Home / Cowork, the digital colleague
What Cowork can reach, and what it must never touch
Cowork's access breaks down into three distinct layers, connected folders, direct use of your applications and screen, and an isolated network that blocks internal addresses by default; in all three cases, permanently deleting a file always asks for your confirmation.
Cowork's access breaks down into three distinct layers, and confusing these layers in your head makes you either underestimate or overestimate what Cowork can reach. The first layer is the folders you explicitly connect: as long as the second layer, computer use, stays switched off, Cowork only reads and writes what you have attached, nothing else on your drive. The second layer, distinct from the first, is direct use of your applications and your screen, switched on separately: when Cowork takes control of your computer, it clicks, types and navigates your applications the way a person sitting at the screen would. The third layer, invisible from the interface, is the network of the session itself: by default, the sandbox that runs a Cowork task has no access to any private, internal, local-network or cloud-metadata address, nor can it reach Anthropic's own internal systems; everything that leaves the session passes through a forced egress point.
Why three separate layers break a chain of attack
A content injection, hidden text in a file carrying instructions meant for Cowork rather than for you, requires two things at once: that Cowork read that untrusted content, and that it can then act with whatever access it holds. Restricting just one of the three layers, connecting only one specific folder rather than the whole drive, leaving computer use switched off when it is not needed, or relying on the network being isolated by default, already breaks part of that chain, without needing to close all three layers at once.
A door that stays shut across all three layers
One action stays protected no matter which layer is concerned: permanently deleting a file always asks for explicit confirmation, in every approval mode. Before a sensitive task, check in practice which folders appear in your project's list of connected items, and whether computer use is switched on for this particular task.
Connected folders: Invoices_2026 (read and write)
Computer use: switched off for this task
Network: isolated by default, no internal address reachable
This triple check ties into the question raised in the lesson on approval levels: the more broadly a task touches one of the three layers, the more manual mode becomes the sensible precaution.
Scope of access and nature of the action
Targeted reading
Cowork only reads this folder, nothing is changed.
Extended reading
Cowork can read more broadly, for instance via computer use, without changing anything yet.
Targeted writing
Cowork changes or creates files, but only within the connected folder.
Broad writing, maximum caution
Cowork acts directly on your applications or a whole connected drive; this is where manual approval mode matters most.
A manager creates a new Cowork project, attaches the Invoices_2026 folder from their drive to it, keeps the approval level on automatic mode, and asks Cowork to rename every file in this folder according to its invoice date.
Write in one sentence what this situation establishes, and in one sentence what it does not establish.
What this establishes: It establishes that Cowork has access to the Invoices_2026 folder explicitly attached to this project, with permission to act on it without prior validation of each step.
What this does not establish: It does not establish that Cowork could reach another folder on the same drive, nor that a file was actually deleted, since permanent deletion would stay subject to confirmation whatever mode was chosen.
The three most common miscalibrations
- Trop large Cowork can now rename or change any file on the whole drive, since automatic mode is active.
- Trop étroit This situation shows nothing more than a file name change, unrelated to Cowork's access levels.
- À côté Sorting files by invoice date shows that this folder concerns an accounting matter rather than another type of document.
- Cowork's access comes down to three distinct layers, the explicitly connected folders, direct use of your applications and your screen, and the network of the session itself.
- A malicious content injection requires both a reading of untrusted text and access to act on it; restricting just one of the three layers already breaks part of that chain.
- By default, a session's sandbox cannot reach any private, internal, local-network or cloud-metadata address, and everything that leaves it passes through a forced egress point.
- Permanently deleting a file always asks for explicit confirmation, whatever approval mode is chosen.
Open your Cowork project's settings, note the exact list of connected folders and whether computer use is switched on or off, then remove any folder the current task does not need to reach.
Every datable claim in this lesson links here to the public text behind it. A source that does not open proves nothing.
- Anthropic, using Claude Cowork safely consultée le 2026-09-02
- Anthropic, Claude Cowork architecture overview consultée le 2026-09-02