25 ChatGPT-5.5 Prompts for Governed KPI Investigation with the Data Agent: Variance, Cohorts, Data Quality, and Executive Readouts

25 ChatGPT-5.5 Prompts for Governed KPI Investigation with the Data Agent: Variance, Cohorts, Data Quality, and Executive Readouts
25 ChatGPT-5.5 Prompts for Governed KPI Investigation with the Data Agent: Variance, Cohorts, Data Quality, and Executive Readouts

Why governed KPI investigation needs a different prompt pattern

The Data plugin in ChatGPT Work and Codex changes the starting point for business analysis: instead of pasting extracts into a chat, authorized users can ask questions against approved enterprise sources and refine the investigation through follow-up prompts. OpenAI describes the Data agent as able to connect to approved sources, investigate business questions, use organization-specific metric definitions, and create dashboards or reports. That makes prompt quality more important, not less, because a natural-language request can now reach governed warehouses, BI systems, business files, and semantic definitions that already carry operational consequences.

This masterclass is built for advanced users who need KPI answers that can survive review by finance, revenue operations, product analytics, data engineering, security, and executive leadership. The goal is not to make ChatGPT sound confident; the goal is to force the analysis to disclose its source, metric definition, filters, period, data freshness, calculation evidence, and uncertainty before anyone relies on it. A variance explanation, cohort trend, funnel drop-off, or executive readout is only useful when the reader can tell which data was used, what was excluded, which definitions were applied, and which conclusions remain hypotheses.

OpenAI’s Data plugin guidance says the plugin must be available in the user’s ChatGPT Work or Codex workspace, while the underlying source plugins and apps may require separate installation, authorization, templates, or workspace access. That distinction matters operationally: seeing Data in the workspace does not mean a user has access to Snowflake, BigQuery, Databricks, Redshift, ClickHouse, MongoDB, SharePoint, Google Drive, a BI dashboard, or a semantic layer. A governed prompt should therefore ask the agent to confirm the authorized connected sources it actually used, not merely assume that a named system is available.

The Work and Codex context: analysis, evidence, and controlled follow-up

In ChatGPT Work, the Data plugin is aimed at business users who need governed answers from approved enterprise data. In Codex, the same context can matter for technical teams investigating engineering, product, quality, or operational metrics that live in warehouses, BI tools, files, repositories, or documented semantic layers. OpenAI’s release notes and product materials describe Data as part of the Work and Codex environment, but availability can vary by workspace configuration, plan, region, rollout, connected tools, and administrator policy. A prompt that depends on Data should therefore include a fallback instruction: if the plugin or source is unavailable, say so and stop rather than fabricating a result.

The Data agent can support iterative investigation: a user can ask why a KPI moved, request a segment decomposition, inspect cohorts, review evidence, and ask for a dashboard specification. That workflow is valuable only if each iteration preserves the analytical chain. If a follow-up changes the period, removes a filter, switches from booked revenue to recognized revenue, or silently changes from account-level to user-level grain, the final answer may appear coherent while no longer matching the original business question. The prompts in this article are designed to make the agent restate the dataset, source, metric definition, filters, comparison period, and freshness every time the analysis changes.

OpenAI’s help guidance says users can invoke the Data plugin explicitly with @Data or ask whether it was used. For governed KPI work, explicit invocation is often safer because it reduces ambiguity about whether the answer came from connected sources, model memory, user-provided text, or a general reasoning response. The prompt pattern should still require the model to identify the sources actually queried and distinguish retrieved evidence from narrative interpretation.

Recommended opening clause for governed analysis:
Use only authorized connected sources available to this workspace and this account.
If @Data or the required source is unavailable, blocked by permissions, stale, or ambiguous,
stop and explain what is missing. Do not estimate or invent KPI values.

Installation is not authorization, and authorization is not correctness

Plugin installation, source authorization, and analytical correctness are three different controls. Installation makes a capability available in a workspace or user surface. Authorization determines whether the connected account can reach a source or app. Correctness depends on whether the right table, semantic model, metric definition, join path, time zone, filters, and data-quality assumptions were used. A user can have the plugin installed but lack source access; a user can have source access but query the wrong metric; and a correct query can still produce misleading results if the business question is poorly defined.

OpenAI’s Data plugin guidance states that administrators can control Data availability by role or group and that underlying data connections enforce the connected account’s existing table, row, and column permissions. This is a critical governance boundary: natural-language access does not create new permissions. If a user cannot see restricted regions, sensitive columns, customer-level rows, or privileged financial details in the underlying system, the query should not bypass those restrictions through ChatGPT. Prompt authors should not ask for credentials, access tokens, permission workarounds, full customer records, identity documents, health data, banking details, privileged legal material, or unnecessary personal data.

A governed prompt should also avoid turning access into over-disclosure. If the task is to explain a renewal-rate variance, the expected output may need account counts, segment-level movement, and aggregate retention by cohort; it usually does not need customer names, personal emails, contract PDFs, support transcripts, or raw payment details. The safest prompt pattern asks for the minimum evidence necessary to validate the KPI and instructs the agent to redact unnecessary sensitive data from the response.

Control layer What it decides Prompt implication
Workspace availability Whether Data is enabled for a user, role, group, or surface such as Work or Codex. Ask the agent to state whether Data was used and stop if the capability is unavailable.
Source authorization Whether the connected account can access a warehouse, file store, BI tool, or business app. Require use of authorized connected sources only and prohibit invented access or credentials.
Table, row, and column permissions Which records and fields the connected account may query in the underlying system. Expect permission-aware analysis and treat missing restricted fields as a disclosed limitation.
Semantic governance Which metric definitions, relationships, calculations, and approved queries are authoritative. Require the metric definition and semantic layer reference before accepting KPI results.
Human validation Whether a qualified owner accepts the conclusion and approves any consequential action. Forbid external action and require review before publishing, messaging, changing permissions, or acting.

Semantic layers: the difference between a number and a governed KPI

OpenAI describes the Data agent as able to incorporate organization-specific metric definitions, calculations, relationships, and semantic layers from approved sources such as dbt, Databricks Genie Ontology, Snowflake Horizon, GitHub, and BI dashboards. A semantic layer is where many organizations define what “ARR,” “active user,” “qualified pipeline,” “gross retention,” “support resolution,” “conversion,” or “usage” actually means. Without that layer, two analysts can answer the same English question with different tables, time zones, exclusion rules, and aggregation grains.

A KPI investigation should begin by asking which authoritative definition was used and whether conflicting definitions exist. For example, “active customer” may mean a paying account with an active subscription in finance reporting, an account with product usage in product analytics, or an account without a churn flag in customer success reporting. Those definitions may all be valid for different decisions, but mixing them inside one executive readout creates false precision. The prompt should require the agent to flag missing or conflicting definitions before calculating a variance.

The semantic layer does not eliminate the need for evidence. A well-governed answer should show the calculation path, including the numerator, denominator, filters, comparison period, and any excluded records when those details are available to the authorized user. If the agent cannot inspect the semantic definition, cannot see the source query, or cannot reconcile a metric against a trusted dashboard, the output should label the result as provisional rather than presenting it as an approved company figure.

The masterclass contract for all 25 prompts

Every prompt in this masterclass follows a strict contract. The agent must use only authorized connected sources; state the dataset, source, metric definition, filters, comparison period, and freshness; preserve user-supplied values; show calculations or evidence; flag missing or conflicting definitions; avoid inventing figures, causes, citations, or access; separate observation from hypothesis; redact unnecessary sensitive data; avoid sharing, publishing, emailing, messaging, or taking external action; and require a qualified human to validate conclusions and approve any action.

This contract is deliberately conservative because KPI investigations often sit close to finance, legal, HR, customer, product, security, and compliance decisions. A prompt may help identify a revenue variance, churn-risk segment, support backlog, conversion anomaly, or data-quality defect, but it must not convert correlation into causation or analytics into financial, legal, tax, medical, HR, or compliance advice. The right output format is evidence plus bounded interpretation, not an automated verdict.

Operational rule: treat the Data agent as an investigation assistant operating inside existing permissions, not as a new source of authority. The source system, semantic definition, data owner, and qualified business reviewer remain responsible for the final decision.

