Cowork

Cloud or local execution — what actually changes

Cowork

Where the agent loop runs decides whether your machine has to stay awake, where your files get processed, and what your admin can see.

Applies to
Claude Fable 5.1 Claude Opus 5 Claude Sonnet 5 Claude Haiku 4.5
Last verified
Reviewed by
Timothy Fehr

Cowork runs in one of two places, and the choice changes four practical things: whether your laptop has to stay awake, where your files are processed, what persists afterwards, and what an administrator can audit.

Cloud sessions — the default

The agent loop and code execution run on Anthropic's servers. Each session gets its own isolated, temporary sandbox, created when the session starts and destroyed when it ends. Sandboxes share no state with each other or across organisations, and every stored record is scoped to your organisation and account. Sessions and files are saved to your Claude account.

Network egress is tightly bounded: all traffic leaves through a mandatory proxy the sandbox cannot reconfigure or bypass, only allow-listed destinations are reachable, and the sandbox cannot reach private, internal, link-local or cloud-metadata addresses, or Anthropic-internal systems.

When a cloud session needs something on your machine, the request travels through the Claude Desktop app over an Anthropic-brokered connection.

What this buys you: the work continues server-side when your computer is offline. Close the laptop, the task carries on.

What it costs: local files Claude opens through the desktop app are processed on Anthropic's servers rather than staying on your computer. For Team and Enterprise, that conversation data is handled under the same commercial commitments as other Team and Enterprise data and is not used to train Claude.

Local sessions

The agent loop runs natively on your device. Code execution happens inside an isolated virtual machine — Apple's Virtualization.framework on macOS, Hyper-V on Windows — with its own network egress filtering, syscall restrictions and per-session user isolation. Shell commands and any code Claude writes run inside that VM, not on your host OS.

What this buys you: the processing stays on your machine.

What it costs: three things, and the third is the one that surprises people.

  1. Your computer must be awake and the Claude Desktop app open while Claude works. Dispatch to local files and apps has nowhere to run otherwise.
  2. Conversation history is stored locally.
  3. That local history is not subject to Anthropic's standard data retention policies, cannot be centrally managed or exported by admins, and deletion endpoints for local sessions are not available yet.

Choosing

Cloud when the task is long, you want to walk away, or you need it captured for compliance.

Local when the constraint is genuinely that the content must not be processed on someone else's infrastructure — and you have accepted that the history then lives outside central control.

What goes wrong

Assuming local means private and cloud means exposed. Both are more specific than that. Cloud is sandboxed, proxied and auditable; local keeps processing on your device but drops it out of central retention and export.

Starting a long local task and closing the laptop. It stops. Cloud sessions survive that; local ones do not.

Picking local for compliance reasons that local makes worse. If the driver is "we need a record of what the AI did", local is the wrong direction.

How to check it worked

Start a task, then close your laptop lid for a few minutes and reopen it. If the work continued, you were in a cloud session; if it stalled, you were local. That is a more reliable answer than the setting you think you chose.

Sources

  1. Claude Cowork architecture overview — Anthropic Help Center Tier 1 2026-08-30
  2. Use Claude Cowork on Team and Enterprise plans — Anthropic Help Center Tier 1 2026-08-30
  3. Assign tasks from anywhere in Claude Cowork — Anthropic Help Center Tier 1 2026-08-30