Updated
The short answer. Claude Cowork can be used for approved business tasks when the organization limits connected folders, network destinations, tools, account access, and approvals. Cloud sessions execute code on Anthropic’s servers, save sessions and files to the member’s Claude account, and process any local files opened through the desktop connection on Anthropic’s servers.
Give Cowork a dedicated working folder, keep sensitive files and credentials outside it, limit network egress, require fresh approval for permission-gated actions, and review the result before it changes a business system.
What Claude Cowork can access
Anthropic states that Cowork’s agent loop, shell commands, and code execution run in an isolated cloud environment. The isolation protects the user’s computer while access still follows the connected folders, tools, and network policy (Get started with Claude Cowork).
For a cloud session, local file or browser access travels through the desktop app. File access is limited to connected folders, and each local tool call is checked against the member’s permissions. Outbound sandbox traffic passes through an enforced proxy and reaches allowed destinations (Cowork architecture overview).
Prompt injection and real actions
Cowork can read, write, and permanently delete files inside granted folders. Anthropic documents an explicit permission prompt before permanent file deletion. It also warns that internet content can carry prompt injection that directs the agent toward unintended actions (Use Claude Cowork safely).
- Connect a dedicated folder containing copies of the files required for the task.
- Keep credentials, financial documents, health records, and unrelated client files outside the connected folder.
- Limit internet access to destinations required for the workflow.
- Require fresh approval for permission-gated tool calls and inspect the planned actions.
- Keep backups and review generated files before publishing or replacing originals.
Cowork in the cloud is excluded from BAA coverage
As of 2026-10-07, Anthropic’s BAA page lists Cowork in the cloud as excluded from BAA coverage. It also states that Cowork in the cloud is unavailable when the HIPAA configuration for local Claude Code and Cowork is applied. Cowork in Claude Desktop has separate eligibility and configuration requirements (Business Associate Agreements for commercial customers).
Use Is Claude HIPAA compliant? to review the eligible products and agreement requirements. Do not place protected health information in Cowork in the cloud.
Safe setup for a company
- Choose the company workspace. Record the plan, organization owner, retention setting, and enabled Cowork surfaces.
- Set the execution choice. Team and Enterprise owners can control whether cloud sessions are enabled (Cowork on Team and Enterprise).
- Create a working folder. Put task copies in one folder and grant access only to that folder.
- Restrict destinations and tools. Approve required sites and MCP connections, and remove unused access.
- Require review. Review the plan, approvals, file changes, and final output before an external action.
- Publish the rule. Add Cowork to the AI acceptable use policy and the shadow AI inventory.
Where Sentinel fits
SUPERWISE® Sentinel replaces credit card numbers, IBANs, Social Security numbers, passport numbers, MAC addresses, VINs, and labeled dates of birth and medical record numbers with placeholders before a prompt leaves the PC, and logs every request. It does not redact names or passwords. Apply it only to routes the company has configured and tested.
Cowork permissions define what the agent can reach. Sentinel addresses supported values in routed requests. The PII redaction guide explains how to test coverage and document limits.
Frequently asked questions
Is Claude Cowork secure?
Claude Cowork uses an isolated execution environment, file permissions, network controls, and approval settings. A company must configure those controls for its data, accounts, destinations, and review process.
Can Claude Cowork access my files?
Cowork can read and write files in connected folders. Cloud sessions reach local files through the desktop app, and each local tool call is checked against the member’s permissions.
Does Claude Cowork run in the cloud?
Anthropic states that Cowork sessions run in the cloud by default on its current surfaces. The agent loop and code execution run on Anthropic servers, and sessions and files are saved to the member’s Claude account.
Is Cowork in the cloud covered by Anthropic’s BAA?
No. Anthropic’s BAA page lists Cowork in the cloud as excluded from BAA coverage and unavailable when the HIPAA configuration for local Claude Code and Cowork is applied.
Sources
All read on 2026-10-07.
- https://support.claude.com/en/articles/13345190-get-started-with-claude-cowork
- https://support.claude.com/en/articles/14479288-claude-cowork-architecture-overview
- https://support.claude.com/en/articles/13364135-use-claude-cowork-safely
- https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans
- https://privacy.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers