One connector. Your existing rules.一个连接器。沿用现有规则。
ChatGPT connects to outside systems through an open standard called the Model Context Protocol (MCP). We add an MCP connector to the portal itself. ChatGPT does not receive a copy of the portal's data. It asks the portal for what it needs, one request at a time, and the portal decides whether to answer.ChatGPT 通过一项名为模型上下文协议(MCP)的开放标准连接外部系统。我们会在平台内加入一个 MCP 连接器。ChatGPT 不会获得平台数据的副本,而是每次按需向平台发出请求,由平台决定是否回应。
Each person adds the portal connector once, in their own ChatGPT Pro settings on the web. The portal, not ChatGPT, decides who may use it.每位员工在自己网页版 ChatGPT Pro 的设置中添加一次平台连接器。谁可以使用由平台决定,而不是由 ChatGPT 决定。
Each person links their own account, on the portal's own sign-in page, with their password and two-factor code. ChatGPT never sees the password.每位员工在平台自己的登录页面,用密码和双重验证码关联自己的账户。ChatGPT 永远看不到密码。
“What is our AML refresh procedure?” “Remind me on Friday to chase the Mauritius licence renewal.”“我们的反洗钱(AML)定期复核流程是什么?” “周五提醒我跟进毛里求斯牌照续期。”
ChatGPT proposes a change and the portal shows it on a card in the conversation. Nothing is saved until the person presses Confirm on that card.ChatGPT 提出更改后,平台会在对话中以卡片形式显示。员工在卡片上按下确认之前,不会保存任何内容。
Everyday work. Within each person's access.日常工作。不超出每个人的权限。
ChatGPT can only do what the connector offers. Each action below is built, tested and permission-checked individually. It is not a general key to the portal. A member who sees three CRM records in the portal sees the same three through ChatGPT. The table shows the most any role can be given; §03 explains how each role is set.ChatGPT 只能执行连接器提供的操作。下列每项操作都逐一开发、测试并进行权限检查,不是进入平台的万能钥匙。在平台上只能看到三条 CRM 记录的成员,通过 ChatGPT 看到的也是同样的三条。本表列出的是任何角色可获得的最高权限;各角色如何设定见 §03。
| Area范围 | What a staff member can ask for员工可以要求的操作 | How方式 | Phase阶段 |
|---|---|---|---|
| Knowledge Hub知识库 | Search the Knowledge Hub, read an entry, and ask questions answered from JY Global's own material, with the entry named as the source. Propose a new entry, or a change to an existing one, saved only when the person confirms it in the chat. Every change is kept as a new version that an owner can restore.搜索知识库、阅读条目,并根据 JY Global 自己的资料回答问题,同时注明出处条目。提出新增条目或修改现有条目,经本人在对话中确认后才保存。每次更改都保存为新版本,所有者可以恢复。 | Read读取 Confirm in chat在对话中确认 | Phase 1第一阶段 |
| Reminders提醒 | Set, list, move, complete and cancel reminders, including a reminder for a colleague. Each change is confirmed in the chat.设置、列出、改期、完成和取消提醒,包括为同事设置提醒。每项更改都在对话中确认。 | Read & write读写 | Phase 1第一阶段 |
| To-do list待办事项 | List to-dos, and propose a new one, assigned to a colleague if required.列出待办事项,并提出新的待办事项,如有需要可指派给同事。 | Read & write读写 | Phase 1第一阶段 |
| CRM: look-upCRM:查询 | Find a client or supplier, read its details, contacts and key dates, and list the documents held on file (other than restricted documents).查找客户或供应商,查看其详细资料、联系人和重要日期,并列出存档文件(受限文件除外)。 | Read读取 | Phase 1第一阶段 |
| CRM: changesCRM:更改 | Propose a new record, or a change to a field or contact. Nothing is saved until the person confirms it in the chat.提出新增记录,或修改字段或联系人。经本人在对话中确认前,不会保存任何内容。 | Confirm in chat在对话中确认 | Phase 2第二阶段 |
| Application forms申请表 | Check the progress of a form issued to a client, and prepare a draft form. Issuing a form to a client remains a step taken in the portal.查看已发给客户的申请表进度,并准备申请表草稿。向客户发出申请表仍须在平台内操作。 | Confirm in chat在对话中确认 | Phase 2第二阶段 |
