Key Takeaways

  • OpenAI introduced connected plugins inside ChatGPT Sites at DevDay, letting pages adapt live based on the logged-in user's identity.
  • Sites inherit user-level permissions for tools like Slack, Notion, and Google Calendar, bypassing shared API keys and server-side secret management.
  • Kath Korevec built an internal incident command center at OpenAI that merges active Slack channels, Notion runbooks, and real-time timelines for engineering teams.
  • Different team members viewing the exact same URL see filtered, role-specific operational data without custom authentication rules.

The Death of the Shared API Key

Every internal dashboard suffers from the same infrastructure trap: authentication overhead. When an engineering team builds an internal tool to monitor incidents or sync project states, someone has to manage service accounts, distribute secrets, and configure database permissions.

At OpenAI DevDay, Product Lead Kath Korevec demonstrated how ChatGPT Sites eliminate that layer entirely. Instead of spinning up backend middleware to talk to third-party tools, Sites inherit user-level connector authorization. When a developer visits a page, the site queries tools like Slack and Notion through that specific person's connected account.

“We just launched something today, which is plugins and sites, which Sam talked about at the keynote,” Korevec explained. “And what that does is it will allow anyone to come to your site and use their connected plugins. And so, you see only your data on that site.”

This changes the economics of building internal tools. You no longer build a backend that requests access to an entire corporate workspace. You write a front-end interface in Codex, connect the relevant services, and let OpenAI handle user identity. As Korevec put it: “And then you don't have to worry about API keys and all this stuff. You just get that magically connected.”

Dynamic Views Without Role-Based Code

Building dynamic, role-based views usually requires complex database queries and explicit access-control lists. If an engineering manager and a marketing lead visit the same status page, you have to code rules that check their departments and decide what to query.

User-level connectors solve this automatically. The site reads the viewer's context directly through their existing enterprise integrations.

“They'll be looking at the exact same site, but they're going to see content based on what their team is,” Korevec said. “And so, if it's like the Codex team or if it's the identity team or something, this site picks up where they're coming from, pulls in that data that's specific to them personally.”

Host Claire Vo observed the shift: “What you're showing us here, which I want people to absorb and get the power of what it allows you to build, is you can inherit connectors as sources of data, and updated real-time data into your app.”

Korevec's primary use case at OpenAI was cutting out status updates during outages. “The reason why I built this is because I'm a product manager and I spend a lot of my time with the team, but I also spend a lot of my time in meetings and all over the place,” she said. “I kind of want to stay in the background and not have to bug them and say, 'Hey, what's going on with this incident?'”

Her incident command center automatically pulls the active Slack channel for an issue, surfaces the matching Notion postmortem runbook, and updates the timeline live. Engineers stay focused on debugging while non-technical team members get real-time context on the same screen.

What to Do With This

Audit your team's top three recurring sync meetings this week. Pick the meeting spent answering "what is the status of X?" and replace that report with a shared ChatGPT Site connected to your team's Notion and Slack workspaces. Stop writing custom API glue code for internal readouts and let user authentication filter the view directly.