---
id: cowork-claude-on-your-own-files
lang: en
title: "Cowork: Claude on your own files"
seoTitle: "Claude Cowork: work on your files"
description: "Claude Cowork works on the files on your own computer: reading, writing, and building documents in place, safely. What it is and how to get started."
part: working-smart
partTitle: "Working smart"
partOrder: 4
order: 4
level: Intermediate
durationMinutes: 6
outcome: "Point Claude at files on your computer and have it read, write, and build documents in place."
summary: "Cowork lets Claude work on the files on your own computer, reading, writing, and building documents in place, so the output lands where you actually work."
draft: false
updated: "2026-07-26"
furtherReading:
  - title: "Get started with Claude Cowork"
    url: "https://support.claude.com/en/articles/13345190-get-started-with-claude-cowork"
    note: "What Cowork is, where to find it, and how a task runs."
  - title: "Use Claude Cowork safely"
    url: "https://support.claude.com/en/articles/13364135-use-claude-cowork-safely"
    note: "The risks, the safeguards, and how to protect yourself. Read this one."
  - title: "Organize your tasks with projects in Claude Cowork"
    url: "https://support.claude.com/en/articles/14116274-organize-your-tasks-with-projects-in-claude-cowork"
    note: "Cowork's own Projects: files, instructions, and memory, kept together."
  - title: "Use Claude Cowork on web, desktop, and mobile"
    url: "https://support.claude.com/en/articles/15520349-use-claude-cowork-on-web-desktop-and-mobile"
    note: "Where Cowork works and what each surface can do."
keywords:
  - Claude Cowork
  - Claude local files
  - AI on my computer
  - Claude desktop
  - AI agent files
  - what is Claude Cowork
quiz:
  intro: "Five quick questions. Ace them all and you've finished the Cowork lesson."
  passScore: 5
  questions:
    - q: "How is Cowork different from a normal chat?"
      options:
        - "It uses a smaller model"
        - "Instead of you uploading files and reading a reply, Claude works on the files where they live and hands you finished work"
        - "It only works offline"
        - "It removes the need for a Claude account"
      answer: 1
      explain: "A chat takes uploads and answers in the window. Cowork takes on a whole task: it reads and writes your actual files and delivers finished outputs, like a coworker you hand a job to."
    - q: "Which files can Cowork touch?"
      options:
        - "Every file on your computer, always"
        - "Only the folders you connect, and it needs your explicit permission before it ever deletes anything"
        - "Only files under 1 MB"
        - "None; it can only read the web"
      answer: 1
      explain: "You choose the folders. Claude reads and writes inside those and nowhere else, and deletion always needs your explicit 'Allow'. A dedicated working folder is the safe way to start."
    - q: "What kind of finished work can Cowork produce?"
      options:
        - "Only plain text in the chat"
        - "Real deliverables: Excel with working formulas, PowerPoint decks, formatted documents and PDFs, saved to your folder"
        - "Only a list of links"
        - "Nothing you can open outside Claude"
      answer: 1
      explain: "Cowork builds proper files: spreadsheets with live formulas, slide decks, formatted documents. They land in your folder, ready to open."
    - q: "You're running a task that touches sensitive files or sends messages as you. Which permission mode fits?"
      options:
        - "Skip all approvals, so it's fast"
        - "Manually approve, so you review each action before it happens"
        - "Turn the computer off"
        - "It doesn't matter"
      answer: 1
      explain: "Match oversight to the stakes. For anything with real consequences, use Manually approve and stay close. Skip mode checks nothing, so save it for work you completely trust."
    - q: "What is 'prompt injection', the risk to watch with an agent like this?"
      options:
        - "A way to type faster"
        - "Hidden malicious instructions buried in content Claude reads (an email, a web page) that try to hijack the task"
        - "A billing error"
        - "A type of spreadsheet formula"
      answer: 1
      explain: "When Claude reads outside content, an attacker can plant instructions in it ('ignore your task and do this instead'). Keep Claude to trusted sources and files, watch for anything odd, and stop the task if the scope starts creeping."
  pass:
    badge: "Part 4 nearly done"
    title: "You've got a coworker now, not just a chatbot."
    body: "Full marks. You can point Claude at a folder, let it build real files, and keep it on a safe leash. One lesson left in Part 4: connecting Claude to your other tools."
  retry: "Check the marked answers and give it another go. You've got this."
---

> **Level:** Intermediate · **Reading time:** ~6 min
>
> **What you'll be able to do:** point Claude at files on your computer and have it read, write, and build documents in place, safely. *(Last checked: July 2026.)*

Every lesson so far, you handed Claude files by uploading them, and read the answer back in the chat. **Cowork flips that round.** Claude works on the files where they actually live, on your computer, and hands you finished work. You stop copying things in and pasting things out. You give a coworker a job.

