The dashboard is not the product. The approved action is.

Your ops lead asks ChatGPT Work why renewals slipped in the top twenty accounts. Ten minutes later she is looking at an interactive dashboard pulled from Snowflake and Datadog. Five minutes after that the same chat recommends who to loop in, drafts the Slack update, and waits for her to approve the send.

That is not "ChatGPT that does SQL." That is an admin-controlled plugin surface where the insight path and the action path share one thread.

OpenAI launched the Data agent inside ChatGPT Work on September 10, 2026. Same week, Klaviyo told K:BOS that more than 260 MCP tools and more than 490 APIs are reachable from Claude, ChatGPT, or a custom agent so work can leave the vendor UI. Treat those as one story: the chat that finds the number is becoming the chat that ships the follow-up. Operators who keep buying "natural language analytics" will miss the control plane that actually decides what happens next.

What changed on September 10

OpenAI's announcement is blunt about scope. The Data agent connects to approved warehouse and observability sources including Amazon Redshift, Datadog, Google BigQuery, ClickHouse, Databricks, MongoDB, and Snowflake. It can pull files from Google Drive and SharePoint into the same investigation. It reads business terms from semantic layers and trusted sources such as Databricks Genie Ontology, dbt, GitHub, Snowflake Horizon, and existing BI dashboards.

It does not stop at a chart dump. It builds interactive dashboards you can edit, share, and refresh. It can also build and interact with dashboards in Omni, Oracle BI, Power BI, Sigma, Tableau, and ThoughtSpot. Then it recommends next steps, identifies who needs to be involved, shares findings through Slack or email, and carries out actions you approve through connected tools.

That last sentence is the product. The dashboard is the receipt.

Enterprise administrators choose which data connections are available and which roles can use them. Queries enforce the connected account's existing permissions, including table, row, and column restrictions. You find the agent listed as Data in the Plugins directory in ChatGPT Work. Admins enable Data plus the relevant data-source plugins (Databricks, Snowflake, and peers), then people start with @Data prompts.

OpenAI attributes heavy internal use to its own teams: nearly all of the product organization and over two-thirds of GTM, per OpenAI's own claims on the launch page. Alpha customers named on the page include NTT DATA, Thermo Fisher Scientific, ServiceTitan, Zipline, Empower, Piston, Doeren Mayhew, CookUnity, Turing, micro1, and Unit8. Those quotes are vendor-supplied. Use them as adoption signal, not as your ROI model.

Secondary coverage the same day (Crypto Briefing) frames the agent as plain-English orchestration over warehouses without a forced migration. Fine as a headline. Incomplete as an operating model. The interesting part is not that SQL got a chat wrapper. The interesting part is that insight and approved action now live in one permissioned conversation.

The mechanism: plugins, rights, and one chat

Strip the marketing and the architecture is three layers.

Person reviewing a glass wall of abstract dashboard color blocks while holding a tablet with abstract shapes.

First, Data is a plugin, not a sidebar toy. Workspace settings decide whether it exists for your tenant. Data-source plugins decide which systems it can touch. That is an admin surface before it is a user delight.

Second, queries inherit the connected account's permissions. Row and column restrictions still apply. That sounds comforting until you remember most enterprises have over-permissioned service accounts and stale role maps. The agent does not invent a new security model. It inherits yours, including your mistakes.

Third, the same conversation that builds the dashboard can share findings and execute approved actions through connected tools. Insight and action share context, history, and the human who clicked approve. That collapses the classic handoff where an analyst emails a screenshot and a PM opens three other apps to do something about it.

Klaviyo's September 9 headless move is the same shape from the CRM side. Business Wire and Klaviyo's own K:BOS framing put more than 260 MCP tools and more than 490 APIs in reach of agents working outside the Klaviyo UI. The vendor story says agents can read, write, and go live. Klaviyo Community's September 9 operator note is more careful: remote MCP needs Owner, Admin, or Manager roles; Composer can prepare supported edits, but you review before anything goes live; campaign creation is in play with human QA, while end-to-end schedule and send is still rolling. Start read-only. Scope tools. Do not confuse "headless" with "every agent can do everything."

Agile Brand Guide's September 10 roundup is useful for framing that control point shift: when a person sits in a UI, screens enforce rules; when an agent hits MCP or APIs, the credential scope is the gate. Its unsubscribe cost scenario is explicitly illustrative math, not a Klaviyo outcome. Keep it that way if you reuse the shape.

What operators get wrong

Mistake one: buying the demo as "ask questions in English." Every vendor can demo a clean question and a pretty chart. The evaluation question is whether admins can constrain connections and roles, whether actions require explicit approval, and whether you can audit who approved what when the Slack blast goes sideways.

