Claude Cowork is one switch and 5 decisions
Claude Cowork is Anthropic's agent that works across the files and connected tools you nominate, generally available on desktop and in beta on web and mobile. Pexon treats Cowork as a rollout question rather than a product question: 5 admin decisions — entitlement, connected folders, connector write actions, egress and spend — decide what Cowork can reach.
We have not delivered a Cowork rollout.
Zero Cowork engagements, zero customer reference, no price list for one. We are saying that at the top of the page rather than at the bottom of a proposal, because the alternative — a page implying delivery experience we do not have — is how this category is mostly being written right now.
What follows is an assessment built from Anthropic's own documentation and verified against it on 4 August 2026. Where this page states a fact about the product, the source is linked and the phrasing stays close to the original. Where it states a judgement, it says so. The part we do sell is unchanged by Cowork: the identity, permission and connector work underneath it.
An agent that works in folders you nominate, not a chat window
Cowork takes a goal and works across the files and tools you point it at, showing each step: the files it opens, the tools it calls, the choices it makes. It reads and writes the formats a department already lives in — Word, PDF, plain text, Markdown, HTML, JSON, CSV, spreadsheets, presentations, images. It launched as a research preview in January 2026 on macOS for Max subscribers, and is now generally available on desktop across macOS, Windows, ChromeOS and Linux, with web and mobile in beta.
The part that matters for a security review is where the work happens. Cloud sessions run in an isolated, temporary sandbox on Anthropic-managed infrastructure — created when the session starts, destroyed when it ends. The sandbox holds only session-scoped tokens that expire within hours, and connector authorisation tokens never enter it at all. One nuance the feature lists skip: the sandbox is ephemeral, the session is not. Sessions and their files are saved to the Claude account, which is a retention question and a separate one.
Sources: Anthropic, Claude Cowork architecture overview and Making Claude Cowork ready for enterprise. Verified 4 August 2026.
Five decisions, and only five
The admin surface is small, which is good news and a trap in equal measure: it is small enough to be clicked through in an afternoon by someone who has not been told what each switch implies. These are the five, what sets them, and what each one actually constrains.
| Decision | Where it is set | What it constrains |
|---|---|---|
| Who gets Cowork | Organization settings, Cowork — and on Enterprise plans only, groups and custom roles | The main Cowork toggle is organisation-wide on every plan: either all members have access or none do. Only Enterprise plans can then narrow it, by granting a custom role to a group — built manually or synced by SCIM — so on Team plans this decision is a yes or a no, not a scoping exercise. |
| Which files it can touch | Each member connects folders in the Claude desktop app | Local file access is limited to the folders that member has connected, and each local tool call is checked against that member's permissions before it runs. |
| What it may do in your systems | Admin console, per MCP connector | Admins can restrict which actions a connector exposes across the organisation — read allowed, write disabled — and connector authorisation tokens never enter the sandbox, because connector calls are made server-side. |
| What it may reach outside | Organization settings, Capabilities; sandbox egress allow-list | Team and Enterprise owners can turn web search off for Cowork and Chat. The sandbox cannot reach private, internal, link-local or cloud-metadata addresses, and egress is enforced outside the sandbox by a proxy that permits only allow-listed destinations. |
| What it costs and what you see | Admin console budgets; admin dashboard, Analytics API, OpenTelemetry | Per-team budgets are set in the console. OpenTelemetry emits events for tool and connector calls, files read or modified, skills used, and whether each AI-initiated action was approved manually or automatically. |
All five controls as documented by Anthropic, read 4 August 2026. Plan scoping for decision one comes from Use Claude Cowork on Team and Enterprise plans, which states that the organisation-wide toggle means either all members have access or none do, and that groups and custom roles are an Enterprise-plan control. Decision two is the one departments get wrong: a connected drive is not a connected folder.
Put these five in the ticket
Copy this into whatever your change process uses. Every line has a named owner or it is not answered, and none of it needs us — an internal admin with the identity system in front of them can close all five.
# Before enabling Claude Cowork — answer all five, in writing
1. ENTITLEMENT Enterprise: which IdP group gets the Cowork
custom role first, and who owns its membership?
Team: the toggle is org-wide — name the owner
who signs off on every member getting it.
2. FOLDERS Which exact folders will that group connect?
Name paths, not drives. A drive is not an answer.
3. CONNECTORS For every connector enabled: is write disabled
until the owner of that system has signed it off?
4. EGRESS Is web search on or off for Cowork, who decided,
and is that decision written down anywhere?
