AI workspace: one place for your team to use AI on company data
An AI workspace is one place where your staff use AI with their work sign-in, on company data they already have permission to see, with a chat history the company controls. The main options are the business plans of ChatGPT and Claude, Microsoft 365 Copilot, Gemini in Google Workspace, and self-hosted workspaces such as Open WebUI and LibreChat that run on your own server. This guide compares what each option connects to, what each vendor says it keeps and trains on, and how a smaller manufacturer or distributor can choose.

What an AI workspace is
An AI workspace is the screen your staff open to ask an AI model a question, draft an email or summarize a document, set up under the company’s control. It differs from a personal chatbot account in five ways:
- Work sign-in. Staff log in with the company identity through single sign-on (SSO), one company login that controls access to many tools. When someone leaves and their account is closed, their workspace access ends with it.
- Permissions. The AI reads only the files and records the person asking could already open.
- History. Conversations are kept for as long as the company decides, and administrators can delete them.
- Admin controls. The company decides who has access, which connections and models are switched on, and whether staff can send feedback to the vendor.
- Connectors. Links to email, SharePoint, Google Drive and other sources let the AI answer from company data without manual uploads.
The workspace is the part staff see. The layer underneath, meaning the models, data connections, tools and approvals that serve several uses at once, is covered in enterprise AI platform. Where each option stores data and where its model processes prompts is covered in private AI for business.
The main AI workspace options
Each entry below reports what the vendor says on its own pages as they stood on September 28, 2026. These settings change often, so check the linked page before you sign.
ChatGPT Business and Enterprise
OpenAI describes ChatGPT Business as “a self-serve workspace plan for teams” with centralized billing and admin controls, for up to 200 paid seats per subscription (OpenAI). “SSO and domain verification are included with ChatGPT Business” (OpenAI). For more seats than that, OpenAI points to ChatGPT Enterprise.
OpenAI’s enterprise privacy page says “We do not train our models on your data by default” for both plans. Apps connect ChatGPT to internal sources, and the page says ChatGPT “respects your organization’s existing permissions,” that each user signs in to a connected app before using it, and that OpenAI does not train on data accessed from apps by default. On retention, ChatGPT Business admins “can control how long your data is retained,” and deleted or unsaved conversations are removed within 30 days, unless the law requires longer or OpenAI needs longer to protect its services or others from harm. On Enterprise, admins control retention and deleted conversations are removed within 30 days unless OpenAI is legally required to keep them.
How OpenAI charges: ChatGPT Business is priced per user per month.
Claude Team and Enterprise
Anthropic’s Team plan takes 2 to 150 seats and includes SSO with domain capture, automatic account creation when a person first signs in, role-based permissions and connectors to Google Drive, Gmail, Google Calendar, GitHub, Microsoft 365 and Slack. The Enterprise plan adds audit logs, SCIM (automatic account setup and removal from your identity system), custom data retention controls, a Compliance API that gives programs access to activity logs and chat histories, and customer-managed encryption keys.
Anthropic says that by default it will not use inputs or outputs from commercial products such as Claude for Work to train its models. The exception is feedback: a thumbs up or down stores the whole conversation for up to 5 years and may be used for training after the user and customer IDs are removed. An owner can switch the button off with the Rate chats setting. Chats stay in the product until a user deletes them, and a deleted conversation leaves Anthropic’s back-end storage within 30 days. Conversations flagged for breaking the usage policy are kept for up to 2 years, and some models require limited retention for safety review.
How Anthropic charges: Team is priced per seat per month. Enterprise charges a seat fee for access and bills all usage separately at API rates.
Microsoft 365 Copilot
Microsoft 365 Copilot works inside Word, Excel, PowerPoint, Teams and the other Microsoft 365 apps, and staff use it with their Microsoft 365 work account. Microsoft’s privacy page says Copilot “only surfaces organizational data to which individual users have at least view permissions,” and that prompts, responses and data accessed through Microsoft Graph “aren’t used to train foundation LLMs.” Microsoft Graph is the service through which Copilot reaches your documents, emails, calendars, chats and meetings.
Microsoft stores each prompt and response, with the citations Copilot used, and administrators can set retention for that data with Microsoft Purview, Microsoft’s compliance tool. The same page says customers outside the EU “may have their queries processed in the US, EU, or other regions.”
How Microsoft charges: Microsoft 365 Copilot Business is an add-on to a Microsoft 365 plan, priced per user per month.
Gemini in Google Workspace
Gemini works inside Gmail, Docs, Sheets and the other Workspace apps, and in the separate Gemini app. Google’s Workspace privacy hub says Gemini accesses Workspace content “that you have permission to access,” and that Workspace “does not use customer data for training models without customer’s prior permission or instruction.” Each person’s conversations are visible only to that person.
Administrators set retention. Google lists 90 days to indefinite for prompts and responses in the Workspace apps, and up to 36 months in the Gemini app. When Gemini app history is off, new chats are still kept for up to 72 hours so Google can provide the service.
How Google charges: Gemini features come with Google Workspace business plans, which Google prices per user per month. The features included depend on the plan.
