The OpenAI integration enables Compliance, Security, and IT teams to automate user access reviews by syncing user data directly from OpenAI into Drata. This reduces manual effort and ensures continuous compliance with access control policies.
Key Capabilities
User data synchronization: Automatically imports user access data from OpenAI.
Access review automation: Streamlines evidence collection for user access reviews.
Error reduction: Minimizes manual data entry errors during compliance audits.
Prerequisites & Data Access
Must have Owner privileges within your OpenAI organization.
Must have access to your organization’s Admin Keys and Project ID.
If your organization uses a Web Application Firewall (WAF), ensure Drata’s IP addresses are allowlist.
Permissions & Data Table
Permission/Scope | Why It’s Needed | Data Accessed (Read Only) |
Admin Key | Authenticates Drata’s access to the OpenAI organization | User access and organization metadata |
Project ID | Identifies which OpenAI project to connect to Drata | Project-level user and access data |
Step-by-Step Setup
Step 1: Copy the Admin Key
Log in to your OpenAI Account.
From the organization dropdown, select Organization overview.
Navigate to the Admin Keys page.
Click + Create new Admin key in the top-right corner.
Enter a Key Name and select Create admin key.
Copy the Admin Key and store it securely. It will be needed for the Drata connection.
Step 2: Copy the Project ID
Navigate to the Projects page in OpenAI.
Locate the project you wish to connect.
Copy the Project ID.
Complete the Connection
In Drata’s Connections page, enter the following information:
Drata Field | OpenAI Value |
Admin Key | The Admin Key generated in OpenAI |
Project ID | The Project ID from the OpenAI Projects page |
For steps on accessing and using the Connections page in Drata, refer to The Connections Page in Drata.
Important Notes
The integration connects one OpenAI project per Drata connection.
Ensure your Admin Key is stored securely and rotated periodically.
If your organization uses a WAF, allowlist Drata’s IP addresses to prevent connection errors.
The integration is read-only and follows the principle of least privilege, ensuring no data modification occurs within your OpenAI environment.