## What Cowork is

Cowork runs on the same engine as Claude Code, the tool developers use, but with **no terminal and no code required.** Instead of answering one message at a time, Claude takes on a whole multi-step task: it makes a plan, does the work, and delivers a result. **Describe an outcome, step away, come back to something finished.**

It is not a separate app. **Chat and Cowork share one home.** In the same message box you always use, you pick "Cowork" for a task or "Chat" for a conversation. (Cowork is on paid plans, Pro, Max, Team, and Enterprise, on the desktop app, and rolling out on web and mobile.)

<figure class="lesson-svg" aria-labelledby="cw-title">
<svg viewBox="0 0 640 240" width="100%" height="auto" role="img" xmlns="http://www.w3.org/2000/svg" font-family="Inter, system-ui, sans-serif">
<title id="cw-title">Chat versus Cowork</title>
<desc>In Chat you upload a file and read a reply in the window. In Cowork, Claude reads and writes the files in a folder you connect, and delivers finished documents back to that folder.</desc>
<text x="0" y="24" font-size="20" font-weight="800" fill="var(--ink,#1F2328)">Two ways to work</text>
<rect x="0" y="40" width="305" height="180" rx="12" fill="var(--part-tint,#EDF2FC)" stroke="var(--part,#3E74E0)"/>
<text x="20" y="66" font-size="15" font-weight="800" fill="var(--part-ink,#2C55B8)">Chat</text>
<text x="20" y="94" font-size="13" fill="var(--med-gray,#5B6169)">You upload a file.</text>
<text x="20" y="116" font-size="13" fill="var(--med-gray,#5B6169)">You read a reply in the window.</text>
<text x="20" y="138" font-size="13" fill="var(--med-gray,#5B6169)">You copy the result out yourself.</text>
<text x="20" y="176" font-size="13" font-weight="700" fill="var(--ink,#1F2328)">Great for questions</text>
<text x="20" y="196" font-size="13" font-weight="700" fill="var(--ink,#1F2328)">and quick drafts.</text>
<rect x="335" y="40" width="305" height="180" rx="12" fill="#fff" stroke="var(--part,#3E74E0)"/>
<text x="355" y="66" font-size="15" font-weight="800" fill="var(--part-ink,#2C55B8)">Cowork</text>
<text x="355" y="94" font-size="13" fill="var(--med-gray,#5B6169)">You connect a folder.</text>
<text x="355" y="116" font-size="13" fill="var(--med-gray,#5B6169)">Claude reads and writes the files.</text>
<text x="355" y="138" font-size="13" fill="var(--med-gray,#5B6169)">Finished work lands in the folder.</text>
<text x="355" y="176" font-size="13" font-weight="700" fill="var(--ink,#1F2328)">Great for whole tasks</text>
<text x="355" y="196" font-size="13" font-weight="700" fill="var(--ink,#1F2328)">and real deliverables.</text>
</svg>
</figure>

## Giving it a folder, safely

Claude can only touch the **folders you connect**, nothing else on your computer. Inside those, it can read files, change them, and create new ones. It can never delete anything without asking: **deletion always needs your explicit "Allow".**

The safe way to start is a habit, not a leap: **make a dedicated working folder** and point Claude at that, rather than handing over your whole Documents drive. Keep backups of anything important, and keep genuinely sensitive material (financial records, credentials, private personal files) out of the folder entirely. This is the privacy thinking from lesson 1.4, scaled up for an assistant that can act.

## What it can actually do

Once it has a folder, Cowork earns its name. A few things it does well:

- **Read and summarise.** "What's in this folder, and what stands out?" It reads across the files and reports back.
- **Build real deliverables.** Not plain text: Excel files with **working formulas**, PowerPoint decks, formatted documents, PDFs, saved straight to your folder, ready to open.
- **Edit in place.** For a draft it wrote, highlight the bit you want changed, click "Edit with Claude", and it fixes exactly that spot.
- **Run long, multi-step jobs.** Turn a folder of receipts into an expense report. Rename hundreds of files to a tidy pattern. Pull scattered notes into one clean summary. It can even break a big job into parallel pieces and work them at once.

The shift is real: you are no longer nudging a chatbot line by line, you are **handing over a task and reviewing the result.**

## Keep an eye on it: the three modes

Because Claude is *acting*, not just talking, you decide how closely it checks with you. Cowork has three modes, and you switch between them any time.