Mistake two: treating semantic layers as optional polish. OpenAI leans on Genie, dbt, Snowflake Horizon, and BI semantics because free-form warehouse access without shared definitions just scales confusion. If your metric dictionary is a Notion page nobody owns, @Data will produce confident answers that disagree with Finance by Thursday.

Mistake three: equating "queries enforce existing permissions" with "we are safe." Existing permissions are often the problem. A Data agent that respects a god-mode warehouse role is a polite exfiltration assistant. Inventory which identities the plugins will use before you celebrate self-serve analytics.

Mistake four: confusing dashboard volume with operating leverage. OpenAI's customer quotes celebrate non-engineers building and refreshing their own views. That is real. It is also how you get seventeen "source of truth" boards for the same pipeline. Without ownership rules, self-serve becomes self-fracture.

Mistake five on the Klaviyo flank: reading "go live" as "no humans in the loop." Community guidance still centers review before publish for Composer edits, and send automation is not fully settled across accounts. Wire write scopes like you are handing a junior marketer production keys, because you are.

Mistake six: separating the warehouse agent from the CRM agent in your head. Same week, OpenAI puts insight-plus-action in ChatGPT Work and Klaviyo opens the CRM to outside agents. Your risk register should treat them as one class of problem: conversational surfaces that can both diagnose and act.

Second-order effects

Analytics headcount does not disappear. The scarce skill moves from writing SQL to certifying definitions, plugin scopes, and approval rituals. The data team that OpenAI describes as enabling internal use did the boring work: shared definitions, access rules, safeguards. Copy that org chart before you copy the demo.

Three colleagues around a dark conference table with three screens showing abstract color panels under soft overhead light.

Procurement language has to change. "Natural language BI" is not an acceptance criterion. You want named connectors, role maps, action allowlists, retention of conversation artifacts that triggered sends, and a kill switch for plugins. If the SOW cannot answer who can approve a Slack share from a @Data thread, you bought a toy.

Liability gets sharper. When a dashboard is wrong, you argue about a chart. When an approved action from the same chat pages the wrong exec list or drafts the wrong customer email, you argue about intent, approval UX, and whether "approve" meant the analysis, the audience, or both. Design the approve step so it shows the blast radius, not just a green button.

Vendor lock-in changes shape. Once leadership readouts, dashboard edits, and action history live in ChatGPT Work plugins, leaving means rebuilding the operating layer, not just exporting CSVs. Same for Klaviyo MCP skills and connectors. Export and portability belong in the contract now, while you still have leverage.

Competitive copycats will sell "chat to dashboard" for the next year. The durable differentiator is whether insight and action share governance. A BI chat that cannot act is incomplete. An action agent that cannot prove the metric definition behind the trigger is reckless. The winners will sell both under one admin pane.

What to do this week

If you run RevOps, Marketing Ops, or Data:

  • Install nothing to production on day one. Stand up Data (or your CRM MCP) in a sandbox workspace with a read-only warehouse role and a disposable Slack channel.
  • Write the metric dictionary the agent will inherit. Pick five KPIs leadership already fights about. Freeze definitions before the first @Data prompt.
  • Draft an action allowlist: which shares are allowed (Slack channel X, email group Y), which are forbidden (customer-facing sends, production CRM writes), and which need a second human.
  • Inventory every existing service account a plugin might use. Rotate anything that can SELECT * across PII and also post to company-wide Slack.
  • For Klaviyo: enable remote MCP only for Owner/Admin/Manager as documented, start with read-only=true, and keep campaign send off the agent token until you have a reviewed draft workflow that matches Community guidance.

If you buy software for the stack:

  • Ask OpenAI (and peers) to show the admin path for disabling action tools while leaving analysis on. If they cannot demo deny-by-default actions, price the risk.
  • Ask Klaviyo which MCP tools can create versus schedule versus send in your account today, not in the keynote. Get it in writing.
  • Add conversation-to-action audit retention to security review. Screenshots of dashboards are not an audit trail.

If you lead a GTM org that will love this immediately:

  • Pick one recurring leadership readout and rebuild it once with @Data against governed sources. Time the human review, not only the generation.
  • Ban "the agent said so" as a decision justification. Require the metric definition and the source connection in the same note as the chart.

Sharp close

September 10 did not make warehouses conversational. That pitch is years old. What OpenAI shipped in ChatGPT Work is a permissioned plugin that lets the same chat that explains the number propose and execute the next move you approve.

Klaviyo's headless MCP surface, announced a day earlier, is the CRM twin of that idea: the interface is optional; the credential and the approval are not.

Stop shopping for prettier dashboards. Start shopping for who can approve the action that leaves the chat.

The dashboard is evidence. The approved action is the product.