ThoughtSpot’s two ChatGPT Work plugins split data analysis from analytics administration
Spotter answers governed questions; SpotterCode can configure live instances. Enterprises should treat them as different risk classes, not one integration.
ThoughtSpot has put two distinct plugins into the ChatGPT Work Plugin Directory, and the important deployment detail is not that both run in chat. It is that they have materially different powers. Spotter is the analytics-facing plugin; SpotterCode can build against and act on a live ThoughtSpot instance. That makes separate approval, identity and audit policies the safe default. ThoughtSpot
One plugin answers; the other changes the system
ThoughtSpot says Spotter lets users ask natural-language questions, investigate metric drivers, forecast trends and follow answers back through search logic to governed definitions. Responses are grounded in ThoughtSpot’s semantic and context layer, while row-, column- and attribute-level controls continue to apply. ThoughtSpot
SpotterCode has a broader operational role. The company says it can generate embedded Spotter and Liveboard components, configure the Visual Embed SDK and authentication, adjust CORS and security settings, and call REST APIs for tasks including tenant creation and user management. Those are administrative actions, not just analytical reads. ThoughtSpot
The practical implication is a two-tier permission model. A business user who needs governed answers should not automatically inherit the identity or scopes used by a developer building embedded analytics. Conversely, a build agent should not run under a shared service account that obscures which person requested a tenant, user or configuration change. ThoughtSpot says connectors are permissioned individually and AI-initiated actions appear in audit logs available through its API or a SIEM; administrators can use those controls to keep the tiers distinct. ThoughtSpot
Four checks before rollout
- Register Spotter and SpotterCode separately. Give Spotter read-oriented access to approved models and analytics objects. Reserve SpotterCode for a smaller developer or platform group with only the REST actions its workflow requires. ThoughtSpot
- Preserve per-user identity. ThoughtSpot says its existing identity provider, SSO, SAML or OIDC federation and per-user enforcement remain in the path. Test that the user represented in ChatGPT maps to the same ThoughtSpot permissions seen in the native product. ThoughtSpot
- Alert on administrative actions. Stream AI-initiated audit events to the SIEM and flag tenant creation, user changes, authentication edits and security-setting changes separately from ordinary questions. ThoughtSpot
- Verify the data-handling claim. ThoughtSpot says the integration copies no data out and does not persist prompts. Security teams should confirm that behavior for their configured connectors, retention settings and downstream ChatGPT Work controls before approving sensitive datasets. ThoughtSpot
The launch expands ChatGPT Work from a place to consume governed analysis into a surface that can also build and administer analytics applications. The useful boundary is therefore not “AI versus no AI.” It is read and reason versus configure and act—and the access model should make that boundary visible. ThoughtSpot
sources
- Put Your Data to Work with ThoughtSpot in ChatGPT Workwww.thoughtspot.com
comments · 0