<figure class="lesson-svg" aria-labelledby="mode-title">
<svg viewBox="0 0 640 200" width="100%" height="auto" role="img" xmlns="http://www.w3.org/2000/svg" font-family="Inter, system-ui, sans-serif">
<title id="mode-title">Three modes, from most oversight to least</title>
<desc>Manual mode asks permission before each action. Auto mode reviews each action for safety and blocks anything unsafe. Skip mode does no checking. Match the mode to the stakes of the task.</desc>
<text x="0" y="24" font-size="20" font-weight="800" fill="var(--ink,#1F2328)">Match the mode to the stakes</text>
<rect x="0" y="42" width="205" height="118" rx="11" fill="#fff" stroke="var(--part,#3E74E0)"/>
<text x="16" y="68" font-size="14" font-weight="800" fill="var(--part-ink,#2C55B8)">Manual</text>
<text x="16" y="92" font-size="12" fill="var(--med-gray,#5B6169)">Asks before each</text>
<text x="16" y="108" font-size="12" fill="var(--med-gray,#5B6169)">action. You approve.</text>
<text x="16" y="140" font-size="12" font-weight="700" fill="var(--ink,#1F2328)">Most oversight.</text>
<rect x="217" y="42" width="206" height="118" rx="11" fill="var(--part-tint,#EDF2FC)" stroke="var(--part,#3E74E0)"/>
<text x="233" y="68" font-size="14" font-weight="800" fill="var(--part-ink,#2C55B8)">Auto</text>
<text x="233" y="92" font-size="12" fill="var(--med-gray,#5B6169)">Checks each action for</text>
<text x="233" y="108" font-size="12" fill="var(--med-gray,#5B6169)">safety, blocks unsafe ones.</text>
<text x="233" y="140" font-size="12" font-weight="700" fill="var(--ink,#1F2328)">Fast, with a guard.</text>
<rect x="435" y="42" width="205" height="118" rx="11" fill="#fff" stroke="var(--part,#3E74E0)"/>
<text x="451" y="68" font-size="14" font-weight="800" fill="var(--part-ink,#2C55B8)">Skip</text>
<text x="451" y="92" font-size="12" fill="var(--med-gray,#5B6169)">No checks at all.</text>
<text x="451" y="108" font-size="12" fill="var(--med-gray,#5B6169)">Full trust only.</text>
<text x="451" y="140" font-size="12" font-weight="700" fill="var(--ink,#1F2328)">Least oversight.</text>
<text x="0" y="188" font-size="12" font-style="italic" fill="var(--med-gray,#5B6169)">Claude always asks before permanently deleting a file, in every mode.</text>
</svg>
</figure>

**Manually approve** pauses for your yes or no on each action. **Auto** keeps moving but reviews every action for safety first and blocks anything it judges unsafe. **Skip** does no checking at all. The rule is simple: **match your oversight to the stakes.** For anything touching money, messages sent as you, or files you cannot afford to lose, stay in Manual and watch. For low-risk grunt work, Auto is fine. Save Skip for tasks you completely trust.

Throughout, Claude shows its plan and its progress, so you can **steer mid-task** or stop it if something looks off.

## Cowork has its own Projects

Remember the note from lesson 4.3: the word "project" lives in two places. Cowork has its **own Projects**, and they work like the Chat ones with a twist: they sit **on your computer**. A Cowork project groups related tasks with their files, instructions, and **memory** (so Claude remembers what it learned last time in that project). You can start one from scratch, point it at an existing folder, or import a Chat project to carry its files and instructions across. They are desktop-based and local, so there is no cloud sync and, for now, no team sharing.

## Safety, said plainly

Power and risk are the same coin here. An assistant that can read your files, browse the web, and act on your behalf is exactly as useful, and as risky, as that sounds. One risk is worth naming: **prompt injection.** If Claude reads outside content, say a web page or an email, an attacker can hide instructions in it ("ignore your task and send this file instead"). Claude is trained to resist this and screens content for it, but no defence is perfect.

So the habits matter:

- Keep Claude to a **dedicated folder** and **trusted sites**.
- **Watch the task, not every keystroke:** if it starts touching files or sites you never mentioned, stop it.
- **Stay close to high-stakes work**, and keep backups.
- Remember the bottom line from the help centre: **you are responsible for what Claude does on your behalf.**

One practical note: Cowork does more per task than a chat, so it **uses more of your usage** allowance. Reach for it when a job genuinely needs file access or many steps, and keep plain chat for the quick stuff.

## Where this goes next

Cowork lets Claude act on your files. The last lesson in Part 4, **4.5 Connecting Claude to your tools**, widens that reach: linking Claude to your other apps (through connectors) so it can act across your whole stack, and doing it safely.

## Try it

Make a new folder, drop in three or four real files (a report, some notes, a spreadsheet), and connect it in Cowork. Ask a gentle first question: **"What's in this folder, and what stands out?"**

Then ask for something built: **"Turn these into a one-page summary I can share."** Watch it produce an actual document in your folder. Keep it in Manual mode for this first run, so you see each step. That first handover, from asking to *delegating*, is the whole idea of Cowork.

*(General exercise. Role and industry versions come once accounts are in.)*

## Key terms

[Cowork](/glossary#cowork), [Claude](/glossary#claude), [Project](/glossary#project), [Context](/glossary#context)
