Notice: This page requires JavaScript to function properly.
Please enable JavaScript in your browser settings or update your browser.
Learn Good to Know | Understanding Cowork
Claude Cowork

Good to Know

Swipe to show menu

A single-slide-per-topic sweep of the important non-obvious things about Cowork - where it isn't the right tool, how regulated data fits (or doesn't), the privacy and sandbox model, async work, and features still in research preview.

Core Concept

Nobody tells you where an agent isn't the right tool. That's why some people end up frustrated with AI - they hand it a task that was never a good fit in the first place, and blame the model. This chapter names the failure modes up front. Ten minutes of "here's where this doesn't work" saves you months of confusion.

How It Works (Step-by-Step)

Step 1 - Recognize where Cowork isn't great

Two red flags mean the task doesn't fit Cowork.

Vague goals
expand arrow

If you can't say what "done" looks like, Cowork can't either. "Make my Slack nicer" is not a goal. "Archive every channel with no posts in the last 90 days" is.

The task is the judgment call
expand arrow

When the thinking IS the work - picking a name for your company, writing a wedding speech, deciding whether to fire someone - that's a Chat conversation, not a Cowork task. Cowork is for execution; you're still the one making the calls that need a human.

On top of both: when Cowork hands you back numbers, legal language, or anything financial - verify it. Ask for the sources. Treat its output like a sharp junior teammate's - useful, fast, mostly right, but check it.

Step 2 - Understand the regulated-data heads-up

Cowork isn't currently certified for HIPAA, FedRAMP, or regulated financial workloads. That doesn't mean you can't use it - most of your day-to-day work isn't covered by those rules. It just means the specific data those frameworks govern (patient records, government-classified material, regulated financial accounts) shouldn't go into Cowork until certification is there.

Note
Note

Practical version: keep that stuff in the tools that are certified, and use Cowork for everything around it. If a compliance team has ever asked you about a file, that's the file.

Step 3 - Understand the privacy model

Cowork lives in a sandbox. Think of it as a glass box on your desk - it can only see and touch what you hand into it.

  • Folders only. And only the folders you specifically grant.
  • Connectors only. And only the connectors you authorize, one at a time.
  • Nothing else on your machine, nothing else in your accounts.

When you grant a folder, that's read and write inside that folder and nowhere else - not even one level up. Your conversation history is stored locally on your device.

Note
Note

Scope tightly. Don't grant your whole Documents folder when a single project folder would do. Don't connect every Slack workspace when you only need one. The smaller the surface area, the more confidently you can hand bigger jobs over.

Step 4 - Recognize that Cowork is async

A working session can run for a long time. If you've handed it a big job - reorganizing a thousand files, researching twenty competitors, building out a deck - you can close the laptop, take a meeting, come back to it later.

The task is still there. If it hit an approval checkpoint while you were gone, it just paused and waited. If it finished, the deliverable is sitting there for you.

This is one of the biggest unlocks compared to Chat, where you have to sit and babysit the conversation. Here you start the thing, walk away, and check in when it's convenient. Treat Cowork less like a chatbot and more like a teammate working in the background.

Step 5 - Know what's still in preview

Two features to flag specifically because they are still research preview.

  • Computer use - Claude actually taking over your cursor and keyboard to operate apps that don't have a connector. Works, but slower and rougher than a clean connector.
  • Dispatch (phone) - kicking off Cowork tasks from your phone. Also real, also early.

Rule of thumb: if there's a connector for what you're trying to do, use the connector. Reach for preview features when there genuinely isn't another way, and expect to babysit them a bit more than usual.

Why This Matters

An agent that takes real actions needs a "don't" lesson early or learners over-trust it. This chapter is that lesson, packaged so you can spot the anti-patterns before they cost you time. Everything from Section 2 onward assumes you know these guardrails.

What Should Be Possible After This

  • Name the two red flags - vague goals and pure judgment calls - that mean a task doesn't belong in Cowork.
  • Explain the regulated-data heads-up and where Cowork does and doesn't belong in a compliance-heavy environment.
  • Describe the sandbox privacy model in one sentence - Cowork sees only the folders and connectors you specifically grant.
  • Explain what "async" means in Cowork's context and why you can walk away mid-task.
  • Distinguish preview features (computer use, dispatch) from stable ones.
Note
Note

You now have the mental model. You know what Cowork is, how it differs from Chat and Code, where its guardrails are, and what a real end-to-end task looks like. Section 2 opens the extension layer - connectors, skills, plugins, and MCP. That's where the real leverage starts.

question mark

Which of the following are red flags indicating a task may not be a good fit for Cowork?

Select all correct answers

Everything was clear?

