Last updated: 14 September 2026
Contents
- 1. TL;DR: The 15 Things That Matter
- 2. Pick Your Posture
- 3. What the Defaults Actually Do
- 4. Key Considerations
- 4.1 Plan Tier Determines Your Controls
- 4.2 Audit and Observability
- 4.3 Browser Automation: Know What's Blocked
- 4.4 MCP and Plugin Supply Chain
- 4.5 Data Residency and Retention
- 4.6 Domain Claiming: Bringing Shadow Accounts Into Enterprise
- 4.7 Role-Based Access Control (Enterprise)
- 4.8 Dispatch and Keep Awake
- 4.9 Computer Use (Pro/Max Only)
- 4.10 Skills
- 4.11 Projects and Artifacts
- 4.12 Cowork on 3P (Third-Party Inference)
- 4.13 Claude Tag (Slack)
- 4.14 Office Agents (Claude for M365)
- 4.15 Cowork in the Cloud vs Local Execution
- 4.16 Permission Modes and the Classifier
- 4.17 Inference Hooks (Enterprise)
- 4.18 Memory
- 4.19 Adjacent Surfaces Cowork Settings Do Not Govern
- 4.20 Model Choice as a Security Control
- 5. Threat Model for Agentic Desktop AI
- 6. Deployment Checklist
- 7. Control Mapping
- A Note on Conflicting Sources
- Anthropic Cowork Resources and References
1. TL;DR: The 15 Things That Matter
If you read nothing else, know these fifteen things before enabling Claude Cowork for your organization.
1. Cowork is not a chatbot. It runs code in an isolated sandbox, reads and writes local files in folders users connect, browses the web, and can execute scheduled tasks unattended. Since July 2026 that sandbox sits on Anthropic's infrastructure by default rather than the user's machine. Local execution remains available for existing desktop deployments.
2. The Compliance API now covers Cowork. The audit log still does not. This reverses our earlier guidance. Enterprise organizations can retrieve full Cowork session transcripts, on desktop, web and mobile, through the Compliance API, generally available since 26 August 2026. The Audit Log CSV export contains no Cowork event types. Enable the Compliance API before you roll out, because the Activity Feed is not retroactive.
3. Prompt injection is still the #1 risk, and the numbers have moved. On Anthropic's current red-teamer-sourced evaluation, pre-safeguard attack success is 3.8% for Claude Opus 5 and 17.6% for Opus 4.5. With injection probes and the action-verification classifier, Anthropic reports 0% for Sonnet 5, Opus 5 and Mythos 5, and 0.3% for Fable 5. Anthropic cautions that these are not comparable with its 2025 figures, so the ~1% we previously quoted is retired rather than improved.
4. Browser automation is now two surfaces. Claude in Chrome went generally available on all paid plans on 26 August 2026, and a browser built into Claude Desktop launched the same day. Default blocked categories have narrowed to just two: adult content and known pirated sites. Financial services, banking, investment platforms and crypto exchanges now only prompt for permission. Healthcare and internal tools are still not blocked.
5. Where conversation history lives depends on where the session ran. Cloud sessions are saved to the member's Claude account. Local sessions keep history on the user's machine, outside Anthropic's retention policies, and admins cannot centrally delete them. Enterprise admins can now read local session transcripts via the Compliance API, but there is still no deletion endpoint.
6. Plugins are powerful and risky, and now partly governable. Each plugin bundles skills, connectors, subagents, slash commands and hooks. Team and Enterprise owners can run a private marketplace from an internal GitHub repository with four install preferences per plugin. Enterprise can enable skill and plugin security scanning, which is off by default and does not scan hooks or MCP servers. Treat them like software dependencies.
7. MCP servers run with significant access. Local servers on stdio transport may have excessive access to the machine. Remote servers on HTTP require authentication but introduce network attack surface. Known supply chain CVEs exist (CVE-2025-59536, CVE-2026-21852), and Anthropic states plainly that it "doesn't security-audit or manage any MCP server". Enforce allowlists on serverCommand or serverUrl, never on serverName, which the user chooses.
8. Scheduled tasks run unattended, and no longer need the machine awake. They now execute in the cloud on cadence with the desktop app closed and the laptop shut. A prompt injection delivered via a poisoned data source can execute silently and repeatedly. Anthropic itself names them a heightened risk and advises against sensitive data or consequential actions in them. There is no dedicated admin toggle.
