Business and governance

Admin controls: what you can actually govern

Claude

The settings that exist, the defaults that differ between Team and Enterprise, and the gap where local sessions sit outside central control.

Applies to
Claude Fable 5.1 Claude Opus 5 Claude Sonnet 5 Claude Haiku 4.5
Last verified
Reviewed by
Timothy Fehr

Governance conversations tend to run on assumptions about what an administrator can switch. Here is what actually exists for the agentic surfaces, where the defaults sit, and the one gap that surprises people.

The settings that exist

Cowork is governed under Organization settings → Cowork. The current toggles and their defaults per plan are listed in Anthropic's Team and Enterprise article; one of them carried a dated transition when this page was first written, which is the kind of detail a copy gets wrong within the month.

Two of the defaults deserve a deliberate decision rather than acceptance.

Cloud sessions decide where processing happens. On Team they are on, which means local files Cowork opens through the desktop app are processed on Anthropic's servers. On Enterprise they are off. Whichever side you are on, be on it because you chose it.

"Always allow" for connector tools is off by default, and that is the conservative setting. Leaving it alone is usually right: it keeps a human in the loop for the actions that reach live systems.

Scope: all-or-nothing versus groups

On Team, Cowork is all-or-nothing for the organisation. There is no mechanism to enable it for one department.

On Enterprise, groups and custom roles can scope both Cowork itself and the separate "Run Cowork in the cloud" capability to specific users or teams.

That difference tends to matter more than any individual toggle. A governance model that assumes per-group control will not survive contact with a Team plan.

Computer use is a separate grant

Worth stating plainly because it is a different category of risk. Computer use lets Claude click and type in desktop applications, and Anthropic is explicit that it has no sandbox between Claude and your applications. It carries per-application permissions and a blocklist, with investment and cryptocurrency platforms blocked by default.

The built-in browser, by contrast, runs inside the sandbox with egress through a mandatory proxy it cannot bypass. Where a task can be done in the browser, that is the safer surface by a wide margin.

The audit gap

The part that catches compliance teams out.

Cloud sessions via Claude, Claude Desktop and Claude Mobile are captured in the Compliance API. OpenTelemetry can stream Cowork events to your SIEM, although Anthropic states this does not replace audit logging for compliance purposes.

Local sessions are different. Conversation history stays on the user's own computer, sits outside Anthropic's standard data retention policies, cannot be centrally managed or exported by admins, and deletion endpoints for it are not available yet.

This inverts a common assumption. Local execution feels like the cautious choice, and for data residency it often is. For governance it is the looser one, because the record lives on a laptop rather than in a system you can query. If your driver is "we need to show what the AI did", local execution works against you.

A shorter checklist than you expect

  • Decide cloud versus local deliberately, and know which default applies
  • Leave "Always allow" for connector tools off unless a specific case earns it
  • Keep computer use off until a task genuinely needs it, then use the blocklist
  • Confirm what your compliance obligations require, then check whether local sessions break that assumption
  • Write down who reviews these settings and when

What goes wrong

Assuming per-group control on a Team plan. It is organisation-wide there.

Accepting defaults as decisions. Cloud sessions and the built-in browser default differently between Team and Enterprise, and both affect where work happens.

Treating local execution as the compliant option. It removes central visibility, which is the opposite of what most compliance drivers want.

Enabling computer use for one task. It stays enabled, and it is the one surface with no sandbox.

Relying on OpenTelemetry as the audit trail. It is observability, and Anthropic says so.

How to check it worked

Open the organisation settings and read the current state aloud against the article's list. Then ask which of those values somebody actually chose. Anything you cannot attribute to a decision is a default you have inherited, and inherited defaults are how a governance model quietly stops describing reality.

Sources

  1. Use Claude Cowork on Team and Enterprise plans — Anthropic Help Center Tier 1 2026-08-31
  2. Claude Cowork architecture overview — Anthropic Help Center Tier 1 2026-08-31
  3. Let Claude use your computer in Cowork — Anthropic Help Center Tier 1 2026-08-31