Event-triggered tasks in ChatGPT run the moment something happens in a connected app, instead of at a fixed time. You connect Gmail, Slack or GitHub, describe the event and the action, and ChatGPT works when a matching message or pull request arrives. OpenAI shipped them on 25 August 2026 inside ChatGPT Work, for Plus, Pro, Business, Enterprise and Edu accounts.
Key Takeaways
- Scheduled tasks used to be time-based only. Event-triggered tasks add the other half of automation — "when this happens" — using webhooks from Gmail, Slack and GitHub.
- Availability: Plus, Pro, Business, Enterprise and Edu, plus eligible ChatGPT for Healthcare workspaces. Free and Go accounts cannot create them, and they are not available in FedRAMP workspaces. Enterprise, Edu and Healthcare admins must switch on Allow event-triggered scheduled tasks first.
- Limits to design around: 30 runs per hour and 720 per day across all your event-triggered tasks, and active task caps of 3 for Free and Go, 5 for Plus, 10 for Business and Edu, 15 for Pro and Enterprise.
- The business case is not that this replaces Zapier or Make. It is that a marketing manager, an SDR or a support lead can build a working trigger in ninety seconds, in the tool they already use, without a ticket to IT.
- The security case is the unglamorous half. A Gmail trigger is a standing listener on an inbox, which makes hostile email a zero-click route to your agent, and OpenAI's confirmation gate does not cover read, summarise or draft actions. Governance ships on day one, not in Q3.
What OpenAI actually shipped on 25 August 2026
Scheduled tasks have been in ChatGPT since early 2025, and until this release they did one thing: run a prompt on a clock. Useful for a Monday morning brief. Useless for anything that has to react to the real world.
The August update added event-triggered tasks — webhook-based tasks that fire when something changes in a connected app. Three sources are supported at launch, and each behaves slightly differently:
| Source | What it can trigger on | Setup detail people miss |
|---|---|---|
| Gmail | A new message, optionally filtered by sender or subject | No channel-level opt-in. Connect an inbox and it listens to that inbox |
| Slack | New messages in a channel | You must add @ChatGPT to every channel you want monitored |
| GitHub | Supported pull request activity | Only in an authorised github.com repository |
Two smaller changes landed alongside it and both matter more than they look. First, shared tasks: you can send a task to a colleague, who reviews the instructions, connects their own apps and schedules an independent copy. That is the difference between one person's clever trick and a team standard. Second, time-based scheduled tasks reached Free accounts, capped at three, one-time or recurring no more than once a day, in flexible windows (morning, afternoon, night) rather than at exact times. Hourly schedules and precise delivery times still require a paid plan. It is a small allowance, but it means every colleague can now see what "ChatGPT does this on a schedule" looks like.
Why webhooks are not just faster polling
The original scheduled tasks used polling. OpenAI's infrastructure checked a connected app at an interval, took what was new, ran the task, and let go. Webhooks reverse the direction: OpenAI registers a listener endpoint with Gmail, Slack or GitHub, and the app pushes a notification the instant a qualifying event happens.
The upside is latency and reliability. The trade is that the access footprint changes from episodic to continuous. Hold on to that sentence. We come back to it in the security section, and it is the single most consequential detail in this release.
How an event-triggered task is built: Trigger, Condition, Prompt
Every event-triggered task is three things, and ChatGPT shows you all three before it saves anything.
| Part | What it means | Example |
|---|---|---|
| Trigger | The app event that wakes the task up | New Gmail message |
| Condition | The filter deciding whether this particular event counts | From @keyaccount.com, subject contains "renewal" |
| Prompt | What ChatGPT does when both are satisfied | Summarise the request, flag anything contractual, draft a reply for review |
You describe it in plain English. ChatGPT parses it into those three fields, asks you to authorise the connection, and the task then lives under Scheduled, where anyone can test, pause, edit or delete it. There is no canvas, no node graph, no branching logic, no retry policy. That is a limitation and also the entire point.