| Delete and archive删除和归档 | Ask for a reminder, to-do, CRM record or contact to be deleted or archived. Only for roles given delete access (by default, owners), and always confirmed in the chat, on a card naming exactly what will be removed.要求删除或归档提醒、待办事项、CRM 记录或联系人。仅限获得删除权限的角色(默认为所有者),并且一律在对话中确认,卡片会明确列出将被删除的内容。 | Confirm in chat在对话中确认 | Phase 2第二阶段 |
Each role sets its own reach. Never beyond the portal.每个角色各有范围。不超出平台权限。
What a role may do through ChatGPT is set separately from what it may do in the portal, in the existing Roles screen. For each area an owner chooses one of four levels. The level can narrow a role's access, never widen it: a member who cannot edit a client record in the portal cannot edit it through ChatGPT, whatever this setting says.角色通过 ChatGPT 能做什么,与其在平台内的权限分开设定,设定位置在现有的“角色”页面。所有者可为每个范围选择四个级别之一。这个级别只能收窄角色的权限,不能扩大:在平台内不能编辑客户记录的成员,无论此处如何设定,通过 ChatGPT 也不能编辑。
ChatGPT is not offered this area at all. The starting level for every role.不向 ChatGPT 提供此范围。所有角色的初始级别。
Search, look up and ask questions. Nothing can be changed.搜索、查询和提问,不能更改任何内容。
Also create and change, each change confirmed by the person before it is saved.另可新增和修改,每项更改都须本人确认后才保存。
Also delete and archive, each one confirmed in the chat.另可删除和归档,每一项都在对话中确认。
| Area范围 | Owner所有者 | Member成员 | Highest level offered可提供的最高级别 |
|---|---|---|---|
| Knowledge Hub知识库 | Read & write读写 | Read读取 | Read & write读写 |
| Reminders and to-dos提醒和待办事项 | Read, write & delete读写及删除 | Read读取 | Read, write & delete读写及删除 |
| CRM recordsCRM 记录 | Read, write & delete读写及删除 | Read读取 | Read, write & delete读写及删除 |
| Application forms申请表 | Read & write读写 | Read读取 | Read & write读写 |
Suggested starting levels, for JY Global to confirm (§07, question 4). Any other role is set the same way, area by area. Write access to reminders, to-dos and the Knowledge Hub arrives in Phase 1; write and delete access to CRM records and forms arrives in Phase 2, when those actions are built. Any level above Read depends on ChatGPT Pro allowing changes through a connector, which we confirm by trial before work begins (§07, question 1).以上为建议的初始级别,由 JY Global 确认(§07,问题 4)。其他角色以同样方式逐项设定。提醒、待办事项和知识库的写入权限在第一阶段提供;CRM 记录和申请表的写入及删除权限在第二阶段提供,届时相关操作才会开发。任何高于“读取”的级别,都取决于 ChatGPT Pro 是否允许通过连接器进行更改,我们会在开工前通过试用确认(§07,问题 1)。
Both the portal role and its ChatGPT level are checked each time ChatGPT asks. Lowering a role takes effect at once, without anyone re-linking their account.每当 ChatGPT 发出请求,都会同时核查平台角色及其 ChatGPT 级别。降低角色权限即时生效,无需任何人重新关联账户。
A person whose role can change or delete through ChatGPT must use a two-factor code to link it. An owner's ChatGPT account can change client records, so losing it would matter.角色可通过 ChatGPT 更改或删除内容的人员,必须使用双重验证码进行关联。所有者的 ChatGPT 账户可以更改客户记录,一旦遗失,后果严重。
An owner has every permission in the portal, but not through ChatGPT. The security controls in §04 are not offered to any role, owners included.所有者在平台内拥有全部权限,但通过 ChatGPT 则不然。§04 中的安全控制不向任何角色提供,所有者也不例外。
Security controls are not offered.安全控制不对外提供。
A chat can be misread, and a ChatGPT account can be lost. Anything that decides who may enter the portal, or what they may see, therefore stays in the portal. These are excluded by design, not deferred.对话可能被误解,ChatGPT 账户也可能遗失。因此,凡是决定谁可以进入平台、可以看到什么的功能,都保留在平台内。这些是刻意排除的设计,并非延后处理。