The same caution applies to executive readouts. OpenAI’s Usage Insights documentation describes activity grouped into use cases and tasks, with metrics such as messages, credits, and active users in that reporting context. Those measures can inform investigation, but they should not be treated as standalone proof of productivity, causation, quality, or financial return. If a KPI investigation uses ChatGPT Work or Codex analytics as an input, the prompt should preserve sampling notices, unclassified activity, selected filters, date scope, and the difference between activity evidence and business outcome evidence.

How to read and adapt the prompts that follow

Each prompt section in the full masterclass is designed as a reusable template, not a magic phrase. The placeholders should be filled with the exact dataset, source, metric, filter, comparison period, and freshness requirement you want preserved. If the business owner says “compare enterprise renewal rate in Q3 versus Q2 for North America accounts excluding migrations,” those values should appear verbatim in the prompt and in the answer. If the agent changes or cannot apply any of them, the answer should disclose the change before offering interpretation.

The verification checkpoint in each prompt is as important as the copy-paste prompt itself. OpenAI’s guidance recommends checking source, period, filters, and metric definition, especially when results differ from existing reports. A discrepancy should be reconciled against the trusted report, source query, semantic definition, or data pipeline before the result is shared or used for action. The correct response to a mismatch is not to pick the more convenient number; it is to identify whether the gap comes from permissions, freshness, grain, joins, filters, definitions, or data quality.

Dashboard and publication prompts require extra care. OpenAI’s Data plugin guidance says dashboards can be edited, shared, and refreshed, but available actions depend on the connected tool and user access. It also warns that publishing a dashboard to a ChatGPT Site copies the analysis data into the published site, so the audience must be checked against data permissions. Any prompt that mentions dashboards, Sites, Slack, email, BI tools, or connected-tool actions must require destination review, content review, audience review, and explicit human approval before anything leaves the private analysis context.

The practical standard is simple: if the output could influence a customer message, executive decision, forecast, hiring action, incident response, pricing change, public statement, permission change, payment, deployment, or compliance position, the agent should not act on it directly. It can prepare evidence, draft options, list approval gates, and identify unresolved questions. A qualified human owner must validate the result, decide whether the evidence is sufficient, and approve any consequential step.

Access and review boundary: Data-plugin installation is separate from source setup and authorization for every underlying plugin or app; separate authorization is required for each source, and every source keeps its own permissions. These analyses are not legal, financial, medical, HR, tax, or compliance advice, and a qualified reviewer must validate any high-stakes conclusion.

Prompts 1–9: governed discovery, definitions, baselines, variance, cohorts, and funnels

25 ChatGPT-5.5 Prompts for Governed KPI Investigation with the Data Agent: Variance, Cohorts, Data Quality, and Executive Readouts — first editorial explainer visual

The first nine prompts establish the investigation frame before asking the Data agent to explain a KPI movement. OpenAI describes the Data agent as able to connect to approved enterprise data sources, use organization-specific metric definitions and semantic layers, investigate business questions, refine analyses through follow-up questions, and create dashboards or reports; these prompts deliberately constrain that capability to authorized sources, explicit definitions, visible evidence, and human validation.

Use these prompts in ChatGPT Work or Codex only where the Data plugin and the underlying source connections are available to your workspace and role. OpenAI’s guidance says administrators control available data connections and roles, while queries enforce the connected account’s existing table, row, and column permissions; a prompt can request disciplined analysis, but it cannot grant access, repair a bad semantic layer, or make an untrusted metric authoritative.

Prompt 1: Source inventory for a governed KPI investigation

Purpose

Use this prompt before analysis to identify which approved sources, semantic definitions, BI dashboards, and business files are in scope. The goal is to prevent the Data agent from mixing exploratory tables with trusted reporting assets without labeling the difference.

Copy-paste prompt

@Data Build a governed source inventory for this KPI investigation.

Business question:
[Insert the KPI question.]

Authorization contract: Use only authorized connected sources available to me in this ChatGPT Work or Codex workspace, and respect existing table, row, and column permissions. Do not request credentials, access tokens, account numbers, or new access. Do not invent unavailable sources or imply access that is not present.

Evidence contract: For every candidate source, state the dataset, system or file source, owner if visible, metric definition if visible, relevant filters, available comparison periods, grain, refresh or freshness timestamp, and whether the source appears authoritative, supporting, or exploratory. Preserve all supplied values exactly. Show the evidence used, including table names, dashboard names, semantic-layer objects, or file names when visible.

Uncertainty contract: Flag missing, conflicting, stale, sampled, or ambiguous definitions. Do not invent figures, causes, citations, owners, schemas, or business meaning. Separate observations from hypotheses.

Privacy contract: Redact unnecessary sensitive data and summarize at the minimum useful level. Do not output full customer records, health data, identity documents, banking details, privileged legal material, or unnecessary personal data.

No-action contract: Do not share, publish, email, message, create tickets, change permissions, execute connected-tool actions, or take external action. Prepare analysis only.

Human-validation contract: A qualified human data owner or business owner must validate the source inventory, metric authority, and any conclusion before the result is used or any action is approved. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • KPI name or business question.
  • Known trusted dashboard, warehouse, semantic layer, or business file, if any.
  • Target business unit, product, geography, or customer segment.

Expected output

A table of candidate sources with authority level, visible definitions, grain, freshness, permission limitations, and reconciliation risks. The best output also states which sources should not be used for executive reporting until a data owner confirms them.

Verification checkpoint

Confirm that the listed source of truth matches your organization’s reporting policy. If the Data agent finds a number in a file but not in the governed warehouse or semantic layer, treat it as supporting evidence rather than the KPI definition.

Prompt 2: Metric-definition audit before calculating the KPI

Purpose

This prompt audits the KPI definition before any variance calculation. It is especially useful when teams use the same label, such as “active customer” or “net revenue retention,” with different filters, exclusions, or date logic.

Copy-paste prompt

@Data Audit the metric definition before calculating or explaining the KPI.

KPI:
[Insert KPI name.]

Known or expected definition:
[Insert definition, formula, inclusion rules, exclusions, and grain if known.]

Authorization contract: Use only authorized connected sources available to me in this ChatGPT Work or Codex workspace, and respect existing table, row, and column permissions. Do not request credentials, access tokens, account numbers, or new access. Do not invent unavailable sources or imply access that is not present.

Evidence contract: State the dataset, source system, semantic-layer object, dashboard, or file used; the metric definition found; filters; comparison period; calculation grain; and latest freshness timestamp. Preserve supplied values exactly. Show formulas, joins, numerator and denominator logic, date handling, and visible evidence.

Uncertainty contract: Flag missing or conflicting definitions, undocumented filters, stale data, sampled activity, and unclear ownership. Do not invent figures, causes, citations, or access. Separate observation from hypothesis.

Privacy contract: Redact unnecessary sensitive data and aggregate where possible. Do not output full customer records, health data, identity documents, banking details, privileged legal material, or unnecessary personal data.

No-action contract: Do not share, publish, email, message, create tickets, change permissions, execute connected-tool actions, or take external action. Prepare analysis only.

Human-validation contract: A qualified human metric owner must validate the final definition and approve any use of this KPI in reporting, planning, external communication, compensation, compliance, finance, legal, HR, or operational action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • KPI label and suspected formula.
  • Reporting period and business context.
  • Any known exclusions, such as test accounts, refunds, internal usage, or canceled orders.

Expected output

A definition audit that compares supplied and discovered definitions, identifies mismatches, and recommends a single calculation path only when the evidence supports it. It should not proceed to business interpretation if the definition is unresolved.

Verification checkpoint

Ask the metric owner to approve the numerator, denominator, grain, date field, timezone, and exclusion logic. If any of those are disputed, do not use the calculated KPI in an executive readout.

Prompt 3: Semantic-layer alignment check

Purpose

Use this prompt when your organization has a semantic layer, dbt project, BI model, ontology, or governed dashboard layer. OpenAI says the Data agent can incorporate organization-specific metric definitions, calculations, relationships, and semantic layers from approved sources, but the user still needs to verify alignment.

Copy-paste prompt

@Data Check whether this KPI analysis aligns with the approved semantic layer.

KPI and business question:
[Insert KPI and question.]