"The reason non-technical teams never adopted automation platforms is not that the platforms were bad. It is that a blank canvas with two hundred connectors is a request to become a developer, and most people politely decline."
Why this matters if you do not have an automation team
We have spent two years watching mid-market companies buy automation tooling and then not use it. The licences get bought, one operations person learns Make or Zapier properly, and every automation in the business becomes a request to that one person. When they take a holiday, the business stops automating. When they leave, nobody can fix the scenarios.
Event-triggered tasks do not solve that for complex, multi-system workflows. They solve it for the enormous long tail underneath: the hundreds of small "when X happens, someone should do Y" moments that were never worth a ticket, and so never got built at all.
Toni Dos Santos, our Co-Founder and AI Advisor, puts the distinction this way: "Automation platforms won every workflow that was worth a project plan. Nobody ever built the ones worth eleven minutes a week, and there are four hundred of those in every company. That is the category this opens."
There is a measurable version of the argument. The CBI, with Oliver Wyman, found that firms leading on AI deployment meet or exceed their expected ROI 49% of the time, against 15% for firms still stuck in pilots, buying in most cases identical software. We wrote that up in our analysis of the CBI Adoption Decade report. The variable is not the tool. It is how many people can put the tool inside a real workflow without asking permission. Event triggers move that number.
Use cases by team, with the trigger and the condition written out
These are the patterns we hand out in workshops. All of them are buildable by the person who owns the work, which is the test that matters.
Marketing
- Inbound brief triage. Trigger: new Gmail message. Condition: sender is your agency domain. Prompt: extract deliverables, dates and open questions into our standard brief format, and flag anything that contradicts the current campaign plan.
- Competitor alert digest. Trigger: new Gmail message. Condition: subject contains "Google Alert". Prompt: strip the noise, keep launches, price changes and senior hires, and write two lines on why each matters to us.
- Campaign channel watch. Trigger: new Slack message in #campaign-launch. Condition: contains "blocker" or "approval". Prompt: summarise the blocker, name who is being waited on, and draft the chase message.
If you are building a marketing operating system rather than a handful of triggers, our CMO playbook for AI-driven marketing operations is the wider frame, and AI training versus AI adoption for marketing teams covers why the training half usually fails.
Sales and revenue
- Inbound lead qualification. Trigger: new Gmail message. Condition: sent to hello@ or your web form address. Prompt: score against the ICP, pull the company's public basics, draft a reply proposing two call slots, and tell me plainly if this is not worth a call.
- Renewal and risk signal. Trigger: new Gmail message. Condition: from a named account, subject contains "contract", "renewal" or "pricing". Prompt: summarise, flag commercial risk language, produce three talking points for the account owner.
- Proposal follow-through. Trigger: new Slack message in #deals. Condition: contains "proposal sent". Prompt: draft the day-three follow-up email in our tone, referencing the deal notes.
The adjacent work is covered in AI-powered sales enablement, and in our AI training for sales teams if you want it done against your own pipeline rather than a generic deck.
Customer support
- Escalation catcher. Trigger: new Gmail message. Condition: subject contains "urgent", "outage", "cancel" or "refund". Prompt: classify severity, summarise the thread history, and draft a first response that promises nothing we cannot do.
- Out-of-hours cover. Trigger: new Gmail message to the support alias. Condition: known customer domains. Prompt: categorise, and write the internal handover note for the morning shift.
- VIP watch. Trigger: new Slack message in #support-escalations. Condition: mentions a tier-one account. Prompt: draft the executive-facing update, three sentences, no jargon.
Support is where the return shows up fastest, because volume is high and the first draft is most of the work. The full picture is in AI for customer support workflows and our customer support AI training.
Operations, finance and HR
- Supplier invoice intake. Trigger: new Gmail message. Condition: subject contains "invoice". Prompt: extract supplier, amount, currency, due date and PO reference into one line, and flag anything above the approval threshold.
- Incident log. Trigger: new Slack message in #incidents. Condition: contains "P1" or "P2". Prompt: open a structured incident summary with timeline, impact and current owner.
