Wodex
News analysis

ChatGPT Can Now Record Employee Computer History: Should Your Company Enable It?

ChatGPT's macOS Computer History lets the assistant reference what employees do in apps and on websites. A governance-first look at what it records, when it helps, and the policies to set before enabling it.

OpenAI introduced Computer History in ChatGPT’s macOS app in August 2026. The opt-in feature lets ChatGPT and Codex use activity from selected apps and websites to create a timeline and memories, so an employee can ask what they were doing earlier, find a recent document, or resume a workflow without reconstructing every step.

That sounds like a productivity feature. For a small business, it is also a governance decision.

Computer History is not a conventional screen recorder, and OpenAI says it does not include screenshots, microphone input, or system audio. But the feature can still capture meaningful context about work: clicks, typing, app switches, keyboard shortcuts, and other information available through macOS accessibility features. It can turn that activity into summaries and local memory files that ChatGPT and Codex can use later.

The right question for an owner or operations lead is not “Can this make employees faster?” The better question is: Can we define a narrow, transparent, consent-based use for this feature without turning an AI assistant into a workplace surveillance system?

What is ChatGPT Computer History?

Computer History is an opt-in feature in the ChatGPT desktop app for macOS. It creates an activity timeline from allowed apps and websites, then gives ChatGPT and Codex recent context that can help answer questions about previous work.

OpenAI’s official Computer History documentation says the feature is off by default for ChatGPT Pro, Business, and Enterprise users. Pro users can choose to turn it on. In Business and Enterprise workspaces, an administrator must explicitly grant access before a member can opt in personally. Granting workspace access does not activate the feature for everyone; each person still has to turn it on.

The feature requires Memories and is available only in the ChatGPT desktop app on macOS. It is not available through an API key or Amazon Bedrock. OpenAI’s documentation currently lists supported regions including the EEA, Switzerland, and the United Kingdom, so older descriptions that exclude those regions should not be reused without checking the current documentation.

Computer History is designed to answer questions such as:

- “What was I working on before my last break?”

- “Where can I find the proposal document I was looking for earlier today?”

- “What tasks did I work on yesterday?”

- “Which parts of this workflow could become a reusable skill?”

Those use cases are materially different from measuring keystrokes to rank employees. The feature supplies context to an assistant. It should not be presented as proof of productivity, attention, or effort.

Does Computer History record the screen?

No. Computer History does not store screenshots in the history and does not record microphone input or system audio. Private-mode web browsing activity is also excluded.

That does not mean the feature records nothing important. OpenAI describes an interaction-event stream that can include clicks, typing, keyboard shortcuts, app switches, and text or other context exposed through macOS accessibility features. The system periodically turns those events into text summaries and local memory files.

The distinction matters because “not a screen recording” is not the same as “not sensitive.” A text summary of a customer conversation, a sequence of work in a financial spreadsheet, or the fact that someone opened a confidential document can still be sensitive business information. A company policy should treat Computer History as contextual work data, not as harmless telemetry.

OpenAI’s documentation also says temporary event files remain on the Mac for up to 48 hours. Generated memory files remain on the filesystem until the user deletes or clears them. The documentation warns that Computer History files can contain sensitive information and are not encrypted by Computer History. That is a practical security consideration for every company-managed Mac.

How does Computer History work on a company Mac?

Computer History uses several separate controls, so an administrator should not describe the feature as a single company-wide recording switch.

First, a Business or Enterprise administrator can grant workspace access. Second, each employee must personally opt in. Third, Memories must be enabled. Fourth, the employee chooses which apps and websites can contribute. The employee can use allow-list or exclusion controls, pause collection, resume it, turn it off, inspect timeline entries, and delete selected history.

OpenAI’s documentation says the feature does not require macOS Screen Recording permission. If the setting does not appear, the employee should confirm that the plan supports Computer History, that the workspace administrator has granted access where required, and that Memories is enabled.

The feature also changes the prompt-injection risk profile. If ChatGPT or Codex uses information from websites or communication tools as context, malicious instructions embedded in those sources may influence the assistant. That is another reason to keep the enabled scope narrow and avoid treating every captured activity as trusted company knowledge.

Why is this a company governance decision?

Computer History becomes a company governance issue when it is used on company devices, inside company workspaces, or for company work. The decision affects privacy, security, employee expectations, retention, offboarding, and the boundaries of acceptable AI use.

