Agents in ChatGPT for Work: How Businesses Can Automate Recurring Workflows

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

Most people still use ChatGPT the way they used Google in 2005, one question at a time, then back to the inbox. The repetitive work that actually eats the week, the morning email triage, the Monday briefing, the weekly status roll-up, never makes it into the prompt.

A second mode was built for exactly that category, then renamed in 2026. Here is what the agentic surface is called now, where it helps a Canadian SMB, and where the governance work sits.

Status check, verified August 5, 2026

The vendor documentation now opens with “ChatGPT agent is no longer available.” That mode is folded into ChatGPT Work, “an agent designed for longer, multi-step work and finished deliverables” (OpenAI, ChatGPT Work and Codex). Browser steps moved to cloud browser.

The connector permissions and review discipline below did not change. The menu item did.

Key Takeaways

  • Agents are workflow assistants, not chatbots. They navigate sites, open files, reach email and document repositories, fill forms and edit worksheets, pausing for confirmation.
  • Workspace agents are the enterprise wrapper: build once, share with the team, run in Slack, schedule it, or trigger it from an API. They ship off by default on Enterprise (OpenAI Help Center).
  • Recurring tasks have per-plan ceilings, not one universal cap: 3 on Go, 5 on Plus, 10 on Business and Edu, 15 on Pro and Enterprise, and one run per hour.
  • Budget for six risks: prompt injection, connector permissions, confidential data, over-automation, auditability, and Canadian privacy duties under PIPEDA and Quebec’s Law 25.

What Are ChatGPT Agents?

Quick self-checkHow AI-ready is your business, really?

Score your AI readiness across data, use cases, governance, people and ROI in about 2 minutes. You get your ranked gaps and a 30/60/90-day plan.

Take the AI readiness assessment →or book a free 30-min call →Free · no email until you see your score, or talk to a senior engineer.

According to OpenAI’s July 2025 launch announcement, the product navigates websites, filters results, runs code, and delivers editable decks and workbooks on its own virtual computer. That description still holds even though the 2025 product name is retired. What a buyer licenses is a task runner with permissions attached.

The three terms that do the work

Agentic mode is what a user turns on inside a conversation. It works through screenshots of a virtual browser, clicking and typing the way a person would. In 2026 it lives under ChatGPT Work.

Workspace agents are the business wrapper. An owner builds an agent, previews it before publishing, attaches apps such as Google Drive, Slack and SharePoint, then shares it. The same agent answers in a Slack channel, runs on a schedule, or fires from a scoped API token.

Scheduled tasks are the recurring layer, executing whether or not anyone is signed in. Two ceilings apply: 3 to 15 active tasks depending on the plan, and a floor of 1 run per hour.

Tenant hygiene first. An agent sees whatever the signed-in account already reaches, so my Pre-Copilot SharePoint audit applies here too.

Classic ChatGPT Chat vs. Agentic WorkSame chat box, very different operating modelCLASSIC CHAT.• One-off question and answer.• No persistent task state.• Cannot click, fill, or browse.• No connectors to email or files.• No scheduled runs.• Human types every prompt.Good for: drafting, summarizing,brainstorming, single-shot research.AGENTIC WORK.• Multi-step task on virtual computer.• Reads files, browses public pages.• Connectors: Gmail, Drive, Calendar,SharePoint, Slack and more.• One-off or recurring schedules.• Pauses for confirmation on actions.• Cites sources or screenshots.Good for: morning briefings,weekly reports, recurring research.Source: OpenAI Help Center, retrieved August 5, 2026. fusioncomputing.ca
The shift is from a chat box to a controllable workflow runtime.

ChatGPT Work vs Workspace Agents vs Scheduled Tasks: What Is the Difference?

According to OpenAI’s Scheduled Tasks documentation (retrieved August 5, 2026), active task ceilings run 3 on Go, 5 on Plus, 10 on Business and Edu, and 15 on Pro and Enterprise. Tasks work with every ChatGPT model except Pro models, cannot run more than once per hour, and pause automatically when their chat is deleted.

The costliest licensing mistake I see in Toronto and Hamilton buying conversations is treating those 4 surfaces as one product. They price differently, they are governed differently, and only one is built to be shared.