9. The org-level toggle is a prerequisite for RBAC, not a fine-grained control. Enable capabilities at org level first, then use custom roles (Enterprise) to restrict access by group. RBAC can only restrict what the org toggle has enabled. On Team plans the toggle remains all-or-nothing.
10. RBAC (Enterprise) now controls 19 capabilities, not 14: Chat, code execution and file creation, memory, web search, public projects, create skills, share skills and plugins with org members, share skills with the full organization, share skills and plugins with groups, skill and plugin security scanning, Claude Code, fast mode, Claude Code dynamic workflows, Claude Security, Claude Code artifacts, Claude Design, Claude Cowork, Cowork in the cloud, and Claude for Chrome. Watch the "Capability access" shortcut: a role set to "All capabilities" silently inherits each new capability as Anthropic ships it.
11. Dispatch is live on Team, whatever the documentation says. Anthropic documents Dispatch as a limited beta for Pro and Max plans only. That is stale: Dispatch appears as a Beta item in the Claude Desktop sidebar on a Team plan, verified 10 September 2026. No admin toggle is documented on any plan, so your exposure is not limited to personal subscriptions on corporate machines. It is running inside your managed tenant under corporate identity.
12. Computer Use runs outside the sandbox and is still Pro/Max only. Anthropic's wording: "Computer use has no sandbox between Claude and your applications." Controls are per-app permission prompts across a three-tier access model, a user-managed app blocklist, and a global Esc kill switch whose keypress is consumed so injection cannot dismiss dialogs. There are no organizational admin controls and no MDM key.
13. Cowork on 3P routes inference through a provider you control, and Claude Desktop now supports six: gateway, anthropic, bedrock, mantle, vertex and foundry. No conversation data reaches Anthropic on Amazon Bedrock or Google Cloud's Agent Platform; Microsoft Foundry does not carry that guarantee, and mantle is not covered by the published statement. Configured entirely via MDM, not the claude.ai admin console. Note that this mode has no Compliance API and no Analytics API at all.
14. Office Agents (Claude for M365) are GA on every paid plan. This corrects our earlier Team/Enterprise-only guidance. Excel, Word and PowerPoint are generally available and Outlook is in beta. It is a separate product with a separate admin surface, Cowork admin settings do not apply, Outlook still requires a one-time Microsoft Graph consent, and its OpenTelemetry collector applies no redaction whatsoever.
15. Claude in Slack is now Claude Tag. The legacy app switched over on 3 August 2026. It is Team and Enterprise only, with its own Owner-only admin surface that is deeper than its beta status suggests: member access, Enterprise role restriction, per-scope access bundles, blocked channel patterns, guest-channel modes and per-channel spend caps. There is no Compliance API coverage and no single per-action log, but four audit trails do exist, the authoritative one being each connected service's own log under the service account you provisioned. In channels Claude acts through its own service accounts and access follows the channel, not the person.
2. Pick Your Posture
Not every organization needs the same level of enablement. Based on conversations with security teams deploying Cowork today, we see three postures. Find yours and use it to scope the rest of this guide.
| Lockdown | Controlled | Open | |
|---|---|---|---|
| Who it's for | Regulated industries, teams awaiting BAA coverage, orgs without admin controls | Most enterprises. Enables Cowork with guardrails. | Innovation teams, individual power users, low-sensitivity workloads |
| Cowork toggle | Off | On | On |
| Run Cowork in the cloud | Off | Decision point. Off keeps sessions on managed devices where MDM policy applies. On gains resilience and mobile access but removes device policy entirely. | On |
| RBAC (Enterprise) | Pre-built roles, no grants | Custom roles restrict Cowork to approved groups. Capability access set to "Only selected", never "All capabilities". | Custom roles grant broad access; used primarily for spend and model limits |
| Permission modes | N/A (Cowork off) | Manual or Auto. Disable "Allow Automatically approve mode" if unattended execution is unacceptable. Leave connector "Always allow" off. | Auto permitted, Skip discouraged |
| Inference hooks (Enterprise) | N/A | Deploy in shadow mode, then enforce | Shadow mode for visibility |
| Dispatch | Present on Team despite the docs. No admin toggle, so govern by policy and endpoint controls | Inventory it, add to the AUP, and move Code permissions off Accept | User discretion with policy |
| Computer Use | N/A (Pro/Max only) | N/A (Pro/Max only) | Enabled with app blocklist (Pro/Max personal accounts only) |
| Chrome extension | Disabled | Disabled or strict allowlist | Enabled with blocklist |
| Cowork built-in browser | Disabled | Disabled. A second browsing surface that needs no extension. | Enabled, cookie import discouraged |
