OpenAI shipped an Admin plugin for ChatGPT Work and Codex in late August 2026. Workspace admins can review usage, manage members and groups, adjust permissions, and action spend requests without leaving the chat window. Recurring admin jobs can be routed to Slack or Teams for sign-off. OpenAI says a related internal agent resolves roughly 45% of its own IT ticket volume.
If you run a business in Sydney or Melbourne with staff on both platforms, the honest read is that admin tooling has stopped being a differentiator. Both vendors now ship enough control surface to satisfy a procurement questionnaire. The question that decides your actual spend is narrower and less flattering: which of those controls are switched on in your account right now, and who checked?
What the Admin plugin actually changes
The capability is not new. Usage reporting, group management and permission editing all existed in the ChatGPT admin console before this. What changed is placement. Admin work moved into the interface people already have open, and requests can be routed to where approvals actually happen, which for most Australian teams is Slack or Teams rather than a console nobody logs into.
That is a real gain and it deserves naming plainly rather than dismissing because a competitor shipped it. Cutting the number of clicks between a usage-limit request and a decision is the difference between a spend policy that runs and one that only exists in a document.
What Claude already gives an administrator
Claude's control surface is wide, and the detail that matters is that it is tiered. Checked against Anthropic's own documentation in late August 2026:
SSO and SAML run on Team and Enterprise. SCIM, the only mechanism that automatically removes a departing staff member's access, is Enterprise only. Just-in-time provisioning creates accounts but never deletes them.
Connector permissions set to allow, require approval, or block apply across the whole organisation, and individual users cannot override them. Enterprise adds domain restriction across roughly fifteen services including Gmail, Drive, Microsoft 365, Slack and Notion.
Claude Code reads a managed policy file that can force permission modes, restrict which MCP servers run, set a minimum version, and send telemetry to your own collector.
Cowork cloud sessions default to on for Team and off for Enterprise. Automatic approval mode is on unless an owner turns it off, and that is the single setting most new accounts never look at.
Domain capture, IP allowlisting and custom roles are Enterprise only. Domain capture is a one-way door with a 30-day migration window.
The pattern matters more than any single line. The sentence "Claude can control that" is frequently true only on Enterprise. A Team-plan account told otherwise finds the gap during an audit rather than before one.
The gaps that survive on both platforms
Here is the part neither announcement leads with. Several controls Australian buyers assume exist do not exist on either side.
There is no review or approval step before an artifact, skill or plugin is published. Audit events are recorded after the fact, not before it.
There is no approval queue for connectors a user asks for.
An administrator cannot pick which MCP servers a given artifact may call. It is all or nothing.
Audit log export is capped at 180 days, arrives as CSV, and records identifiers rather than content.
Claude for Excel sits outside the enterprise perimeter. It does not inherit custom retention settings and is not covered by enterprise audit logs. Finance is usually the team using it.
Under the Privacy Act, and under CPS 234 for APRA-regulated entities, a picture that is only visible after the fact is not automatically a failure. It is a control design question you have to answer in writing, and "the vendor handles it" is not the answer.
The arithmetic, in AUD
Take a 40-person Australian firm running both platforms at roughly $2,400 a month in combined seats. That is $28,800 a year in visible spend, and the visible number is rarely the problem.
Three costs sit underneath it. First, dormant seats: without automatic deprovisioning, a person who left in March can still hold a licence in September. Ten stale seats at $60 a month is $7,200 a year of pure waste. Second, duplicated tooling, where two teams buy overlapping capability because nobody owns the usage report. Third, the rework when an unreviewed artifact reaches a client and someone has to reconstruct where its numbers came from.
None of those three is fixed by an admin plugin or an admin console. They are fixed by a named person owning a review cadence.
What to check this week
Open your Cowork settings and confirm whether automatic approval is on. Decide deliberately either way.
List every connector enabled across the organisation and name the person who asked for each one.
Reconcile your seat list against your payroll list, then count the difference.
Ask finance directly whether anyone is using Claude for Excel, and decide what that means for your retention position.
Book a monthly 30-minute review with a named owner. Most governance failures we see in Australian mid-market accounts are calendar failures, not tooling failures.
Governance tooling is now table stakes on both platforms. What separates them in practice is whether the settings match how your business actually works, and whether anyone looks at them after week one.
If you want a second pair of eyes on your Claude setup before the next audit cycle, book a short call.



