Computer Use Permissions in Claude Cowork

Computer Use lets Claude inspect the screen and operate supported desktop apps through mouse and keyboard actions. It is currently a research preview for Pro and Max plans on macOS and Windows.

This capability carries more risk than a connector or a direct file tool because Claude is interpreting a visual interface and can act inside accounts that are already signed in. Cowork prefers more precise tools first and uses Computer Use when the task requires the visible interface.

Before enabling it

  • Update Claude Desktop.
  • Close unrelated apps and private windows.
  • Sign out of accounts the task does not need.
  • Make a backup or use copied files.
  • Choose a task that stops before saving, submitting, or sending.

Do not run Claude Desktop as an administrator merely to bypass a blocked action. Elevated access increases the damage a mistaken click or malicious instruction could cause.

macOS permissions

Claude Desktop may ask for permissions such as Accessibility and Screen Recording. Approve them through System Settings → Privacy & Security only when you understand why the task needs them. Restart the app if macOS asks you to do so.

If the task still cannot see or control an app, check that the current Claude Desktop build is listed and enabled. Remove stale entries only if the operating system or official troubleshooting guidance calls for it.

Windows permissions

Use Claude Desktop in your normal user account. Keep User Account Control prompts and administrator-only windows under direct human control. If Claude cannot interact with an elevated app, change the workflow or perform that step yourself instead of elevating the whole Claude session.

Human-in-the-loop pattern

  1. Ask Claude to name the apps and actions it expects to use.
  2. Let it inspect before changing anything.
  3. Stop before a consequential action.
  4. Review the visible fields, destination, and account.
  5. Approve only the final action you intended.
  6. Check the result and any files Claude created.

This pattern is especially important for messages, publishing, purchases, account changes, customer records, and financial systems.

Prompt-injection defenses

A webpage, email, PDF, or document can contain text that tries to redirect Claude. The instruction may be hidden from you while still visible to the model.

  • Limit the task to named sources and named actions.
  • Use a clean browser profile without saved payments or unnecessary logins.
  • Tell Claude to ignore instructions found in source content unless you approve them.
  • Stop when a site asks for credentials, downloads an unexpected file, or opens a new destination.
  • Do not let Claude paste secrets into a page or prompt.

A safe first test

  1. Open a blank spreadsheet.
  2. Create a copied text file with three fictional rows.
  3. Ask Claude to type the rows into the blank spreadsheet.
  4. Tell it to stop before saving.
  5. Check every cell and close the file without saving if anything is wrong.

Troubleshooting boundaries

  • If Claude cannot see the app, recheck the requested operating-system permission.
  • If it clicks the wrong place, stop the run and simplify the layout.
  • If a connector can do the task, prefer the connector.
  • If the task needs administrator access, do that step yourself.
  • If a page contains untrusted content, use a read-only workflow and verify the source.

Privacy reminder

Computer Use is not a local-only process. Cowork runs remotely by default, and Claude must process the screen information needed to decide what to do. Review your Claude plan, organization policy, retention terms, and account settings before using sensitive information.

Related Guides

Last updated: July 17, 2026