Claude Enterprise became a self-serve purchase in February 2026. A card number, an SSO config, invitations sent, and an organization exists before lunch (Anthropic, 2026). OpenAI's business tiers buy the same way.
The audit logs come with it. So do the usage analytics, the identity integration, the retention controls, the spend limits and the programmatic compliance export. All of it arrives switched off. In most companies that is where it stays, which means the governance is already paid for and has never once been enabled.
That is the whole gap. Not missing tooling, not a budget line nobody approved, not a vendor limitation. A settings page nobody opened.
For a CIO, Head of IT or COO it shows up as four questions with no good answer. Who is using this. On what data. At what cost. And is any of it approved. Every one of those four has a specific setting behind it, on both platforms, in a console you are already paying for. This is where they are and what order to turn them on in.
What you already own and have probably never opened
Four consoles are in play. Most organizations have touched one.
On the Anthropic side, organization settings live at claude.ai/admin-settings for Team and Enterprise plans, and the Claude Console is the separate surface for API organizations. On the OpenAI side, workspace administration lives inside the ChatGPT workspace itself, with the platform dashboard covering API usage separately.
Two things decide how much of this you can act on today.
The first is tier. Some controls exist on Claude Team and ChatGPT Business. Others are Enterprise-only. Custom roles, audit logs, SCIM and custom data retention are all Enterprise features on Claude, while SSO reaches further down the stack (Anthropic, 2026). Which side of that line a control sits on turns "we should configure that" into either an afternoon of work or a procurement conversation. Those are very different answers, and you want to know which one you are in before you promise anything to legal.
The second is that the four questions map cleanly onto four groups of settings. That mapping is the useful part, because it is the one thing neither source in this market will give you. Vendor documentation explains what a toggle does without saying why you would want it. Analyst frameworks explain why governance matters without ever naming a toggle. The bridge between them is empty, and it is where the actual work lives.
| The question | What you configure | Claude | ChatGPT |
|---|---|---|---|
| Who is using it? | Seats, SSO, SCIM, usage analytics | SSO on Team and Enterprise, SCIM on Enterprise, Analytics in admin settings | SAML SSO and SCIM, workspace member management |
| On what data? | Workspace and project structure, connectors, retention, training posture | Projects, connector controls, custom data retention on Enterprise | Workspaces, connected internal sources, admin-set retention |
| At what cost? | Billing model, spend limits, group budgets | Seat fee plus usage at API rates, spend limits and group spend limits on Enterprise | Seat types plus flexible pricing and workspace credits |
| Is it approved? | Audit logs, compliance export, roles | Audit logs and Compliance API on Enterprise, custom roles on Enterprise | Compliance Logs Platform, eDiscovery and DLP integrations |
Four rows. The rest of this article is detail on each one, starting with the question your board asks first.
Question one: who is actually using it
In most companies the answer is a number somebody guessed in a meeting. The real one has been sitting in the console the whole time.
Seats, and what a seat actually covers
Seat structure is the first place the two platforms diverge, and the divergence changes what a seat costs you.
ChatGPT Enterprise is built around two seat types. Standard ChatGPT seats cover the main product. Codex seats, introduced in April 2026, offer Codex-only access on flexible pricing (OpenAI, 2026). Seat type determines what a user can reach and how you are billed for them, which makes seat assignment a budgeting decision rather than an onboarding formality.
Claude Enterprise takes a different shape. The seat fee covers access to the platform and nothing else. All usage bills separately at API rates (Anthropic, 2026). If your mental model is "we pay X per person per month and that is the number," Claude Enterprise will not behave the way you expect, and finance should hear that before the second invoice rather than after.
So assign seats by role and workload, not by handing one to everyone with a laptop. An unused seat is a line item. An unused seat on a usage-billed plan is a line item that also makes your analytics lie to you about adoption.
SSO and SCIM, the controls that make every other control real
This is the highest-leverage item in the article, and the one most often skipped, because it is the only step that requires borrowing someone from the identity team.
Claude supports SAML 2.0 and OIDC for single sign-on across Team plans, Enterprise plans and Console organizations (Anthropic, 2026). OpenAI ships SAML SSO across its business tiers, and SCIM directory sync for ChatGPT Enterprise and Edu workspaces, supporting Okta Workforce, Microsoft Entra ID, Google Workspace and Ping (OpenAI, 2026).