| Plugins | Blocked org-wide | Private marketplace only, admin-curated, manifest SHA pinned | Marketplace + user-installed |
| Skill and plugin scanning | On | On | On |
| Skills | User creation disabled | User upload disabled, centrally managed with organization skills, org-wide sharing off | Enabled with code execution and file creation |
| MCP servers | No user MCP | Org allowlist only via managed-mcp.json, enforced on command or URL | Allowlist + user-added with review |
| Connectors | Disabled | Admin-approved only, write tools blocked per tool | User-enabled |
| Scheduled tasks | N/A (Cowork off) | Read-only tasks, reviewed inventory | User discretion with policy |
| Network egress | Off | Off, or package managers plus a tested allowlist. Egress pinned to a corporate proxy. | Broader allowlist |
| Memory | Off | Off, or on with sensitive topics excluded | On with policy |
| Monitoring | Tenant restrictions to block shadow use | Compliance API + OTel to SIEM, weekly review | Compliance API + OTel with alerting |
| Account switching | Blocked via tenant restrictions (Enterprise) | Blocked via tenant restrictions (Enterprise) | No control available below Enterprise |
| User training | Communicate "not approved" | Mandatory before access | Recommended |
| Projects | N/A (Cowork off) | Permitted; AUP-scoped folder hygiene enforced with allowedWorkspaceFolders; project instructions reviewed in access reviews | User discretion with policy |
| Artifacts | Off | On, external sharing off, artifact connectors off | User discretion; artifact connector calls in OTel |
| Claude Tag (Slack) | Slack admin does not approve the app install | Slack admin approves; member access restricted to the organization; access bundles reviewed per scope; blocked channel patterns set; guest channels left at Restrict; direct messages off | Approved with policy; connected-service audit logs shipped to SIEM |
| Office Agents (M365) | Add-in not deployed; Outlook Graph consent withheld | Add-in deployed by IT; "Let Claude work across apps" only if approved; OTel to SIEM | Deployed with policy; OTel to SIEM |
2.1 Lockdown: "We're Not Enabling Cowork Yet"
This is a valid and common posture. But "not enabling" doesn't mean "nothing to do." You still need to actively prevent shadow usage and prepare for when your organization is ready.
What to do right now (even if Cowork stays off)
☐ Toggle Cowork OFF: Organization settings > Cowork > "Enable for your organization". Do this explicitly; it is on by default for Team and Enterprise
☐ Turn off "Run Cowork in the cloud" in the same place. It is on by default on Team, off by default on Enterprise
☐ Disable Claude in Chrome: Organization settings > Claude in Chrome. On Enterprise it became on by default on 10 September 2026 unless you had already disabled it, so verify the live state rather than assuming it is still off
☐ Disable the Cowork built-in browser: Organization settings > Cowork > Built-in browser. The same default flip landed on Enterprise on 10 September 2026, and users are not notified when it is enabled, so verify this one too
☐ Enterprise with RBAC: pre-build your custom roles and group structure now, with capability access set to "Only selected" rather than "All capabilities", so that flipping the org toggle later grants nothing by accident. When you are ready, migrate a pilot group to Custom roles before enabling Cowork org-wide
☐ Enable the Compliance API now, even with Cowork off. The Activity Feed only reaches back to the moment it was first enabled, so turning it on before any pilot is the difference between having an audit trail and not having one. Primary Owner only, at Organization settings > API
Prevent account switching and shadow AI (Enterprise plans and Console organizations)
Tenant restrictions are your primary defense against employees bypassing managed controls by using personal Claude accounts. Without them, a user on your corporate network can simply switch to a personal account where Cowork, both browsers, and all plugins are fully enabled with no admin oversight.
☐ Configure tenant restrictions by having your network proxy inject the anthropic-allowed-org-ids HTTP header into all requests to claude.ai, claude.com, anthropic.com and api.anthropic.com
☐ Find your Organization UUID in Settings > Account or Admin Settings > Organization (scroll to bottom)
☐ Header format: anthropic-allowed-org-ids: <your-org-uuid> (comma-delimited for multiple orgs, no spaces). For larger estates, append ;n=K to the base header and add numbered continuation headers; the documented ceiling is 10 header lines and 500 organization UUIDs
☐ TLS inspection is required for the proxy to inject headers into HTTPS traffic
Documented coverage is web access (claude.ai), the desktop app, API key authentication and OAuth token authentication. Mobile apps and the Chrome extension are not listed as covered, so do not assume they are. Supported proxy platforms include Zscaler ZIA, Palo Alto Prisma Access, Cato Networks, Netskope, Cloudflare Zero Trust, and any HTTPS proxy with header injection.