5. EVIDENCE Where do the OpenTelemetry events land, and who
is rostered to read them in week two?Who should wait, and why
Cowork is the fastest-moving thing Anthropic ships and the search results for it are almost entirely feature lists. The useful information is the other half — the conditions under which enabling it produces a governance problem instead of a productivity gain.
Access lives in a spreadsheet
On Enterprise plans, scoping Cowork to some teams and not others means granting a custom role to a group. A department that manages access as a list of names in a shared file has nothing to assign it to, and the first rollout decision turns into an identity project. On Team plans there is no scoping at all — the toggle is organisation-wide, so the only options are everyone or nobody.
The source data has no connector
Where the underlying system has no connector, Cowork ends up working on exported copies sitting in a folder. That is the least governable version of the tool: stale by definition, outside the access model of the system it came from, and invisible to the connector-level controls.
The processing record is not written
Cloud sessions run on Anthropic-managed infrastructure, and the default differs by plan: Run Cowork in the cloud is on by default on Team plans and off by default on Enterprise. Anthropic documents tenant isolation, short-lived session-scoped tokens and a 30-day backend deletion window for a deleted task. Those are answers to a data protection review — but only once someone has put them in the record.
The business case is counted in seats
Anthropic states that Cowork consumes usage limits faster than Chat. A rollout costed on headcount is therefore costed on the wrong variable. Per-team budgets exist in the admin console, which makes cost per team per month the unit a department head can actually own.
The access model, not the product
Nobody needs a consultancy to switch Cowork on. What a department does need, before it does, is groups that mean something in the identity provider, a connector inventory with a named owner per system, a write-permission decision per connector, and somewhere for the telemetry to land where a human reads it. That is the same engineering as any Claude rollout past the pilot team, which is the work we already do — and it is the reason this page sells no Cowork package.
What buyers ask about Cowork
Is Claude Cowork still a research preview?
No. Cowork launched as a research preview in January 2026, on macOS for Max subscribers only. It is now generally available on desktop — macOS, Windows, ChromeOS and Linux — with web and mobile rolling out in beta, and it is included in the Pro, Max, Team and Enterprise plans. Usage limits apply.
Where does a Claude Cowork session actually run?
Cloud sessions run in an isolated, temporary sandbox on Anthropic-managed infrastructure, created when the session starts and destroyed when it ends. Anthropic documents tenant isolation at the data layer, meaning every stored record is scoped to one organisation and account. The sandbox is ephemeral; the session and its files are saved to the Claude account, which is a separate retention question.
Can Claude Cowork read files nobody gave it?
Anthropic documents that local file access is limited to the folders a member has connected in the desktop app, and that each local tool call is checked against that member's permissions before it runs. Claude also requires explicit permission before permanently deleting a file. The practical risk is therefore not the sandbox — it is a department connecting a whole shared drive because that was quicker than naming four folders.
What can an administrator actually control in Claude Cowork?
Five things: whether Cowork is on for the organisation at all — and, on Enterprise plans only, which groups a custom role narrows it to — which folders each member connects on the desktop, which actions each MCP connector permits, whether web search is available to Cowork, and the per-team budget. Activity surfaces in the admin dashboard, the Analytics API and OpenTelemetry events.
Does a seat count predict what Claude Cowork costs?
No. Cowork is included in the paid plans, but Anthropic states that Cowork consumes usage limits faster than Chat, so headcount does not predict consumption. Because per-team budgets are set in the admin console, the honest planning unit is cost per team per month — a figure a department head can own — rather than cost per seat.
Does Anthropic train on Claude Cowork data?
Anthropic states that Cowork data carries the same commercial commitments as other Team and Enterprise data and is not used to train Claude. A deleted Cowork task leaves task history immediately and is removed from Anthropic's backend storage within 30 days, in line with its published retention periods. Both statements belong in your processing record verbatim, not paraphrased.
Has Pexon delivered a Claude Cowork rollout?
Not yet. We have no Cowork engagement, no customer reference and no price list for one, and this page states that rather than implying otherwise. What we do run today is the identity, permission and connector work a Cowork rollout depends on, because that work is identical to any other Claude deployment.
Who should wait before enabling Claude Cowork?
On Enterprise plans, any department whose access model lives in a spreadsheet rather than in identity-provider groups, because scoping Cowork means granting a custom role to a group and there is nothing clean to grant it to. On Team plans, anyone not ready for every member to have it, since the toggle is organisation-wide. And anyone whose source data sits in systems with no connector, because Cowork then works on exported copies in a folder.
Not a sales call. An architecture call.
Thirty minutes with the architect who would actually run the engagement.
