# 7.8 The same envelope on both AI vendors (/managing-ai-workers/the-authority-envelope/both-ai-vendors)

---
type: Document
title: "7.8 The same envelope on both AI vendors"
description: "How Anthropic's and OpenAI's own pages say you can set the same limits, the three differences that change your setup, and what stays the same on both."
status: stable
order: 207.8
ksor:
  owner: team:panaversity
  audience: [ public ]
  approval:
    by: process:panaversity
    at: 2026-10-06T21:02:42Z
chapter: "07"
part: II
expert_status: required
concepts: [ "7.8" ]
last_verified: 2026-10-07
sources:
  - id: anthropic-one-claude
    title: "Claude Cowork and chat are one Claude (Claude Help Center, verified 2026-10-07)"
    resource: https://support.claude.com/en/articles/16761823-claude-cowork-and-chat-are-one-claude
  - id: anthropic-cowork
    title: "Get started with Claude Cowork (Claude Help Center, verified 2026-10-07)"
    resource: https://support.claude.com/en/articles/13345190-get-started-with-claude-cowork
  - id: anthropic-cowork-safely
    title: "Use Claude Cowork safely (Claude Help Center, verified 2026-10-07)"
    resource: https://support.claude.com/en/articles/13364135-use-claude-cowork-safely
  - id: anthropic-connectors-docs
    title: "Get started with connectors (Claude documentation, verified 2026-10-07)"
    resource: https://claude.com/docs/connectors/getting-started
  - id: anthropic-connectors
    title: "Use connectors to extend Claude's capabilities (Claude Help Center, verified 2026-10-07)"
    resource: https://support.claude.com/en/articles/11176164-use-connectors-to-extend-claude-s-capabilities
  - id: anthropic-cowork-team
    title: "Use Claude Cowork on Team and Enterprise plans (Claude Help Center, verified 2026-10-07)"
    resource: https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans
  - id: anthropic-chrome-permissions
    title: "Claude in Chrome permissions guide (Claude Help Center, verified 2026-10-07)"
    resource: https://support.claude.com/en/articles/12902446-claude-in-chrome-permissions-guide
  - id: anthropic-computer-use
    title: "Let Claude use your computer in Cowork (Claude Help Center, verified 2026-10-07)"
    resource: https://support.claude.com/en/articles/14128542-let-claude-use-your-computer-in-cowork
  - id: anthropic-prompt-injection-research
    title: "Mitigating the risk of prompt injections in browser use (Anthropic, 24 November 2025, verified 2026-10-07)"
    resource: https://www.anthropic.com/research/prompt-injection-defenses
  - id: anthropic-scheduled-tasks
    title: "Schedule recurring tasks in Claude Cowork (Claude Help Center, verified 2026-10-07)"
    resource: https://support.claude.com/en/articles/13854387-schedule-recurring-tasks-in-claude-cowork
  - id: anthropic-routines
    title: "Automate work with routines (Claude Code Docs, verified 2026-10-07)"
    resource: https://code.claude.com/docs/en/routines
  - id: anthropic-custom-roles
    title: "Manage custom roles on Enterprise plans (Claude Help Center, verified 2026-10-07)"
    resource: https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans
  - id: openai-permissions
    title: "Permissions (OpenAI, ChatGPT Learn, verified 2026-10-07)"
    resource: https://learn.chatgpt.com/docs/permission-modes
  - id: openai-prompting
    title: "Prompting (OpenAI, ChatGPT Learn, verified 2026-10-07)"
    resource: https://learn.chatgpt.com/docs/prompting
  - id: openai-app-permissions
    title: "Managing app permissions in ChatGPT (OpenAI Help Center, verified 2026-10-07)"
    resource: https://help.openai.com/en/articles/20001495-managing-app-permissions-in-chatgpt
  - id: openai-agent-intro
    title: "Introducing ChatGPT agent: bridging research and action (OpenAI, verified 2026-10-07)"
    resource: https://openai.com/index/introducing-chatgpt-agent/
  - id: openai-agent
    title: "ChatGPT agent (OpenAI Help Center, verified 2026-10-07)"
    resource: https://help.openai.com/en/articles/11752874-chatgpt-agent
  - id: openai-atlas
    title: "Using Ask ChatGPT sidebar and ChatGPT Agent on Atlas (OpenAI Help Center, verified 2026-10-07)"
    resource: https://help.openai.com/en/articles/12628199-using-ask-chatgpt-sidebar-and-chatgpt-agent-on-atlas
  - id: openai-resist-injection
    title: "Designing AI agents to resist prompt injection (OpenAI, verified 2026-10-07)"
    resource: https://openai.com/index/designing-agents-to-resist-prompt-injection/
  - id: openai-lockdown
    title: "Lockdown Mode (OpenAI Help Center, verified 2026-10-07)"
    resource: https://help.openai.com/en/articles/20001061-lockdown-mode
  - id: openai-admin-apps
    title: "Admin controls, security, and compliance for plugins and apps (OpenAI Help Center, verified 2026-10-07)"
    resource: https://help.openai.com/en/articles/11509118-admin-controls-security-and-compliance-for-plugins-and-apps
  - id: openai-scheduled-tasks
    title: "Scheduled tasks in ChatGPT (OpenAI Help Center, verified 2026-10-07)"
    resource: https://help.openai.com/en/articles/10291617-scheduled-tasks-in-chatgpt
  - id: openai-workspace-agents
    title: "ChatGPT Workspace Agents for Enterprise and Business (OpenAI Help Center, verified 2026-10-07)"
    resource: https://help.openai.com/en/articles/20001143-chatgpt-workspace-agents-for-enterprise-and-business
generated:
  at: 2026-10-06T21:02:42Z
  by: esl-rewrite/1.2.0+ksor.1
trust_tier: unverified
build_id: sha256:c93b28093c2f70c60faae2645a693d881b657ff94d00f7dd9f8c06427ff61c87
dirty: true
ksor_version: 0.0.60
---