Preferred semantic assets:
[Insert dbt model, BI dashboard, ontology, governed dataset, or approved metric catalog if known.]

Authorization contract: Use only authorized connected sources available to me in this ChatGPT Work or Codex workspace, and respect existing table, row, and column permissions. Do not request credentials, access tokens, account numbers, or new access. Do not invent unavailable semantic assets or imply access that is not present.

Evidence contract: State the dataset, source, semantic object, metric definition, relationship logic, filters, comparison period, and freshness. Preserve supplied values exactly. Show evidence for each join, dimension, calculated measure, and hierarchy used.

Uncertainty contract: Flag missing semantic objects, conflicting BI definitions, unsupported joins, unmodeled dimensions, stale builds, and ambiguous ownership. Do not invent figures, causes, citations, or access. Separate observation from hypothesis.

Privacy contract: Redact unnecessary sensitive data and summarize at the aggregate level unless row-level detail is required and authorized. Do not output full customer records, health data, identity documents, banking details, privileged legal material, or unnecessary personal data.

No-action contract: Do not share, publish, email, message, create tickets, change permissions, execute connected-tool actions, or take external action. Prepare analysis only.

Human-validation contract: A qualified human data owner must validate semantic alignment and approve any downstream dashboard, report, recommendation, or action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • KPI name and intended dimensions.
  • Known semantic-layer object names or trusted dashboards.
  • Any dimension hierarchy, such as region, product, channel, or account tier.

Expected output

A mapping from business KPI to semantic-layer objects, including which dimensions are approved, which calculations are reusable, and which requested cuts require ungoverned logic or additional review.

Verification checkpoint

Compare the Data agent’s mapped metric and dimensions with a trusted BI report. If totals differ, reconcile the semantic definition, source filters, and data freshness before investigating causes.

Prompt 4: Permission-aware discovery without overexposure

Purpose

This prompt asks the Data agent to discover what analysis is possible under current permissions without exposing unnecessary sensitive detail. It is useful for analysts who need to know whether they can answer a question before requesting any additional access through normal governance channels.

Copy-paste prompt

@Data Perform permission-aware discovery for this KPI question without exposing unnecessary sensitive data.

Question:
[Insert question.]

Scope:
[Insert business unit, product, region, period, and intended audience.]

Authorization contract: Use only authorized connected sources available to me in this ChatGPT Work or Codex workspace, and respect existing table, row, and column permissions. Do not request credentials, access tokens, account numbers, new roles, or permission changes. Do not invent access, bypass controls, infer restricted row values, or suggest workarounds around source permissions.

Evidence contract: State the accessible dataset, source, metric definition, filters, comparison period, freshness, and visible limitations. Preserve supplied values exactly. Show what can be answered, what cannot be answered, and what evidence supports that boundary.

Uncertainty contract: Flag missing columns, masked fields, restricted rows, conflicting definitions, stale data, and inaccessible sources. Do not invent figures, causes, citations, or access. Separate observation from hypothesis.

Privacy contract: Redact unnecessary sensitive data; aggregate results; suppress small-cell detail when it may identify people or customers. Do not output full customer records, health data, identity documents, banking details, privileged legal material, or unnecessary personal data.

No-action contract: Do not share, publish, email, message, create tickets, request permissions, change permissions, execute connected-tool actions, or take external action. Prepare a discovery summary only.

Human-validation contract: A qualified human owner must validate whether the current permission scope is appropriate and approve any access request, analysis use, or action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • Business question and intended reporting audience.
  • Known sensitivity constraints or restricted populations.
  • Minimum aggregation level acceptable for analysis.

Expected output

A permissions-aware feasibility summary that distinguishes answerable questions, blocked questions, and questions that require data owner review. It should never recommend bypassing workspace, warehouse, BI, or file permissions.

Verification checkpoint

Review whether any output reveals small groups, individual behavior, confidential customer detail, or restricted business context. If it does, reduce granularity and re-run with safer aggregation.

Prompt 5: Baseline design for a KPI investigation

Purpose

This prompt designs a baseline before variance analysis. A useful baseline defines comparison periods, seasonality expectations, segment mix, data freshness, and exclusion rules so the later explanation is not anchored to an arbitrary date range.

Copy-paste prompt

@Data Design a governed baseline for this KPI before calculating variance.

KPI:
[Insert KPI.]

Current period:
[Insert dates.]

Candidate comparison periods:
[Insert prior period, same period last year, trailing average, or planned target.]

Authorization contract: Use only authorized connected sources available to me in this ChatGPT Work or Codex workspace, and respect existing table, row, and column permissions. Do not request credentials, access tokens, account numbers, or new access. Do not invent unavailable data or imply access that is not present.

Evidence contract: State dataset, source, metric definition, filters, comparison period options, baseline rationale, and freshness. Preserve supplied values exactly. Show calculations or evidence for each proposed baseline and explain tradeoffs.

Uncertainty contract: Flag missing history, calendar changes, business model changes, data-quality gaps, conflicting definitions, and stale data. Do not invent figures, causes, citations, or access. Separate observation from hypothesis.

Privacy contract: Redact unnecessary sensitive data and use aggregate baseline statistics. Do not output full customer records, health data, identity documents, banking details, privileged legal material, or unnecessary personal data.

No-action contract: Do not share, publish, email, message, create tickets, change permissions, execute connected-tool actions, or take external action. Prepare baseline recommendations only.

Human-validation contract: A qualified human business owner must validate the baseline choice before the KPI variance is interpreted or used for action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • KPI and current analysis period.
  • Candidate baseline periods or targets.
  • Known events such as launches, pricing changes, outages, policy changes, or holidays.

Expected output

A baseline recommendation table comparing prior period, year-over-year, trailing average, and target-based baselines where available. The output should identify which baseline is best for executive explanation and which is best for operational diagnosis.

Verification checkpoint

Confirm that the chosen baseline matches the business cadence. Weekly operational metrics, monthly finance metrics, and cohort retention metrics often require different comparison windows.

Prompt 6: Period-over-period KPI variance

Purpose

This is the core variance prompt for a governed KPI. It asks the Data agent to calculate period-over-period movement while preserving the source, filters, freshness, and formula used to produce the number.

Copy-paste prompt

@Data Calculate period-over-period variance for this governed KPI.

KPI:
[Insert KPI.]

Current period:
[Insert dates.]

Comparison period:
[Insert dates.]

Filters:
[Insert product, region, segment, channel, customer type, or other filters.]

Authorization contract: Use only authorized connected sources available to me in this ChatGPT Work or Codex workspace, and respect existing table, row, and column permissions. Do not request credentials, access tokens, account numbers, or new access. Do not invent unavailable data or imply access that is not present.

Evidence contract: State dataset, source, metric definition, filters, comparison period, grain, timezone if visible, and freshness. Preserve supplied values exactly. Show numerator, denominator, absolute change, percentage change, and any calculation steps.

Uncertainty contract: Flag missing or conflicting definitions, incomplete current-period data, stale refreshes, sampling notices, restricted dimensions, and data-quality warnings. Do not invent figures, causes, citations, or access. Separate observed variance from possible explanations.

Privacy contract: Redact unnecessary sensitive data and keep the output aggregated. Do not output full customer records, health data, identity documents, banking details, privileged legal material, or unnecessary personal data.

No-action contract: Do not share, publish, email, message, create tickets, change permissions, execute connected-tool actions, or take external action. Prepare variance analysis only.

Human-validation contract: A qualified human must validate the calculation and approve any operational, financial, staffing, customer, legal, compliance, or executive action based on it. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • KPI definition or approved source.
  • Current and comparison periods.
  • Filters and reporting grain.

Expected output

A variance table with current value, comparison value, absolute delta, percent delta, calculation evidence, and limitations. The explanation should state what changed, not why it changed unless supporting evidence exists.

Verification checkpoint

Check that the current period is complete enough for comparison. If the data refresh is partial, ask for a run-rate view and label it as an estimate rather than a confirmed variance.

Prompt 7: Segment decomposition of KPI movement

Purpose

Use this prompt after a KPI variance is confirmed to determine which segments contributed most to the change. Segment decomposition prevents teams from overreacting to an aggregate number that may be driven by mix shift, one region, one channel, or one product family.

