Choosing what it may see: folders, connectors, and the screen
Cowork
This page covers tools outside your selection. You can still read it. Find matching guides
Three separate grants, three separate decisions. Most people make the first one carefully and the other two by accident.
Cowork's reach is the sum of three grants you make separately. They are usually discussed together, which hides the fact that they carry very different risk.
1. Folders
You connect specific folders; Claude reads and writes inside them. Each local tool call is checked against your permissions before it runs.
The rule is simple, and be boring about it: connect the narrowest folder that contains the work. Anthropic's own guidance goes further — avoid granting access to local files holding sensitive information such as financial documents.
2. Connectors
Connectors reach into live systems: Google Workspace, Microsoft 365, Slack, Jira and others, including any MCP server. This is where "read" quietly becomes "act". With write tools enabled on Microsoft 365, for instance, Claude can send email, manage drafts and calendar events, change mailbox settings, and create and update files in OneDrive and SharePoint.
One genuinely reassuring detail from the architecture: connector authorization tokens never enter the sandbox. Only session-scoped tokens that expire within hours do. A compromised sandbox does not walk away with your Google credentials.
Be selective about extensions and MCP servers. Anthropic's guidance is to stick to verified extensions from the Claude Desktop directory and to evaluate what permissions any extension requests — see MCP server risk when that page lands.
3. The screen
Computer use is a separate toggle in Settings → General, and it is a different category of thing:
There are per-application permissions — Claude asks before accessing each app — and a blocklist you can add to. Investment and cryptocurrency platforms are blocked by default. Anthropic advises against using computer use to manage or act on sensitive information at all, and suggests blocking healthcare portals, banking and dating apps so Claude does not encounter things you would rather it did not.
Claude reaches for the most precise tool available first: a connector, then the browser, then screen interaction. Screen control is the fallback, not the mechanism — which means if you never enable it, most work still happens.
The network
Worth knowing, because it bounds a whole class of worry. In a cloud session all sandbox traffic passes through a mandatory proxy the sandbox cannot reconfigure or bypass, and only allow-listed destinations are reachable. The sandbox cannot reach private, internal, link-local or cloud-metadata addresses, or Anthropic-internal systems.
Separately, and under your control: only give Claude internet access to sites you trust. Untrusted pages are how prompt injection arrives.
What goes wrong
Granting folder access thoughtfully and connectors thoughtlessly. People think hard about which folder and then connect their whole mailbox. The mailbox is the bigger grant.
Enabling computer use because a task needed it once. It stays enabled. Turn it off again.
Treating "Claude asks before accessing each app" as the safety mechanism. It is a prompt, and prompts get approved by tired people. The blocklist is the control that works when you are not paying attention.
How to check it worked
Open Settings and list, out loud, everything Cowork can currently reach: which folders, which connectors and with what write scopes, whether computer use is on, and what is on the blocklist. If that list is longer than the task you are about to run needs, trim it before you start rather than afterwards.
Sources
- Use Claude Cowork safely — Anthropic Help Center Tier 1 2026-08-30
- Let Claude use your computer in Cowork — Anthropic Help Center Tier 1 2026-08-30
- Claude Cowork architecture overview — Anthropic Help Center Tier 1 2026-08-30
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.