Claims last verified 2026-07-2822 confirmed · 6 documented · 1 stale riskverification log →
Anthropic's policies and products change frequently —
always confirm current specifics with your Anthropic contact before relying on this for a compliance decision.
Folder & Desktop Access
When you let Claude work with files on your computer, *where* you let it work is the whole ballgame. This domain covers how to set up working folders so Claude sees exactly what you intend — and nothing else.
Where this comes from: the findings below are drawn from the working group's
own document (its “§” numbers are that document's sections) and, where marked
✓Confirmed,
checked against Anthropic's primary pages — see the verification log.
This module is a teaching aid, not compliance or legal advice — patient-data
decisions belong to your organization, its counsel, and its Anthropic contact.
How to read the chips
✓Confirmedchecked against Anthropic’s own page on the date shown, and the receipt kept.
▪Documentedcarried from the working group’s document (context as of July 2026), not re-checked since.
⚠︎Stale riskknown-volatile, or the check found a discrepancy — treat as a question, not a fact.
⚑compliancea claim a patient-data decision could hang on — always confirm with your Anthropic contact first.
✎our practicethe group’s recommended practice, not an Anthropic product fact.
What we found
Each finding opens with the plain-language version; the detail, the source, and the related
claims sit one click below. The chips tell you how much to lean on it.
✓ checked against Anthropic's page · ▪ carried from the group's doc, not re-checked · ⚠ treat as a question
Use a dedicated working folder, not broad desktop access
Anthropic *suggests* giving Claude its own folder to work in rather than your whole Desktop, Documents, or home directory — and keeping backups of important files. Inside a folder you've connected, Claude can read and write files, and — with your permission — delete them.
Detail, source & related
Detail
Anthropic’s guidance for Cowork/Desktop is phrased as a suggestion, not a directive: “Consider creating a dedicated working folder for Claude rather than granting broad access, and keep backups of important files.” Both halves matter — the backup companion is part of the same sentence, and it is the recovery plan for the deletion capability the same passage describes: “Since Claude can read, write, and permanently delete these files, be cautious about granting access to sensitive information like financial documents, credentials, or personal records.”
Status: CONFIRMED 2026-07-25 (receipt R10): both quoted passages verified on the live page this date. Corrected 2026-07-25 — the prior version rendered the source’s “Consider …” suggestion as “Anthropic’s own guidance … is to create,” and dropped the “keep backups of important files” clause from the same sentence.
▪ Documented ✎our practice
source: working-group doc
A simple structure that keeps the access boundary obvious: `raw/` holds untouched source files Claude never sees, `work/` is the only folder Claude is granted, and `out/` holds final deliverables. Anyone can audit the boundary at a glance.
Detail, source & related
Detail
A common pattern recommended by Anthropic and practitioners: three tiers — raw/ (untouched source files), work/ (the only folder Claude is granted access to), and out/ (final deliverables) — so the access boundary is explicit and easy to audit. Originals stay safe by construction; Claude works on copies; outputs land somewhere you review before they go anywhere else.
Source & currency
Source: the working-group document §1 (practice pattern; attributed there to Anthropic guidance and practitioner practice — no single page cited).
Status: DOCUMENTED · register: recommendation — practice guidance, not a product behavior of Claude. Currency check 2026-07-22 (receipt R1): the cited Cowork-safety page does not carry the raw/work/out pattern — it stands as the working group’s adopted practice, attributed by the source doc to Anthropic-and-practitioner guidance.
Cowork's isolation is narrower than it sounds. It protects your computer and network from the *code Claude runs* — it does not limit *what Claude reads or does* through the access you granted. And because sessions run on Anthropic's servers, files Claude opens on your machine are processed there, not kept on your computer.
Detail, source & related
Detail
The source page states the boundary and then immediately warns against over-reading it. Three facts, in the order that matters:
What isolation does. “Isolation protects your computer and network from the code Claude runs; it doesn’t change what Claude can read or do through the access you’ve granted.” Said plainly by the page: “Isolation limits where Claude’s code runs. It doesn’t limit what Claude reads or does.” Depending on access granted, a remote session can still “browse the web, read email and documents through your connected apps, work in folders you’ve connected, and take actions through those same channels” — and the page notes each of those is “a path for untrusted content to reach Claude, and for Claude’s actions to reach the real world.”
Where your files end up. “Because sessions run on Anthropic’s servers, the work Claude does there, including any local files it opens through the desktop app, is processed on Anthropic’s servers rather than staying on your computer.” A connected folder is not a local-only boundary — it is an ingress to a remote environment. This is the fact that matters for anything sensitive.
When the session can reach you (unchanged, still true): “A remote session reaches your computer only when the Claude Desktop app is open, only for the folders you’ve connected there, and with the permissions you’ve already set.” If the desktop app is offline, the session can’t reach your computer. The environment itself is temporary, per-session, can’t reach your home or company network, and is removed when the session ends.
Status: CONFIRMED 2026-07-25 (receipt R10) — all three quoted passages verified on the live page this date. This node was corrected on 2026-07-25: the prior version extracted the isolation sentence as reassurance and omitted the off-machine-processing fact, which the source states in the same paragraph.