Surface What it is Who can run it The ceiling that bites
ChatGPT Work Agentic mode for long, multi-step tasks and finished deliverables Eligible paid plans on web, mobile, desktop Usage follows the Codex structure, so heavy runs draw credits
Cloud browser Remote browser for public web steps a connector cannot do Paid plans except Free and Go Cannot sign in to sites or complete payments at launch
Workspace agents Reusable agent shared across a team, Slack, a schedule or an API Business and Enterprise, off by default on Enterprise Slack use forces every app onto shared authentication
Scheduled tasks The recurring trigger layer under all of the above Go, Plus, Pro, Business, Enterprise 3 to 15 active tasks by plan, one run per hour

That last column is where budgets go wrong. A team on Plus gets five active tasks, so the fifth recurring report is a prioritisation decision, not a purchase. Ask us to size the plan against the workflows you want to run.

Why ChatGPT Agents Matter for Businesses

The problem in most Canadian SMBs is a flood of small information chores, not a shortage of intelligence. A Toronto owner reads four inboxes before lunch, then two CRMs, a project tool and a folder of PDFs. Skipping that work still costs: missed follow-ups, stale numbers on Monday, the deal that quietly went cold.

My test for whether a workflow is worth automating is boring and reliable. If I cannot describe the output in 1 sentence, the agent will not produce it consistently either. In my experience at Fusion Computing, more rollouts fail on a vague output spec than on model quality.

For where AI fits across the wider operation, my AI strategy guide for Canadian SMBs sets out the prioritisation framework I use in client sessions.

Not sure which workflow to automate first? Get in touch to map your first agent →

Field note from Mike

The first agent workflow I shipped was a Friday operations report for a 28-person Toronto professional services firm, in March 2026. Their controller had been spending roughly 90 minutes every Friday on the same five spreadsheet pulls and the same paragraph of commentary.

We scoped it against three named SharePoint files and one Power BI export, fixed a template, and put human review in front of the send. Run one produced the right artefact in 4 minutes. Run two drifted because a source file had been renamed, so we pinned file paths in the prompt. By week six she reviewed for about 12 minutes instead of assembling for 90.

Anonymized client data from an FC engagement, March 2026. Client identifiers changed.

Practical Examples of ChatGPT Agent Workflows

According to OpenAI’s July 2025 launch announcement, useful opening prompts include “look at my calendar and brief me on upcoming client meetings based on recent news” and “analyze three competitors and create a slide deck.” Across our Canadian SMB client base, almost every workflow that survives past month one lands in one of six patterns.

  • Daily email briefing. Scans the last 18 hours of inbox traffic, groups by sender and thread, surfaces anything mentioning a deadline or invoice, and posts to Slack before 8:30 AM.
  • Contract review. Extracts renewal date, payment terms, indemnification clauses and non-standard language from a vendor agreement, then writes a one-page memo for a human to check.
  • Competitor monitoring. Checks an approved source list daily for mentions of the company and its top three competitors, then ranks what matters.
  • Meeting preparation. Opens the invite, pulls public information on the company, references the last CRM interaction, drafts a one-page brief.
  • Weekly operations report. Collects data from two or three fixed workbooks, fills a template, emails leadership. Where the work stays inside one workbook an in-grid assistant usually wins, and my best AI for Excel comparison covers that choice.
  • Sales follow-up tracking. Flags deals gone quiet against an agreed cadence, with a suggested next action for each.
Six Starter Workflows, Ranked by Hours RecoveredObserved ranges from FC pilots with 10 to 50-person Canadian SMBs, 2026Daily email briefing4 to 5hWeekly operations report3 to 4hMeeting preparation2 to 3hNews & competitor monitoring2 to 3hContract & document review2 to 3hSales follow-up tracking1 to 2h0h1h2h3h4h5hPer knowledge worker. Time is recovered, not eliminated:it goes back into customer-facing and decision-making work.Source: Fusion Computing pilot observations, six workflows, 2026. Ranges, not audited figures. fusioncomputing.ca
The pattern is that the highest-value workflow is usually the most boring one.

Fusion mapped AI opportunities to our actual day-to-day workflows, deployed Copilot for leadership, and cut month-end reporting from two days to four hours.

Rachel D., Managing Partner, Financial Planning Firm, Toronto

What Makes a Good AI Agent Workflow: A Six-Point Checklist

According to OpenAI’s agent documentation (2026), the system “will pause for clarification or confirmation when needed” and “can be guided or interrupted mid-task.” That control surface separates a workflow that lasts from a prompt that worked once. Six ingredients decide which one you get.

