Most people who hear "ChatGPT plugin" remember 2023, when plugins were a short-lived add-on that arrived, confused everyone, and quietly disappeared. That memory is now wrong in every way that matters. The word came back in 2026 meaning something different, and if you pay for ChatGPT seats for your staff, the difference decides what they are allowed to install and what you are responsible for approving.
What is a ChatGPT plugin?
A ChatGPT plugin is a package that bundles everything needed for one repeatable job. OpenAI's own definition is that a plugin can contain skills, apps and app templates. It is not a single tool. It is a wrapper around several tools, assembled so one workflow runs without the person using it configuring anything.
That is the whole idea in one sentence, and it is worth sitting with, because it explains why the name changed.
Think of the difference between handing a new hire a screwdriver and handing them a job packet. The screwdriver is a tool. The job packet contains the written procedure, the key to the storeroom, and the form your office manager already filled in so the key works. A plugin is the job packet.
The practical consequence: when a member of staff installs a plugin, they are not switching on one thing. They are switching on a bundle, and at least one item in that bundle is usually a connection to a system that holds your company's data.
What is the difference between an app, a skill and a plugin?
These three words are used interchangeably in most coverage, and they are not interchangeable. OpenAI defines each one separately in its Help Centre documentation on plugins, and the distinction is the difference between a plugin that reads nothing and one that reads your invoices.
--- Skills are reusable instructions, prompts and workflow patterns. They tell the AI how to do something. They connect to nothing.
--- Apps are the connections to systems, data and actions approved for your workspace. This is the part that touches your files.
--- App templates help an admin create or configure the app a plugin needs. They are the paperwork, not the capability.
Back to the analogy. The skill is the written procedure. The app is the key to the filing cabinet. The template is the form your office manager fills in to get that key cut.
So the question to ask about any plugin is not "what does it do". It is "which apps does it need, and what do those apps reach". A plugin made only of skills is a set of instructions and carries almost no data risk. A plugin that requires an app is a door.
Why did the App directory become the Plugin directory?
On 9 July 2026 OpenAI migrated the App directory to the Plugin directory. Apps did not disappear. They became one ingredient inside a larger container, and the container is what people now browse and install.
On 21 August 2026 OpenAI shipped a further change, listed in its public release notes as improved plugin discovery on web and mobile. The mechanics of that change matter more than the announcement.
Rankings in the directory now prioritise plugins people keep using after installation. Not plugins with the most downloads. Not plugins with the best description. Plugins that survived contact with real work.
That is a genuinely useful signal for a non-technical buyer, and it is the closest thing the directory has to a review system. What sits near the top is what other businesses did not uninstall in week two.
One limitation is stated plainly in the same release note and is easy to miss: desktop is not included in this update. If your staff live in the desktop app, they are not seeing the improved ordering.
Who decides which plugins your staff can use?
On a Business or Enterprise workspace, the answer is the workspace admin, which in most Hong Kong SMEs means the owner or whoever set up the billing. Controls sit in Workspace settings, then Plugins.
For each plugin, an admin sets an installation policy per role, and there are two settings that sound similar and are not:
--- Available means the plugin appears and the staff member chooses to install it.
--- Installed means it is switched on for that role automatically, with no action from the person.
The default settings are where most owners get caught out, because they are not the same across plans. Per OpenAI's documentation, Business apps are enabled by default, while Enterprise and Edu apps are disabled by default.
Read that again if you are on Business. The cheaper, more common tier for a small company is the more open one out of the box. The tier bought by large organisations with compliance teams starts closed.
There is one more line worth knowing: personal skills in ChatGPT Work are available on paid plans except Free and Go. So a staff member on a free login cannot save personal skills at all, which is often why one person's setup does not match another's.
This is the same governance question covered in UD's earlier piece on the AI tools staff use without telling you, arriving from a different direction. The directory is not shadow AI. It is the opposite: a place where the boss can actually see and set the rules.
Why is the Connect button greyed out for some staff?
This is the most common support question a Hong Kong office will hit, and OpenAI answers it directly. Plugin availability depends on your plan, your region, and your workspace settings, and the Connect button for a given app may be greyed out because of geo restrictions, workspace settings, or plan type.