SSO is the login story. SCIM is the leaving story, and the leaving story is the one that gets audited. Without directory sync, access removal depends on somebody remembering to open an AI console during an offboarding process that already has fourteen other steps. With it, the AI account closes because HR ended the employment record. That is the difference, and it is worth the calendar invite.
One sequencing note that will save you a week: configure SSO before you invite people at scale. Merging or migrating accounts that already exist outside your identity provider is manual work, and the bill for it grows with every person you added first.
Reading the analytics you already generate
Claude's admin surface includes usage analytics, with a dedicated view under Analytics for Claude Code so administrators can monitor usage across both Claude.ai and Claude Code (Anthropic, 2026). ChatGPT Enterprise includes centralized member management and workspace administration alongside its admin features.
The output is a list of names and numbers: who is active, how often, on which surfaces. Not a maturity score. That is enough to answer the board question, and enough to spot the two patterns that matter. A team with heavy usage and no complaints has found a workflow worth studying and copying . A department with assigned seats and near-zero activity has a training problem, a workflow problem, or seats that belong somewhere else.
Anthropic's own administrator guidance offers concrete targets to measure against, including seat utilization around 70 percent of licensed seats and feature adoption of things like Projects and Artifacts reaching roughly 40 percent of active users (Anthropic, 2026). Treat those as reference points rather than commitments, and note whose reference points they are: a vendor publishing a seat-utilization target is also describing its own renewal case. The value at this stage is having any number at all, because the next question assumes you know who is in there.
Question two: what data it can see
This is the question legal asks, usually at short notice, usually attached to a customer security questionnaire that is already overdue.
Workspace and project structure is a data-boundary decision
Workspaces, organizations and projects look like organizational tidiness. They are the container that determines what context the model can reach, which makes them the one decision on this list you cannot cheaply reverse.
Get it wrong and the fix is manual. Moving work between containers later is not a bulk operation, and the longer the structure runs the more there is to move. So decide deliberately: separate by department, by function, by data sensitivity, or by client, and write the decision down somewhere other than one person's memory.
The useful question is not "how should we organize this." It is "what is the set of material we would not want sitting in the same place." Structure falls out of that answer.
Connectors are a governance decision wearing a convenience costume
Both platforms let admins control which internal sources are connected. OpenAI states plainly that you control which internal sources are connected as part of its enterprise privacy commitments (OpenAI, 2026). On the Claude side, connectors an organization has added, such as Slack or Google Drive, are among the capabilities that custom roles can grant or restrict (Anthropic, 2026).
Every connector you approve extends the perimeter. That is the point of connectors. It is also the thing to be deliberate about, because a connector added when one team asked for it on a Tuesday in March is still connected in December.
Training and retention, stated accurately
Two separate questions get collapsed into one all the time. Keeping them apart is most of what makes a good questionnaire answer.
Does the vendor train on our data? OpenAI states that it does not train its models on business data from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers or the API platform by default, and that you own your inputs and outputs where allowed by law (OpenAI, 2026). That is a public, citable commitment. Cite it directly rather than paraphrasing it into something vaguer, because the paraphrase is what gets challenged.
How long is our data kept? This one is yours to set. OpenAI gives workspace admins control over retention duration for ChatGPT Enterprise, Edu and Healthcare, with deleted conversations removed from its systems within 30 days unless it is legally required to retain them (OpenAI, 2026). For the API, inputs and outputs are removed after 30 days unless legally required, and zero data retention is available for eligible endpoints with a qualifying use case. Anthropic offers custom data retention controls as part of the Enterprise plan (Anthropic, 2026).
OpenAI is candid about the tradeoff, and it is worth repeating to whoever asks for the shortest window available: retention is what enables conversation history, so shorter periods can degrade the product experience (OpenAI, 2026). A thirty-day policy that makes the tool irritating to use is a policy your teams will route around, and routed-around policies are worse than permissive ones, because you stop being able to see the traffic.
The failure mode here is not choosing badly. It is never choosing, and discovering months later that the default became the policy because nobody touched it.
Question three: what it costs
Both vendors moved off flat per-seat pricing, in different directions, and the difference lands on whoever owns the budget.
Two billing shapes
Claude Enterprise splits the bill. The seat fee covers access. Usage across Claude bills separately at API rates (Anthropic, 2026). That is closer to a metered utility than a subscription, and it means the monthly number moves with adoption. Either a feature or a nasty surprise, depending on whether anyone warned finance.