  1. A clear trigger. A time, 08:00 every weekday, or an event such as a file landing in a folder.
  2. Trusted data sources. Name the drive, the calendar, the CRM view. “The whole inbox” is almost never the right scope.
  3. Specific instructions. What to include, what to ignore, what format. Most failed rollouts trace to a one-line prompt nobody refined.
  4. A defined output. One channel, one template. Consistency keeps the workflow useful three months in.
  5. Human review. One accountable person who checks output before it leaves the building.
  6. Security boundaries. Which apps it may query, which it may write to, who can run it. On Business and Enterprise these are workspace settings, and write actions default to “Always ask”.

Where Businesses Need to Be Careful

According to OpenAI’s workspace agents documentation (retrieved August 5, 2026), workspace agents are off by default at launch for ChatGPT Enterprise, admins enable them per eligible workspace, and the same role-based access controls carry into Codex. That default-off posture is the clearest signal this is meant to be governed first.

Prompt injection is the risk specific to agents

OpenAI describes an attack where a malicious comment on a page tricks the agent into pulling a password reset code from Gmail and sending it to a hostile site. Because an agent acts rather than only answers, a successful injection does damage a chatbot never could. Confirmations on high-impact actions and a supervised watch mode are the documented mitigations.

Permissions and confidential data

An agent inherits the permissions of whoever configured it, plus every connector granted to it. OpenAI advises “extra caution when using apps with ChatGPT agent to prevent unauthorized access to sensitive information.” Client matter data, payroll and HR files need classifying first.

PIPEDA and Quebec’s Law 25 both require knowing what you collect, why, and where it goes. Law 25 goes further: section 12.1 obliges an enterprise to tell a person when a decision about them came from exclusively automated processing.

Over-automation and auditability

A wrong invoice or client email costs far more than the minute it takes to read it first, so not every recurring task should run unattended. Agent conversations appear in the Compliance API for Enterprise, but individual actions, virtual computer usage and chain of thought do not. Your audit trail has to live in the destination systems.

Where to Deploy an Agent: A Risk MapSort the workflow before turning it on, not afterLOW DATA SENSITIVITY.HIGH DATA SENSITIVITY.HIGH OVERSIGHT.LOW OVERSIGHT.SAFE TO DEPLOY.News briefings, public research,competitor monitoring, draftsummaries reviewed by a human.Start here.DEPLOY WITH GUARDRAILS.CRM-driven follow-ups, internalops reports, scoped contractreview with explicit data classes.MSP scope review required.PILOT CAREFULLY.Auto-posting summaries to Slack,scheduled emails to internal lists,spreadsheet updates without review.Add a checkpoint before sending.DO NOT DEPLOY.Auto-replies to clients, automatedpayments or filings, unsupervisedhandling of personal information.Human approval mandatory.
Source: Fusion Computing client engagement framework, 2026.

Why IT and Cybersecurity Still Matter

According to OpenAI’s safety guidance (2026), signing an agent into websites or enabling apps lets it reach emails, files and account settings and act on your behalf, which “creates potential privacy risks, including prompt injection attacks.” The vendor is saying plainly that the control work belongs to the customer. In an SMB it has no owner by default.

Field note from Mike

The failure I see most often is scope, not a bad model answer. When we run an AI access review across our Canadian SMB client tenants, the first connector someone attaches is almost always the whole mailbox or the whole drive, because that is the default on the consent screen.

We measured that gap on a 40-seat Hamilton engagement in Q2 2026. The folder the workflow needed held 9 files; the connector reached roughly 12,000. Nothing leaked. The exposure was larger than anyone had decided to accept.

First-person field observation. FC internal benchmark from Q2 2026, anonymized.

An MSP earns its keep at four points:

  • Choosing which workflows deserve automating.
  • Reviewing permissions before connectors go live.
  • Integrating agents with Microsoft 365 and SharePoint so classification and DLP rules still bite.
  • Helping people adopt sanctioned tooling instead of opening personal accounts.

Fusion Computing does that inside a broader AI services and managed IT engagement, with cybersecurity reviewing the perimeter. Book a scoping call to review your connector permissions →

Getting Started With ChatGPT Agents

According to OpenAI’s workspace agents documentation (2026), an agent can be previewed before publishing, connected to apps including SharePoint, Slack and Google Drive, and constrained so a connector only acts within rules an admin writes in plain language. My advice is to start narrow.