When blocked, users see: "Access restricted by network policy. Contact IT Administrator." with a 403 and error code tenant_restriction_violation.
☐ Test by making an API call from the restricted network with your org's key to verify the header is being injected and validated
⛔ Without tenant restrictions, your admin toggles are a suggestion, not a control. A user can switch to a personal Pro/Max account on the same machine and bypass every organizational guardrail you've configured. Anthropic scopes this to "members of Enterprise plans and Console organizations", so a Console organization can enforce it too, finding the setting at Settings > Organization on platform.claude.com. Team plans cannot enforce it at all.
Other Lockdown actions
☐ Communicate to your org: "Cowork is not approved for use. It is disabled. If you need agentic AI capabilities, here is the process for requesting access."
☐ Monitor: even with Cowork off, users may have personal Claude accounts. Your DLP and CASB should be watching for claude.ai traffic on non-managed accounts. Note that Free accounts can now use connectors, remote MCP, desktop extensions, code execution, file creation and artifacts, though not skills, even though Cowork itself is not available to them
☐ Team plan without tenant restrictions: consider blocking claude.ai at the proxy level entirely, or use Chrome enterprise policies (GPO/MDM) to prevent the Claude in Chrome extension from being installed on managed browsers. The extension ID is fcoeoabgfenejglbffodgkkbkcdhcgfn
☐ Enable OpenTelemetry anyway. It gives you baseline visibility into Chat and Code usage that you'll want when you eventually evaluate Cowork
☐ Track Anthropic's roadmap. The audit log gap that used to be the blocker for regulated orgs is now largely closed by the Compliance API. What remains: Cowork is still excluded from Anthropic's BAA, there is no session deletion endpoint, and no Anthropic page states whether Cowork sits inside the SOC 2 or ISO audit boundary. Ask for that scope statement in writing
⚠ The defaults matter. On Team plans, Cowork, cloud sessions, Claude in Chrome and the built-in browser are all enabled by default. If you're on a Team plan and haven't explicitly disabled these, your users may already have access.
2.2 Controlled: "Enable with Guardrails"
This is the posture most Enterprise and mature Team organizations should target. Cowork is on, but the browsers, plugins, MCP servers, and connectors are tightly scoped.
The minimum viable secure configuration
☐ Compliance API enabled before rollout, with session transcripts pulled into your retention and eDiscovery tooling
☐ Cowork ON, both browsers OFF (or a strict allowlist of 5-10 trusted domains)
☐ Decide "Run Cowork in the cloud" deliberately. On Enterprise it is off by default and requires both the org toggle and the "Cowork in the cloud" role capability. Understand that device MDM policy does not reach cloud sessions
☐ RBAC (Enterprise only): Create custom roles granting Cowork access. Assign to approved groups. Migrate members to the Custom role. Set capability access to "Only selected" so future betas are not inherited silently. Note: this controls access to Cowork itself, not what Cowork can do. Browsers, plugins, MCP, connectors, and scheduled tasks are still governed by org-wide settings
☐ Permission modes: decide whether "Allow Automatically approve mode" stays on. It is on by default, and in that mode a classifier rather than a person is your last line. Leave "Allow Always allow for connector tools" off, which is the default
☐ Network egress: keep defaults. New Enterprise organizations default to no network access at all. Only allowlist domains you've tested. Remember egress is read at session creation and does not apply to web fetch, web search, or any MCP including Claude in Chrome
☐ Pin egress to inspectable infrastructure with egressProxyUrl or egressProxyPacUrl in managed configuration, remembering that Anthropic calls this a reachability setting rather than an egress control, and that the Cowork workspace VM on Linux bypasses it entirely
☐ MCP servers: centrally allowlisted via managed-mcp.json deployed through MDM (Jamf, Intune), with allowManagedMcpServersOnly set. Users cannot add their own
☐ Connectors: admin-approved only. Prefer read-only connectors. Set write tools (send_email, post_message) to Blocked per tool unless explicitly justified
☐ Skills and plugins: user creation off, org-provisioned skills only, org-wide sharing off, private marketplace with manifest SHA pinning, and skill and plugin security scanning turned on
☐ Deploy disableBypassPermissionsMode and blockReadsOutsideWorkingDirectories, and scope connectable folders with allowedWorkspaceFolders
☐ Scheduled tasks: permitted but restricted to read-only tasks (summaries, reports). No tasks that send messages, make purchases, or modify external systems
☐ Memory: off, or on with sensitive topics excluded. It is off by default on Team and Enterprise
☐ Artifacts: on, with external sharing off and artifact connectors off
☐ Global instructions: add defensive prompts (see Section 6 for recommended text)
☐ OpenTelemetry: enabled and routed to SIEM with alerting for anomalies, and content capture decided deliberately rather than left to a default that Anthropic's own pages describe two different ways
☐ User training: mandatory before access. Cover prompt injection, folder hygiene, incident reporting
This posture gives you meaningful value from Cowork (file processing, document generation, research synthesis, data analysis) while cutting off the highest-risk attack surfaces (both browsers, unvetted MCP servers, uncontrolled plugins).