- Candidate response. Trigger: new Gmail message. Condition: from the careers alias. Prompt: summarise against the role brief, and draft either the screening invite or the decline, for a human to send.
Team-by-team detail lives in AI for operations teams, AI for finance teams and AI for HR teams.
Executives and their EAs
- Board and investor mail. Trigger: new Gmail message. Condition: from named board members or investors. Prompt: summarise in three bullets, identify the decision being asked for, draft a holding reply.
- Signal, not volume. Trigger: new Slack message in #leadership. Condition: contains "decision needed". Prompt: one-paragraph brief with the options and what happens if we do nothing.
For the wider leadership frame, see the executive's guide to leading AI transformation and why C-suite AI literacy is the missing link.
Want your teams building these instead of reading about them?
See the enterprise adoption programme →ChatGPT training for teamsHalf-day workshops in role groups. Everyone leaves with two live triggers on their own inbox and a written rule sheet, not a slide deck. UK engagements from £3,500.
How to set one up, start to finish
- Connect the app. Settings → Apps, then connect the Gmail, Slack or GitHub account you want to listen to. Use the account that actually receives the messages. For Slack, add @ChatGPT to each channel you want monitored.
- Open Work and describe the automation in one sentence: the event, the filter, and what you want done.
- Review Trigger, Condition and Prompt. ChatGPT shows you its interpretation. Tighten the condition here. This is the step people skip, and it is the difference between eight useful runs a day and two hundred noisy ones.
- Complete any required authorisation for the connected app.
- Test with a deliberate event. Send yourself a message that matches the condition. Check what ran, and check what it did with the content.
- Manage it under Scheduled, where you can review, edit, pause or delete. Set notification preferences under Settings → Notifications (push, email or both).
Two practical notes. Creation and editing of trigger conditions happens on the web or in supported mobile apps; the desktop app can display existing event-triggered tasks but not create or edit their conditions. And a task created inside a project cannot access files uploaded to that project, which catches people out constantly.
OpenAI's own reference is the Scheduled tasks in ChatGPT help article, with the walkthrough at ChatGPT Learn. Both update faster than any blog post, this one included, so check them for current limits before you design around a number.
Shared tasks: how one good trigger becomes a team standard
Sharing is the feature that turns this from a personal productivity trick into something a department runs. From Scheduled, open a task's more-options menu, choose Share, and copy the link. The recipient reviews the instructions, adjusts the schedule for their time zone, and schedules their own separate copy against their own apps.
What travels in that link is a snapshot: title, instructions, schedule and original time zone. What does not travel: your name, chat history, previous results, memories, custom instructions, attached files, connected app data and app credentials. Recipients run on their own permissions and their own connections. Links created in a Business, Enterprise, Edu or Healthcare workspace can only be opened by members of that workspace.
Two cautions worth putting in your internal guidance. The task title can appear in a link preview, and anyone who can open the link reads the full instructions — so no account numbers, health details, credentials or client names in a task title. And edits to the original task do not propagate; you have to reopen the Share dialog and copy the link again to refresh it.
The limits, stated plainly
| Constraint | Where it lands |
|---|---|
| Event-triggered run rate | Up to 30 runs per hour and 720 per day, across all your event-triggered tasks combined. Multiple events may be grouped into one run |
| Time-based frequency, paid plans | Recurring up to once per hour, with exact delivery times |
| Time-based frequency, Free | One-time, or recurring no more than once per day, in flexible windows (morning, afternoon, night) |
| Active tasks per plan | 3 Free and Go, 5 Plus, 10 Business and Edu, 15 Pro and Enterprise |
| Event sources | Gmail, Slack, GitHub. No Outlook, Teams, Jira, Notion, Linear or Asana |
| Plan availability for event triggers | Plus, Pro, Business, Enterprise, Edu, eligible Healthcare workspaces. Not Free, not Go, not FedRAMP |
| Not supported at all | Voice chats and GPTs |
Read the run rate carefully, because it is shared across your tasks. Thirty an hour sounds generous until one person points a trigger at an unfiltered shared inbox and consumes the budget before lunch. Conditions are not a nicety. They are your rate limiting.
