Scope and evidence
Self-serve ABI and OpenAI account connections
Status: local prototype and product proposal, 5 October 2026.
The product
The GPT Agency’s specialist capability remains persona development and Conversation Engine Management. Self-serve creation widens access to that capability. Account connections make CEM a potential operating workspace for a brand’s paid distribution and personality, with separate permissions and measurement for each.
The visitor journey: meet Arthur and Pre; understand Digital DNA and the Gauntlet; prepare a brand brief; try a reviewed hosted character when generation is available; explore account reporting; discuss production, integration and management. A consultation should be an invitation, not a hidden condition of account access.
What exists now
- /create: a browser-local design brief using the eight reusable compounds, brand purpose and text/Markdown materials. Nothing is sent to a model or stored. It does not interpret source material or create a conversational agent. No persona download is offered.
- /connect/openai: account access instructions and a read-only report view backed by a server-side OPENAI_ADS_API_KEY. The key is separate from the model-project key used for voice. An account and Advertiser API access are required.
- /api/openai-ads: loopback-only, same-origin report endpoint. Fixed upstream GET endpoints; no account edits, arbitrary upstream URLs, raw provider errors or persistent reporting storage.
- Current reporting is capped at the first 100 campaign rows. Pagination uncertainty is displayed as partial; missing fields stay unavailable. Spend is in the account’s currency. Ad clicks are not persona handoffs or incremental sales.
- /business-manager/personas: existing illustrative CEM controls. Its performance figures are demo data; connection does not replace those figures with claimed live persona data.
This is not a public multi-client account service. The local operator can access the configured account. Reports remain in page memory until cleared or the page closes; normal API-provider processing still occurs. No visitor lead collection or consultation booking is live.
Account access and one-way data
OpenAI identity, model-project access and Ads account access are distinct. The documented Ads integration uses an account-scoped Advertiser API key. A ChatGPT login alone is not a reporting authorisation. The connector never substitutes the voice API key.
The initial connection reads account metadata and selected campaign reporting fields. It does not change campaigns, upload documents or transmit persona data into the Ads account. Editing supported campaign settings would require a separate, explicit write mode and approvals. The Ads API does not establish a persona-import format or a Sponsored Agent lifecycle contract.
CEM can derive additional insights by combining authorised advertising fields with its own measured conversation events. It cannot expose information OpenAI does not provide, obtain private ChatGPT conversations through an Ads key or attribute causal sales lift from clicks alone.
Public launch requirements
Before inviting external clients to connect: authenticate the client; bind an account to its tenant; encrypt account secrets in a server-side secret manager; isolate reports and uploaded documents; enforce authorised roles; provide revocation and deletion; publish precise processing, retention and subprocessor information; test cross-client isolation. Account permissions and API eligibility must be checked.
Operational audit records should contain connection time, tenant identity, permission scope, errors and revocation, not keys or unnecessary report content. Account reporting remains client data. Optional contact consent can record name, contact details and a request to discuss the service; it must not grant unrestricted prospecting access to advertising data. No shared ecosystem learning from client material without separate agreement.
Hosted persona creation
Secure document ingestion and a guided DNA questionnaire produce an evidence-linked draft. Separate established facts, authored character choices and unresolved assumptions. Let the visitor test a hosted draft with usage limits. Run the four Gauntlet failure models and require human approval before production. A client's own model account can fund inference through an isolated server-side integration, subject to provider permissions; never ship its secret in browser code.
Downloads are excluded from the exploratory hosted journey. Paid production agreements should still define ownership, portability and exit rights explicitly. Restricting a demo download does not justify undisclosed lock-in.
Open standard versus hosted product
An open-source SDK is feasible but not yet released. Candidate scope: Digital DNA schema and validation; prompt/adaptor interfaces; Gauntlet test-case format and evaluation hooks; event vocabulary; examples that run in the developer’s own model account. Publish a versioned package, documentation and licence only after scope and IP review.
Open-source software lets developers build and export their own entities. It cannot enforce the hosted service’s no-download policy. Differentiation therefore comes from research quality, character craft, proprietary evaluation datasets, CEM workflow, reliable operations and supported integrations. Keep client data and the managed service separate from the public SDK.
Commercial implications
Retain build, deployment and management charges. The variable persona CPC is the attributable outbound handoff click; platform entry clicks remain a distinct platform charge. Voice/provider costs require an explicit client-funded arrangement. A CEM subscription and account-integration fee are possible additions, not agreed prices. Do not promise a platform revenue share, accreditation or guaranteed distribution.
Delivery sequence
First validate the local read-only connector against an authorised Ads account. Then create secure client tenancy, secret handling and optional consultation capture. Add evidence-backed hosted draft generation with budget limits and Gauntlet review. Combine measured persona events with Ads reporting while preserving provenance. Introduce approved campaign writes only when requested. Publish the SDK after the schema and adapter contract have stabilised.
Plugin distribution
A GPT Agency plugin is a proposed distribution channel for persona creation and management. OpenAI’s current plugin architecture supports workflow skills, an MCP server and optional UI. We have no packaged GPT Agency SKILL.md workflows or published plugin today; existing character-coaching skills are persona configuration, not installable workflow skills.
A first plugin could offer five workflows: research a brand; shape its Digital DNA; author a grounded character; run the Gauntlet; review performance and propose CEM changes. Each should use the same schema and hosted workflow as the website. Server-backed tools would authenticate the client and expose narrowly scoped draft, test and review operations. Production release still requires human approval.
For the hosted model, return persona references and test results rather than a downloadable full configuration. Instructions alone cannot enforce secrecy or billing. Hosted client data, account permissions, usage metering and lifecycle operations belong in the service; an open-source SDK remains a separate choice permitting independent builds.
PixVerse provides a relevant commercial pattern: its CLI uses website subscription credits, while separate developer API subscriptions and enterprise plans exist. Our proposed free plugin would lead into paid hosted creation/evaluation usage, CEM subscriptions and specialist build/deployment/management services. Outbound-handoff CPC remains contingent on a supported, attributable deployment; installing the plugin does not create media distribution or revenue share.
Sources reviewed 5 October 2026: OpenAI plugin architecture, PixVerse CLI, PixVerse pricing, PixVerse API plans.
Primary sources
- Ads API overview: account access, supported resources and server-side keys.
- Authentication: account-scoped bearer key and base URL.
- API partner setup: client-account integration and gated capabilities.
- Reporting: reporting dates, currency, ratios and attribution distinctions.
- Insights reference: campaign fields and pagination.
Reviewed 5 October 2026. Access and reporting shape must be verified with a real account before describing this integration as validated.