2.3 Open: "Full Enablement with Policy"
Appropriate for innovation teams, low-sensitivity workloads, or organizations with high risk tolerance. Browsers are enabled, plugins are broadly available, and users have more autonomy. Controls shift from prevention to detection and response.
Key controls for the Open posture
☐ Chrome and the built-in browser: enabled with a blocklist covering financial services, healthcare, cloud consoles, and internal admin tools. Note that financial sites are no longer blocked by default, only prompted, so they must be added explicitly
☐ Plugins: marketplace available, users can self-install. Org-level plugins auto-installed for consistency, and scanning on
☐ MCP servers: allowlist at org level, but users can request additions through a lightweight review process
☐ Scheduled tasks: user discretion within the acceptable use policy. Regular audit of active tasks
☐ Monitoring: Compliance API and OTel to SIEM with real-time alerting. Weekly review of connector usage and scheduled task patterns
☐ Incident response: users trained to stop suspicious tasks immediately. Clear escalation path documented
⚠ Even in the Open posture, Cowork remains outside Anthropic's BAA, and organizations with HIPAA readiness enabled capture no local session data in the Compliance API at all. The constraint on regulated workloads is now contractual and scope-based rather than an absence of logging.
3. What the Defaults Actually Do
Cowork's out-of-the-box defaults are more restrictive than you might expect in some places and considerably more permissive in others, and several changed in the second half of 2026. Those defaults vary by plan. Understanding what's already locked down on YOUR tier helps you focus your hardening effort on the real gaps.
🔒 Restrictive by default
| Control | Plans | Behaviour |
|---|---|---|
| Sandbox isolation | All plans | Cloud sessions run in a per-session sandbox on Anthropic infrastructure, destroyed at session end, with no state shared between sessions or organizations, and no reach to private, internal, link-local or cloud-metadata addresses. Local sessions run shell and code in a dedicated Linux VM isolated by Apple Virtualization.framework, Hyper-V or QEMU with KVM. |
| Egress enforcement point | All plans | Egress is enforced outside the sandbox by a mandatory proxy the sandbox cannot reconfigure or bypass. |
| Connector credentials | All plans | Connector authorization tokens never enter the sandbox; connector calls are made server-side. Sandbox tokens are session-scoped and expire within hours. |
| File access | All plans | Cowork can only read and write files in folders users explicitly connect. Claude's own configuration and session data stay off-limits, as do SSH keys, AWS and Google Cloud credentials, and bash, zsh and PowerShell profile files. |
| Deletion protection | All plans | Cowork requires explicit user permission before permanently deleting any file, in every permission mode including Skip. |
| Network egress | Enterprise | No network access is the default for new Enterprise organizations. |
| Connector "Always allow" | Team, Enterprise | Off by default. Write-capable connector tools are re-approved each task, and previously saved always-allow preferences are not honoured while it is off. Custom roles cannot override it. |
| Memory | Team, Enterprise | Off by default since 25 August 2026. "Include sensitive topics in memory" is a separate setting, also off. |
| Artifact external sharing | Team, Enterprise | Off by default. An owner must enable it before anyone can create a public link. Artifacts using connectors or asking Claude questions can never be shared publicly on any plan. |
| Data training | Enterprise, Team | Data is not used for model training by default. No opt-out action required. |
| Desktop extensions | Team, Enterprise | Do not load unless isDesktopExtensionEnabled is explicitly true in managed configuration. |
| Managed config failure mode | Managed fleets | Since late August 2026, unreadable managed MCP and desktop extension values fail closed rather than being ignored, and an unreadable Claude Code managed settings file stops sessions starting. |
⚠️ Not restrictive by default: your hardening targets
| Control | Plans | Behaviour |
|---|---|---|
| Cowork toggle | Team, Enterprise | On by default at Organization settings > Cowork. Org-wide only on Team; per-group on Enterprise via groups and custom roles. |
| Cowork toggle | Pro / Max | Always on. No admin toggle exists. Not available on Free at all. |
| Run Cowork in the cloud | Team | On by default. Sessions and files save to the member's Claude account, and device MDM policy does not apply to them. |
| Chrome extension state | Team | Enabled by default. Users can start using Chrome automation immediately unless an admin disables it. |
| Chrome extension state | Enterprise | Disabled at launch, then ON by default from 10 September 2026 unless already disabled. Treat it as on unless you checked. |
| Chrome extension state | Pro / Max | Enabled. No admin toggle exists to disable it. |
