Skip to content
Mastering Claude

Home / Cowork, the digital colleague

Cowork, the digital colleague8 minFondation

What Cowork can reach, and what it must never touch

Cowork's access breaks down into three distinct layers, connected folders, direct use of your applications and screen, and an isolated network that blocks internal addresses by default; in all three cases, permanently deleting a file always asks for your confirmation.

Cowork's access breaks down into three distinct layers, and confusing these layers in your head makes you either underestimate or overestimate what Cowork can reach. The first layer is the folders you explicitly connect: as long as the second layer, computer use, stays switched off, Cowork only reads and writes what you have attached, nothing else on your drive. The second layer, distinct from the first, is direct use of your applications and your screen, switched on separately: when Cowork takes control of your computer, it clicks, types and navigates your applications the way a person sitting at the screen would. The third layer, invisible from the interface, is the network of the session itself: by default, the sandbox that runs a Cowork task has no access to any private, internal, local-network or cloud-metadata address, nor can it reach Anthropic's own internal systems; everything that leaves the session passes through a forced egress point.

Why three separate layers break a chain of attack

A content injection, hidden text in a file carrying instructions meant for Cowork rather than for you, requires two things at once: that Cowork read that untrusted content, and that it can then act with whatever access it holds. Restricting just one of the three layers, connecting only one specific folder rather than the whole drive, leaving computer use switched off when it is not needed, or relying on the network being isolated by default, already breaks part of that chain, without needing to close all three layers at once.

A door that stays shut across all three layers

One action stays protected no matter which layer is concerned: permanently deleting a file always asks for explicit confirmation, in every approval mode. Before a sensitive task, check in practice which folders appear in your project's list of connected items, and whether computer use is switched on for this particular task.

Connected folders: Invoices_2026 (read and write)
Computer use: switched off for this task
Network: isolated by default, no internal address reachable

This triple check ties into the question raised in the lesson on approval levels: the more broadly a task touches one of the three layers, the more manual mode becomes the sensible precaution.

Figure 1

Scope of access and nature of the action

Precisely connected folder
Broad access or active computer use
Read only

Targeted reading

Cowork only reads this folder, nothing is changed.

Extended reading

Cowork can read more broadly, for instance via computer use, without changing anything yet.

Writing or real action

Targeted writing

Cowork changes or creates files, but only within the connected folder.

Broad writing, maximum caution

Cowork acts directly on your applications or a whole connected drive; this is where manual approval mode matters most.

The matrix crosses the breadth of the access granted with the read-or-write nature of the action: the bottom-right quadrant, broad access and real writing, is where vigilance needs to be highest.
Calibrate it yourself

A manager creates a new Cowork project, attaches the Invoices_2026 folder from their drive to it, keeps the approval level on automatic mode, and asks Cowork to rename every file in this folder according to its invoice date.

Write in one sentence what this situation establishes, and in one sentence what it does not establish.

What to remember
  • Cowork's access comes down to three distinct layers, the explicitly connected folders, direct use of your applications and your screen, and the network of the session itself.
  • A malicious content injection requires both a reading of untrusted text and access to act on it; restricting just one of the three layers already breaks part of that chain.
  • By default, a session's sandbox cannot reach any private, internal, local-network or cloud-metadata address, and everything that leaves it passes through a forced egress point.
  • Permanently deleting a file always asks for explicit confirmation, whatever approval mode is chosen.
Do this now

Open your Cowork project's settings, note the exact list of connected folders and whether computer use is switched on or off, then remove any folder the current task does not need to reach.

Check the source

Every datable claim in this lesson links here to the public text behind it. A source that does not open proves nothing.