ChatGPT Enterprise uses flexible pricing, with workspace credits available for usage beyond the included rate limits (OpenAI, 2026). Seat type shapes the cost too, since Codex seats are priced differently from standard ChatGPT seats.
Neither shape is worse than the other. But a spreadsheet built on "seats times price" will be wrong on both platforms, and it will be wrong in the direction of under-forecasting.
Spend limits, and one default worth knowing
Claude Enterprise supports spend limits, including group spend limits managed alongside groups (Anthropic, 2026). Anthropic's administrator guidance notes that spend limits for Claude Code seats default to zero, so an administrator has to set a limit for usage-based Claude Code access to work at all (Anthropic, 2026).
That default is doing two jobs at once. It is a safety property, since nothing can run away before somebody decides what a reasonable ceiling looks like. It is also a silent blocker, and it is the kind of thing that produces a support ticket reading "Claude Code is broken" when the real answer is that nobody set a number.
Set limits per group rather than globally wherever the platform allows it. A global limit tells you the company overspent. A per-group limit tells you which team did, which is the only version you can act on.
The broader point is that a cost figure without a usage figure is not a decision input at all. Spend that produced nothing and spend that produced a quarter of your engineering throughput look identical on an invoice. We have written separately about why the bill is not the same thing as the result . The console is where you get the other half of that picture.
Question four: whether any of it is approved
This is the question that arrives with a deadline attached, usually from audit, legal, or a customer's security team, and usually without warning.
Audit logs
Claude Enterprise includes audit logs that capture key information about user actions, system events and data access (Anthropic, 2026). That is the raw material for answering "what happened, and when," which is the only form the question ever takes.
Programmatic access for compliance and eDiscovery
Claude's Compliance API gives programmatic access to usage data including activity logs, chat histories and file content, with filtering by user and time range (Anthropic, 2026). The filtering is what makes it usable under a legal hold, where the request is never "everything" and always "this person, these dates."
OpenAI's Compliance Logs Platform gives Enterprise and Edu workspace owners conversation logs and workspace metadata, either accessed directly or routed through pre-built integrations with eDiscovery, DLP and SIEM vendors (OpenAI, 2026). Workspace admins can access an audit log of conversations and GPTs through it (OpenAI, 2026).
The practical test is not whether the endpoint exists. It is whether anyone at your company has ever successfully pulled an export from it. Find that out on a quiet Tuesday rather than during an incident.
Delegating admin without handing over the keys
Claude Enterprise supports role-based permissions and custom roles. A custom role is a set of permissions controlling access to capabilities such as chat, Claude Cowork, Claude Code and web search, plus the connectors the organization has added. Custom roles can also grant admin permissions for specific areas like billing, identity or privacy without making that person an Owner (Anthropic, 2026).
That last clause is the one to act on. The common failure is a binary: three Owners who can do everything and everyone else who can do nothing, so every routine request escalates to one of the three and the three become the bottleneck. Scoped roles let the finance lead manage billing without touching identity, and the identity team manage provisioning without seeing billing.
Approval only means something when the set of people who can approve is deliberate. The same logic extends to anything your teams build on top of these platforms, which is a harder inventory problem and one we have written about in why you cannot govern what you cannot list .
The order to configure things in
Sequence matters more than completeness, because several of these steps cost far less before people are using the platform than after.
- Verify your domain and claim the organization. Establishes that this is a company account rather than a collection of individual ones.
- Configure SSO, then SCIM, before inviting anyone at scale. Both vendors support SAML. Retrofitting identity onto existing accounts is the expensive version of this step.
- Decide the workspace and project structure, and write the decision down. Ask what should not share a container, then build from that.
- Set data retention deliberately. Pick a window, note the tradeoff against conversation history, record who decided and when.
- Confirm and record the training posture. Both vendors publish commitments. Save the link, not a paraphrase, because the questionnaire will ask for a source.
- Review and approve connectors. Decide what is connected on purpose rather than accumulating them.
- Assign seat types by role. Match seat type to actual workload, especially where seat types are priced differently.
- Set spend limits, per group where possible. Remember that Claude Code seat limits start at zero.
- Create custom roles and delegate scoped admin. Billing, identity and privacy admin without full ownership.
- Turn on audit logs and test the compliance export. Confirm an export works before anyone needs it to.
- Read the analytics and record a baseline. You cannot report a change from a number you never wrote down.