Three causes, one symptom. Diagnosing them in the wrong order wastes an afternoon, so work through them cheapest first.
--- Check the plan. Is this person on Free or Go? That explains most of it and costs nothing to confirm.
--- Check the workspace policy. Open Workspace settings, then Plugins, and see whether that role is set to Available.
--- Assume geography last. If plan and policy are both fine and it is still grey, the app is not offered in your region, and no setting on your side will change that.
The third case is the one that catches Hong Kong businesses, because there is no error message explaining it and no support ticket that fixes it. A greyed-out Connect button is sometimes simply a map, not a bug.
What this looks like in a Hong Kong office
Picture a 12-person trading company in Sheung Wan on ChatGPT Business. Three staff use it daily, two occasionally, and the boss pays the bill without ever opening Workspace settings.
Because Business apps are enabled by default, staff have been installing plugins for months. Nobody did anything wrong. Nobody was asked.
The fix is a thirty-minute job and requires no IT vendor. Open Workspace settings, then Plugins. Look at what is set to Installed for each role. For anything that requires an app touching mail, files or accounting, decide whether it should be Available rather than Installed, so a person has to choose it deliberately.
Then write down the decision, because the value is not the setting. It is that somebody in the company can now answer the question "which outside systems can our AI read" without guessing.
Two operational details save time later. Admins can export the public plugin catalogue as a CSV, but it is a daily snapshot and may be up to 48 hours old, so a brand-new plugin will not appear immediately, and the export is not available in FedRAMP workspaces. Separately, in Codex, directory changes can take up to six hours to refresh. If you change a policy and nothing happens, wait before escalating.
Three things people get wrong about plugins
"Plugins are the same thing that failed in 2023." They are not. The 2023 plugins were single add-ons a user switched on inside a chat. A 2026 plugin is a package of skills, apps and templates with admin-level policy attached to it. The word survived. The design did not.
"Approving a plugin means installing it for everyone." No. Available and Installed are separate policies, set per role. Approving something so a team can reach it is a different decision from pushing it onto their account, and conflating the two is how a company ends up with connections nobody remembers authorising.
"If my colleague can install it, so can I." Not necessarily. Plan, region and workspace settings are three independent gates, and any one of them can close on its own. Two people sitting at the same desk on different plans will genuinely see different directories.
Frequently asked questions
Do plugins cost extra?
The plugin itself is a container. What it may cost you is whatever the underlying app or service charges, which is billed by that provider and not by OpenAI. Treat any plugin that requires an outside account as a potential second invoice, and check before rolling it out to a team.
Can staff install plugins without me knowing?
On a Business or Enterprise workspace, only within the policy you set. If you have never opened Workspace settings and you are on Business, the practical answer today is closer to yes than most owners assume, because Business apps are enabled by default.
Does a plugin see all my company data?
It sees what its apps are connected to and nothing more. A plugin built only from skills connects to nothing at all. This is why the useful question is which apps a plugin requires, not what the plugin claims to do.
Is this the same as the Model Context Protocol?
They solve overlapping problems and are not the same thing. Plugins are OpenAI's packaging and distribution layer inside its own products. Deciding between them is a supplier question, not something an SME needs to resolve before switching on a useful workflow. See UD's guide to AI workflow automation for how these pieces fit together.
What should I actually do this week?
Open Workspace settings, then Plugins, and read the list. That is the entire task. You are not deciding strategy, you are finding out what is already switched on, and almost every owner who does this finds at least one surprise.
The takeaway
A plugin is a bundle, an app is a door, and a skill is a set of instructions. Once those three words separate in your head, the directory stops looking like an app store and starts looking like an access list, which is what it actually is.
You do not need to understand how any of it is built. You do need to know who in your company can open a door to your data, and right now that answer is sitting in a settings page most owners have never opened.
That is the part nobody sends you an email about, and it is exactly the kind of gap that turns into an awkward question a year later. We understand AI. UD stands with you.
Reviewed by the UD AI team.
Not sure what your workspace already allows?
Knowing the vocabulary is step one. Knowing what your own business has already switched on, and what it should switch on next, is step two. We will walk you through it step by step, from a plain-language review of where you stand to a plan you can actually act on.