GreenLoop IT Solutions : Articles

Digital padlock representing application permission approval and access control in Microsoft 365

Why a Security Assessment Comes Before Rolling Out ChatGPT or Claude

Executive Summary

  • What it is: ChatGPT and Claude are already in use at most organizations, whether or not IT ever approved them. A security assessment identifies exactly how they’re being used today, and what needs to happen before a company-wide rollout.
  • The risk: Employees pasting client data, financial records, source code, or internal strategy into personal ChatGPT or Claude accounts creates data exposure with no logging, no audit trail, and no easy way to delete it if that employee leaves.
  • Why it matters now: Compliance obligations, client contracts, and industry regulations are more important to consider than ever in the age of informal AI adoption. Even signing up for an “Enterprise” subscription doesn’t automatically mean enterprise-grade security — most of the real protection has to be configured deliberately, and the right plan depends on what your organization actually needs.
  • The fix: GreenLoop’s ChatGPT and Claude security posture review provides a snapshot of your current state, helps you choose the right plan tier for your goals, and — depending on what you decide — we can configure identity enforcement, usage constraints, data retention, logging, and app governance.
  • Who this applies to: Every organization considering or already using ChatGPT or Claude, regardless of size. Smaller organizations are frequently the ones with the least visibility into how widely these tools have already spread.

Why Compliance and Privacy Are on the Line

ChatGPT and Claude are not neutral tools from a compliance standpoint. Free and personal-tier accounts can use submitted content to train underlying models unless a user manually opts out, and your organization has no way to enforce or verify that opt-out across every employee’s personal account. In addition, the lifecycle of personal accounts and data are invisible to you, and may follow employees via their personal-tier account even after they are no longer employed by your organization. If your business has contractual data-handling obligations to clients, industry compliance requirements, or a reasonable expectation of confidentiality around internal data, personal AI accounts create significant business risk.

Business and Enterprise-tier plans for both platforms close most of that gap — but only if they’re configured correctly, and only if you’re on the right plan to begin with. Identity enforcement, audit logging, data retention policy, and access controls all have to be set up deliberately. Left at default settings, an “Enterprise” subscription doesn’t automatically mean enterprise-grade security, and the default configuration differs meaningfully between plan tiers on both platforms.

The Real Risk: Data Leakage Through Unsecured Personal Accounts

Here’s the scenario we see most often: an employee pastes a client contract, source code, financial data, or internal strategy notes into their personal ChatGPT or Claude account to get a quick answer. That data now lives on a platform your organization doesn’t own, isn’t logged anywhere you can review, and isn’t covered by any agreement your company has in place. There’s no IT visibility, no audit trail, and no straightforward way to delete it if that employee leaves the company.

It’s worth distinguishing between two different flavors of “personal account” here, because they carry very different levels of risk:

  • Accounts tied to a personal email address. These are effectively invisible to your organization. There’s no way for GreenLoop or your IT team to see they exist, let alone what’s been shared through them. This is the bigger blind spot, and it’s a genuine black hole from a governance standpoint.
  • Accounts registered with a company email address, but never brought under central management. These are visible in principle — the account is tied to your domain — but if it was never provisioned through SSO or added to a managed workspace, it’s still outside your policy controls, logging, and retention settings.

This is often called “shadow AI,” and it’s the AI-era version of shadow IT — except the data going out the door tends to be more sensitive, and it goes out faster, one prompt at a time.

Turning on a company ChatGPT or Claude subscription doesn’t fix this by itself. Both platforms have a well-documented gap: enforcing single sign-on for your official workspace does not stop an employee from simply opening a personal account in another browser tab or on a personal device. Closing that gap requires deliberate configuration at the identity and device level — not just buying the right license.

Why an Assessment Comes First

A security assessment tells us — and you — exactly where your organization stands before any rollout decision gets made:

  • Which employees or departments are already using ChatGPT or Claude, and on what type of account.
  • Whether your existing Microsoft 365 / Entra ID environment is ready to enforce identity controls on top of ChatGPT or Claude.
  • What data retention, logging, and compliance requirements apply to your business or your clients’ contracts.
  • Which plan tier actually fits your goals — Claude Team vs. Claude Enterprise, or ChatGPT Business vs. ChatGPT Enterprise — based on the features you need and what you’re trying to accomplish.
  • What to do about personal accounts already tied to your company email domain.

Skipping this step means you’re either locking down a platform you don’t fully understand yet, or leaving a known gap open because nobody looked for it.

Choosing the Right Plan: It Depends on Your Goals

One of the most consequential decisions in this whole process is plan selection, and it’s not a one-size-fits-all answer. Both vendors have a real feature cliff between their mid-tier and top-tier plans:

  • Claude Team vs. Claude Enterprise. Team covers a fair amount of ground for smaller teams, but Enterprise adds directory sync, custom roles, audit logging, IP allowlisting, and other governance features that larger or more regulated organizations typically need.
  • ChatGPT Business vs. ChatGPT Enterprise. Business is self-serve and lacks directory sync, custom-role permissions, audit logging, and IP restriction. Enterprise adds all of it, but also comes with a materially higher seat minimum and a custom contract.

Our implementation approach depends heavily on which plan you’re on and what you’re actually trying to achieve — a small professional-services firm with light compliance requirements has a very different ideal setup than a healthcare or financial services client with contractual audit obligations. Talking through this tradeoff, and landing on the plan that fits your organization, is one of the key outcomes of the assessment itself.