Adding or disabling users, passwords, roles and permissions.新增或停用用户、密码、角色和权限。
Two-factor authentication and each user's IP whitelist.双重验证,以及每位用户的 IP 白名单。
CDD and other restricted client documents. Their names and contents are not offered to ChatGPT at all.CDD(客户尽职调查)及其他受限的客户文件。其名称和内容完全不向 ChatGPT 提供。
Portal settings, AI and email configuration, and stored API keys.平台设置、AI 和电邮配置,以及已存储的 API 密钥。
Read only in the portal, by owners. ChatGPT activity is written to it, never read from it.只能由所有者在平台内查看。ChatGPT 的操作会写入日志,但永远不能从中读取。
External customer accounts cannot use the connector. It is for JY Global staff only.外部客户账户不能使用连接器,连接器仅供 JY Global 员工使用。
Bulk changes are also left out of both phases. Deleting or archiving a single item is offered in Phase 2, only to roles given delete access, and each one is confirmed in the chat (§03).批量更改在两个阶段中均不包含。删除或归档单个项目在第二阶段提供,仅限获得删除权限的角色,并且每一项都在对话中确认(§03)。
Six controls, included in Phase 1.六项控制,第一阶段即包含。
These are part of the build, not options. They carry over the portal's existing controls to a new way in.这些是开发内容的一部分,而非可选项。它们将平台现有的控制延伸到新的使用途径。
No shared account and no master key. Every request carries the person's own role, CRM groups and permissions, checked by the same code the portal uses.没有共享账户,也没有万能密钥。每个请求都带有本人的角色、CRM 群组和权限,并由平台所用的同一套代码进行核查。
Every change arrives as a proposal on a card in the chat, and is saved only when the person presses Confirm. ChatGPT cannot press it for them: the saving step is not offered to ChatGPT at all. Knowledge Hub changes are kept as versions an owner can restore. The AI proposes and a person decides, as elsewhere in the portal.每项更改都以提案卡片的形式出现在对话中,本人按下确认后才会保存。ChatGPT 无法代为确认:保存这一步根本不提供给 ChatGPT。知识库的更改会保存为版本,所有者可以恢复。AI 提出建议,由人来决定,与平台其他部分一致。
Each request is recorded in the portal's audit log with the person's name and marked as coming from ChatGPT.每个请求都会记录到平台的审计日志,注明操作人姓名,并标明来自 ChatGPT。
A new ChatGPT section in the existing Roles screen sets each role's level, area by area (§03). Every role starts at Off, and no role can be given more than it has in the portal.在现有的“角色”页面新增 ChatGPT 设定,按范围逐项设定每个角色的级别(§03)。所有角色初始均为“关闭”,且任何角色获得的权限都不能超过其在平台内的权限。
Owners see every connected account and can disconnect any of them at once. Connections also expire and must be renewed.所有者可以看到所有已关联的账户,并可随时断开任何一个。关联也会过期,须重新续期。
CDD and other restricted documents are excluded at the connector itself, whatever the person's own access in the portal.CDD 及其他受限文件在连接器层面即被排除,与本人在平台内的权限无关。
Two phases. Use the first before the second.分两个阶段。先用第一阶段,再定第二阶段。
Phase 1 is useful on its own and carries little risk: it reads, writes reminders and to-dos, and proposes Knowledge Hub entries, each confirmed in the chat and restorable. We recommend using it for a few weeks before settling the Phase 2 list, since real use shows which changes are worth making by chat.第一阶段本身就很有用,风险也低:它可以读取、写入提醒和待办事项,并提出知识库条目,每一项都在对话中确认且可恢复。我们建议先使用几周,再确定第二阶段的内容,因为实际使用最能说明哪些更改值得通过对话来完成。
- Portal connector, and sign-in to it with password and two-factor code平台连接器,并以密码和双重验证码登录
- Knowledge Hub search and reading, and new entries and changes proposed from ChatGPT知识库搜索和阅读,以及从 ChatGPT 提出的新增条目和修改