Self-hosted: Open WebUI and LibreChat
A self-hosted workspace is software you install on your own server, so the chat history and uploaded files stay in your own database. Open WebUI describes itself as “a self-hosted AI platform” built to run entirely offline, with support for Ollama and OpenAI-compatible APIs. Ollama is a tool for running open models. Its feature list includes roles, user groups, per-model access, sign-in through SSO, OIDC or LDAP, and SCIM. LibreChat calls itself “The Open-Source AI Platform” and lists models from Anthropic, AWS, OpenAI, Azure and others, with sign-in through OAuth, SAML and LDAP.
What an outside provider sees depends on the model you connect. If the model runs on the same server, no outside provider sees the prompts. If you connect a hosted model through its API, that provider’s API terms apply to each request, as private AI for business explains. Someone on your side or at your vendor installs updates, backs up the database and keeps the server running. Local LLM covers the hardware for a model on your own server.
What it costs: the server and its upkeep, plus the model: your own hardware, or a hosted model’s API usage.
AI workspace options side by side
The table sums up the entries above, from each vendor’s own pages on September 28, 2026.
| Workspace | Sign-in | Company data it reads | Training on your data | What it keeps | How it charges |
|---|---|---|---|---|---|
| ChatGPT Business or Enterprise | SSO, included with Business | Connected apps, within each user’s existing permissions | Not by default | Admins set retention; deleted chats removed within 30 days, with legal exceptions | Business per user per month |
| Claude Team or Enterprise | SSO, with SCIM on Enterprise | Connectors such as Google Drive, Microsoft 365 and Slack | Not by default; rated chats kept up to 5 years | Chats until deleted, then removed within 30 days; custom retention on Enterprise | Team per seat; Enterprise seat fee plus usage at API rates |
| Microsoft 365 Copilot | Microsoft 365 work account | Microsoft 365 data the user can view | Not used to train foundation models | Prompts and responses, with retention set in Purview | Add-on per user per month |
| Gemini in Google Workspace | Google Workspace account | Workspace content the user can access | Not without your permission | 90 days to indefinite in Workspace apps, up to 36 months in the Gemini app, as admins set | Part of Workspace plans, per user per month |
| Open WebUI or LibreChat | Your identity provider through SSO, OIDC or LDAP | What you connect and upload | No outside provider sees data when the model runs on your server | Whatever you configure, in your own database | Your server, upkeep and model |
Choose a workspace your records can live with
Tell Derik which email and file systems your team uses and which records must stay in Canada. He will tell you which workspace fits and what it takes to set up.
Start a conversationHow to choose an AI workspace
- Start from your email and files. Copilot sits closest to a company on Microsoft 365, and Gemini to a company on Google Workspace, because each reads its own suite’s data with the permissions already in place. ChatGPT and Claude reach the same sources through connectors.
- Fix permissions before you connect anything. Every option here shows each person what that person can already open. Microsoft says it is important to use the permission models in services such as SharePoint so the right people have the right access. If a folder is shared with everyone, the workspace can show its contents to everyone.
- Set retention and feedback before rollout. Decide how long chats are kept, who can delete them and whether staff may send rated chats to the vendor, then set each control on day one.
- Decide which models staff may use. The model decides where prompts are processed. Private AI for business and sovereign AI cover the Canadian questions.
- Weigh the upkeep of self-hosting. Open WebUI or LibreChat keeps history on your server, and your team or vendor takes on updates, backups and uptime.
- Train people and write the rules. Staff need to know what they may put into the workspace and what stays out. AI training covers hands-on sessions, and AI governance covers the policy and the law. AI security covers the threats a workspace adds.
Ask each vendor, in writing, which data the workspace can read, how long it keeps each conversation, whether anything your staff type can be used for training, including feedback, and where the model processes prompts. The answers above came from the vendors’ own pages, and a contract can change them.
For a wider comparison of business assistants on how they charge, where data is stored and model choice, see ChatGPT alternatives for business in Canada.
Where a workspace stops
A workspace answers questions and drafts text for the person using it. Work that runs by itself or writes into your ERP, such as entering orders from email, needs approvals, logs and a connection to the system of record. AI agents for business covers those jobs. MCP servers are one way to connect an assistant to your systems, and RAG is how an assistant answers from your documents with a citation for each answer.
Questions people ask
What is an AI workspace?
Does ChatGPT Business train on our data?
Which AI workspace fits a company that runs on Microsoft 365?
Can we host our own AI workspace?
How long do AI workspaces keep our chats?
Can an AI workspace show a person files they are not allowed to open?
How ThriveAI helps
ThriveAI is an AI engineering company in Ottawa. It builds private AI systems on the client’s own data for manufacturers and distributors in Ontario and Quebec. Derik Lawlis, the founder, leads every project and stays close to the build, and ThriveAI runs hands-on AI training for teams on their own documents.
The platform is designed to keep each client’s data on its own server in Canada. You choose the model: one that runs on that server, or a hosted model under a written zero data retention agreement, under which the provider keeps no copy of a request or its answer. A hosted model may process requests outside Canada, so the contract names the model. A named person at your company approves every action before anything is sent or saved. About ThriveAI covers the company.