Copy-paste prompt

@Data Decompose this KPI variance by approved segments.

KPI:
[Insert KPI.]

Current period:
[Insert dates.]

Comparison period:
[Insert dates.]

Candidate segments:
[Insert approved dimensions such as product, region, channel, plan, cohort, account tier, or sales motion.]

Authorization contract: Use only authorized connected sources available to me in this ChatGPT Work or Codex workspace, and respect existing table, row, and column permissions. Do not request credentials, access tokens, account numbers, or new access. Do not invent unavailable dimensions, segments, or access.

Evidence contract: State dataset, source, metric definition, filters, comparison period, segment grain, and freshness. Preserve supplied values exactly. Show segment-level current value, comparison value, delta, share of total change, and calculation method.

Uncertainty contract: Flag missing segment mappings, small-cell risk, conflicting definitions, stale data, restricted dimensions, and segments that do not reconcile to the total. Do not invent figures, causes, citations, or access. Separate observed contribution from hypothesized driver.

Privacy contract: Redact unnecessary sensitive data, aggregate small cells, and avoid exposing identifiable customer or employee details. Do not output full customer records, health data, identity documents, banking details, privileged legal material, or unnecessary personal data.

No-action contract: Do not share, publish, email, message, create tickets, change permissions, execute connected-tool actions, or take external action. Prepare decomposition analysis only.

Human-validation contract: A qualified human must validate the segment mapping and approve any follow-up action, customer outreach, staffing change, budget move, or executive communication. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • Confirmed KPI variance from Prompt 6.
  • Approved segment dimensions.
  • Minimum cell-size or aggregation rules if applicable.

Expected output

A ranked contribution table that reconciles segment deltas to the total variance or clearly explains why reconciliation is not possible. The output should distinguish large absolute movement from large percentage movement on a tiny base.

Verification checkpoint

Ensure segment totals reconcile to the governed KPI total within an explained tolerance. If they do not, inspect joins, null segment values, late-arriving data, and permission-filtered rows.

Prompt 8: Cohort retention investigation

Purpose

This prompt structures retention analysis by cohort start period, age, and retention definition. It is useful when an aggregate active-user or revenue metric changes because newer or older cohorts behave differently.

Copy-paste prompt

@Data Investigate cohort retention for this KPI using governed definitions.

Retention KPI:
[Insert retention metric.]

Cohort definition:
[Insert signup month, first purchase week, contract start quarter, activation date, or other cohort rule.]

Observation window:
[Insert dates.]

Filters:
[Insert product, region, plan, channel, or customer type.]

Authorization contract: Use only authorized connected sources available to me in this ChatGPT Work or Codex workspace, and respect existing table, row, and column permissions. Do not request credentials, access tokens, account numbers, or new access. Do not invent unavailable cohort fields, records, or access.

Evidence contract: State dataset, source, retention definition, cohort definition, filters, comparison period, grain, censoring treatment, and freshness. Preserve supplied values exactly. Show cohort sizes, retained counts or retained value, retention rates, and calculations.

Uncertainty contract: Flag incomplete cohorts, late-arriving events, survivorship bias, conflicting definitions, small-cell risks, stale data, and missing identifiers. Do not invent figures, causes, citations, or access. Separate retention observations from hypotheses.

Privacy contract: Redact unnecessary sensitive data and report cohorts in aggregate. Do not output full customer records, health data, identity documents, banking details, privileged legal material, or unnecessary personal data.

No-action contract: Do not share, publish, email, message, create tickets, change permissions, execute connected-tool actions, or take external action. Prepare cohort analysis only.

Human-validation contract: A qualified human must validate the retention definition, cohort construction, censoring treatment, and any recommended action before use. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • Retention metric and cohort-start rule.
  • Observation window and filters.
  • Definition of retained, churned, reactivated, expanded, or downgraded where relevant.

Expected output

A cohort table or matrix with cohort size, retained count or value, retention rate by period age, and notes about incomplete cohorts. The output should avoid comparing mature cohorts with immature cohorts as if they had equal observation time.

Verification checkpoint

Confirm that the cohort date field is correct and that incomplete recent cohorts are labeled. If retention depends on revenue recognition, contract status, or product activity, validate the governing source before drawing conclusions.

Prompt 9: Funnel analysis from entry to conversion

Purpose

This prompt investigates a multi-step funnel while preserving event definitions, ordering rules, and time windows. It is useful for signup, activation, purchase, support resolution, onboarding, sales, and internal workflow funnels.

Copy-paste prompt

@Data Analyze this funnel using approved event and metric definitions.

Funnel objective:
[Insert objective.]

Funnel steps in order:
1. [Step 1]
2. [Step 2]
3. [Step 3]
4. [Optional additional steps]

Population and time window:
[Insert eligible population, entry rule, and dates.]

Filters:
[Insert product, region, channel, plan, device, account tier, or other approved filters.]

Authorization contract: Use only authorized connected sources available to me in this ChatGPT Work or Codex workspace, and respect existing table, row, and column permissions. Do not request credentials, access tokens, account numbers, or new access. Do not invent unavailable events, records, identities, or access.

Evidence contract: State dataset, source, event definitions, metric definitions, filters, comparison period, conversion window, ordering rules, deduplication logic, and freshness. Preserve supplied values exactly. Show counts, step conversion rates, drop-off counts, overall conversion, and calculation steps.

Uncertainty contract: Flag missing events, conflicting event names, instrumentation gaps, identity-resolution limits, stale data, sampled activity, and restricted dimensions. Do not invent figures, causes, citations, or access. Separate observed drop-off from hypothesized reason.

Privacy contract: Redact unnecessary sensitive data and aggregate results. Do not output full customer records, health data, identity documents, banking details, privileged legal material, or unnecessary personal data.

No-action contract: Do not share, publish, email, message, create tickets, change permissions, execute connected-tool actions, or take external action. Prepare funnel analysis only.

Human-validation contract: A qualified human must validate event definitions, funnel construction, and any proposed experiment, customer contact, product change, or executive message before action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • Ordered funnel steps and eligible population.
  • Time window, conversion window, and filters.
  • Known event names or trusted funnel dashboard, if available.

Expected output

A funnel table showing entrants, completions, step conversion, step drop-off, total conversion, data freshness, and instrumentation limitations. The strongest output identifies whether the funnel can be trusted before ranking drop-off points.

Verification checkpoint

Validate that event ordering, deduplication, bot or test-account exclusions, and identity stitching match your analytics standard. If the funnel differs from a trusted BI dashboard, reconcile definitions before proposing product or growth actions.

Prompts 10–18: anomaly triage, data quality, reconciliation, dashboards, and chart evidence

25 ChatGPT-5.5 Prompts for Governed KPI Investigation with the Data Agent: Variance, Cohorts, Data Quality, and Executive Readouts — second editorial workflow visual

OpenAI says the Data plugin can investigate business questions against approved enterprise data sources, incorporate governed metric definitions from semantic layers, and build dashboards or reports when the workspace and underlying tools are configured for those actions. These prompts keep the investigation inside that boundary: they ask for source, metric, period, filters, freshness, evidence, and validation rather than treating natural-language access as proof that a KPI result is correct.

Prompt 10: Anomaly triage before escalation

Purpose

Use this prompt when a KPI moved sharply and the team needs a disciplined triage before alerting executives, opening an incident, or assigning root cause. The goal is to separate a real business change from reporting delay, changed filters, permission gaps, pipeline issues, or metric-definition drift.

Copy-paste prompt

@Data Investigate the anomaly in this KPI using only authorized connected sources. Dataset: [dataset or table family]. Source: [warehouse, BI report, semantic layer, file, or dashboard]. Metric definition: [exact definition]. Filters: [regions, products, channels, customer types, workspace groups, or other filters]. Comparison period: [current period] versus [baseline or prior period]. Freshness: [expected refresh time, latest partition, or report timestamp].

Safety contract: use only authorized connected sources; state dataset, source, metric definition, filters, comparison period, and freshness; preserve supplied values exactly; show calculations or evidence; flag missing or conflicting definitions; avoid inventing figures, causes, citations, or access; separate observation from hypothesis; redact unnecessary sensitive data; avoid sharing, publishing, emailing, messaging, or taking external action; require a qualified human to validate conclusions and approve any action.