Also plan for pausing. Tasks pause when they go inactive, when an action needs your approval, or when the chat they live in is deleted. Nobody gets an alert that automation has quietly stopped, so a monthly look at the Scheduled list belongs in someone's calendar.
What this is not
We would rather you knew the edges before telling your board you have replaced your automation stack.
- It is not multi-step orchestration. One trigger, one prompt. No branching, no loops, no conditional paths across four systems.
- It has no real error handling. No retry policy, no dead-letter queue. A human notices a bad run, or nobody does.
- The audit trail has a hole. Scheduled tasks are covered by the Compliance API, but shared task links and their saved snapshots currently are not, and they are absent from personal data exports too. If you are in a regulated sector, that gap is the sentence to take to your compliance lead.
- The connector list is three apps. No CRM, no ticketing, no ERP. Zapier and Make have thousands of connectors and that gap is not closing this quarter.
- It is not deterministic. The same email can produce a slightly different output twice. Fine for a draft. Not fine for anything that posts to a ledger.
That last point is the real architectural difference from Zapier. A deterministic automation cannot be redirected by the content it processes. A generative model can. The flexibility is exactly what makes it useful for knowledge work, and exactly what makes the next section non-optional.
Meera Sanghvi, our other Co-Founder, draws the line for clients like this: "Use event triggers where a human reads the output before anything irreversible happens. The moment the output writes to a system of record with no person in between, you are back in automation-platform territory, and you should be."
For the deeper comparison, we covered platform-based automation in the Zapier and AI workflow tutorial, the design of durable systems in building production-ready agentic workflows, and where the category is heading in AI agents in enterprise.
The security part, which is not optional
Go back to how this works. When you attach a Gmail trigger you are not granting a scheduled read. You are granting a standing listener on an inbox, with a push notification landing in an agent the instant a qualifying message arrives, and it stays that way until you revoke it.
That is a real capability upgrade and a real change in your threat model. A hostile email now reaches your agent with no click, no open, no human in the loop. Researchers documented this pattern before webhooks existed as a formal feature, in the ShadowLeak class of attack against Gmail-connected agents: instructions hidden in email HTML using white-on-white text, CSS tricks or microscopic fonts, invisible to the reader, parsed and acted on by the model. OpenAI patched that specific vulnerability. The class of attack remains. Tech Times covered the implications for this release in "ChatGPT Work Adds Gmail Webhooks and Inbox Login: New Automation, New Attack Route".
The detail most coverage skips: OpenAI does build a confirmation gate, and it does work — bookings, payments and flagged actions pause for review. But the gate applies to consequential actions. It does not apply to read, summarise and draft, which is the overwhelming majority of what a webhook task does. So the gate limits what an injected prompt can make the agent do. It does not stop the agent processing hostile content and being influenced by it.
OpenAI has been unusually candid, stating publicly that prompt injection, much like scams and social engineering on the web, is unlikely ever to be fully solved. Take them at their word and design accordingly.
Six rules we give every client before they switch a Gmail trigger on:
- Never point a trigger at an unfiltered inbox. Condition on known senders, known domains or known subject patterns. An open trigger on a public alias is an open door.
- Keep permissions read-only where the connector allows it. A successful injection that produces a bad summary is a different severity of incident from one that sends mail.
- Keep the prompt read-and-draft. Summarise, classify, draft. Do not authorise a task to send, pay, delete or share on its own.
- Treat message content as hostile input, not instruction. Write the prompt so the email is data to be described, never a source of commands to follow.
- For Slack, monitor closed channels. @ChatGPT only sees channels you add it to. Use that. Anything posted by any member of a monitored channel, including a compromised account, reaches the agent automatically.
- Review connected apps and the task list monthly. Standing OAuth connections nobody remembers granting are how small problems become incidents.
None of this is a reason to avoid the feature. It is a reason to write one page of internal guidance before you roll it out.
