How to Actually Get Real Work Out of ChatGPT Work (Without Torching Your Usage Credits)
OpenAI's new agent mode ships finished spreadsheets, decks, and reports if you brief it right. Seven habits that separate the people getting deliverables out of ChatGPT Work from the people burning credits on polished-but-wrong output.
Here's the thing about ChatGPT Work: it isn't the same product you were half-heartedly poking at six months ago. On July 9, 2026, OpenAI replaced the old Agent mode with ChatGPT Work, a real multi-step agent that takes a brief, works in the background for minutes or hours, and hands you back an actual file. A spreadsheet with your comparison data in it. A deck built from your meeting notes. A report with cited sources. A small web app you can share. Not a wall of text you have to copy-paste into something else.
It's powered by the new GPT-5.6 model family, it's bundled into Plus, Pro, Business, Enterprise, and Edu at no extra list price, and it draws from the same metered usage pool as Codex. That last part is the catch. Tasks that run for hours burn through your allowance fast, and a task that comes back polished-but-wrong is more dangerous than one that comes back rough-but-wrong, because you're tempted to skip the check. I've spent the last two weeks running Work against the kind of tasks I actually do in a week (vendor research, first-draft financial models, competitive teardowns, prep decks) and the gap between "this saved me a day" and "this cost me two credits and produced nothing usable" is almost entirely in how you brief it. These seven habits are the ones that consistently land the deliverable.
1. Brief it like a project, not a prompt
This is the single biggest mindset shift, and it’s where most people fail on the first try.
Regular ChatGPT trained us to type a question and see what comes back. Work punishes that habit. You’re not asking a question, you’re handing over an outcome you describe, letting it gather the information it needs across your connected apps, break the job into smaller steps, and carry them out on its own, so the output isn’t a wall of text to copy and paste, it’s the actual artifact, delivered as a file you can open and use.
Every good Work brief has four pieces. The outcome, one sentence describing the finished artifact. (“A spreadsheet comparing these 15 CRM vendors on price, seat minimums, and native integrations.”) The scope, the specific list, the date range, the geography, the audience. The rules, what to include, what to skip, what format to use, what to do when data is missing. The deliverable format, .xlsx, .pptx, .pdf, or a Sites page.
Skip any of those and you get a beautifully executed version of the wrong task. Include all four and you get something you can actually send.
2. Use Plan mode before you turn it loose
The second habit is refusing to let it start until you’ve seen its plan.
Work will happily run for an hour in the wrong direction if you let it. The fix is to ask, in the same brief, for it to lay out its plan first and wait for your approval before executing. Something like: “Before you start, list the sources you’re planning to check, the columns you’re planning to include, and any assumptions you’re making. Wait for me to approve before executing.” That one paragraph is worth more than any prompt template you’ll find on Reddit.
The reason it matters: Work is powerful, but it isn’t a stand-in for domain expertise. It doesn’t know your company’s specific standards, so it produces a competent generic version unless your brief spells out the details, and it also won’t reliably verify its own numbers, which means a polished-but-wrong spreadsheet is a real risk.
Catching a wrong assumption in the plan takes thirty seconds. Catching it in the finished deck takes an hour of unwinding.
Read the plan. Push back on anything vague. Then approve.
3. Ration your credits, treat Work as your Tuesday-morning intern, not your always-on assistant
On web and mobile, Work is rolling out to paid plans except Free and Go, with Pro, Pro Lite, Enterprise, and Edu users getting access first, and Plus and Business users following. Every plan has a metered usage pool, and Work shares that pool with Codex. Long tasks eat it fast.
The people getting real value out of Work aren’t running it constantly. They’re picking two or three high-value tasks a week, the ones that would normally eat half a day of manual clicking, and spending their credits there. Vendor research. First-draft financial models. Competitive teardowns. Prep decks built from a folder of notes.
The wrong use is “hey, summarize this article” or “write me a quick email.” That’s what regular Chat mode is for. Firing up an agent to do a 30-second job is like calling an Uber to go to your mailbox. You’ll run out of gas by Thursday and have nothing to show for it.
A simple rule: if the task takes you less than fifteen minutes manually, don’t use Work. If it takes you more than an hour, and there’s a clear finished artifact at the end, that’s the sweet spot.
4. Connect the right plugins, and only the right plugins
The new Plugin Directory is what makes Work more than a browser agent.