  1. Pick one recurring workflow. Weekly or more often, over 30 minutes, producing a written artefact. Email briefings and ops reports are the safest first picks.
  2. Name the data sources. The inbox, the folder, the calendar, the sheet. Avoid “everything I can see” as an opening scope.
  3. Define the output. Where it goes, in what format, to whom.
  4. Add human approval. For 30 days a named person reviews every output before it leaves. Then decide what may run unattended.
  5. Review security, then iterate. Walk the connectors and write approvals with your MSP, then refine the prompt from what the first month teaches you.

Where an agent must read two or more business systems to answer one question, the licence question becomes a build question. My custom AI platform vs Microsoft 365 Copilot comparison sets out when that build repays the engineering, and Copilot vs ChatGPT vs Claude covers the platform choice underneath it.

If the comparison lands on Microsoft’s side, price the outcome before the seats. Our Microsoft 365 Copilot ROI model for Canadian businesses works the payback from the add-on rate rather than a headline time-savings figure.

Want a second opinion on governance? Our AI readiness assessment covers tools, data classes and policy in 1 working session, run by a CISSP-led team at Fusion Computing, or talk to a senior engineer first.

Final Thoughts

Agents are workflow assistants rather than magic automation, and the 2026 rename to ChatGPT Work leaves the buying question unchanged. Pick the workflow, scope the data, set the governance, then tune the output. I cover the companion use in using ChatGPT agents to distill scattered knowledge across your SMB.

Frequently Asked Questions

What are ChatGPT Agents?

ChatGPT Agents are an operating mode that carries out multi-step tasks on a virtual computer: navigating websites, reading uploaded files, reaching email and document repositories, filling forms and editing spreadsheets, pausing for confirmation when an action has consequences. As of August 5, 2026 OpenAI has retired the standalone agent menu item and folded the capability into ChatGPT Work, with browser steps in cloud browser (OpenAI).

Are ChatGPT Agents safe for business use?

They can be, with the right configuration. Workspace agents are off by default at launch on ChatGPT Enterprise, app access is controlled centrally, role-based access control applies, write actions default to “Always ask”, and conversations appear in Compliance API logs. The risk profile follows the connectors an agent may reach, so personal accounts running unsanctioned are the exposure.

Can ChatGPT Agents summarize emails and documents?

Yes. With connectors enabled, an agent reads recent email, summarizes threads by topic, extracts action items and produces a daily briefing. The same applies to PDFs, Word documents and SharePoint files where access has been granted. One gotcha: a scheduled task created inside a project cannot reach that project’s files.

Do ChatGPT Agents replace traditional automation tools?

No, they sit alongside them. For deterministic, rule-based work such as accounts payable matching or ETL, a purpose-built automation platform is still the right answer. Agents earn their place where the work means reading unstructured information and writing an output that varies on all 5 runs.

What is the best first workflow to automate?

For most Canadian SMBs, a daily email briefing or a weekly operations report. Both run on a predictable cadence, produce a written artefact, and carry low downside if the first run gets something wrong. Sales follow-up tracking is a strong second once the first is stable.

Do businesses need an AI policy before using agents?

Yes. A short written acceptable use policy listing approved tools, classifying data that may be entered into them and requiring annual training is now standard in Canadian cyber insurance renewals. PIPEDA applies, and Law 25 section 12.1 requires telling a person when a decision about them came from exclusively automated processing. My guide on what should be in an AI acceptable use policy has a template.

Which ChatGPT plans support agent mode?

OpenAI documents agent mode on Pro, Plus, Business, Enterprise and Edu, never on the free plan, with monthly ceilings of 40 messages on Plus, 400 on Pro and 40 per user on Business and Enterprise; flexible-pricing tenants meter at 30 credits per message. As of August 5, 2026 that capability sits inside ChatGPT Work, and cloud browser excludes Free and Go.

How many recurring agent tasks can run at once?

The ceiling depends on the plan rather than being one number: 3 active tasks on Go, 5 on Plus, 10 on Business and Edu, 15 on Pro and Enterprise. Tasks cannot run more than once per hour, and one pauses automatically if its chat is deleted. Review them at chatgpt.com/schedules (OpenAI, Scheduled Tasks in ChatGPT).

Led by Mike Pearlstein, CISSP. Fusion Computing has run managed IT for Canadian SMBs since 2012.

Book a Consultation

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Led by a CISSP-led team, Fusion supports organizations with 10 to 150 employees from Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611