Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Next Generation API Data Protection Platform
    Next Generation API Data Protection for ChatGPT Enterprise
    Configure ChatGPT Enterprise for the Next Generation API Data Protection

    Configure ChatGPT Enterprise for the Next Generation API Data Protection

    When integrating ChatGPT Enterprise with Next Generation API Data Protection, customers can onboard access in one of two ways:

    • Enterprise Workspace onboarding — Provides coverage for conversations, messages, memories, and users.

    • Organization Project onboarding — Provides coverage for fine-tuning datasets.

    Each ChatGPT instance can be configured for one type of onboarding only. Once selected, the access type cannot be changed for that instance. To switch from workspace-level to project-level access (or vice versa), customers must create and onboard a new ChatGPT instance.

    For customers who want to begin scanning fine-tuning data, this means the ChatGPT instance must be onboarded at the project level, even if an existing instance is already onboarded at the workspace level.

    Prerequisite

    • Role requirement:

      • For enterprise workspace onboarding, a ChatGPT Enterprise workspace administrator account.

      • For organization project onboarding, the user generating the key must have the owner role for both the OpenAI platform organization and the specific project where the fine-tuning data resides.

    • Make sure the Organization ID in the OpenAI Platform API settings (https://platform.openai.com/settings/organization/general) matches the Organization ID of the ChatGPT workspace where you want to enable the Compliance API (https://chatgpt.com/admin/settings).

      If the Organization IDs do not match, contact support at support@openai.com to resolve the issue before proceeding.

      Organization ID in the OpenAI Platform API settings
      Organization ID of the ChatGPT workspace
    Enterprise Workspace Onboarding
    Organization Project Onboarding

    Enterprise Workspace Onboarding

    Create an API Key

    This section describes the steps to create a new API key for the ChatGPT organization. This API key will be required when you set up the ChatGPT Enterprise instance on the Netskope tenant UI.

    1. Log in as an owner to your ChatGPT organization and create a new API Key at https://platform.openai.com/api-keys.

      Be sure to create the API key within the same organization as your ChatGPT Enterprise workspace. You can find the organization ID at https://platform.openai.com/settings. Only an owner of both the OpenAI organization and the ChatGPT Enterprise workspace can create the key.
    2. Click + Create new secret key.

      You may be prompted to verify your mobile number.
    3. On the pop-up window, enter the following details:

      • Under Owned by, select You.

      • Enter the name of the API key.

      • Select the default project.

      • Under Permissions, select All.

    4. Click Create secret key.

    5. Save the key.

      The API key is only visible once, so be sure to copy it securely. The API key will be required when you set up the ChatGPT Enterprise instance on the Netskope tenant.
    6. Send an email to support@openai.com requesting access to the Compliance API. Include the last 4 characters of the API key, the name of the key, who created it, and the requested scope (read, write, or both).

      OpenAI team will verify the key and grant the requested Compliance API scopes. Once OpenAI team grants the Compliance API scopes, you should enter the API key when you set up the ChatGPT Enterprise instance on the Netskope tenant.

      Next, configure Netskope to access your ChatGPT Enterprise account.

    Organization Project Onboarding

    The Next Generation API Data Protection product does not currently support users or groups for project-level instance onboarding. As a result, exposure-level visibility is not available for fine-tuning datasets at this time.

    Create an API Key

    This section describes the steps to create a new API key for the ChatGPT organization project. This API key will be required when you set up the ChatGPT Enterprise instance on the Netskope tenant UI.

    1. Log in as an owner of your OpenAI platform organization and create a new API Key at https://platform.openai.com/api-keys.

      Be sure to create the API key within the same organization as your ChatGPT Enterprise workspace. You can find the organization ID at https://platform.openai.com/settings. Only an owner of both the OpenAI organization and the ChatGPT Enterprise workspace can create the key.
    2. Select a project that contains the fine-tuning data you wish to scan.

    3. Click + Create new secret key.

      You may be prompted to verify your mobile number.
    4. On the pop-up window, enter the following details:

      • Under Owned by, select You.

      • Enter the name of the API key.

      • Select the default project (or the project you selected in step 2).

      • Under Permissions, select All.

    5. Click Create secret key.

    6. Save the key.

      The API key is only visible once, so be sure to copy it securely. The API key will be required when you set up the ChatGPT Enterprise instance on the Netskope tenant.

    Next, configure Netskope to access your ChatGPT Enterprise account.

    Configure Netskope to Access your ChatGPT Enterprise Account

    To authorize Netskope to access your ChatGPT Enterprise account, follow the steps below:

    Continue only after OpenAI has approved the requested Compliance API scopes for the new API key. This requirement applies to Enterprise Workspace onboarding.
    If you are onboarding a project at the organization level, you may proceed without this approval step.
    1. Log in to the Netskope tenant UI and go to Settings > Configure App Access > Next Gen > CASB API.

    2. Under Apps, select ChatGPT Enterprise and click Setup CASB API Instance.

      The Setup Instance window opens.

    3. Under Administrator Email, enter the email address of the user who will receive an email notification when a policy violation or event triggers. This step is optional.

    4. If you are onboarding an enterprise workspace, enter the following details:

      • Under Workspace ID, enter your ChatGPT account’s workspace ID.

        The Workspace ID can be obtained from https://chatgpt.com/admin/settings. Ensure that you are a workspace administrator to access the URL.
        Ensure that the Organization ID on the this page matches the one used to create the API key.
      • Under API Key for Enterprise Workspace, enter the API key that was previously created for enterprise workspace.

      Leave the rest of the fields empty.

    5. If you are onboarding an organization project, under API Key for Project, enter the API key that was previously created for organization project.

      Leave the rest of the fields empty.

    6. Under Instance Name, enter a name of the SaaS app instance. This step is optional and if left blank, Netskope will determine the name of the app instance post grant.

    7. Click Grant Access.

    Refresh your browser, and you should see a green check icon next to the instance name.

    Next, you can view the Next Generation API Data Protection Inventory page to get deep insights on various entities on your ChatGPT Enterprise instance. For more information on the Inventory page, see Next Generation API Data Protection Inventory.

    Next, you should configure a Next Generation API Data Protection policy. To do so, see Next Generation API Data Protection Policy Wizard.

    In this Topic
    • Configure ChatGPT Enterprise for the Next Generation API Data Protection