# ChatGPT for Word deployment checklist

**Package version:** 1.0.0  
**Source refresh:** 2026-09-21  
**Start with:** `Readiness gates`

This package is a blank evidence template for a real managed-tenant pilot. Every seeded row begins at `Not started`. Blank observation, evidence, decision and approval fields require a real tenant test or an authorized owner decision; the expected-result text is not evidence that a check passed.

## Three control layers

1. **Microsoft 365 deployment** controls whether the OpenAI-published add-in is assigned and appears in a supported Word client.
2. **ChatGPT workspace access** controls whether the pilot user can sign in, select the intended workspace and use Word under that workspace's settings.
3. **Task context** controls what the sidebar can use: the open document, deliberately pasted text, or a separately authorized connected source. An unopened local file is not assumed accessible.

## Sheet instructions

- **Readiness gates:** complete this first. Assign owners and collect evidence for the tenant, deployment route, Word workspace setting, supported client, data controls and observation window.
- **Context permissions:** approve each context route separately. A connected-source row must cover ChatGPT workspace availability, provider/source permission and user authorization where required.
- **Pilot tests:** run the rows in order with a harmless, reproducible fixture. Preserve a clean copy and record only evidence references, never document contents or credentials.
- **Rollout sign-off:** complete the separate owner decisions after the readiness and pilot evidence is available. Do not choose `Expand` while a required gate or critical required test is unresolved or a high/critical issue remains open.

Each worksheet freezes the header row and first column, enables table filters, and uses the exact same cell values as its matching CSV. The CSVs are the canonical portable records.

## Controlled values

- `status`: `Not started`, `In progress`, `Blocked`, `Pass`, `Fail`, or `Not applicable`.
- `required`: `Yes` or `No`.
- `criticality`: `Critical`, `High`, `Medium`, or `Low`.
- `user_authorization_required`: `Yes`, `No`, or `Unknown`.
- `decision`: blank initially, then `Hold`, `Pilot only`, `Expand`, `Rollback`, or `Not applicable`.
- Dates use `YYYY-MM-DD`. Observation and decision timestamps use RFC 3339 with a timezone, for example `2026-10-02T14:30:00-04:00`.
- Related row IDs and source claim IDs use semicolons with no spaces.

## Evidence and completion rules

A `Pass` needs the assigned owner, an observed result, an evidence reference and a timestamp. A `Fail` or `Blocked` status needs both a blocker and a next action. `Not applicable` needs a reason in `notes`; required controls need independent approval before that exception can be used.

Evidence references may be ticket IDs, approved internal paths or HTTPS URLs. They must not use `file://`, traverse above the approved workspace or contain embedded credentials. Store the reference, not the evidence payload. Connected-source evidence must cover workspace availability, provider/source permission and any required user authorization.

Microsoft documents possible upper bounds of **24 hours** for a new deployment or removal and **72 hours** for an update or on/off change. These are not an SLA. Record the change type and the relevant observation point before calling deployment a failure.

## No secrets or sensitive content

Do not enter passwords, access tokens, OAuth codes, cookies, private keys, authorization headers, customer data, document bodies or sensitive source content in the workbook or CSVs. A no-secrets scan can catch common patterns but cannot certify that human-entered data is safe. Use a bounded, non-sensitive pilot fixture and point to an approved evidence location.

## Source review rule

Review the sources again whenever OpenAI or Microsoft changes the add-in, manifest, permissions, rollout defaults or deployment documentation. The October 1, 2026 Word-access default described in the OpenAI guide must be rechecked on or after that date before this package is sealed or republished.

Primary sources refreshed on 2026-09-21:

- [OpenAI: ChatGPT for Word](https://help.openai.com/en/articles/20001526-chatgpt-for-word)
- [OpenAI: Word product page](https://chatgpt.com/apps/word/)
- [OpenAI: Admin controls, security, and compliance in apps and connectors](https://help.openai.com/en/articles/11509118)
- [Microsoft Marketplace: ChatGPT for Excel, Word, PowerPoint](https://marketplace.microsoft.com/en-us/product/office/WA200010215)
- [Microsoft: Deploy add-ins in the admin center](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-deployment-of-add-ins?view=o365-worldwide)
- [Microsoft: Centralized Deployment requirements](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/centralized-deployment-of-add-ins?view=o365-worldwide)
- [Microsoft: Centralized Deployment FAQ](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/centralized-deployment-faq?view=o365-worldwide)