- A confirmation card shown inside ChatGPT for every proposed change, prototyped first在 ChatGPT 内为每项更改显示确认卡片,先做原型
- Knowledge Hub changes from ChatGPT saved as new versions, marked as from ChatGPT来自 ChatGPT 的知识库更改保存为新版本,并标明来自 ChatGPT
- CRM look-up within each person's groups在每个人所属群组范围内查询 CRM
- Reminders and to-dos提醒和待办事项
- ChatGPT access levels per role in the Roles screen (§03), prototyped first在“角色”页面按角色设定 ChatGPT 权限级别(§03),先做原型
- All six safeguards in §05§05 中的全部六项安全措施
- Tested end to end in ChatGPT against the staging portal在 ChatGPT 中针对测试平台进行端到端测试
- The Phase 1 confirmation card, extended to the changes below将第一阶段的确认卡片扩展到以下更改
- CRM: create a record, change fields and contactsCRM:新增记录,修改字段和联系人
- Application forms: progress and draft preparation申请表:进度查询和草稿准备
- Delete and archive, for roles given delete access, confirmed in the chat删除和归档,仅限获得删除权限的角色,并在对话中确认
- Final list agreed with JY Global after Phase 1 use最终清单在第一阶段使用后与 JY Global 共同商定
Phase 1 starts once the decisions and Pro trial in §07 are settled, and the Knowledge Hub version history now being completed is live on the portal. Phase 2 starts only on JY Global's instruction.第一阶段在 §07 的各项决定和 Pro 试用完成,且正在完成的知识库版本历史功能已在平台上线后开始。第二阶段仅在 JY Global 指示后开始。
Four questions before we start.开始前的四个问题。
Each of these is JY Global's to decide, and each changes what we build.以下每项都由 JY Global 决定,每项都会影响我们开发的内容。
JY Global staff use individual ChatGPT Pro accounts. OpenAI's own documentation currently disagrees on whether Pro lets a custom connector make changes, or only read. Reading is not in doubt. Before Phase 1 starts, we would connect a small test connector to one of your Pro accounts for a day and settle it, including whether the confirmation card shows and works on Pro. If changes work, this proposal stands as written. If Pro only reads, there are three ways on: Phase 1 reads only and every change stays in the portal; the connector is published as a reviewed app in OpenAI's directory; or the people who need to make changes move to ChatGPT Business.JY Global 员工使用的是个人 ChatGPT Pro 账户。对于 Pro 是否允许自定义连接器进行更改、还是只能读取,OpenAI 自己的文档目前说法不一。读取功能没有疑问。在第一阶段开始前,我们会在您的一个 Pro 账户上连接一个小型测试连接器,用一天时间确认这一点,包括确认卡片能否在 Pro 上正常显示和使用。如果可以进行更改,本方案维持不变。如果 Pro 只能读取,有三种做法:第一阶段只做读取,所有更改仍在平台内完成;将连接器作为经审核的应用发布到 OpenAI 的应用目录;或让需要进行更改的人员改用 ChatGPT Business。
Requests through the connector come from OpenAI's servers, not from the person's own network, so a per-user IP whitelist cannot check them directly. We propose that linking an account must happen from a whitelisted address, and that the connector then accepts requests only from OpenAI's published addresses. This is a weaker check than today's. The alternative is that users with an IP whitelist do not use the connector at all.通过连接器发出的请求来自 OpenAI 的服务器,而不是员工自己的网络,因此个人 IP 白名单无法直接核查这些请求。我们建议:关联账户必须在白名单地址上进行,之后连接器只接受来自 OpenAI 公布地址的请求。这比现有的核查要弱。另一种做法是设有 IP 白名单的用户完全不使用连接器。