What admins and compliance leads need to know
If you run a workspace rather than a personal account, four things sit on your desk before anyone builds a trigger.
- The toggle is yours. Enterprise, Edu and ChatGPT for Healthcare admins must enable Allow event-triggered scheduled tasks before members can create them. That is a decision, not a formality — make it deliberately, with the rules written first.
- Healthcare has a hard line. In ChatGPT for Healthcare, event-triggered tasks are off by default and are not covered under a Business Associate Agreement. They must not be used to transmit, store or process protected health information.
- Mind the Compliance API gap. Scheduled tasks are covered. Shared task links and their saved snapshots are not currently included, and nor are they in data exports. Decide now whether sharing is permitted in your workspace.
- Personal plans have no admin layer. On Plus and Pro there is no admin-managed control over which apps get connected for webhook monitoring. If your staff are on personal seats, your governance is a policy document and nothing else — which is an argument for moving them onto managed seats.
There is a regulatory clock running too. The EU AI Act's Article 50 transparency obligations for agentic systems took effect on 2 August 2026, three weeks before this feature shipped. If you operate in the EU and you are about to let a model act on inbound content automatically, that obligation applies to what you are building. Our EU AI Act Article 4 and AI literacy guide covers the wider picture, and AI governance and the ICO framework has the one-page policy template we use.
Not sure whether your teams are ready to be trusted with standing inbox access?
Run the free AI Adoption Scorecard →Book a free 20-minute callTen minutes, no sales call attached. You get a written read on where your automation and governance gaps actually are.
How to roll this out to a non-technical team in two weeks
- Days 1–3: pick three triggers, not thirty. One per team, chosen by the person doing the work. High volume, low risk, output read by a human.
- Days 4–5: publish the one-page rules. Which inboxes and channels may be connected, what a task may never do, whether sharing is allowed, who to ask. Ambiguity suppresses usage more effectively than any policy.
- Days 6–10: build in role groups. Ninety minutes per team, everyone builds their own trigger live, on their own inbox, with a real condition. Managers build one too, and go first.
- Days 11–14: review, share the winners, delete the rest. Use shared task links to distribute the two that worked. Record what each one saves, in minutes, so the next round has a number attached.
The order matters more than the speed. Teams that start with the rules and end with a measured saving keep the habit. Teams that start with an enthusiastic Friday afternoon and never measure anything have forty paused tasks by October. We wrote about that failure pattern in from prompting to task delegation.
The line worth keeping
Automation stopped being a tooling problem some time ago. It became a permission problem: who in your business is allowed to build a small thing without asking. Event-triggered tasks quietly hand that permission to everyone with a paid ChatGPT seat and an inbox.
That is worth a great deal if you spend two weeks putting rails around it, and very little if you announce it and walk away. The feature is not the win. The number of people using it inside a real workflow, every week, is the win.
Frequently Asked Questions
What are event-triggered tasks in ChatGPT?
Event-triggered tasks are webhook-based scheduled tasks that run when something happens in a connected app rather than at a set time. They run in ChatGPT Work and respond to supported Gmail, Slack or GitHub activity: a new email optionally filtered by sender or subject, a new message in a Slack channel where @ChatGPT has been added, or supported pull request activity in an authorised github.com repository. OpenAI released them on 25 August 2026.
Which ChatGPT plans include event-triggered tasks?
They are available to eligible users on Plus, Pro, Business, Enterprise and Edu plans, and in eligible ChatGPT for Healthcare workspaces. Free and Go accounts cannot create them, and they are not available in FedRAMP workspaces. Enterprise, Edu and Healthcare admins must enable "Allow event-triggered scheduled tasks" before members can create any. In Healthcare workspaces they are off by default and are not covered under a BAA.
How many ChatGPT tasks can I run, and how often?