**In everyday life.** Two banks both let you set limits on your card. One puts the setting in its app. The other makes you call. Your budget is the same either way.

The Authority Envelope, the written limit on what an AI Worker may do, describes the job, so it does not change between AI vendors. The settings that enforce it do change. The two boxes follow the same seven lines in the same order.

> **Anthropic, as verified 7 October 2026.**
> - *The conversation setting.* Manual asks you before each action, except for tools you set to Always allow.[^anthropic-cowork] Auto keeps working, with automated safety checks before each action.[^anthropic-one-claude] Cowork, where Claude carries out longer tasks for you, and Claude in Chrome add a third mode, Skip all approvals, in which Claude asks nothing and no safety check runs before it acts.[^anthropic-cowork-safely]
> - *Per-tool control (7.4).* In the settings of each connector, a link from Claude to another app, you set each tool or group of tools to Always allow, Needs approval or Blocked.[^anthropic-connectors-docs] On Team and Enterprise plans, organization owners can set the same choices for the whole organization. Read tools are grouped apart from write and delete tools, and members cannot change the owners' choices.[^anthropic-connectors] On those plans, Cowork asks before connector tools that can write, in every task, unless an organization owner allows Always allow for them.[^anthropic-cowork-team]
> - *Consequential actions (7.2).* Cowork asks before permanently deleting files.[^anthropic-cowork-safely] Anthropic says Claude in Chrome is built not to make purchases, create accounts, delete permanently or follow instructions found in emails or web pages. Anthropic also says it is built to ask before changing permissions or entering sensitive information.[^anthropic-chrome-permissions] These statements describe how it is meant to behave. They are not a guarantee.
> - *Tool order (7.5).* Anthropic's computer-use page puts connectors first, as the fastest and most reliable path, then the browser, then the screen. Computer use, on the Pro and Max plans, asks before each app and blocks investment and cryptocurrency apps by default. It has no sandbox, or closed-off space, between Claude and your apps.[^anthropic-computer-use]
> - *Prompt injection (7.6).* Anthropic's Cowork safety page says an attack needs two things at once. Claude reads information from outside your trusted boundary, and Claude can take actions that could harm you.[^anthropic-cowork-safely] Its research says no browser agent is immune, or fully protected.[^anthropic-prompt-injection-research]
> - *Runs no one watches.* You can choose an approval mode when you set up a Cowork scheduled task by hand. But the help page does not say what happens when an approval is needed and nobody is there.[^anthropic-scheduled-tasks] Anthropic advises against scheduling tasks that send messages or are hard to undo.[^anthropic-cowork-safely] Claude Code routines, a tool for developers, run without permission prompts and act as you.[^anthropic-routines]
> - *Admin policy (7.4).* Owners choose which connectors members may use,[^anthropic-connectors] and on Enterprise, custom roles can make tool permissions stricter, never looser.[^anthropic-custom-roles]

