Setting up Claude Cowork
What to set up in Claude Cowork before the first real task, in what order, and what to leave until later.
The setup, in order
- One folder for one stream of work
- Short instructions Claude reads every time
- Connected apps for this week's work only
- Manual approval until a task runs clean
- One real task, checked against what you know
Add skills and schedules after the first task comes back right.
Cowork is the mode in the Claude app where Claude carries out a task rather than answering a message. It works on files in a folder you choose and in apps you connect, then hands back finished work. Without setup, every task starts knowing nothing about you, and you retype the same background each time. The setup moves that background into places Cowork reads on its own.
As of September 2026, you need a paid Claude plan, and local folders need the
desktop app on Mac or Windows. Anthropic also offers a guided start. Type
/setup-claude in your first task and it installs a prepackaged kit for your
role, called a plugin, then connects your apps. That route is faster. This one
connects less at the start and loosens permissions later, and each step says
why.
Give it one small folder
- One folder per client or stream of work
- Not Documents, Desktop, or your home folder
- Real files, copied in, nothing sensitive
- Recurring work becomes a project
The folder is the boundary. Keep it small.
When you choose a folder, Claude can read and change everything in it. Anthropic's safety guide recommends a dedicated working folder rather than broad access, and keeping financial documents out of it. You set a folder once and stop thinking about it, so pick one you'd be comfortable with on a bad day.
Use real material so you can judge the result, but copy it in. A mistake then costs a fresh copy, not an original. Cowork always asks before it permanently deletes a file.
For recurring work, like one client or one monthly report, make the folder a project. A project keeps its own instructions, files, and memory. Memory stays inside the project, so what Claude learns about one client doesn't carry into another's work.
Write instructions it reads every time
- Global: who you are, your shorthand, how you want output
- Project: the client, the deliverable, the house rules
- Each rule says what to do, and why
- A correction you keep repeating becomes a line
If Claude keeps ignoring a rule, the file is probably too long.
Global instructions live under Settings → Cowork, and Claude reads them in every session, scheduled tasks included. Anthropic suggests three things: who you are and what you do, the shorthand you use, and how you want output delivered. If your office calls it "the Friday numbers," say once what that means.
Write each rule as the thing to do, with its reason. "Write in paragraphs, because clients forward these" works better than "no bullet points." You don't need it complete on day one. A correction you keep giving is the next line to add.
Anthropic's guidance for Claude Code, Cowork's sibling for software work, says a rule Claude keeps ignoring is usually lost in a file that's too long. It's written for Claude Code, so treat it here as a working rule rather than a documented one. Claude can also edit folder instructions during a session, so reread them now and then.
Connect only what this week needs
- A connector lets Claude read from, and act in, another app
- Start with the one your first task touches
- Remove the ones you stop using
An unused connector is still access you've granted.
A connector links Cowork to another app, such as Gmail, Google Drive, Slack, or Notion. Claude can read from it and, depending on the app, act in it. Add them from the + menu in the message box or from Customize → Connectors. Anthropic's setup course suggests an order: email and calendar, messaging, file storage, then your customer database or project tracker. Connect the one your first task needs and stop there.
Each connector adds to what Claude can read and to what it can do. The next two steps are about that pairing. With a handful of connectors, the default Tool access setting is fine. Anthropic suggests switching to On demand only past about 30 tools.
Keep approval on Manual at first
- Manual: asks before every action
- Auto: acts on its own after a safety check
- Skip: no checks, for short tasks on trusted content
- Deleting a file always asks
Loosen approval one task at a time, after it has run clean.
The approval mode decides when Claude stops to ask you. Change it from the selector in the message box. Manual asks before every connector action, read or write. Auto lets reads through and screens each write for safety, and it uses more of your plan's allowance than the other modes. Skip removes the checks.
Anthropic's safety guide says to use Manual for sensitive files or accounts, and for any tool or site you're using for the first time. Use it too for anything hard to undo, like sending a message or making a purchase. Manual gets tedious, and a prompt you click through without reading protects nothing. When that starts on a task you've watched run clean, move that task to Auto.
What it reads can give it orders
- Instructions hidden in a file, email, or web page
- An attack needs outside content and the power to act
- Keep the two apart where the stakes are high
A task that reads strangers' email shouldn't also be able to send email.