| Cowork built-in browser | Team | On by default. Enterprise off at launch, then ON by default since 10 September 2026 unless disabled, with no user notification. |
| Automatically approve mode | Team, Enterprise | "Allow Automatically approve mode" is on by default. In the Chrome side panel, automatic approval is the default mode. |
| Network egress | Team | Package managers only. Anthropic's own article states this two contradictory ways, so verify in your tenant. |
| Network egress | Free, Pro / Max | Network access is enabled. No admin controls exist to configure it. |
| Egress scope gap | All plans | Egress permissions do not apply to web fetch, web search, or MCPs including Claude in Chrome. Web search is separately disableable at Organization settings > Capabilities. |
| Connectable folders | All plans | Since 4 September 2026, members can attach the home folder, Windows Documents and AppData, the macOS Library folder, and whole drives. Scope this with allowedWorkspaceFolders; policy alone is no longer sufficient. |
| Skill and plugin scanning | Enterprise | Off by default, and unavailable to CMEK, ZDR and HIPAA organizations. Does not scan pre-existing installs, Claude-created skills, MCP-served skills, MCP servers, or hooks. |
| Skills | All paid plans | Available. Org-wide skill sharing has no approval workflow: any user with the capability can publish to the organization directory without review. |
| Plugins | All paid plans | Users can install from any marketplace by default, and can add their own marketplaces from a GitHub repo. Team and Enterprise admins can set up a private marketplace and restrict access, but this requires active configuration. No first-party org toggle to stop user-added marketplaces is documented. |
| Plugin group overrides | Enterprise | Where a member is in multiple groups the most permissive setting wins, and Anthropic states groups here are "not a security boundary". Hard blocking requires org-wide "Not available". |
| MCP servers | All plans | User-configured by default with no restrictions. Enterprise and Team admins can deploy managed-mcp.json via MDM to enforce an allowlist, but this requires active setup. |
| Connectors | All plans | Multiple connectors are available in the catalog. On Team and Enterprise an owner must add each connector before members can authenticate, but per-tool policy defaults are permissive until set. |
| Scheduled tasks | All Cowork plans | No dedicated admin toggle, no approval workflow, and no documented cap on number or frequency. They now run in the cloud with the machine asleep. |
| Computer Use | Pro / Max only | Runs outside the VM sandbox on the user's actual desktop. Enabled per user, not per organization. No admin controls, no MDM key. Not available on Team or Enterprise. |
| Dispatch | Pro / Max documented; observed on Team | Limited beta. Anthropic's docs say Pro/Max only, but it is present and enabled on Team, verified 10 September 2026. No admin toggle exists on any plan, and its own panel defaults Code permissions to Accept. |
| Memory | Free, Pro / Max | On by default. |
| Projects | All Cowork plans | No admin control at all. Owners cannot restrict project creation, and project instructions are not admin-visible. |
| Web search | All plans | Bypasses all network egress restrictions. Claude can search the broader web regardless of your allowlist configuration. |
| Cross-app data flow | All plans | Data moves between Excel, PowerPoint, both browsers, and local files within a session with no per-transfer approval or data loss controls. |
| Data training | Free, Pro / Max | Governed by the user's own "Help improve our AI models" toggle. When on, data is retained de-identified for up to five years in training pipelines, applying only to new or resumed chats after enabling. Incognito chats are never used, and raw connector and MCP content is excluded unless pasted into the conversation. |
| Account switching | Free, Pro / Max, Team | No ability to prevent users switching to a personal Claude account on the same machine, bypassing all organizational controls. Enterprise can block this with tenant restrictions, which require network proxy configuration with TLS inspection. |
| Audit log coverage | All plans | The Audit Log CSV export has no Cowork, Claude Code, Claude Tag or Office Agents event types. This is no longer the whole picture: the Compliance API now covers Cowork sessions on Enterprise. See 4.2. |
| Endpoint visibility | All plans | Anthropic states that host security tools cannot inspect activity inside the Cowork VM, and cannot observe cloud sessions at all. EDR is not a viable detection layer here. |
ℹ Bottom line: Enterprise gets the strongest controls but no longer the best defaults, because two browsing surfaces switch themselves on in September. Team gets admin controls with permissive defaults across the board. Pro/Max users have no admin controls at all, and Free users can still reach connectors, skills and code execution without Cowork. Your hardening work scales inversely with your plan tier.