The productivity benefit is easy to explain. An employee can pause work and later ask the assistant to reconstruct the recent context. A recurring research or operations workflow may become easier to document. A team could identify repeated work that is worth turning into a shared skill or automation.

The governance risk is equally concrete. Employees may work across personal and professional contexts. Communication apps may contain messages from customers, partners, family members, or colleagues who did not consent to having their interactions included in an AI activity timeline. A timeline item may be deleted by the employee, but the company still needs to explain what the feature does, what data is in scope, how long it is retained, and who can access the resulting work product.

A company should not enable Computer History because it wants a hidden way to score effort. Activity volume is a poor proxy for value, and surveillance-heavy policies can encourage performative work, discourage honest communication, and create new security obligations. The feature is more defensible when the purpose is employee-controlled context recovery, workflow documentation, or voluntary process improvement.

What should an SMB policy say before enabling it?

A small company does not need a 40-page policy. It does need a clear written rule that employees can understand before they make a choice.

1. State the purpose in plain language

Say what the company is trying to achieve. A reasonable purpose might be helping employees resume interrupted work, document repeatable workflows, or reduce the time spent re-explaining context to an AI assistant. “Monitor productivity” is too broad and invites misuse.

2. Define what is in scope

List the roles, devices, apps, and websites that may be included. Start with a narrow pilot. For example, a staff member may include a project-management tool and a documentation site while excluding personal email, banking, health portals, customer messaging, and financial systems.

Avoid the phrase “all work activity” unless the company can explain exactly what that means. Vague scope creates vague consent and makes later disputes harder to resolve.

3. Explain the difference between access and opt-in

Employees should know that an administrator granting workspace access does not automatically turn Computer History on. Personal opt-in still matters. A company should never imply that an employee must activate the feature merely because the workspace permits it, unless there is a separate, legally reviewed employment requirement.

4. Explain review, deletion, and retention

The policy should say who can review timeline items, whether the company expects employees to delete personal or irrelevant items, and which work outputs should be copied into an approved company system. Do not treat a local memory file as the company’s official record of work.

The company should also define what happens when an employee leaves. Revoke workspace access, confirm the feature is off on managed devices where appropriate, and move only the documented work product that the company is entitled to retain. Do not attempt to collect an employee’s entire personal activity history.

5. Establish a complaint and correction path

Employees need a way to report an incorrectly scoped app, an unexpectedly sensitive timeline item, or an AI-generated summary that misrepresents what happened. A manager should not be the only person reviewing a complaint about monitoring. For a small company, an owner, operations lead, or external HR adviser can own the process.

When should a company enable Computer History?

Enable Computer History only when the company can name a specific, limited workflow that benefits from recent activity context and can explain the controls to the people involved.

Good candidates may include:

- An employee who frequently resumes interrupted research across a defined set of work apps.

- A voluntary pilot for documenting repeatable internal operations.

- A technical workflow where the employee wants Codex to help turn repeated steps into a reviewed skill or automation.

- A small team that has already agreed on an acceptable-use policy, app exclusions, and a deletion process.

Even in these cases, start with a time-limited pilot. Review whether the feature actually saves time, whether employees understand the boundaries, and whether the generated summaries contain information the company should not be retaining.

When should a company leave it off?

Leave Computer History off when the company cannot define a narrow purpose, cannot obtain meaningful employee understanding and consent, or cannot secure the Macs and local files involved.

It is also reasonable to keep it off for roles that routinely handle highly sensitive personal, financial, legal, health, or customer information. OpenAI specifically recommends pausing or excluding apps that contain sensitive health, financial, or personal information and turning the feature off during communications with other people unless prior express consent exists.

A company should not use Computer History as a substitute for data-loss prevention, access control, project management, or performance management. It does not tell an owner whether work is valuable, compliant, or complete. It provides context that an assistant may use. The company still needs human review and ordinary operational controls.

How should a small company audit the rollout?

An SMB can run a lightweight monthly review without reading everyone’s activity.

1. Access review: Which workspace roles are allowed to use Computer History, and does each role still need access?

2. Scope review: Which apps and websites are included, and do those choices match the written policy?

3. Consent review: Can each participating employee explain what is collected, what is excluded, and how to pause or delete history?

4. Security review: Are company Macs protected with separate user accounts, current operating-system updates, disk encryption, and appropriate device management?