⚑ Compliance-relevant: confirm current specifics with your Anthropic contact before relying on this for anything involving patient data — product behavior moves between releases. This is a teaching aid, not compliance or legal advice.
Permanent deletion is the one action that is always gated. Cowork requires your explicit "Allow" before it permanently deletes any file, and that holds even in the approval mode where nothing else is checked. The delete button stays in your hand.
Detail, source & related
Detail
Deletion protection is stated by the source as unconditional across approval modes: “Claude always asks before permanently deleting files, in any mode.” The mechanism: “Cowork requires your explicit permission before permanently deleting any files. You’ll see a permission prompt and must select ‘Allow’ before Claude can perform deletion tasks.”
Do not generalize this to other actions. The approval modes differ sharply in what else they check: in “Automatically approve” mode, “Claude still reviews each action for safety before it runs”; in “Skip all approvals,” “nothing checks its actions.” Deletion is carved out of that difference — nothing else is. In particular, computer use is a separate surface with a different (weaker) protection model — see Computer use: you grant apps, but nothing checks each action — and there is no sandbox.
This is a guardrail, not a substitute for scoping. The folder boundary (Use a dedicated working folder, not broad desktop access) is the primary protection; the permission gate is the second layer; and a deletion you approve is still a deletion, which is why the source pairs the folder advice with keeping backups.
Status: CONFIRMED 2026-07-25 (receipt R10) — both quoted passages verified on the live page this date. This node was narrowed on 2026-07-25: the prior version added “and it’s designed to ask permission before other high-risk actions too,” which over-generalized a claim the source makes only about deletion, and which the computer-use section of the same page contradicts for that surface.
When Claude drives your screen, it asks permission for each *application* — but unlike file operations, its individual actions aren't checked, and there is no sandbox between Claude and whatever is on your screen. Block healthcare portals, banking, and dating apps before you start.
Detail, source & related
Detail
Computer use is the weakest-protected surface in Cowork, and its protections work differently from the file-side ones. Four facts, and the distinction between the first two is the whole point:
Per-application permission exists. “When Claude uses your computer, it asks for your permission before accessing each application.”
Per-action checking does not. The source warns to “be especially cautious with computer use — Claude clicks, types, and navigates your screen directly, without the permission checks that gate other Cowork tools.” So: you decide which apps; you do not approve what it does inside them.
No sandbox. “Unlike file operations (which go through permission checks) or code execution (which runs in an isolated environment), computer use has no sandbox between Claude and what’s on your screen.”
The app grant leaks through links. “Although it can only use apps that you’ve given it permission to use, if it clicks a link in one app that link will open, even if you haven’t given Claude permission to access that app.” A link is enough to cross the boundary you set.
Also: “Claude takes screenshots to understand your screen” — everything visible is read, not only the app you had in mind.
The source’s own first instruction is the clinical one: “Block sensitive apps (healthcare portals, banking, dating apps) so Claude doesn’t encounter information you’d rather keep private.” Healthcare portals are named first on that list. Do this before a session, not after.
Source: Use Claude Cowork safely — Claude Help Center — under “5. Be cautious with computer use”, “4. Match your oversight to the stakes”, and the safeguards list. (All quotes are on that page; the separately-linked “Let Claude use your computer in Cowork” article is further reading, not the source cited here.)
Status: CONFIRMED 2026-07-25 (receipt R10) — all four quoted passages verified on the live page this date. This node was created on 2026-07-25 by splitting the over-general “asks before other high-risk actions” claim off Claude always asks before permanently deleting files — in any mode. Note for reviewers: an external audit proposed teaching that computer use has “no permission check” at all; that is not what the source says — the per-application ask exists (fact 1). What is absent is per-action checking and any sandbox. Both halves are carried above deliberately.
⚑ Compliance-relevant: confirm current specifics with your Anthropic contact before using computer use anywhere near patient data. This is a teaching aid, not compliance or legal advice.
This module's open questions for the Anthropic contact — also in the
consolidated printable register.
Recommended folder structure for isolating each org's files
Ask Anthropic to recommend a folder layout for the working group's actual files — conference logistics, registry/biorepository spreadsheets, grant materials — so a session working on one org's task can't wander into another org's sensitive files.
Per-project folder access scoping in Cowork
Ask whether Cowork can wall off one project's file access from another's, so a task running in Project A truly cannot reach files granted to Project B.
Reviewing and revoking granted folder access
Ask whether there's an audit trail showing exactly which files Claude read, wrote, or deleted, and how to pull back access once it's no longer needed.
Access control within a shared Cowork Project
If the working group sets up one shared Cowork "Project" for multiple people, ask how access between those members is actually governed — who can see, add, or remove what.
Folder access differences: chat vs Cowork vs Claude Code
Before picking a surface for a given task, ask Anthropic to lay out plainly what each surface — chat, Cowork, Claude Code — can and can't reach on your files, so the group picks the right tool instead of guessing.