4. Key Considerations
This section covers the essential decisions and controls for each attack surface. Use it as your planning guide before diving into the detailed checklist in Section 6.
4.1 Plan Tier Determines Your Controls
Your Anthropic subscription tier dictates what security controls you can actually enforce. The gap between Enterprise and everything else is significant, and it widened during 2026 as the strongest new controls landed on Enterprise only.
| Security Control | Free | Pro / Max | Team | Enterprise |
|---|---|---|---|---|
| Cowork available | ✗ | ✓ | ✓ | ✓ |
| Cowork on web and mobile | ✗ | ✓ (beta) | ✓ (beta) | Admin-enabled only |
| Admin console | ✗ | ✗ | ✓ | ✓ |
| SAML 2.0 SSO | ✗ | ✗ | ✓ | ✓ |
| JIT provisioning | ✗ | ✗ | ✓ | ✓ |
| SCIM provisioning | ✗ | ✗ | ✗ | ✓ |
| Domain verification, restrict org creation | ✗ | ✗ | ✓ | ✓ |
| Domain claiming and account migration | ✗ | ✗ | ✗ | ✓ |
| Tenant restrictions (HTTP header, also Console organizations) | ✗ | ✗ | ✗ | ✓ |
| IP allowlisting | ✗ | ✗ | ✗ | ✓ (by request) |
| Session security duration | ✗ | ✗ | ✗ | ✓ |
| Cowork on/off toggle (org-wide) | ✗ | ✗ | ✓ | ✓ |
| Per-user Cowork access (RBAC) | ✗ | ✗ | ✗ | ✓ (custom roles + groups) |
| RBAC scope | N/A | N/A | N/A | 19 capabilities, 7 admin permission areas, per-tool connector permissions, model entitlements |
| Inference hooks | ✗ | ✗ | ✗ | ✓ (beta) |
| Model entitlements and effort caps | ✗ | ✗ | ✗ | ✓ (beta) |
| Skill and plugin security scanning | ✗ | ✗ | ✗ | ✓ (beta, off by default) |
| Dispatch | ✗ | Some plans (beta) | ✓ (observed, undocumented) | Unverified |
| Computer Use | ✗ | User-enabled (no admin controls) | ✗ | ✗ |
| Private plugin marketplace | ✗ | ✗ | ✓ | ✓ + per-group overrides |
| Chrome: default state | N/A | On | On | Off, ON by default from 10 Sept 2026 |
| Chrome site allowlist/blocklist | ✗ | ✗ | ✓ | ✓ |
| Organization instructions | ✗ | ✗ | ✓ | ✓ |
| Connector admin controls | ✗ | ✗ | ✓ | ✓ + per-role, per-tool |
| Network egress allowlist | ✗ | ✗ | ✓ | ✓ |
| OpenTelemetry for Cowork | ✗ | ✗ | ✓ | ✓ |
| Audit logs (180-day export) | ✗ | ✗ | ✗ | ✓ (no Cowork events) |
| Compliance API, including Cowork sessions | ✗ | ✗ | ✗ | ✓ |
| Analytics API | ✗ | ✗ | ✗ | ✓ |
| Organization data export | Self-serve | Self-serve | Primary Owner | Primary Owner |
| Zero Data Retention (ZDR) | ✗ | ✗ | ✗ | Claude Code only, not Cowork |
| Custom data retention | ✗ | ✗ | ✗ | ✓ (30-day minimum) |
| CMEK | ✗ | ✗ | ✗ | ✓ (by request) |
| US-only inference | ✗ | ✗ | ✗ | Usage-based Enterprise only, at 1.1x rates |
| Trusted Devices (Claude Code Remote Control only) | ✗ | ✗ | ✓ (off by default) | ✓ (off by default) |
| Claude Tag (Slack) | ✗ | ✗ | ✓ (beta) | ✓ (beta) |
| Data used for training | User toggle | User toggle | No (default) | No (default) |
| Retention default | Until deleted | Until deleted | Indefinite | Indefinite unless custom |
| Spend controls | None | User's own credits | Org and per-user limits | Org, group and per-user, plus Spend Limits API |
| Seat range | N/A | N/A | 2 to 150 | 20 self-serve, 50 sales-assisted |
Three corrections to note against earlier versions of this table. Team plans do have SAML SSO, JIT and domain verification; only SCIM is Enterprise-only, and OIDC is not documented anywhere, so SAML is the only supported protocol. Enterprise has moved to a single seat type covering web, desktop, mobile, Claude Code and Cowork, with legacy seat types closed to new contracts; on legacy dual-seat plans, custom roles cannot override seat-level restrictions in either direction. And two Anthropic pages disagree on the Enterprise seat minimum, quoting 20 on one and 20 or 50 on another.