What GreenLoop’s ChatGPT and Claude Hardening Includes

Once the assessment identifies what your organization needs, our hardening engagement puts the applicable controls in place. Exactly which of these apply, and how they’re configured, depends on the plan tier you choose and the goals we’ve talked through together:

  1. Identity and access control. We connect ChatGPT or Claude to your Microsoft 365 / Entra ID identity system, enforce single sign-on so personal logins and social sign-in are disabled for provisioned users, and set up user provisioning and deprovisioning tied to your existing employee groups. When someone leaves the company, their access to the company AI workspace is removed the same way their email access is.
  2. A path forward for existing personal accounts. GreenLoop doesn’t perform personal-account cleanup directly — that’s account-level access we don’t hold. What we do is identify which accounts are tied to your company email domain, and map out a clear path for your organization to migrate or retire them, using the platform’s own account-migration tools where available.
  3. Role-based access and least-privilege defaults. Not every employee needs the same level of access. We set up role-based permissions so the default access level is conservative, and higher-risk capabilities — like custom AI agents, third-party integrations, or developer-level features — are limited to specific approved roles.
  4. Usage constraints on approved platforms. What we can reliably put in place: ensuring your company-approved AI workspace is only reachable through approved platforms and devices, and that any AI account tied to a company email address is brought under central policy management — SSO enforcement, provisioning, and admin visibility — rather than left as an unmanaged, company-email-linked account outside your controls.
  5. Network-level blocking of personal accounts (advanced, optional). It’s technically possible to block personal ChatGPT or Claude accounts outright at the network level, but in practice this requires TLS inspection and an enterprise-grade firewall or SASE platform capable of header-based filtering. It’s a legitimate, effective control — it’s just a heavier lift than the other items on this list, and we’ll scope it as its own project if your environment supports it and your risk profile calls for it.
  6. Data retention, logging, and compliance controls. Where your plan supports it, we configure how long conversation and file data is retained, enable audit logging and compliance export so activity can be reviewed or handed to your compliance and legal teams if needed, and configure data residency settings where your contractual or regulatory obligations require it.
  7. App and connector governance. Both platforms allow AI to connect to other tools — email, calendars, SharePoint, Google Drive, and more. We review what’s enabled by default (often more than expected), disable anything not explicitly approved, and scope the remaining integrations to read-only or limited actions so the AI can’t take actions on your data without a human approving it first.
  8. Ongoing review. AI platforms change their admin controls frequently — sometimes monthly. We include a recurring review of your configuration so new features, default changes, or emerging risks get addressed rather than left unaddressed.

What This Looks Like for Your Team

Most employees won’t notice a change for the parts of ChatGPT or Claude they already use for approved work. What changes is what happens underneath: accounts tied to your company email are provisioned and managed centrally instead of self-registered, access to the approved workspace is enforced through your identity system, and — if you’ve opted into the network-level control — the approved company workspace becomes the only reachable option from company devices.

Behind the scenes, GreenLoop handles the identity connection, the account provisioning, the app approvals, and the ongoing review — so your team gets the productivity benefit of these tools without the exposure that comes with letting them run unmanaged.

FAQ

Does buying ChatGPT Enterprise or Claude Enterprise automatically make our AI usage secure?
No. Both platforms ship with strong security features available, but most of them — single sign-on enforcement, audit logging, data retention policy — require deliberate configuration. Out of the box, an Enterprise subscription still leaves the personal-account gap open unless it’s specifically addressed.

Do we need Enterprise, or is the mid-tier plan (Claude Team / ChatGPT Business) enough for us?
It depends on what you need. If you require directory sync, custom-role permissions, audit logging, or IP restriction, you likely need the Enterprise tier of whichever platform you choose. If your compliance requirements are lighter, the mid-tier plan may cover you at a lower seat minimum and cost. We walk through this tradeoff with you as part of the assessment.

We think our employees are already using ChatGPT or Claude informally. Is that a problem?
It can be, especially if anyone has pasted client data, financial information, source code, or internal documents into a personal account. The risk is highest for accounts tied to a personal email address, since your organization has no visibility into them at all. Accounts registered with a company email address are somewhat more recoverable — we can identify them and help you map a path to bring them under management. A security assessment is the fastest way to find out how widespread this is in your organization.

Will GreenLoop handle migrating or deleting our employees’ personal AI accounts?
Not directly — that requires access we don’t hold to individual personal accounts. What we do is identify accounts tied to your company email domain and map out a clear, practical path for your organization to migrate or retire them, using the platform’s built-in account migration tools where they exist.

Can you just block personal ChatGPT or Claude accounts on our network?
In theory, yes — but in practice it requires TLS inspection and an enterprise-grade firewall or SASE platform, which is a more advanced project than most of the other controls here. What we can reliably deliver without that investment is ensuring your approved AI workspace is only reachable through approved platforms, and that any account tied to your company email is under central policy management. Full network-level blocking is something we scope separately if it fits your environment and risk tolerance.

Is the process the same for both ChatGPT and Claude?
The two platforms map to each other closely on most security controls, so the process looks similar for both. There are some platform-specific differences — for example, seat minimums and mobile device management options vary — which is part of why the assessment includes a recommendation on which platform, or both, makes sense for your organization.

What’s the first step if we want to move forward?
Contact your Account Manager to schedule a ChatGPT or Claude security assessment for your organization.