Published Aug 17, 2026, 4:00 PM EDT Mahnoor Faisal is a tech journalist covering AI and productivity tools with bylines at XDA, SlashGear, MakeUseOf, Laptop Mag, and Android Police. She's been writing professionally since she was sixteen, and has since penned hundreds of articles. This includes in-depth coverage of AI tools like NotebookLM to breaking news across the AI space. Her passion for technology started when she received her first iPod Touch (4th generation) on her 8th birthday, and she's been deep in the tech world ever since. Currently pursuing a degree in computer science, Mahnoor brings both a journalist's eye and a technical foundation to her coverage of how AI is reshaping the way we work and learn. I've said this countless times before, and I'll say it yet again: Cowork is one of Claude's most underrated products. I use it constantly, and it's one of the features that's been keeping me from canceling my Claude subscription for good. If you haven't used Claude Cowork much, it's essentially Claude Code, but geared toward non-technical users who don't want to deal with an intimidating terminal. It takes Claude Code's underlying agentic architecture and wraps it in a much more approachable interface, letting Claude work with your files, browse the web, use connected apps, and carry out multistep tasks on your behalf. While Cowork is incredibly capable, that's exactly why I'm a little more cautious with it than I am with a regular Claude Code chat. So, here are a few settings and permissions I always check before letting Cowork anywhere near important work. I switch Cowork from Auto to Manual approvals I’d rather be the one saying yes The first thing I change is Cowork's approval mode. Cowork gives you three options: Manual, Auto, and Skip. With Auto, Claude can keep working without stopping to ask you about every step. Instead, each action is reviewed for potential safety issues before it runs, and Claude will block actions it determines are unsafe. That's certainly more convenient, but when I'm letting Cowork anywhere near important work, I switch it to Manual. In this mode, Claude asks for my approval before taking actions instead of making those decisions entirely on its own. Anthropic itself recommends switching to Manual when a task involves sensitive files, accounts or websites, or actions that would be difficult to undo, like sending messages or making purchases. This does mean clicking through more permission prompts, but that's a tradeoff I'm more than willing to make when the work actually matters. There's also a small bonus. Auto mode consumes more of your Claude usage limit than the other modes because of the additional safety checks it performs in the background. I keep Computer Use off until I actually need it Claude doesn’t need the keys to my Mac Computer Use is easily one of Cowork's coolest features, but it's also one I don't keep enabled just because I can. When Cowork can't use a connector or the browser to complete a task, Computer Use lets Claude interact with your desktop directly, which means it can click, type, open apps, and navigate them much like you would yourself. The problem is that this gives Claude significantly more access to what's happening on your computer. Anthropic says there's no sandbox between Claude and your applications when Computer Use is active. Claude also takes screenshots to understand what's on your screen, which means it can potentially see anything visible inside an app you've given it permission to access, including sensitive documents or other private information. So, I only enable Computer Use when a task genuinely requires it. Claude does ask for permission before accessing each new application, but Anthropic itself warns that its safeguards aren't perfect and recommends avoiding access to sensitive apps altogether. You can also add apps to Cowork's blocklist, which automatically denies any attempt Claude makes to access them. I keep Cowork confined to one folder One folder is plenty, thank you One of Cowork's biggest advantages is that you don't need to manually upload every file you want Claude to work with. You can simply give it access to a local folder, and its file tools can read from and write to the folders you've connected. As convenient as that is, I try to be very selective about which folders I hand over. Instead of giving Cowork broad access to a folder containing a bunch of unrelated work, I usually create a dedicated folder for whatever I'm working on and copy only the files it actually needs into it. Anthropic recommends doing the same, specifically suggesting a dedicated working folder rather than granting Claude broad file access. There's a good reason to be selective here. Within the local folders you've given it access to, Claude can read, write, and even permanently delete files. Anthropic consequently recommends being particularly careful with folders containing things like financial documents, credentials, personal records, or other sensitive information, and keeping backups of important files. It takes a few extra seconds to move the relevant files into a separate folder before starting a task, but I much prefer knowing Cowork only has access to the files it actually needs. I clean up Cowork's browser permissions “Always allow” adds up fast Cowork can work inside your browser through the Claude in Chrome extension, which is incredibly useful when a task involves websites Claude needs to navigate or interact with. But that also means the permissions you've given Claude in Chrome matter when you're using Cowork. Anthropic lets you grant a site one-time access or choose Always allow actions on this site, and those permanent permissions stick around until you revoke them. I try not to let that list pile up. Every so often, I head into the extension's permissions and check which websites still have "always allow" status, then revoke anything Cowork no longer needs access to. Anthropic also recommends limiting Cowork's browser access to sites you trust, since web content is a major source of prompt-injection attacks. I turn off model improvement My chats don’t need to become training material This last setting isn't exclusive to Cowork, but it's one I make sure is disabled on my Claude account anyway. If you're using Claude through a consumer account like Pro or Max, Anthropic lets you choose whether your chats and coding sessions can be used to help improve its models. You can check this by heading to Settings > Privacy > Help Improve our AI models. Turning it off means new chats and coding sessions won't be used for future model training. Anthropic also says previously stored conversations will no longer be used in future training runs after you disable the setting, although anything already included in training that's begun or in an already-trained model can't be removed retroactively. Given how much access I tend to give Cowork and how frequently I use Claude in general, I'd simply rather keep that data out of model training where I have the choice. It's a small privacy setting, but it's also one that's easy to overlook if you've never gone digging through Claude's privacy options. When used right, Claude Cowork is incredible None of these settings are meant to scare you away from using Cowork. If anything, I'm comfortable giving it as much responsibility as I do precisely because I know I can put boundaries around what it can see and do. Cowork is still one of the most capable AI tools I've used, and when you give it the right amount of access for the task at hand, it can take a surprising amount of work off your plate. I just don't think getting the most out of an AI agent means giving it unrestricted access to everything by default.
5 settings I change in Claude Cowork before I let it near my work
Full Article
Original Source
Read the full article at Xda-developers →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.