Triage the anomaly in this order: confirm the latest available data, confirm the metric definition and filters, identify the first period where the movement appears, compare absolute and percentage change, decompose by the highest-signal segments, check whether the movement appears in trusted reports, and list plausible hypotheses without asserting causation. Return a concise anomaly brief with evidence tables and unresolved questions. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • The KPI name, exact calculation, and owner-approved definition.
  • The current anomalous period, comparison period, and accepted freshness expectation.
  • Known filters, exclusions, and trusted reports used for escalation decisions.

Expected output

The Data agent should produce a triage brief with observed movement, segment breakdowns, freshness checks, definition checks, and a ranked list of hypotheses. The brief should explicitly distinguish “observed in the data” from “possible explanation” and should identify the evidence required before escalation.

Verification checkpoint

Before acting, compare the result with the trusted operational report for the same period and filters. If the figures differ, resolve the source, semantic-definition, row-permission, or refresh discrepancy before sending an alert or assigning ownership.

Prompt 11: Seasonality and calendar-effect review

Purpose

Use this prompt when a variance may be caused by weekday mix, holidays, fiscal calendars, campaign timing, billing cycles, or known seasonal patterns. It prevents teams from mislabeling expected calendar movement as a business failure or success.

Copy-paste prompt

@Data Review seasonality and calendar effects for this KPI using only authorized connected sources. Dataset: [dataset or table family]. Source: [warehouse, BI report, semantic layer, file, or dashboard]. Metric definition: [exact definition]. Filters: [scope]. Comparison period: [current period] versus [prior period, same period last year, rolling average, or fiscal equivalent]. Freshness: [latest known refresh or partition].

Safety contract: use only authorized connected sources; state dataset, source, metric definition, filters, comparison period, and freshness; preserve supplied values exactly; show calculations or evidence; flag missing or conflicting definitions; avoid inventing figures, causes, citations, or access; separate observation from hypothesis; redact unnecessary sensitive data; avoid sharing, publishing, emailing, messaging, or taking external action; require a qualified human to validate conclusions and approve any action.

Check whether the KPI movement changes after accounting for weekday mix, fiscal calendar alignment, holidays, month length, quarter boundaries, campaign windows, subscription renewal cycles, or other documented seasonality in the approved sources. Provide raw comparison, seasonality-aware comparison, and a short explanation of which adjustment is appropriate or not supported. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • The business calendar or fiscal calendar source, if one is approved.
  • The comparison method the organization normally uses for the KPI.
  • Known events such as holidays, launches, outages, billing cycles, or campaigns.

Expected output

The response should show whether the apparent movement remains after calendar-aware comparison. It should not smooth away a real operational issue merely because a seasonal pattern exists; it should show both the unadjusted and adjusted view where the data supports both.

Verification checkpoint

Ask the KPI owner whether the proposed seasonal adjustment is part of the governed reporting method. If the semantic layer or trusted dashboard uses a different calendar, use that definition for decision reporting and treat alternate views as exploratory.

Prompt 12: Data freshness and refresh-lag check

Purpose

Use this prompt before interpreting a same-day, weekly, or recently closed-period KPI. OpenAI’s Data guidance tells users to verify source, period, filters, and metric definition; freshness is part of that validation because late-arriving data can create false declines or spikes.

Copy-paste prompt

@Data Check data freshness for this KPI before calculating or interpreting movement. Use only authorized connected sources. Dataset: [dataset or table family]. Source: [warehouse, BI report, semantic layer, file, or dashboard]. Metric definition: [exact definition]. Filters: [scope]. Comparison period: [periods]. Freshness: [expected refresh SLA, latest partition, source timestamp, or dashboard refresh time].

Safety contract: use only authorized connected sources; state dataset, source, metric definition, filters, comparison period, and freshness; preserve supplied values exactly; show calculations or evidence; flag missing or conflicting definitions; avoid inventing figures, causes, citations, or access; separate observation from hypothesis; redact unnecessary sensitive data; avoid sharing, publishing, emailing, messaging, or taking external action; require a qualified human to validate conclusions and approve any action.

Report the latest available timestamp or partition for each relevant source, compare it with the expected freshness, identify partial-period risks, and state whether the KPI is safe for interpretation. If freshness is insufficient, estimate only the completeness status and do not infer business performance from incomplete data. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • The expected refresh cadence or service-level expectation for the KPI source.
  • The latest reporting cutoff used by the trusted dashboard or finance report.
  • Any known upstream jobs, ingestion tables, or semantic models used in calculation.

Expected output

The output should be a freshness report that lists each source, its latest available data, the expected freshness, and whether current-period interpretation is safe, provisional, or blocked. It should avoid filling missing periods with invented values.

Verification checkpoint

If the agent cannot inspect freshness metadata because of permissions or missing source documentation, treat the KPI result as unverified. Ask the data owner or administrator to confirm the approved refresh status before using the analysis in a decision memo.

Prompt 13: Missingness profile for KPI inputs

Purpose

Use this prompt when a KPI depends on fields that may be null, blank, defaulted, late-arriving, or conditionally populated. Missingness can bias rates, funnel conversion, cohort retention, and revenue metrics if excluded rows are not reported.

Copy-paste prompt

@Data Profile missingness for the fields that feed this KPI using only authorized connected sources. Dataset: [dataset or table family]. Source: [warehouse, BI report, semantic layer, file, or dashboard]. Metric definition: [exact definition]. Filters: [scope]. Comparison period: [periods]. Freshness: [latest known refresh or partition].

Safety contract: use only authorized connected sources; state dataset, source, metric definition, filters, comparison period, and freshness; preserve supplied values exactly; show calculations or evidence; flag missing or conflicting definitions; avoid inventing figures, causes, citations, or access; separate observation from hypothesis; redact unnecessary sensitive data; avoid sharing, publishing, emailing, messaging, or taking external action; require a qualified human to validate conclusions and approve any action.

Identify required KPI input fields, calculate missingness counts and rates by period and key segment, show whether missingness changed during the comparison period, and explain how the governed metric definition treats missing values. Do not expose full customer records or unnecessary personal data; use aggregate counts and representative field names only. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • The fields required for numerator, denominator, segmentation, and time assignment.
  • The approved handling of nulls, blanks, unknowns, and late-arriving records.
  • Segments where missingness has previously affected reporting quality.

Expected output

The agent should return a missingness matrix by field, period, and segment, plus a plain-language note on how missing values affect the KPI. If the semantic layer does not define null handling, the output should flag that as a governance gap rather than choose a rule silently.

Verification checkpoint

Review whether the missingness pattern could change the denominator or segment mix enough to explain the KPI movement. If so, pause business interpretation until the data owner confirms the correct treatment.

Prompt 14: Duplicate-record and grain validation

Purpose

Use this prompt when joins, event streams, order lines, user actions, or customer-account hierarchies could duplicate records. Many KPI errors come from calculating at the wrong grain, such as counting line items as orders or events as users.

Copy-paste prompt

@Data Validate record grain and duplicate risk for this KPI using only authorized connected sources. Dataset: [dataset or table family]. Source: [warehouse, BI report, semantic layer, file, or dashboard]. Metric definition: [exact definition]. Filters: [scope]. Comparison period: [periods]. Freshness: [latest known refresh or partition].

Safety contract: use only authorized connected sources; state dataset, source, metric definition, filters, comparison period, and freshness; preserve supplied values exactly; show calculations or evidence; flag missing or conflicting definitions; avoid inventing figures, causes, citations, or access; separate observation from hypothesis; redact unnecessary sensitive data; avoid sharing, publishing, emailing, messaging, or taking external action; require a qualified human to validate conclusions and approve any action.

State the intended grain of the KPI, identify likely primary keys or composite keys from authorized metadata, test duplicate counts at the intended grain, and check whether joins multiply rows. Show examples only as aggregate patterns or masked identifiers. Recommend the safe calculation grain, but do not change production definitions or dashboards. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • The intended business grain, such as user-day, order, account-month, session, or invoice line.
  • Known join paths, bridge tables, event tables, or dimensional relationships.
  • The trusted report or semantic model that defines the production calculation.