The portal already sends data to OpenAI through its API, under API terms. ChatGPT is a separate service with separate terms. On an individual Pro account, whether chats are used to train OpenAI's models depends on each person's own setting, and JY Global cannot enforce it centrally. We recommend every connector user switches that setting off. Given JY Global's obligations under the Cayman Islands Data Protection Act, we recommend the question is put to your data-protection or legal adviser before Phase 1 goes live.平台目前已通过 API 向 OpenAI 发送数据,适用的是 API 条款。ChatGPT 是另一项服务,适用不同的条款。在个人 Pro 账户上,对话是否会被用于训练 OpenAI 的模型,取决于每个人自己的设置,JY Global 无法统一管控。我们建议每位使用连接器的员工关闭该设置。鉴于 JY Global 在开曼群岛《数据保护法》下的义务,我们建议在第一阶段上线前,先就此征询贵公司的数据保护或法律顾问。
Which roles are switched on, and at what level in each area. §03 suggests a starting point: owners read, write and delete; members read only. Also, which two or three people pilot Phase 1 before it is opened more widely.开放哪些角色,以及每个范围的级别。§03 提供了一个起点:所有者可读写及删除;成员只能读取。另外,请指定两三位人员先试用第一阶段,再扩大开放。
ChatGPT's answers are ChatGPT's own. The portal's assistant is instructed to stay within JY Global's advisory boundary and not to give legal opinions. ChatGPT does not follow those instructions. The connector controls what ChatGPT can reach and change, not what it writes in reply. We recommend staff are reminded of this when the connector is introduced.ChatGPT 的回答是 ChatGPT 自己的。平台内置助手被设定为须遵守 JY Global 的咨询服务范围,不提供法律意见。ChatGPT 不受这些设定约束。连接器控制的是 ChatGPT 能接触和更改什么,而不是它回复的内容。我们建议在推出连接器时提醒员工注意这一点。
Outside this proposal.不在本方案范围内。
- Everything in §04: user management, sign-in protections, restricted documents, settings, keys and the audit log§04 中的全部内容:用户管理、登录保护、受限文件、设置、密钥和审计日志
- Changes or deletions saved from ChatGPT without the person confirming them未经本人确认即从 ChatGPT 保存的更改或删除
- Use of the connector by external customer accounts外部客户账户使用连接器
- ChatGPT subscriptions, which are JY Global's own cost with OpenAIChatGPT 订阅费用,由 JY Global 自行向 OpenAI 支付
- Bulk changes, such as updating or deleting many records at once批量更改,例如一次更新或删除多条记录
- Uploading files to the portal from ChatGPT, including files attached to Knowledge Hub entries从 ChatGPT 上传文件到平台,包括知识库条目的附件
- Other assistants that use the same standard, such as Claude. The connector is built to that standard, so this would be an extension rather than a rebuild使用同一标准的其他 AI 助手,例如 Claude。连接器基于该标准开发,因此属于扩展,无需重新开发
Settle four questions. Then Phase 1.先确定四个问题。然后开始第一阶段。
Our recommendation is to proceed with Phase 1. It gives staff the most useful part of the request, asking questions of JY Global's own knowledge and records from ChatGPT, while the portal keeps every control it has today. Changes to client records follow in Phase 2, once Phase 1 has been used and the list of changes worth making by chat is clear.我们建议先推进第一阶段。它提供了本次需求中最有用的部分:让员工在 ChatGPT 中查询 JY Global 自己的知识和记录,同时平台保留现有的全部控制。客户记录的更改放在第二阶段,待第一阶段使用一段时间、明确哪些更改值得通过对话完成之后再进行。
JY Global answers the four questions in §07, and we run the one-day Pro trial. Question 3 may need your adviser's input, so it is worth raising first.JY Global 回答 §07 中的四个问题,我们进行为期一天的 Pro 试用。问题 3 可能需要顾问意见,建议优先提出。
Built and tested on the staging portal, then piloted by the two or three people you name.在测试平台上开发和测试,然后由您指定的两三位人员试用。
After a few weeks of use, we agree the Phase 2 list together, or conclude that Phase 1 is enough.使用几周后,我们共同商定第二阶段的清单,或确认第一阶段已经足够。
Commercial terms for this change request are provided separately. ChatGPT is a product of OpenAI; its features, plans and terms are set by OpenAI and may change.本变更需求的商务条款另行提供。ChatGPT 是 OpenAI 的产品,其功能、方案和条款由 OpenAI 制定,可能会有变动。