> **OpenAI, as verified 7 October 2026.**
> - *The conversation setting.* In the desktop app, a permissions control sets local actions, the actions on your own computer. Its choices are Ask for approval, Approve for me or Full access. Approve for me sends a request to an automatic review instead of to you.[^openai-permissions] OpenAI's prompting guide also advises adding a rule to your prompt. The rule requires your approval before ChatGPT sends, publishes or changes information other people rely on.[^openai-prompting] That is advice about prompts, not a setting.
> - *Per-tool control (7.4).* Each app, OpenAI's name for a connector, can have one of four levels: Always ask, Allow read actions, Allow low-risk actions or Allow all actions. Allow read actions reads without asking and asks before any change. At Allow low-risk actions, the product decides which actions count as low risk.[^openai-app-permissions]
> - *Consequential actions (7.2).* ChatGPT agent, the mode in which ChatGPT carries out a task for you, is trained to ask before actions with real-world consequences, such as a purchase. It asks you to watch it during tasks such as sending email, and it is trained to refuse high-risk tasks such as bank transfers.[^openai-agent-intro] These statements describe how it is meant to behave. They are not a guarantee. OpenAI lists sending messages, changing records, changing access, payments and sharing sensitive data as higher-risk actions.[^openai-app-permissions]
> - *Tool order (7.5).* OpenAI advises turning on only the apps a task needs,[^openai-agent] and its pages do not put apps ahead of agent browsing. In Atlas, OpenAI's web browser, agent mode pauses on sensitive sites such as banks.[^openai-atlas]
> - *Prompt injection (7.6).* OpenAI says an attack needs a source, a way to influence the system, and a sink, a capability that becomes dangerous in the wrong context. It says dangerous actions, or sending sensitive data, should not happen silently or without appropriate safeguards.[^openai-resist-injection] Lockdown Mode limits outgoing requests.[^openai-lockdown] OpenAI says its app safeguards do not remove prompt-injection risk.[^openai-admin-apps]
> - *Runs no one watches.* A scheduled task may pause when one of its actions needs approval.[^openai-scheduled-tasks]
> - *Admin policy (7.4).* Admins choose which read or write actions each app may use, and how new actions are treated.[^openai-admin-apps] In workspace agents, write actions are set to Always ask by default.[^openai-workspace-agents]

**The comparison.** Both AI vendors separate reading from writing. Both let you set permissions per tool or per app. Both let admins set limits that users cannot loosen. And both offer settings that ask a person before consequential actions, the actions with real effects. Three differences change your setup.

The first difference is where the product decides for you. On Claude you set each tool's level yourself. But the conversation setting decides what Needs approval means. Manual asks you, Auto lets Claude's safety checks decide, and only Blocked works the same in every setting.[^anthropic-cowork] On ChatGPT, the Allow low-risk actions level lets the product decide which actions are low risk. So keep Claude on Manual for any action a person must approve. On ChatGPT, compare what the product counts as low risk with your envelope, or choose a stricter level. On either AI vendor, a level that asks before changes still leaves the worker able to change things once you approve. That is execute with approval, not draft.

The second difference is unattended runs, the runs no one watches. ChatGPT's documentation says a scheduled task may pause when an action needs approval, and Claude's scheduling page does not say what happens. Check your setup before you schedule anything with a write tool (Chapter 9).

The third difference is that only Anthropic publishes the connector-first order. On ChatGPT that order is your rule, not the product's.