Expected output

The response should identify whether the KPI is vulnerable to duplicate inflation or undercounting. It should include duplicate rates, affected joins, and a recommended validation query or calculation pattern that a data owner can review.

Verification checkpoint

Do not accept a KPI change based only on detected duplicates. Confirm with the semantic-layer owner whether the duplicates are expected business records, source-system artifacts, or modeling errors.

Prompt 15: Reconciliation against a trusted report

Purpose

Use this prompt when the Data agent’s answer differs from an existing dashboard, finance pack, board report, or operational scorecard. OpenAI’s Data guidance explicitly recommends reconciling discrepancies against existing reports and resolving incorrect analysis at the source or semantic-definition level before sharing or action.

Copy-paste prompt

@Data Reconcile this KPI result against the trusted report using only authorized connected sources. Dataset: [dataset or table family]. Source: [agent-calculated source] and trusted report: [trusted dashboard, finance report, BI workbook, or semantic model]. Metric definition: [exact definition]. Filters: [scope]. Comparison period: [periods]. Freshness: [timestamps for both sources].

Safety contract: use only authorized connected sources; state dataset, source, metric definition, filters, comparison period, and freshness; preserve supplied values exactly; show calculations or evidence; flag missing or conflicting definitions; avoid inventing figures, causes, citations, or access; separate observation from hypothesis; redact unnecessary sensitive data; avoid sharing, publishing, emailing, messaging, or taking external action; require a qualified human to validate conclusions and approve any action.

Compare the two results step by step: metric formula, date boundaries, timezone or fiscal calendar, filters, exclusions, row and column permissions, freshness, null handling, duplicate handling, and semantic-layer version. Quantify the variance and produce a reconciliation table with likely discrepancy sources and next validation owners. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • The trusted report name, owner, timestamp, and exact KPI value to reconcile.
  • The Data agent calculation scope, source, filters, and period.
  • Known business rules that may differ across reports.

Expected output

The expected result is a reconciliation worksheet, not a declaration that one number is right. It should show where definitions, filters, permissions, or freshness differ and identify the smallest set of checks needed to converge on the governed KPI value.

Verification checkpoint

Require the report owner or data steward to approve the reconciled number before it appears in an executive readout, dashboard publication, email, message, or external system.

Prompt 16: Causal-hypothesis limits and evidence plan

Purpose

Use this prompt after a variance or anomaly analysis has identified possible drivers. It prevents correlation, segment movement, or temporal coincidence from being presented as causation, especially in finance, HR, legal, compliance, medical, or customer-impacting contexts.

Copy-paste prompt

@Data Convert the KPI findings into causal hypotheses with evidence limits using only authorized connected sources. Dataset: [dataset or table family]. Source: [warehouse, BI report, semantic layer, file, or dashboard]. Metric definition: [exact definition]. Filters: [scope]. Comparison period: [periods]. Freshness: [latest known refresh or partition].

Safety contract: use only authorized connected sources; state dataset, source, metric definition, filters, comparison period, and freshness; preserve supplied values exactly; show calculations or evidence; flag missing or conflicting definitions; avoid inventing figures, causes, citations, or access; separate observation from hypothesis; redact unnecessary sensitive data; avoid sharing, publishing, emailing, messaging, or taking external action; require a qualified human to validate conclusions and approve any action.

List observations supported by the data, then list hypotheses that could explain them. For each hypothesis, state the evidence supporting it, evidence missing, alternative explanations, tests needed, and decision risk if treated as causal too early. Do not present correlation as causation or provide financial, legal, tax, medical, HR, or compliance advice. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • The observed KPI movement and candidate drivers from prior prompts.
  • Known interventions, launches, outages, campaigns, or policy changes.
  • The decision being considered and the risk of acting on an unproven cause.

Expected output

The response should produce an evidence plan with ranked hypotheses, confounders, recommended tests, and a clear warning where the available data supports association only. This is useful for deciding whether to run deeper analysis, not for bypassing expert review.

Verification checkpoint

Before operational action, ask the qualified business owner, analyst, or domain expert to approve the evidence threshold. For consequential decisions, require the organization’s normal governance path rather than a chat-generated conclusion.

Prompt 17: Dashboard specification for governed KPI monitoring

Purpose

Use this prompt to turn a completed investigation into a dashboard specification. OpenAI says the Data plugin can create dashboards or reports and that dashboards can be edited, shared, and refreshed depending on connected tools and user access; however, publishing to a ChatGPT Site copies analysis data into the published site, so audience review is mandatory.

Copy-paste prompt

@Data Draft a governed dashboard specification for this KPI using only authorized connected sources. Dataset: [dataset or table family]. Source: [warehouse, BI report, semantic layer, file, or dashboard]. Metric definition: [exact definition]. Filters: [scope]. Comparison period: [default comparison]. Freshness: [refresh cadence and latest known timestamp].

Safety contract: use only authorized connected sources; state dataset, source, metric definition, filters, comparison period, and freshness; preserve supplied values exactly; show calculations or evidence; flag missing or conflicting definitions; avoid inventing figures, causes, citations, or access; separate observation from hypothesis; redact unnecessary sensitive data; avoid sharing, publishing, emailing, messaging, or taking external action; require a qualified human to validate conclusions and approve any action.

Specify dashboard audience, purpose, source-of-truth tables or semantic models, KPI cards, trend charts, segment views, quality checks, freshness indicators, filters, caveats, refresh expectations, and validation owners. If a ChatGPT Site or BI publication is requested, stop before publishing and list the permission, audience, and copied-data review required. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • The intended audience, decision cadence, and dashboard owner.
  • The governed KPI definition, source, filters, and refresh expectation.
  • Any sensitive segments or fields that should not appear in published views.

Expected output

The agent should return a dashboard design brief with visual components, source mappings, validation checks, and publication risks. It should avoid exposing row-level records unless the approved dashboard purpose and permissions require them.

Verification checkpoint

Before publishing, confirm that the audience is authorized for the data copied into the site or BI destination. A successful source connection does not create new source permissions, and a visually polished dashboard is not evidence that definitions or permissions are correct.

Prompt 18: Chart evidence and visualization integrity review

Purpose

Use this prompt before placing a chart in an executive readout, board appendix, or operational incident review. The aim is to ensure that the chart supports the claim, preserves sampling or scope limitations, and does not hide denominator shifts, partial periods, or incompatible measures.

Copy-paste prompt

@Data Review the chart evidence for this KPI claim using only authorized connected sources. Dataset: [dataset or table family]. Source: [warehouse, BI report, semantic layer, file, or dashboard]. Metric definition: [exact definition]. Filters: [scope]. Comparison period: [periods shown in the chart]. Freshness: [latest known refresh or partition].

Safety contract: use only authorized connected sources; state dataset, source, metric definition, filters, comparison period, and freshness; preserve supplied values exactly; show calculations or evidence; flag missing or conflicting definitions; avoid inventing figures, causes, citations, or access; separate observation from hypothesis; redact unnecessary sensitive data; avoid sharing, publishing, emailing, messaging, or taking external action; require a qualified human to validate conclusions and approve any action.

Evaluate whether the chart type, axis, aggregation, denominator, time grain, filters, color encoding, labels, and annotations accurately support the stated claim. Show the underlying numbers behind the chart, identify partial-period or sampling caveats, and recommend a safer chart if the current one could mislead. Do not create or publish the final external readout without human approval. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • The exact claim the chart is intended to support.
  • The chart data source, calculation, filters, period, and refresh timestamp.
  • Any sampling notice, unclassified activity, or known reporting limitation.

Expected output

The output should include a chart-integrity checklist, the table of numbers behind the visual, and recommended wording for the evidence caveat. If the chart uses measures such as messages, credits, tokens, active users, or task classifications, the response should keep those measures distinct rather than treating them as interchangeable.

Verification checkpoint

Have the chart owner confirm that the visualization, title, and executive takeaway match the governed data. If the evidence supports only a descriptive observation, remove causal language before the chart is shared, published, emailed, or used to approve action.

