Skip to main content
Cowork is the same agentic architecture that powers Claude Code, with the terminal removed and ordinary work put in its place. Instead of answering one message at a time, Claude takes a whole outcome, plans it, breaks it into subtasks, runs code and tools for as long as the job needs, and returns finished work: a formatted spreadsheet, a sorted folder, a cited report, a deck. The mental shift is from conversation to delegation. In chat, you are in every loop. In Cowork, you describe the destination, approve the route, and step away. You can steer at any point, but the work no longer waits for you between steps.

One home, two gears

There is no separate Cowork app to find. Chat and Cowork share the same message box on every surface. Select Cowork, describe the task, review the plan, let it run. Select Chat to go back to a conversation. Cowork is available on paid plans, and sessions run in the cloud, which produces its best trick: start a task at your desk, close the laptop, check progress from your phone in line for coffee, and collect the output on any device. When Claude finishes or needs input, your phone gets a notification.

Where a session actually runs

This is the part almost everyone gets wrong, and it is worth getting right because every safety property flows from it. A Cowork session is not “Claude using your computer.” It is a temporary, isolated workspace on Anthropic’s servers, with narrow, brokered bridges to everything else. Trace the routes yourself.
Four properties of that map do most of the security work:
  1. The sandbox is disposable. It is created for your session and destroyed when the session ends. Nothing persists in it, and no two sessions share state.
  2. It cannot see your network. Private, internal, and cloud-metadata addresses are unreachable, and all outbound traffic exits through a proxy the sandbox cannot reconfigure.
  3. Connector tokens never enter it. When a session uses your Gmail connector, the call happens on Anthropic’s server side. Code running in the sandbox could be fully compromised and still not hold your credentials.
  4. Your computer is reachable only through the desktop app, only for folders you connected, only while the app is online. Each local call is permission-checked before it runs. Close the app and the bridge is gone.
One honest consequence to hold alongside those: because the session runs on Anthropic’s servers, work done there, including local files opened through the bridge, is processed on those servers rather than staying on your device. On Team and Enterprise plans it is covered by the same commercial commitments as the rest of your data and is not used for training. Earlier desktop deployments ran the whole loop locally, with code executing in a dedicated Linux virtual machine on your own hardware. If you see references to hypervisors and local VMs, that is the same design philosophy, isolation around code execution, implemented on the device instead of in the cloud.

Ride along on a real task

Watching one session beats reading ten descriptions. Replay this one: twenty-three receipts in a folder become a finished expense report. You hold the same power you would in a live session, including the approval that gates the one risky step.
Everything in that replay generalizes. Claude opens with a plan you can veto. It narrates as it works, so drift is visible. Sub-agents fan out when the work is parallel. Write actions surface for approval based on your settings. And the deliverable lands as real files, not as a message you must copy somewhere.

The three approval modes

The mode selector in the chat box decides when Claude pauses for you. This choice, times the per-tool permissions you set on each connector, is the entire control surface of Cowork.
ManualManually approve

Claude pauses and asks before actions. You review each request and choose Allow or Deny. The right gear for sensitive files, first runs with a new tool, and anything hard to undo.

AutoAutomatically approve

Claude keeps moving, but a safety check reviews every action before it runs, screening for data exfiltration and prompt injection, and blocks what it judges unsafe. Blocked repeatedly, it falls back to asking you. Costs more usage, because the checking is real work.

SkipSkip all approvals

No pauses, and nothing screens actions automatically. Only defensible when you completely trust every file, site, connector, and tool in the blast radius of the task.

Two constants hold in every mode. Claude asks before permanently deleting files, always. And a tool you set to Blocked stays blocked; no mode overrides it. On Team and Enterprise plans there is a third constant worth knowing: an org setting gates whether “Always allow” even applies to write-capable connector tools in Cowork, and it is off by default, so members re-approve those per task until an admin turns it on.

The machinery around a session

Five features turn Cowork from a long-running chat into an operations desk. Each is small alone; together they change what a week looks like.
Scheduled tasks

Type /schedule in any task to make it recur, or run on demand from the sidebar. Scheduled runs happen in the cloud with no device awake. Monday metrics digests, weekly folder cleanups, recurring research sweeps.

Projects

Persistent workspaces that group related tasks with their own files, links, instructions, and memory. Within Cowork, memory lives in projects, so a project is how work stops starting from zero.

Plugins

Role-in-a-box bundles of skills, connectors, and sub-agents. Run /setup-cowork in a first session for a guided install matched to your role. Worth respecting too: installing one expands Claude’s scope of action in a single click.

Instructions

Global instructions under Settings then Cowork apply to every session: your tone, your formats, your role context. Folder instructions ride along with a connected folder, and Claude can update them as it learns the project.

Real deliverables

Excel files with working formulas, PowerPoint decks, formatted documents. Highlight text in a drafted document and choose Edit with Claude to revise in place instead of describing the change in the thread.

Where the work touches Office, Cowork passes context between the add-ins: analyze in Excel, chart it, and place the chart in a deck without shepherding the file yourself.

The two frontier capabilities

Two capabilities reach beyond the sandbox entirely, and both deserve more caution than the rest of the page put together. Browser actions let Claude open Chrome and click, type, and fill forms on real websites through the desktop app. Computer use goes further: Claude sees your screen via screenshots and operates your actual applications, asking permission per app. There is no sandbox between computer use and your desktop. Claude is trained to avoid risky operations and to flag signs of manipulation, but the honest guidance is Anthropic’s own: start with low-stakes apps, block anything with health or financial data, and watch it work, the way you would watch a capable new hire with your keyboard.

What it costs and where it still falls short

Cowork burns usage faster than chat, because multi-step work is exactly that: many model calls, many tool results, and in Auto mode a safety review on top of each action. Batch related work into one session, keep quick questions in chat, and check Settings then Usage if you are curious where it goes. Current gaps worth knowing before you lean on it: chat memory does not carry into Cowork sessions, and within Cowork, memory works through projects only. Sessions cannot be shared with other people. Live artifacts and plugins that include local MCP servers work through the desktop app only.

Failure modes

You now know what connected, delegated work looks like when it goes right. The next page is a tour of the four ways it goes wrong, including the one that is an actual attack.