![The title reads "One envelope. Different controls." The line below it reads "Availability varies by product, plan and workspace." A dark banner says to write the Authority Envelope once, with its four parts: actions and levels, thresholds, never automated, and escalation. A table compares Anthropic Claude and OpenAI ChatGPT in seven rows, and gold marks the differences to check. Approval modes. On Claude: Manual, Auto or Skip all approvals, depending on surface. On ChatGPT: desktop local actions of Ask for approval, Approve for me or Full access. Tool and app controls, in gold. On Claude: per tool or group, Always allow, Needs approval or Blocked. On ChatGPT: app controls that may offer four levels, where Allow low-risk actions uses the product's risk assessment. Consequential actions. On Claude: Cowork asks before permanent deletion, and Chrome has action prohibitions. On ChatGPT: an agent trained to seek confirmation for purchases, which declines bank transfers. Preferred access path, in gold. On Claude: a published order of connector, browser, then screen. On ChatGPT: enable only needed apps, with no ranking found in the chapter's sources. Prompt injection. On Claude: untrusted input plus harmful action capability, and no browser agent is immune. On ChatGPT: source and sink, restricting harmful actions and sensitive-data transfers. Unattended runs, in gold. On Claude: Cowork's handling of approvals when unattended is unspecified in the cited guide, and Code routines run with no prompts. On ChatGPT: scheduled tasks may pause when an action requires approval. Admin controls. On Claude: organization limits apply, and Enterprise roles can tighten them. On ChatGPT: admins control available app actions and policies for new actions. A note says documented behavior is not a guarantee that every unsafe action will be blocked. Two boxes sit at the foot. Approval is still Execute, because if the worker acts after you approve, it has execution authority. Record enforcement gaps, because if no setting enforces a limit, that action stays with a named person. A footer reads: recheck the exact product and account settings before use.](img/both-ai-vendors.png)

*Figure 7.8. The same envelope on both AI vendors, as verified 7 October 2026. The gold rows are the differences that change your setup.*

**What stays the same.** The envelope is written once, by its owner, and it stays the same on either AI vendor. Settings only come close to it. A line that no setting can enforce goes on the gap list. It stays with a person until a system such as DSoR, the Data System of Record, enforces it.

[^anthropic-cowork]: Get started with Claude Cowork, Claude Help Center.
[^anthropic-one-claude]: Claude Cowork and chat are one Claude, Claude Help Center.
[^anthropic-cowork-safely]: Use Claude Cowork safely, Claude Help Center.
[^anthropic-connectors-docs]: Get started with connectors, Claude documentation.
[^anthropic-connectors]: Use connectors to extend Claude's capabilities, Claude Help Center.
[^anthropic-cowork-team]: Use Claude Cowork on Team and Enterprise plans, Claude Help Center.
[^anthropic-chrome-permissions]: Claude in Chrome permissions guide, Claude Help Center.
[^anthropic-computer-use]: Let Claude use your computer in Cowork, Claude Help Center.
[^anthropic-prompt-injection-research]: Mitigating the risk of prompt injections in browser use, Anthropic.
[^anthropic-scheduled-tasks]: Schedule recurring tasks in Claude Cowork, Claude Help Center.
[^anthropic-routines]: Automate work with routines, Claude Code Docs.
[^anthropic-custom-roles]: Manage custom roles on Enterprise plans, Claude Help Center.
[^openai-permissions]: Permissions, ChatGPT Learn, OpenAI.
[^openai-prompting]: Prompting, ChatGPT Learn, OpenAI.
[^openai-app-permissions]: Managing app permissions in ChatGPT, OpenAI Help Center.
[^openai-agent-intro]: Introducing ChatGPT agent, OpenAI.
[^openai-agent]: ChatGPT agent, OpenAI Help Center.
[^openai-atlas]: Using Ask ChatGPT sidebar and ChatGPT Agent on Atlas, OpenAI Help Center.
[^openai-resist-injection]: Designing AI agents to resist prompt injection, OpenAI.
[^openai-lockdown]: Lockdown Mode, OpenAI Help Center.
[^openai-admin-apps]: Admin controls, security, and compliance for plugins and apps, OpenAI Help Center.
[^openai-scheduled-tasks]: Scheduled tasks in ChatGPT, OpenAI Help Center.
[^openai-workspace-agents]: ChatGPT Workspace Agents for Enterprise and Business, OpenAI Help Center.