How can we improve it?

Thanks for your feedback!

Section 1. Chapter 4

Ask AI

expand

Ask AI

ChatGPT

Ask anything or try one of the suggested questions to begin our chat

Good to Know

A single-slide-per-topic sweep of the important non-obvious things about Cowork - where it isn't the right tool, how regulated data fits (or doesn't), the privacy and sandbox model, async work, and features still in research preview.

Core Concept

Nobody tells you where an agent isn't the right tool. That's why some people end up frustrated with AI - they hand it a task that was never a good fit in the first place, and blame the model. This chapter names the failure modes up front. Ten minutes of "here's where this doesn't work" saves you months of confusion.

How It Works (Step-by-Step)

Step 1 - Recognize where Cowork isn't great

Two red flags mean the task doesn't fit Cowork.

Vague goals
expand arrow

If you can't say what "done" looks like, Cowork can't either. "Make my Slack nicer" is not a goal. "Archive every channel with no posts in the last 90 days" is.

The task is the judgment call
expand arrow

When the thinking IS the work - picking a name for your company, writing a wedding speech, deciding whether to fire someone - that's a Chat conversation, not a Cowork task. Cowork is for execution; you're still the one making the calls that need a human.

On top of both: when Cowork hands you back numbers, legal language, or anything financial - verify it. Ask for the sources. Treat its output like a sharp junior teammate's - useful, fast, mostly right, but check it.

Step 2 - Understand the regulated-data heads-up

Cowork isn't currently certified for HIPAA, FedRAMP, or regulated financial workloads. That doesn't mean you can't use it - most of your day-to-day work isn't covered by those rules. It just means the specific data those frameworks govern (patient records, government-classified material, regulated financial accounts) shouldn't go into Cowork until certification is there.

Note
Note

Practical version: keep that stuff in the tools that are certified, and use Cowork for everything around it. If a compliance team has ever asked you about a file, that's the file.

Step 3 - Understand the privacy model

Cowork lives in a sandbox. Think of it as a glass box on your desk - it can only see and touch what you hand into it.

  • Folders only. And only the folders you specifically grant.
  • Connectors only. And only the connectors you authorize, one at a time.
  • Nothing else on your machine, nothing else in your accounts.

When you grant a folder, that's read and write inside that folder and nowhere else - not even one level up. Your conversation history is stored locally on your device.

Note
Note

Scope tightly. Don't grant your whole Documents folder when a single project folder would do. Don't connect every Slack workspace when you only need one. The smaller the surface area, the more confidently you can hand bigger jobs over.

Step 4 - Recognize that Cowork is async

A working session can run for a long time. If you've handed it a big job - reorganizing a thousand files, researching twenty competitors, building out a deck - you can close the laptop, take a meeting, come back to it later.

The task is still there. If it hit an approval checkpoint while you were gone, it just paused and waited. If it finished, the deliverable is sitting there for you.

This is one of the biggest unlocks compared to Chat, where you have to sit and babysit the conversation. Here you start the thing, walk away, and check in when it's convenient. Treat Cowork less like a chatbot and more like a teammate working in the background.

Step 5 - Know what's still in preview

Two features to flag specifically because they are still research preview.

  • Computer use - Claude actually taking over your cursor and keyboard to operate apps that don't have a connector. Works, but slower and rougher than a clean connector.
  • Dispatch (phone) - kicking off Cowork tasks from your phone. Also real, also early.

Rule of thumb: if there's a connector for what you're trying to do, use the connector. Reach for preview features when there genuinely isn't another way, and expect to babysit them a bit more than usual.

Why This Matters

An agent that takes real actions needs a "don't" lesson early or learners over-trust it. This chapter is that lesson, packaged so you can spot the anti-patterns before they cost you time. Everything from Section 2 onward assumes you know these guardrails.

What Should Be Possible After This

  • Name the two red flags - vague goals and pure judgment calls - that mean a task doesn't belong in Cowork.
  • Explain the regulated-data heads-up and where Cowork does and doesn't belong in a compliance-heavy environment.
  • Describe the sandbox privacy model in one sentence - Cowork sees only the folders and connectors you specifically grant.
  • Explain what "async" means in Cowork's context and why you can walk away mid-task.
  • Distinguish preview features (computer use, dispatch) from stable ones.
Note
Note

You now have the mental model. You know what Cowork is, how it differs from Chat and Code, where its guardrails are, and what a real end-to-end task looks like. Section 2 opens the extension layer - connectors, skills, plugins, and MCP. That's where the real leverage starts.

Everything was clear?

How can we improve it?

Thanks for your feedback!

Section 1. Chapter 4
some-alt