Skip to main content
Everything in this lab happens in your real account with real systems, which is the point. You will wire one connector properly, feel the difference between a connected chat and a Cowork delegation, and then break things deliberately while nothing is at stake, so the failure tells are familiar before they ever matter. Plan for about 30 minutes. You need a paid Claude plan, the desktop app installed and signed in, and one everyday account you are comfortable connecting, Google Calendar or Google Drive are ideal first picks.
Part 1

Wire a connector and shape its permissions

8 min
Part 2

Work the same job in chat, then in Cowork

12 min
Part 3

Trip three failures on purpose

10 min

Part 1: Wire

  1. Open Customize, then Connectors, and click the + button to browse the directory. Find your service and notice its trust label and its capability list before you click anything.
  2. Click Connect and complete the sign-in. Read the OAuth screen for once in your life: it names exactly what you are granting.
  3. Back in Customize, then Connectors, open your new connector and find the tool permissions. Count the tools. Say out loud which are reads and which are writes.
  4. Set every write-capable tool to Needs approval. Leave reads on Always allow.
You now have the configuration this course recommends as a default: a fast reader that must ask before it acts. That took ninety seconds, and it is the single highest-leverage safety move in this entire section.

Part 2: Work

First, in a regular chat, give Claude a read task that needs the connector. For Calendar: “What does my next week look like? Flag the two most fragile days.” For Drive: “Find the three documents I touched most recently and summarize what each one is.” While it runs, watch the conversation surface the tool calls. Expand one. You are looking at the same request and result cycle from the tool call x-ray, live, with your data. Then probe inherited permissions with one question: ask for something that exists but that your account cannot see, a colleague’s private calendar, a file never shared with you. The correct behavior is a clean miss: Claude reports it cannot find or access it. Note the phrasing; this is what a permission failure looks like when nothing is broken. Now the delegation. Select Cowork in the message box, set the mode to Manual, and hand over a compound version of the same job:
Go through my next two weeks of calendar. Build me a one-page briefing document: every external meeting, who the counterpart is, and one suggested preparation note each. Draft, do not send or modify anything.
Watch three moments. The plan: Claude proposes an approach before working, and you can edit it. The narration: each step is visible as it happens. The finish: the deliverable arrives as a real document. If any approval prompts appear, read each one fully before clicking, and notice how the request is phrased as a specific action, not a vague intention.

Part 3: Break

Three sabotage probes, in ascending order of interest. Do them all. Probe one, the honest miss. Ask Claude, through the connector, for a thing that has never existed: “Find the meeting with Meridian Group about the Q9 renewal.” Watch whether it says it found nothing, or confabulates. A clean “nothing matches” is the connector working exactly as designed. If you ever see confident detail about the nonexistent, you have witnessed a judgment failure firsthand, and you will never fully trust an unverified answer again. Good. Probe two, the severed pipe. Mid-conversation, open Customize, then Connectors, and disconnect the service. Return to the chat and ask a follow-up that needs it. This is pure plumbing: note how the error announces itself compared to the quiet specificity of the permission miss in Part 2. Reconnect afterward. Probe three, the ambiguous verb. Create a scratch folder on your desktop with five junk files. In Cowork, Manual mode, point at the folder and say exactly this: “Clean this up.” Nothing more. Watch what Claude does with the ambiguity: does it ask what you mean, propose a plan, or pick an interpretation? Whatever happens next, deletions require your explicit approval, in every mode, so read the prompt with full attention and decide deliberately. Then redo the task with a bounded prompt, “Rename the files to a consistent date-first pattern, delete nothing,” and compare the two runs.

Flight card

Check items off as you land them. All ten is a completed lab.

Debrief with your facilitator

  1. Which felt more different than expected: chat with a connector, or Cowork with the same connector?
  2. Of the three probes, which failure would have fooled you a month ago, and what is the tell you will remember?
  3. Look at your real week. Name one task you would now hand to Cowork as-is, one you would hand over only with write tools on approval, and one you would not connect at all.
  4. What is the first connector you will shape for your actual work, and which of its tools will you leave on Needs approval permanently?