Active task limits depend on the plan: 3 for Free and Go, 5 for Plus, 10 for Business and Edu, and 15 for Pro and Enterprise. Event-triggered tasks can run up to 30 times per hour and 720 times per day across all of your event-triggered tasks combined, and multiple events may be grouped together. Paid plans support recurring time-based tasks up to once per hour with exact delivery times; Free users get one-time or once-daily tasks in flexible morning, afternoon or night windows.
Do ChatGPT event-triggered tasks replace Zapier or Make?
No, and treating them as a replacement is the fastest route to disappointment. They handle single-step, human-reviewed work from three apps, with no branching, no retry policy and a gap in the audit trail around shared tasks. Automation platforms still win on multi-step orchestration, thousands of connectors, deterministic execution and logging. What ChatGPT tasks win is the long tail: small automations that were never worth a project, and so were never built.
Are ChatGPT Gmail triggers safe to use at work?
They are safe with conditions and unsafe without them. A Gmail trigger creates a standing listener on the inbox, so a malicious email reaches the agent with no user action, and hidden instructions in email HTML are a documented indirect prompt injection technique. OpenAI's confirmation gate covers consequential actions such as payments and bookings, but not read, summarise or draft. Filter triggers to known senders, keep app permissions read-only, keep tasks read-and-draft rather than send-and-act, and review connected apps monthly.
How do I create an event-triggered task in ChatGPT?
Go to Settings, then Apps, and connect the Gmail, Slack or GitHub account you want to monitor. For Slack, add @ChatGPT to each channel to be watched. Open Work and describe the event and the action in plain English. Review the Trigger, Condition and Prompt that ChatGPT proposes, tighten the condition, and complete the authorisation. The task then appears under Scheduled, where you can review, edit, pause or delete it. Trigger conditions can be created and edited on the web and in supported mobile apps, but not in the desktop app.
Can I share a ChatGPT task with my team?
Yes. Sharing works for eligible active or paused tasks, including event-triggered ones, and is available across plans. The link carries a snapshot of the title, instructions, schedule and original time zone, and nothing else: no chat history, no previous results, no memories, no files, no connected app data or credentials. Recipients schedule an independent copy using their own permissions and their own app connections. Workspace-created links open only for members of that workspace.
Why did my ChatGPT task pause on its own?
A task pauses when it becomes inactive, when an action requires your approval before it can proceed, or when the chat it is attached to is deleted. Deleting a chat pauses the task but does not delete its shared link, which has to be removed separately. Go to Scheduled to resume, edit or delete. Since nothing alerts you when automation stops, put a monthly review of the Scheduled list in someone's calendar.
What is the best first event-triggered task for a non-technical team?
Inbound triage on a shared alias with a tight sender or subject filter. It is high volume, low risk, the output is a draft a human reads before anything is sent, and the time saved is easy to measure. Start there, record the minutes saved per week, and use that number to justify the second and third trigger.
We sit in the passenger seat for this exact problem
We're We Call Shotgun, a founder-led AI consulting and training boutique working across the UK and France. We are tool-agnostic across ChatGPT Enterprise, Microsoft Copilot, Google Gemini and Claude, and every engagement ships with workflow-first adoption training, because a feature nobody uses is not an advantage. 1,500+ professionals trained, 50+ companies, 4.98/5 average rating. UK engagements from £3,500.
Run the Free AI Adoption Scorecard Book a Free 20-Minute CallSources and further reading
- OpenAI Help Center, "Scheduled tasks in ChatGPT" — the authoritative reference for triggers, plan availability, sharing and run limits
- ChatGPT Learn, "Scheduled tasks" — OpenAI's step-by-step walkthrough
- OpenAI Help Center, ChatGPT release notes — where the 25 August 2026 webhook, shared-task and Free-tier changes are logged
- OpenAI Help Center, ChatGPT Business release notes — workspace rollout and admin controls
- Tech Times, "ChatGPT Work Adds Gmail Webhooks and Inbox Login: New Automation, New Attack Route" — the security analysis referenced above (26 August 2026)
- We Call Shotgun: ChatGPT Work and GPT-5.6 business guide, start AI automation, AI tool stacking masterclass, prompt literacy for non-technical managers