Cowork

When it runs unattended: what to set up first

Cowork

Walking away removes the only control most people rely on. Five things to settle before you do, starting with where the task actually runs.

Applies to
Claude Fable 5.1 Claude Opus 5 Claude Sonnet 5 Claude Haiku 4.5
Last verified
Reviewed by
Timothy Fehr

Watching an agent work is a control, even when it feels like idling. You see a file open that should not be open, you stop it. Walk away and that control is gone, and nothing replaces it automatically.

Five things to settle first. The first one decides whether the task runs at all.

Where it runs decides whether it survives you leaving

The most common surprise. A local task needs your machine present: "Your computer must be awake and the app must be open for Claude to work on tasks". Close the lid and it stops.

A cloud session is the one that keeps going. Anthropic's own instruction is direct: "If you want Claude to keep working while your computer is off, start a cloud session instead."

So "unattended" has two meanings, and only one of them means you can leave. Cloud or local covers what else changes with that choice, including the governance side, which runs opposite to intuition.

Scope, because you will not be there to narrow it

Everything in reach is in reach for the whole run. The folder, connector and screen grants you make are the boundary, and mid-task is exactly when you cannot adjust them.

Connect the narrowest folder that contains the work. For anything you could not reconstruct, work on a copy — an unattended task acting on the only version of something is the scenario with no recovery path.

The stopping condition, written down

An agent with no criterion for done keeps going. Anthropic's advice for writing a goal applies harder here, because nobody is present to say "that's enough".

State what finished looks like, what is out of scope, and what to do when something is ambiguous. "Where a field is missing, write 'unclear' rather than inferring it" is a better instruction unattended than it is while watching, because you will not be there to catch an inference.

Where the approvals will land

You get a push notification "when a task is done or when Claude needs your go-ahead". That is the mechanism, and it only helps if the notification reaches somewhere you are.

Check this before a long run: are notifications on, on the device you will actually have? An approval prompt nobody answers is a task that stalled rather than one that failed, and the two look different in the trail.

What you will read afterwards

You are going to review work you did not watch. That review is a different skill from watching, and it has its own page: reviewing agent output you did not watch being made.

The short version: read the step trail for what it touched, then check the filesystem rather than the summary. The summary is the agent's account of itself.

Try this

Before your first genuinely unattended run, do the same task while watching and note every point where you intervened. Each one is a control you are about to remove.

Turn the ones that mattered into instructions, and the ones you cannot turn into instructions are the reason to keep that task attended for now.

What goes wrong

Assuming local keeps running. It needs the machine awake and the app open.

Granting for the hardest case. Broad access set up once persists into every later run, including the ones you did not think about.

No stopping condition. The failure is not an error, it is thirty steps of plausible work in a direction you did not want.

Notifications off. The approval arrives and nothing surfaces it.

Reviewing the summary. It is generated by the thing you are checking.

How to check it worked

After the run, compare what the step trail says it touched against what actually changed on disk. If those match and the result is right, the setup held. If the trail lists something you did not expect it to reach, the scope was wider than the task needed. Fix that before the next run; after a worse one is too late.

Sources

  1. Assign tasks from anywhere in Claude Cowork — Anthropic Help Center Tier 1 2026-09-04
  2. Use Claude Cowork safely — Anthropic Help Center Tier 1 2026-09-04