Prompt injection is the name for instructions planted in something Claude reads, which it may follow as if they came from you. Anthropic's safety guide says an attack needs two conditions: Claude reading content from outside trusted sources, and Claude being able to take consequential actions. In January 2026, researchers at PromptArmor showed a document with hidden instructions getting Cowork to upload a user's files to an account the attacker controlled.
Anthropic trains Claude to refuse such instructions and scans incoming content for them. Simon Willison, a developer who writes about AI security, names the limit: those protections can't guarantee that no future attack will be found. The earlier steps each narrow one side. The folder limits what Claude can touch, connectors limit where it can reach, and Manual approval puts you in front of each action.
Brief the first task, then check it
- Where to look
- What done looks like
- What to check it against
- No persona, no pep talk
Ask for the evidence you'll need to review it.
Start with a task you can grade. Anthropic's setup course suggests asking Cowork to summarize the folder you connected, then checking the summary against what you know.
For later briefs, borrow a pattern from Simon Scrapes' video on Claude Code mistakes. Spend your words on three things: where the material is, what finished looks like, and what to check it against. The same video suggests cutting the "you are a senior copywriter" opener. A 2024 study of 162 personas across 2,410 factual questions found they didn't make answers more accurate. Anthropic still says a one-line role can set the tone.
Ask for evidence you can review: the source file behind each figure, and a list
of what changed. Karo Zieminski's Cowork guide describes keeping a
what-changed.md file for this. Anthropic says Claude Opus 5 already checks
its own work. The evidence is for you: reading it is faster than redoing the
work to check it.
Write a skill once the task repeats
- A skill is a saved brief for one recurring task
- Run the task by hand a few times first
- Then ask Claude to package it
- Several small skills, not one large one
Automate what already works.
A skill is a saved set of instructions for one recurring task, which Claude uses when that task comes up. Anthropic's suggested order is instructions and connectors first, then a skill once you've run the same task a few times. When a run goes well, ask Claude to turn that run into a skill.
Tom Osman's Cowork setup guide warns that automation magnifies unclear instructions as fast as good ones. Karo Zieminski found several small skills worked better than one large one. Plugins bundle skills and connectors for a role, and some run programs on your computer with your permissions, so install only from sources you trust.
Simon Scrapes' video found two catches. Skills built in Claude Code don't carry over, so upload them under Customize. And Cowork loads skills when a session starts, so open a new task after adding one.
Schedule only what can run unwatched
- Runs on a timer, with your laptop shut
- Summaries and roundups, not sending or buying
- Review each run, and pause what you've stopped reading
Nobody watches a scheduled task while it runs.
A scheduled task is a saved prompt that Cowork runs hourly, daily, weekly, or on
weekdays. Type /schedule in a task, or open Scheduled in the sidebar. As of
September 2026 these run in Anthropic's cloud, so they keep going with your
laptop shut. They work from your connectors and the files saved to your Claude
account, not a folder on your computer. Guides from April 2026 still say the
computer must stay on, so check the date on whatever you read.
Anthropic's safety guide says to start with summaries and keep sensitive data out. Don't schedule anything that sends messages or makes purchases. Review each run, and pause what you're not using. Simon Theakston's 7am weekday briefing fits that shape. It reads and summarizes, and Claude can draft email in that setup but never send it.
What it costs, and what stays out
- More of your plan than chat, and Auto uses more still
- Team plans share projects, not sessions
- Money, passwords, and personal records stay outside
Pick a first task that reads more than it writes.
Cowork uses more of your plan's allowance than chat, and Auto mode uses more than the other approval modes. Settings → Usage shows where you stand. Questions that don't need your files still belong in a normal chat.
On Team and Enterprise plans, projects can be shared with view or edit access, and admins can turn off automatic approval. Individual sessions can't be shared. Anthropic's safety guide lists what to keep out of Cowork: financial documents, credentials, personal records, and banking or healthcare sites. That work still needs a person.
Your next decision is the first task. Pick one that recurs, reads more than it writes, and produces something you can check against what you already know.
What would make your
work a little easier?
A recurring task, a half-formed idea, a system that could work better. That’s a good place to start.
Let’s talk it through