Prompts 19–25: refresh checks, lineage, sensitivity, stakeholder review, actions, approvals, and executive readouts

The final seven prompts turn a KPI investigation from a promising analysis into a governed decision artifact. OpenAI says the Data plugin can connect to approved enterprise sources, use semantic-layer context, build dashboards or reports, and refresh shared analysis depending on connected tools and user access; OpenAI also warns that users must verify source, period, filters, freshness, and metric definitions before relying on results. Use these prompts after the variance, cohort, quality, reconciliation, dashboard, and chart-evidence work is complete, not as a substitute for those controls.

Prompt 19: Refresh check for dashboard and KPI evidence

Purpose

Use this prompt before a KPI dashboard, Site, or report is distributed. It asks the Data agent to document whether the analysis reflects the intended refresh window, whether upstream tables or files lag the business period, and whether a stale extract could change the conclusion.

Copy-paste prompt

@Data Review the refresh status for this KPI investigation using only authorized connected sources. State the dataset, source system, governed metric definition, filters, comparison period, and latest available freshness timestamp for every table, file, semantic-layer object, dashboard, or report used. Preserve all supplied values exactly; do not normalize dates, segments, or thresholds unless I ask. Show the evidence for each freshness claim, including last refresh time, latest business event date, expected cadence, and any lag versus the analysis period. Flag missing or conflicting definitions, unavailable freshness metadata, partial refreshes, failed jobs, stale extracts, or filters that could change the KPI. Avoid inventing figures, causes, citations, permissions, or access. Separate observation from hypothesis. Redact unnecessary sensitive data and summarize personal or customer-level details only when essential. Do not share, publish, email, message, update a dashboard, trigger a refresh, or take any external action. A qualified human must validate the conclusion and approve any action before the analysis is used. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • KPI name, metric definition, source system, and semantic-layer object if one exists.
  • Analysis period, comparison period, reporting cutoff, and expected refresh cadence.
  • Dashboard, report, workbook, Site, or connected BI artifact under review.

Expected output

The agent should return a refresh matrix with source name, latest data timestamp, refresh cadence, freshness status, known failures, and conclusion impact. The strongest output is not “fresh” or “stale” alone; it explains whether the lag is material to the KPI decision.

Verification checkpoint

Compare the reported freshness against the warehouse scheduler, BI refresh history, semantic-layer metadata, and the trusted operating report. If any source is stale or ambiguous, mark the executive finding as provisional.

Prompt 20: Source lineage map for KPI evidence

Purpose

This prompt creates a lineage record from operational source to governed metric, so reviewers can see where transformations, joins, filters, and semantic definitions enter the calculation. It is especially useful when a KPI differs from a trusted report or when multiple BI tools expose similar-looking measures.

Copy-paste prompt

@Data Build a source-lineage map for this KPI using only authorized connected sources. State the dataset, source system, governed metric definition, filters, comparison period, and freshness for each upstream object. Preserve supplied values exactly. Trace the KPI from original source tables or approved business files through transformations, semantic-layer definitions, joins, filters, derived fields, dashboards, and final chart or table outputs. Show calculations or evidence for every material transformation. Flag missing or conflicting definitions, undocumented joins, ambiguous grain, inactive models, stale dashboards, and permissions that prevent verification. Avoid inventing figures, causes, citations, lineage, or access. Separate observation from hypothesis. Redact unnecessary sensitive data and avoid exposing raw customer, employee, health, banking, legal, or identity data unless explicitly authorized and necessary. Do not share, publish, email, message, modify models, change permissions, or take external action. A qualified human must validate conclusions and approve any action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • KPI, source-of-truth preference, and named dashboards or semantic-layer objects.
  • Known transformations, dbt models, BI calculations, spreadsheet formulas, or warehouse views to inspect.
  • Business grain, such as account-day, subscription-month, order-line, opportunity, or user-session.

Expected output

The output should be a lineage chain, a transformation summary, a grain declaration, and a list of unverifiable links. Treat unverifiable links as risks, not as proof that the number is wrong.

Verification checkpoint

Have the metric owner or analytics engineer confirm the lineage before the KPI is cited externally or used for compensation, forecast, staffing, or customer commitments.

Prompt 21: Sensitivity and privacy review before sharing KPI outputs

Purpose

Use this prompt to reduce overexposure before a dashboard, Site, slide, or narrative leaves the analyst’s working context. OpenAI’s Data plugin guidance says publishing a dashboard to a ChatGPT Site copies the analysis data into the published site, so audience and permission review are mandatory.

Copy-paste prompt

@Data Perform a sensitivity review of the KPI analysis using only authorized connected sources. State the dataset, source system, governed metric definition, filters, comparison period, and freshness. Preserve supplied values exactly. Identify whether the output contains customer records, employee data, health information, identity documents, banking details, privileged legal material, security-sensitive paths, contractual terms, small-cell segments, confidential forecasts, or other unnecessary sensitive data. Show evidence for each sensitivity classification without exposing more detail than needed. Flag missing or conflicting definitions, unresolved permissions, audience mismatch, copied analysis data in a published Site, and any result that should be aggregated, suppressed, redacted, or withheld. Avoid inventing figures, causes, citations, sensitivity labels, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, email, message, change permissions, or take external action. A qualified human must validate conclusions and approve any action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • Intended audience, distribution channel, and whether the output may be published to a Site or BI tool.
  • Minimum acceptable aggregation level and any legal, HR, finance, security, or customer-contract restrictions.
  • Draft tables, charts, dashboard tiles, or narrative bullets to review.

Expected output

The agent should produce a sensitivity register with data category, exposure reason, recommended treatment, and reviewer owner. Recommended treatments may include aggregation, suppression, redaction, audience restriction, or withholding until policy review.

Verification checkpoint

Confirm the audience against source permissions and organizational policy. Treat a bearer-style shared artifact, exported file, message, or copied screenshot as potentially visible beyond the original workspace.

Prompt 22: Stakeholder questions and unresolved decision gaps

Purpose

This prompt converts analysis uncertainty into review questions for metric owners, operators, finance partners, security teams, or executives. It keeps the Data agent from presenting a polished but under-reviewed conclusion when business context is missing.

Copy-paste prompt

@Data Generate stakeholder review questions for this KPI investigation using only authorized connected sources. State the dataset, source system, governed metric definition, filters, comparison period, and freshness. Preserve supplied values exactly. Base questions on the observed calculations, evidence, lineage, data-quality checks, reconciliation status, and dashboard outputs. Flag missing or conflicting definitions, unverified assumptions, unexplained variance, cohort or segment shifts, freshness risks, small-sample concerns, and decisions that need business-owner judgment. Avoid inventing figures, causes, citations, stakeholder positions, or access. Separate observation from hypothesis and label each question by owner type, such as metric owner, analytics engineer, finance, sales operations, product, support, legal, privacy, or security. Redact unnecessary sensitive data. Do not share, publish, email, message, assign tasks, update systems, or take external action. A qualified human must validate conclusions and approve any action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • Current KPI finding, variance amount, affected segments, and confidence level.
  • Known unresolved issues from refresh, lineage, reconciliation, or sensitivity review.
  • Decision deadline and stakeholder roles, not private personal details.

Expected output

The agent should return a prioritized question list with owner type, reason, required evidence, and decision impact. Good questions distinguish “needed to validate the number” from “needed to decide what to do.”

Verification checkpoint

Review the questions for unnecessary personal data, implied blame, or premature causality. Analytics evidence can show activity and association; it does not, by itself, prove cause, financial value, legal compliance, or individual performance.

Prompt 23: Action options without premature automation

Purpose

Use this prompt after the KPI movement is validated enough to discuss operational responses. The goal is to frame reversible, evidence-linked options without letting the agent execute writes, send messages, change permissions, or make commitments.

Copy-paste prompt

@Data Propose action options for this KPI finding using only authorized connected sources. State the dataset, source system, governed metric definition, filters, comparison period, and freshness. Preserve supplied values exactly. Tie each option to observed evidence, calculations, affected segments, cohort behavior, funnel step, data-quality limitation, or stakeholder question. Flag missing or conflicting definitions, weak evidence, unvalidated causal assumptions, material privacy or security concerns, and actions that require finance, legal, HR, compliance, customer, or executive approval. Avoid inventing figures, causes, citations, projected gains, costs, access, or guaranteed outcomes. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, email, message, create tickets, change dashboards, execute connected-tool actions, change permissions, make purchases, or take external action. A qualified human must validate conclusions and approve any action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • Validated KPI movement, impacted segment, confidence level, and known limitations.
  • Business constraints, acceptable risk level, reversibility requirement, and decision owner.
  • Actions that are explicitly off-limits without separate approval.