The App Directory has been replaced with the Plugin Directory. Existing app connections aren’t affected, and plugins can package skills, apps, and app templates for specific workflows, available from ChatGPT on web and desktop, including Work and Codex. In practice that means Work can pull directly from your Google Drive, your Gmail, your Salesforce, your GitHub, your Linear, whatever you’ve connected, and use that context to build the deliverable.
But there’s a security reason to keep the connection list short. Enable only the apps needed for the current task, and think about the data sensitivity of the sites you log into via agent. If you’re building a vendor comparison spreadsheet, it doesn’t need access to your inbox. If you’re drafting a client update, it doesn’t need your GitHub. Enable, use, disable. Every extra connection is an extra attack surface for prompt injection, which isn’t theoretical, and I’ll get to that in step 6.
The workflow: turn on the two or three plugins the task actually needs, run the task, turn them off. Your future self will thank you.
5. Use Scheduled Tasks for anything you do more than once
This is the feature people are sleeping on, and it’s the single biggest productivity win in the July release.
Work can keep projects moving through Scheduled Tasks that run once, repeat on a schedule or trigger, or monitor for changes. Every Monday morning, refresh the competitive pricing sheet. Every Friday, pull the week’s new signups and generate a first-draft summary. Every time a specific SEC filing hits, extract the numbers and drop them into a tracker.
Set it up once with a good brief, review the first two or three outputs to make sure it’s landing where you want, and then let it run. The delta between “I’m going to do this manually every week” and “the finished file is in my inbox before I open my laptop” is enormous, and it costs you exactly one good briefing session.
The trap: don’t automate anything you haven’t verified manually first. If the one-off version comes back wrong, the scheduled version comes back wrong on a schedule. Which is worse.
6. Take the safety guidance seriously, this isn’t paranoia
I know, I know. Nobody wants to read the security section. Read it anyway.
When you sign ChatGPT agent into websites or enable apps, it can access sensitive data like emails, files, or account settings, and take actions on your behalf. That creates real privacy risks, including “prompt injection” attacks. Translation: a malicious page on the web can, in principle, feed instructions to the agent that override yours. OpenAI has built defenses against this, but they’re defenses, not guarantees.
The rules are simple, and they’re the ones OpenAI itself publishes: don’t type passwords or private info directly into messages; use takeover mode for sensitive inputs; enable only the apps needed for the current task; think about the data sensitivity of sites you log into via agent; avoid vague, open-ended prompts like “check my email and handle everything”; stop tasks right away if something seems off. That last one is the important one. If the agent is doing something you didn’t ask for, even something innocuous-looking, kill the task. Don’t wait to see what happens.
And when a login is required, don’t paste your password into the chat. If a task needs a login, ChatGPT agent pauses and prompts you to take control of the virtual browser, and while you’re driving the browser, screenshots aren’t captured, which helps protect passwords and other sensitive data you enter. Use takeover mode. Every time.
7. Always ask it to audit its own output before you trust it
The single most valuable line to add to the end of every brief: “When you’re done, list every source you used with URLs, every assumption you made, and every data point you’re uncertain about.”
That one instruction is the difference between a deliverable you can actually send and one you have to re-verify from scratch. Work will happily produce a beautiful spreadsheet with three cells that are quietly wrong. It won’t, on its own, tell you which three. But if you ask it to flag its own uncertainties, it usually will, and that gives you a targeted list of things to spot-check instead of a wall of numbers you have to trust or reject wholesale.
The other version of this: for anything that goes to a client, a boss, or into a system of record, require sources. If a number appears in the deliverable, there should be a URL next to it. If there isn’t, the number gets a flag. It’s more work up front, and it saves you from the one truly catastrophic failure mode of agent tools, a confident wrong answer buried in three hundred correct ones.
A bonus, because it matters: know when to walk away from the agent and back to plain Chat
Not every task is a Work task. If you want a paragraph rewritten, a code snippet debugged, a concept explained, a translation, that’s Chat. If you want a finished multi-source, multi-step deliverable file, that’s Work. Using Work for a Chat-sized job is how you burn a week of credits by Wednesday. Using Chat for a Work-sized job is how you spend three hours copy-pasting between tabs when the agent could have done the whole thing while you were at lunch.
The one habit that ties it all together: treat Work like a contractor, not a chatbot. You brief a contractor with an outcome, a scope, rules, and a deliverable format. You check their plan before they start. You review their work when they’re done. You don’t hand them the keys to every system you own on day one. Do that with Work and you’ll get an hour of real output for fifteen minutes of briefing. Skip any of those steps and you’ll get a polished, confident, cited, beautifully formatted document that’s quietly wrong in exactly the places you don’t have time to check.