Cowork

Undo, blast radius, and working on copies

Cowork

Cowork has no documented undo. Deletion asks permission; editing does not. Decide what it can reach before you start, not after.

Applies to
Claude Fable 5.1 Claude Opus 5 Claude Sonnet 5 Claude Haiku 4.5
Last verified
Reviewed by
Timothy Fehr

This is the first page in this track for a reason. Everything else about Cowork is convenience; this is the one that stops you losing a folder.

The asymmetry

Claude requires explicit permission before permanently deleting any file. That is a real protection and it is worth knowing you have it.

Editing is not deletion. A file rewritten badly is not recovered by a deletion prompt that never fired. Overwriting, restructuring, reformatting, "tidying" — these are ordinary agent actions on a folder you connected, and nothing stops them the way deletion is stopped.

Decide the blast radius first

Blast radius is simply: if this task goes as badly as it plausibly could, what is gone? You set that number when you connect a folder, not when something goes wrong.

Connect the narrowest folder that contains the work. Not your home directory. Not Documents. The project folder. Everything outside it is free protection that costs you nothing.

Work on a copy for anything you cannot reconstruct. Duplicate the folder, point Cowork at the duplicate, review the result, then move it across yourself. This feels like ceremony for about a week, until the first time it saves you.

Put the real work under version control if it is the kind of work that can be. Then "undo" is a command rather than a hope.

Switch to Manually approve when the task touches sensitive files or accounts, or — in Anthropic's own framing — when mistakes would be hard to undo. The three modes are Manual, which asks each time; Auto, which lets Claude decide with safety checks; and Skip, which does no automatic review. Auto is convenient. It is not the mode for the folder containing the only copy of something.

Blast radius is bigger than the folder

Two things extend it past your filesystem, and both are worth a separate decision:

Connectors act in live systems. A connector that can send email can send email. Write access to Microsoft 365 or Google Workspace means drafts, calendar entries and files in OneDrive or SharePoint are all in range.

Computer use has no sandbox at all. Anthropic states this plainly: "computer use has no sandbox between Claude and your applications." Everything your logged-in desktop can do, it can do. Investment and cryptocurrency platforms are blocked by default and you can add your own blocklist entries — do that before the first session, not after.

Try this

Before your first real task, spend five minutes on this: duplicate a project folder, connect the duplicate, and ask Cowork to reorganise it in some way you would find annoying. Then look at what happened to the files. You are not testing Claude. You are finding out how much you can tell, after the fact, about what changed — because that is the skill you will need when it matters.

What goes wrong

Connecting a folder that is broader than the task. The most common and most expensive mistake, and the easiest to avoid. Scope is set once, at the start, by someone not yet in a hurry.

Leaving Auto approval on for everything. It is the right default for low-stakes work and the wrong one for the folder you cannot rebuild. The mode is per your judgement of the task, not a setting you configure once.

Scheduling a task that touches things you would not let it touch unsupervised. Anthropic's guidance is explicit: do not schedule tasks that access sensitive files, send messages on your behalf, or make purchases. A recurring task is an unsupervised task that runs forever.

Assuming the progress trail is a rollback log. It tells you what happened. It does not put anything back.

How to check it worked

After a task finishes, look at the folder's modification times, not at Claude's summary. Files you did not expect to change, that changed, are the finding. If you cannot answer "which files did this touch" from the folder itself, your blast radius was too wide to review — narrow it before the next run.

Sources

  1. Use Claude Cowork safely — Anthropic Help Center Tier 1 2026-08-30
  2. Get started with Claude Cowork — Anthropic Help Center Tier 1 2026-08-30
  3. Claude Cowork help collection (13 articles) — Anthropic Help Center Tier 1 2026-08-30
  4. Checkpointing — Claude Code documentation Tier 1 2026-08-30