Expected output

The agent should provide an option table with evidence link, expected mechanism, risk, reversibility, required approval, and monitoring metric. It should include a “do nothing yet” option when evidence is insufficient.

Verification checkpoint

Do not treat suggested actions as approved actions. Require an accountable human owner for any external communication, operational write, budget change, customer impact, policy change, or dashboard publication.

Prompt 24: Approval gate before publication or operational action

Purpose

This prompt turns a KPI investigation into an approval checklist. It is designed for teams that need a clean record showing what was validated, what remains uncertain, and who must approve publication or action.

Copy-paste prompt

@Data Prepare an approval-gate checklist for this KPI investigation using only authorized connected sources. State the dataset, source system, governed metric definition, filters, comparison period, and freshness. Preserve supplied values exactly. Summarize evidence for calculations, lineage, refresh status, reconciliation, data quality, sensitivity review, stakeholder questions, and proposed actions. Flag missing or conflicting definitions, unapproved audiences, copied analysis data in any Site or shared artifact, unresolved source discrepancies, and approval gaps. Avoid inventing figures, causes, citations, reviewers, permissions, or access. Separate observation from hypothesis and label any recommendation as a recommendation. Redact unnecessary sensitive data. Do not share, publish, email, message, approve, execute, modify permissions, update dashboards, or take external action. A qualified human must validate conclusions and approve any action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • Draft executive finding, dashboard or report location, intended audience, and action proposal.
  • Names of role-based approvers or approval groups, avoiding unnecessary personal details.
  • Known exceptions, limitations, and required sign-off sequence.

Expected output

The output should be an approval checklist grouped by metric validity, source governance, privacy, security, business decision, and publication readiness. It should clearly mark “approved,” “blocked,” “conditional,” and “not reviewed.”

Verification checkpoint

Require explicit human approval for publication, external messages, connected-tool actions, permission changes, financial decisions, legal or compliance assertions, HR use, or customer-facing commitments.

Prompt 25: Executive readout and reproducibility packet

Purpose

The final prompt produces an executive-ready summary plus a reproducibility packet that another authorized reviewer can inspect. It should not hide uncertainty; it should make the conclusion, evidence, limitations, and approval status easy to audit.

Copy-paste prompt

@Data Create an executive readout and reproducibility packet for this governed KPI investigation using only authorized connected sources. State the dataset, source system, governed metric definition, filters, comparison period, and freshness. Preserve supplied values exactly. Include the KPI question, calculation steps, evidence tables, chart references, source lineage, refresh status, data-quality checks, reconciliation result, sensitivity review, stakeholder questions, action options, approval-gate status, and unresolved limitations. Show calculations or evidence for every material claim. Flag missing or conflicting definitions, stale data, audience risks, unapproved actions, and any result that differs from a trusted report. Avoid inventing figures, causes, citations, access, approvals, savings, legal conclusions, compliance conclusions, or guaranteed outcomes. Separate observation from hypothesis and recommendation. Redact unnecessary sensitive data. Do not share, publish, email, message, update a Site, trigger connected-tool actions, change permissions, or take external action. A qualified human must validate conclusions and approve any action. Control contract: Use only authorized connected sources. State the source, metric definition, filters, comparison period, and data freshness. Preserve supplied values and show calculations and evidence. Flag missing or conflicting definitions and do not invent figures, causes, citations, or access. Separate observation from hypothesis. Redact unnecessary sensitive data. Do not share, publish, send, message, or take external action. A qualified human must validate conclusions and provide human approval before any action.

Required inputs

  • Final KPI question, source-of-truth selection, comparison period, dashboard references, and decision deadline.
  • Approved audience, required reviewers, and publication constraints.
  • All unresolved caveats that must remain visible in the readout.

Expected output

The readout should contain a concise executive summary, a decision table, evidence appendix, reproducibility steps, data dictionary excerpt, review log, and approval status. The reproducibility packet should enable an authorized reviewer to rerun or inspect the analysis without requesting credentials or exposing unnecessary sensitive records.

Verification checkpoint

Before circulation, verify that the metric owner accepts the definition, the data owner accepts the source and permissions, and the business owner accepts the decision framing. If the output is published to a Site, confirm that copied analysis data is appropriate for the audience.

KPI-risk table for the final review

Risk area Typical failure mode Minimum control before action
Freshness The dashboard uses a stale extract while the warehouse has newer data, or one upstream table refreshed later than another. Record latest data timestamp, expected cadence, refresh failures, and whether lag could change the conclusion.
Lineage A KPI is calculated through undocumented joins, spreadsheet logic, or a BI-only measure that differs from the semantic layer. Trace source tables, transformations, semantic definitions, filters, grain, and final report objects.
Sensitivity A chart or table exposes small segments, customer records, employee details, or copied analysis data to an audience that should not receive it. Aggregate, suppress, redact, restrict audience, or withhold until privacy, security, legal, or data-owner review is complete.
Causality A variance is described as caused by a campaign, product change, outage, or team behavior without independent evidence. Separate observed movement from hypothesis and define the evidence needed to test the hypothesis.
Action authority The analysis is used to trigger messages, operational writes, budget shifts, customer commitments, or permission changes without approval. Use an approval gate with named role owners and block external action until a qualified human approves it.

Reviewer workflow for governed KPI investigations

  1. Analyst review: Confirm the prompt inputs, metric definition, source, filters, comparison period, and freshness. Preserve the agent’s limitations rather than rewriting them away.
  2. Metric-owner review: Validate the governed KPI definition, semantic-layer alignment, numerator, denominator, grain, and business interpretation.
  3. Data-owner or analytics-engineering review: Check lineage, refresh status, joins, transformations, reconciliation against trusted reports, and known data-quality issues.
  4. Privacy and security review: Inspect whether the output contains unnecessary sensitive data, small-cell exposure, confidential forecasts, privileged material, or audience-permission mismatches.
  5. Business-owner review: Decide whether the evidence supports an action, a monitoring period, a deeper investigation, or no action yet.
  6. Approval and distribution: Approve only the specific artifact, audience, channel, and action. A dashboard, Site, exported file, email, or message can create a new disclosure context.

Final operating guidance

OpenAI describes the Data agent as able to connect to approved enterprise data sources, investigate business questions, refine analyses through follow-up questions, and create dashboards or reports, while administrators control available connections and roles. That capability does not remove the need for semantic governance, source-of-truth selection, data-quality checks, human review, or independent validation.

Use these final prompts as a closing control sequence: refresh, lineage, sensitivity, stakeholder questions, action options, approval gate, and executive readout. If any step fails, do not polish the narrative to compensate; return to the source definition, data pipeline, dashboard specification, or stakeholder review that failed.

Do not ask the Data agent for credentials, access tokens, full customer records, health information, identity documents, banking details, privileged legal material, or unnecessary personal data. Queries may enforce connected-account table, row, and column permissions, but permission enforcement is not the same as suitability for a particular audience or use.

When a result conflicts with a trusted report, treat the discrepancy as a governance event. Verify source, time period, filters, freshness, metric definition, grain, and semantic-layer logic before escalating a business claim. If the discrepancy remains unresolved, the executive readout should say that directly.

For ChatGPT Work and Codex users, remember that current behavior can vary by workspace policy, plan, region, connected app, rollout, and administrator configuration. A prompt that works in one workspace may produce a blocked, partial, or differently scoped result in another, and that difference should be documented rather than hidden.

Access 40,000+ AI Prompts for ChatGPT, Claude & Codex — Free!

Get instant access to our complete Notion Prompt Library — the largest curated collection of prompts for ChatGPT, Claude, OpenAI Codex, and other leading AI models. Optimized for real-world workflows across coding, research, content creation, and business.

Access Free Prompt Library →

Useful Links

Get Free Access to 40,000+ AI Prompts for ChatGPT, Claude & Codex

Subscribe for instant access to the largest curated Notion Prompt Library for AI workflows.

More on this