Connectors
A clear look at what audit evidence each ChatGPT tier exposes, why Free, Plus and Team leave a gap, and the practical routes to close it.
5 June 2026 · 7 min read
If you run IT or compliance, "we use ChatGPT" is not an answer you can stand behind. The honest follow-up is: which tier, on whose accounts, and what record does it leave? Those answers vary enormously across OpenAI's plans, and the gap between them is exactly where governance falls down. This is a plain explainer of what evidence each tier actually exposes — and what to do about the tiers that expose almost nothing.
OpenAI does provide a proper audit surface, but it lives on one side of a hard line. The Compliance API — the export and audit interface that exposes conversation logs, file events and admin actions — is available only on ChatGPT Enterprise (and the equivalent Edu plan).
That is the whole story in one sentence: an API that lets a third party pull a structured, complete record of usage exists for Enterprise and Edu, and does not exist for Team, Plus or Free. It is not a question of turning on a setting or paying a little more on a smaller plan. The data interface is simply not there below Enterprise.
So when someone says "we have ChatGPT for Business", the first thing to establish is whether that means Enterprise or Team. The names sound adjacent. The evidence they leave behind is not.
In plain terms:
Team gives you an admin console. It does not give you an audit trail. Those are not the same thing, and treating them as equivalent is where a lot of firms quietly fail an audit.
The trap is that Team *feels* governed. It has a workspace, an owner and a billing relationship, so it is easy to assume the evidence is there. It is not. And Plus and Free accounts — including personal accounts staff use on the side — sit entirely outside anything you administer.
The approach depends on the tier, because the available evidence does.
On Enterprise and Edu, Evaident connects through the Compliance API and pulls usage into one tamper-evident record, with optional billed costs alongside it. You are using the audit surface OpenAI exposes, consolidated into a record you control.
For Team, Plus, Free and personal accounts, there is no Compliance API to lean on, so the evidence has to come from somewhere you do control. There are two routes:
That metadata-by-default point matters. The standard posture is to record the *fact and shape* of use — who, when, which tool — without storing what was typed. If you need more, preview or full content capture is opt-in, and full verbatim transcripts require the Enhanced Content Capture add-on. You decide how deep the record goes; it is not all-or-nothing.
Many firms reach first for what they already have: firewall, secure web gateway or SIEM logs. These are genuinely useful for one job. They show that chatgpt.com is being reached, and by whom, which is how you discover usage you never sanctioned.
But there is a firm limit, and it is worth stating plainly. Those logs work by destination. They cannot see inside the encrypted (TLS) connection, so they never reveal prompt content. You learn that ChatGPT is in use and roughly by which user; you learn nothing about what was actually sent. For discovery that is fine. As an evidence base for how AI is being used, it stops well short.
So the layers stack like this: network logs tell you a tool is in use; the Gateway and the extension tell you how it is being used and at what cost; and on Enterprise, the Compliance API gives you OpenAI's own audit export. Each covers a different part of the picture.
Match the route to the tier, and be honest about the limits:
None of this turns a Team plan into Enterprise, and it is not meant to. The goal is an honest, defensible record of AI use across whichever tiers your people actually have — supporting your compliance work, not standing in for legal advice.
To see which tools and accounts are already in use across your firm, run an exposure check. To compare the routes and what they cost, see /pricing.
The free AI Exposure Check gives you an instant score across visibility, shadow AI, evidence, governance and data-leak risk — no data connection needed.