Eleven steps, and most of them are one focused session with the right two people in the room: someone who can authorize identity changes, and someone who owns the budget. On Claude Team or ChatGPT Business the list is shorter rather than harder: the SCIM half of step two, the retention window in step four, the custom roles in step nine and the audit export in step ten sit at the Enterprise tier, so a lower-tier reader works the remaining steps and treats the rest as a procurement question. The harder discipline is the next part, because configuration nobody has tested is not yet a control.
How to tell it actually worked
Configuration that has never been tested is a belief, not a control. Five checks, each of which takes minutes.
- Offboard a test account through your identity provider and confirm access to both platforms is gone, without anyone touching an AI console.
- Pull a compliance export with a user filter and a date range, and confirm the output is what a legal request would actually need.
- Check a seat with no spend limit configured and confirm it behaves the way you expect rather than the way you assumed.
- Confirm the retention setting is visible in the console, not only in a policy document. Those two drift apart.
- Open the analytics view and name your ten most active users. If you cannot, the reporting is not yet configured well enough to answer the board question.
Anything that fails here is a finding, not a failure. Far better discovered on your own schedule.
Where these controls stop
Being precise about the boundary is what makes everything above it credible.
Consoles measure usage, not value. Message counts, seat utilization and active-user percentages tell you the tool is being opened. They do not tell you whether the work got better. BCG's December 2025 analysis of the adoption gap and McKinsey's 2026 State of AI survey both land on the same uncomfortable finding: usage has climbed while measured impact has not followed (BCG, 2025 and McKinsey, 2026). Admin analytics will not close that gap, because it is a different measurement problem, one we have written about in why adoption is not the same thing as usage .
Vendor controls govern the vendor's surface. Anything your teams build directly on the API, any third-party wrapper, any tool someone expensed on a personal card, sits outside this perimeter. The admin console has nothing to say about it.
Retention settings are not a records-management program. They control how long the vendor keeps conversations. Your obligations around what must be retained, and what must be destroyed, are broader and belong to whoever owns records management.
Tier gaps are real. When the control you need is Enterprise-only and you are on Team or Business, no amount of configuration produces it. That is a procurement conversation, and naming it as one is more useful than hunting for a workaround that does not exist.
The common mistakes all rhyme. Inviting users before SSO is live. Letting workspace structure grow by accident. Treating the default retention window as a decision. Making everyone an Owner because custom roles looked like an afternoon of work, which they are, once.
The first thirty days
If the full sequence looks like more than you can start this week, here is the short version.
Week one. Verify the domain. Get the identity team on a call and configure SSO. Open the analytics view and write down what it currently says, even if what it says is unflattering.
Week two. Decide retention and set it. Save the vendors' training and privacy commitments somewhere your security questionnaire responses can reach. Review the connector list and remove what nobody has asked for twice.
Week three. Set spend limits by group. Assign seat types against actual roles rather than the original headcount request. Create the custom roles that let you stop being the only person who can change anything.
Week four. Turn on audit logs, pull one compliance export, run the offboarding test. Compare the analytics against the week-one baseline and write two sentences about what changed.
Four weeks, mostly configuration, no new spend. At the end of it, all four questions get answered with a console screenshot instead of an estimate. What that buys is control and visibility, not throughput. No amount of console work makes the work itself faster, and that is a separate problem with a separate measurement. The distance between paying for AI governance and having it is usually an afternoon of settings, not a procurement cycle.
Where it gets harder is deciding which of the four questions matters most for your business, and what comes after the console work. A company facing a customer security review has a different first move than one trying to justify next year's seat count . If that is the conversation you are in, our AI Readiness Snapshot is a free 30-minute call that maps where the effort pays back first. The configuration above you can do yourself, and should.
Key takeaways
- The governance tooling is already inside the plan you pay for. Both Anthropic and OpenAI ship admin consoles, identity integration, usage analytics, retention controls, spend limits and audit access with their business tiers. It ships switched off.
- Four questions organize all of it: who is using it, on what data, at what cost, and is it approved. Each maps to a specific group of settings on both platforms.
- SSO and SCIM are the highest-leverage controls, because directory sync makes access removal automatic rather than remembered. Configure them before inviting people at scale.
- Both vendors moved off flat per-seat billing, so forecast on the actual model. Claude Enterprise bills seats and usage separately, and Claude Code spend limits start at zero.
- Check which controls are Enterprise-only for your platform before promising them to legal. Where a control does not exist at your tier, that is a procurement decision, not a configuration one.