Skip to content
Mastering Claude

Home / Putting Claude to work on real files

Putting Claude to work on real files10 minFoundation

What Cowork sees and what it does not see

The files Cowork reads and modifies are those in the folders you have connected, but its view does not stop at files: depending on how you open it, it also sees your screen.

Cowork only modifies files inside folders you have explicitly connected. The rest of the disk, including a neighbouring folder you consult every day, escapes its writes for as long as you have not added it yourself. But the file boundary is not the only one, and this lesson would be misleading if it stopped there.

What Cowork sees beyond the files

As recorded on 2 September 2026, Anthropic's documentation states two things a beginner must know before their first task. First, when you authorise it to use your computer, application by application, Claude takes screenshots of your screen to understand what is happening there. Second, in a session opened from Chrome's side panel, it sees the displayed page, including a page behind authentication. The isolation of execution, often presented as a sandbox, protects your computer from the code being run, it does not reduce what Claude can read through the access you have granted it. The immediate practical consequence: close or hide whatever has nothing to do with the task before starting a session, the way you would before sharing your screen on a video call.

What happens inside a connected folder

Once a folder is connected, the boundary changes nature. Claude can read, write and permanently delete files there, which means an imprecise instruction, or an instruction hidden inside a document Claude reads, can genuinely erase something. One safeguard nonetheless holds across all approval modes, including the most permissive: Anthropic's documentation, as recorded on 2 September 2026, states that Claude asks for confirmation before any permanent file deletion. This is a dated fact, not a law of nature: reopen the source if you need to rely on it for a decision that carries consequences. The basic recommendation remains simple, create a dedicated working folder rather than connecting a broad folder that also mixes in documents unrelated to the task at hand. Connected folders are, in any case, only one of Cowork's boundaries, alongside the applications it can open and the network it can reach, but this lesson deliberately limits itself to the file boundary, the most concrete one for a first task.

What depends on your organisation, not on Cowork

The exact list of locations you can offer for connection, a folder synced to the cloud, a network drive, a local folder, depends on how your organisation has deployed Cowork, not on a universal rule of the tool. Two colleagues in the same department can have different folders available depending on their own machine and their own permissions. The only reliable way to know what is actually accessible for your team is to ask your administrator, rather than assuming it from what a colleague has managed to do on their side.

In practice, keep a written record of what you connect, for example:

Dossiers connectés à Cowork :
- Contrats en cours (poste local)
Dossiers non connectés :
- Comptabilité
- Ressources humaines

This list serves as a reference when a reply from Claude seems incomplete: if the expected folder is not on it, the most likely explanation is not an error by Claude, it is a folder that was never connected. The lesson on Cowork as the default mode details how to open this connection for the first time.

Figure 1

What Cowork can do depending on the folder

Folder not connected
Folder connected
Read requested

Invisible

The folder does not exist for Claude, no reading is possible.

Visible

Claude reads the folder's content normally.

Write or delete requested

Out of reach

No writing is possible on a folder that has not been connected.

Modified in place

Claude can write or permanently delete, with a confirmation requested before any deletion.

The matrix crosses a folder's connection status with the requested action: outside connection, neither reading nor writing is possible; once connected, reading opens up and writing or deletion remain possible, with permanent deletion always confirmed.
Calibrate it yourself

An administrative manager connects the Contracts folder from her machine to Cowork, then asks for a summary of the last ten documents added. The same day, she also asks for a summary of the invoices stored in the Accounting folder on that same machine.

Write in one sentence what this situation establishes, and in one sentence what it does not establish.

What to remember
  • Cowork only modifies files inside connected folders, but once authorised to use your computer it takes screenshots of the screen, and from a browser's side panel it sees the open page.
  • Inside a connected folder, Claude can read, write and permanently delete; the documentation describes a confirmation requested before any permanent deletion, in every mode.
  • Closing or hiding whatever has nothing to do with the task before starting a session is the same reflex as closing your tabs before sharing your screen.
  • A dedicated working folder limits the possible damage of an imprecise instruction better than broad access that mixes in unrelated documents.
  • The locations actually available for connection depend on each organisation's own deployment, not on an identical rule for everyone.
Do this now

Write down the list of folders you would like to connect, then send it to your administrator today asking which ones are actually possible on your machine. While waiting for a reply, do not entrust any real task to a folder you are not sure about.

What still needs checking

These points depend on an interface or a rule that may have changed since this was written. Check them on your own screen before relying on them.

  • The precise list of location types offered for connection, a folder synced to the cloud, a network drive, a local folder, along with the exact wording of the connection interface, is not confirmed by the September 2026 record for this text: it depends on each organisation's own deployment and should be checked with the administrator before any promise made to a colleague.
Check the source

Every datable claim in this lesson links here to the public text behind it. A source that does not open proves nothing.