what was said.
  • Choose your capture depth deliberately: metadata by default, content only where you have decided it is justified.

None of this turns a Team plan into Enterprise, and it is not meant to. The goal is an honest, defensible record of AI use across whichever tiers your people actually have — supporting your compliance work, not standing in for legal advice.

To see which tools and accounts are already in use across your firm, run an exposure check. To compare the routes and what they cost, see /pricing.

See where your firm stands

The free AI Exposure Check gives you an instant score across visibility, shadow AI, evidence, governance and data-leak risk — no data connection needed.