Skip to content
Rush Commerce
AI & Automation3 min read

ChatGPT reads Dropbox, Box and SharePoint — audit permissions

ChatGPT Library now browses Dropbox, Box and SharePoint natively. Your file permissions just became your AI permissions. Here is what to check first.

On September 10, Box, Dropbox and SharePoint joined Google Drive as native sources inside the ChatGPT Library. Not a plugin that fetches a file. Browse, search, @mention, preview beside the conversation, follow a citation back to the original, and point ChatGPT at a whole folder. It is a real upgrade to how work gets done. It is also the moment your file permissions stop being an IT housekeeping item and start being the boundary that decides what an AI can read on your behalf.

What actually happened

Per OpenAI's release notes, the integrations rolled out September 10 to Go, Plus, Pro, Business, Edu, Healthcare and Enterprise users on the web, in both Chat and Work. Mobile comes later. You add files through Add from Library or an @mention without re-uploading them, keep previews open next to the conversation, and select a folder so the model works across everything inside it.

Dropbox's own post is specific on the security question: "existing Dropbox permissions continue to apply." You can only surface files your connected account could already open. The source of truth stays in Dropbox, and citations link back to it. Dropbox frames itself as a customer-owned context layer for whichever AI tool you pick — which is the same build-for-the-standard argument we made when Work connectors shipped.

That statement is accurate and it is also the whole problem.

Why file permissions matter for your business

"Existing permissions apply" is a promise about the mechanism, not about your configuration. If a shared folder is set to anyone-at-the-company because someone needed it open for an afternoon in 2023, ChatGPT now reads it as fluently as your best analyst. The blast radius of a sloppy share went from "somebody would have to go looking" to "somebody asks a question and the model goes looking for them."

Three specific things break in small operations:

The catch-all folder. Most shops have one — Ops, Admin, Shared — with payroll spreadsheets, a signed contract, and the 2024 pricing model sitting next to the meeting notes. Folder-level queries mean a question about vendor terms can pull the compensation file into the same answer.

Departed-employee shares. Links created by people who left, still live, still inherited by whoever got the account.

Client work in a multi-client Drive. Point at the wrong parent folder and Client A's margins inform an answer you paste into Client B's thread.

None of this is a ChatGPT flaw. It is the pre-existing state of your file system, newly load-bearing. The fix is boring and takes an afternoon: enumerate top-level shares, kill anything open to "anyone with the link," move anything with compensation, banking or unredacted customer data into a folder with an explicit member list, and decide on purpose which accounts get connected. Do that before you tell the team the feature is live, not after someone demonstrates why you should have.

Key takeaways

  • Box, Dropbox and SharePoint became native ChatGPT Library sources on September 10, web only, across Go through Enterprise
  • You can browse, search, @mention, preview, and point the model at an entire folder without re-uploading
  • Dropbox confirms existing permissions apply - the model sees exactly what your connected account can see
  • That guarantee is only as good as your current share settings, which most small teams have never audited
  • Highest-risk patterns: catch-all Ops folders, links from departed employees, multi-client parent folders
  • Audit top-level shares and revoke anyone-with-the-link access before enabling the connection, not after
  • Keeping documents in a system you control - and connecting AI to it - beats pasting copies into a chat window

An AI connector is only as safe as the folder tree behind it. We audit file-share permissions before wiring AI into them, then build the connection so the model reads what it should and nothing it shouldn't. See how we scope AI access, or send us your folder structure and we'll tell you what's exposed.

Sources: Dropbox: trusted project context directly into the ChatGPT Library, OpenAI ChatGPT release notes.

  • #chatgpt
  • #file-permissions
  • #dropbox
  • #sharepoint
  • #access-control
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.