5. Outcome review: Did the pilot reduce repeated briefing or improve a documented workflow? If not, turn it off.

6. Offboarding review: Was access revoked, and was legitimate company work moved into the approved system without collecting unrelated personal history?

The audit should focus on enablement, scope, security, and outcomes. It should not become a routine inspection of individual activity. That distinction is the line between governance and surveillance.

What does this mean for companies without an Enterprise plan?

The underlying business problem is broader than one OpenAI setting. Companies need to decide who can use AI, which models and tools are approved, how usage is paid for, what configuration employees receive, and how access is revoked when a role changes.

A company-controlled layer can make those decisions more consistent across employees and tools. Wodex is designed as a company-controlled AI workstation: the company manages gateway access, configuration, quotas, billing, and audit while employees use the app without managing API keys. That does not give Wodex authority over an employee’s ChatGPT Computer History, and it does not remove the need for OpenAI’s own privacy controls. It addresses the adjacent control problem: distributing and governing AI access without scattering personal accounts and credentials across the company.

If you are still clarifying the basic operating model, start with the Wodex overview. If the question is cost and team fit, compare the Wodex pricing options. If your team is moving from a chatbot toward governed agent workflows, read what the OpenAI Agents API changes for companies.

The practical answer: pilot for workflow value, not employee surveillance

Computer History is neither a harmless convenience nor proof that ChatGPT has become a workplace spy. It is an opt-in macOS feature that turns selected computer interactions into AI-usable context. The data can be useful, and the data can be sensitive.

For most small companies, the defensible approach is simple: write the policy first, grant access only to roles with a concrete use case, require personal opt-in, exclude sensitive apps and websites, set a short pilot period, and measure workflow outcomes rather than activity volume. If the company cannot explain the purpose or protect the resulting data, leave the feature off.

The larger lesson is that AI features are moving closer to the employee’s working context. A company should not respond by chasing every new toggle in every vendor console. It should establish a stable control layer for identity, access, configuration, usage, billing, and accountability, while preserving the employee’s right to understand and challenge how work data is handled.

Further reading

Sources

- OpenAI’s Computer History documentation, covering supported plans, macOS availability, opt-in and administrator controls, activity events, local storage, deletion, privacy, and prompt-injection risks.

- OpenAI ChatGPT Release Notes, the official release-note archive for the August 2026 Computer History launch entry.

- OpenAI Data Controls FAQ, linked from the Computer History documentation for chat-level data controls.

FAQ

Is ChatGPT Computer History a screen recorder?
No. OpenAI says Computer History does not include screenshots in the history and does not record microphone input or system audio. It does create activity events and summaries from allowed apps and websites, so it can still contain sensitive work context.
Can an employee turn on Computer History without the company knowing?
On Business and Enterprise workspaces, an administrator must first grant workspace access, but each employee still opts in personally. Granting access is not the same as activating the feature. A company policy should explain both controls and define how enablement is reviewed.
Is Computer History available on Windows or through an API key?
The current official documentation describes Computer History as a feature of the ChatGPT desktop app on macOS. It is not available with an API key or Amazon Bedrock. Do not assume that an API gateway or Windows deployment provides the same feature.
Can employees choose which apps and websites Computer History includes?
Yes. The employee can choose which apps and websites contribute, exclude sources, pause collection, resume it, and turn the feature off. Private-mode web browsing activity is excluded. Company policy should still identify categories of apps and websites that must remain excluded.
Can employees delete their Computer History?
Yes. OpenAI says users can inspect and delete individual timeline items or clear a recent period or all history. Clearing history cannot be undone. Companies should preserve legitimate work outputs in approved systems rather than relying on an employee’s local AI memory as the official record.
Does Computer History send activity data to OpenAI?
The official documentation says interaction events are captured locally and temporary event files are processed on OpenAI’s servers to generate memories. OpenAI says it does not retain those event files after processing unless required by law and does not use them for training. Relevant memory or event content may be included in a later chat, subject to the applicable chat-level data controls.
Should a small company enable Computer History for everyone?
Usually not as a blanket rollout. Start with a voluntary, time-limited pilot for a specific workflow, use narrow app and website permissions, explain the purpose and controls, and review whether the feature produces a measurable benefit without creating unacceptable privacy or security risk.

Deploy ChatGPT with company control from day one

Wodex is the managed workstation for ChatGPT now, and the control layer for more team agents later.