Cowork
Developer tasks, maintained context, and checked results with Cowork.
Cowork
This page covers tools outside your selection. You can still read it. Find matching guides
- The built-in browser: forms, logins, and what not to let it near Cowork
Every page it opens is untrusted input. Prompt injection is not a theoretical risk here; it is the expected one.
- Cloud or local execution — what actually changes Cowork
Where the agent loop runs decides whether your machine has to stay awake, where your files get processed, and what your admin can see.
- Computer use: no sandbox, per-app permissions, the blocklist Cowork
A categorically different grant from the built-in browser. Anthropic's own words: no sandbox between Claude and your applications.
- Cowork on mobile: steering from away Cowork
The phone is a good remote control for an agent and a poor cockpit. Start and redirect from anywhere; keep the heavy work where the files and review are.
- Your first Cowork task Cowork
Pick something multi-step, real, and cheap to get wrong. Fifteen minutes, on a copy.
- Parallel chunks: when splitting helps and when it fragments Cowork
You do not choose the split. Cowork decides, automatically, and what you actually control is the goal that makes a good split possible.
- Reviewing agent output you did not watch being made Cowork
The output looks the same whether it is right or wrong. Review the joins, the edges, and the things it did not say.
- When it runs unattended: what to set up first Cowork
Walking away removes the only control most people rely on. Five things to settle before you do, starting with where the task actually runs.
- Scheduled and recurring tasks Cowork
Tell it once and it runs on a schedule. Which means a grant you made in January is still acting in June, on inputs nobody reviewed.
- Reading the step trail: files opened, tools used, decisions made Cowork
Learn what a healthy run looks like while nothing is at stake, so you can recognise an unhealthy one when something is.
- Undo, blast radius, and working on copies Cowork
Cowork has no documented undo. Deletion asks permission; editing does not. Decide what it can reach before you start, not after.
- What Cowork is, and how it differs from a chat Cowork
A chat answers you. Cowork goes and does the work — across your files, your connected tools, and optionally your actual screen.
- Choosing what it may see: folders, connectors, and the screen Cowork
Three separate grants, three separate decisions. Most people make the first one carefully and the other two by accident.
- Writing a goal an agent can actually finish Cowork
Describe the finished state and what must not happen. Leave the method alone — and say what to do with the cases that do not fit.
- Chat, Projects, Cowork or Code: picking the right mode Claude + Cowork + Claude Code
Four surfaces, four cost profiles. Picking wrong is the most common reason people burn an allowance on work that did not need it.
- Incident response when an agent did something Claude + Cowork + Claude Code
The playbook assumes a human actor and an agent breaks its first three questions. Decide before the incident what your records will be able to say.