ℹ Free deserves a line of its own, because a control model that assumes "no paid seat means no risk" is wrong. A Free user cannot reach Cowork, Claude Code, Claude in Chrome, projects or Claude Tag. They can reach connectors and remote MCP with one custom connector, desktop extensions, code execution, file creation, artifacts, and memory that is on by default. Skills are not among them: Anthropic scopes those to Pro, Max, Team and Enterprise.
4.2 Audit and Observability
This section previously described the audit gap as a complete blind spot with no configuration path to close it. That is no longer accurate, and it is the most consequential correction in this guide.
The Compliance API now covers Cowork. Session endpoints for Cowork and Claude Code reached general availability on 26 August 2026. Local sessions, meaning those running on a member's own machine, are served from /v1/compliance/apps/sessions/local; sessions started on claude.ai web or mobile come from /v1/compliance/apps/sessions/remote. The product_surface values are cowork, cowork_remote, claude_code, claude_science and office_agents variants. Local sessions are captured server-side as requests reach the Claude API, so nothing is installed on the device, and on-device activity that never reaches the API remains invisible.
Access is Enterprise, excluding Public Sector. Only the Primary Owner can enable it, at Organization settings > API, and the earlier claim that it requires an NDA via the Trust Center is wrong. A Compliance Access Key reaches every endpoint; an Admin API key reaches only the Activity Feed. Scopes are read:compliance_activities, read:compliance_user_data, read:compliance_org_data and delete:compliance_user_data. The rate limit is 600 requests per minute per parent organization.
⛔ Enable the Compliance API before you pilot Cowork, not after. The Activity Feed is not retroactive: it only reaches back to the point the Compliance API was first enabled. Retention is then six years. Enabling it late means permanently losing the window you most want to review.
What transcripts contain. User prompts, assistant text, tool calls, text tool results, file text read via tools, skill content sent as message content, and session metadata. What they exclude: thinking blocks, the system prompt, tool definitions, MCP server configuration, images, PDFs and binary blocks, and token usage and cost. Tool inputs and each tool result are truncated to 10,000 bytes by default, raisable to roughly 1 MiB with tool_use_input_max_bytes and tool_result_max_bytes.
Known exclusions. Claude Code on the web, Claude Code authenticated with a Console API key, and any session on Bedrock, Google Vertex or Microsoft Foundry are not captured. Organizations with HIPAA readiness enabled capture no local session data at all. ZDR sessions return 404. Session endpoints are read-only: there is still no deletion endpoint, and Anthropic's documentation says deletion "isn't available yet". Content a user deletes in claude.ai returns with deleted_at populated but no content, so pull for legal hold while it is available.
Audit logs remain a separate, narrower thing. Enterprise-only, exported by Owners from Organization settings > Data and privacy, capped at a 180-day lookback, delivered as an aggregated CSV by email on a link valid 24 hours. Recorded events are authentication, administrative and resource lifecycle only. Chat and project titles and content are never exportable. The export button is unavailable to organizations using CMEK. There are still no Cowork event types. Audit log events are now also served through the Compliance API, which Anthropic describes as the surface to standardize on.


.png)
.png)
