Anthropic agents compared
Claude Cowork vs Claude Code: knowledge work or software engineering
You get a dated comparison of two Anthropic agents, Claude Cowork and Claude Code, on audience, where each runs, what each can touch, approvals and data handling.
Claude Cowork is Anthropic's agent for knowledge work: it takes a goal and works across your files and tools without a terminal. Claude Code is Anthropic's agent for software engineering: it edits code, runs commands and works with git. Both are on paid Claude plans and share a lot of agent design. The differences that matter are who they are for, where they run and what each can reach. Facts below are from Anthropic's own pages, read on 2026-10-07.
Last verified 2026-10-07. Sources are listed at the end of the page.
What is Claude Cowork, and is it just Claude Code with a new name?
Claude Cowork is an Anthropic product with its own pages on claude.com and the Claude help centre. Anthropic's product guide, dated 2026-06-05, calls it a knowledge work agent that carries multi-step tasks through to real deliverables. The Cowork get-started article says it uses the same agentic architecture that powers Claude Code, with no terminal required.
It is not Claude Code renamed. Anthropic positions Cowork for cross-app knowledge work, chat for conversational drafting and Claude Code for coding. Both appear in the Claude desktop app, and the computer-use beta is available in Cowork and in Claude Code there.
Naming and behaviour are moving. The same get-started article says Cowork is now just Claude: you ask for what you need and Claude decides whether it is a quick answer or a task. Another support page says new Cowork tasks on Pro and Max plans run in the cloud by default as of 2026-10-06. Re-read the vendor pages before you decide.
Cowork and Claude Code at a glance
Each cell comes from Anthropic's own pages, read on 2026-10-07.
| Topic | Claude Cowork | Claude Code |
|---|---|---|
| Made for | Knowledge workers with repetitive, multi-step tasks. The product page lists marketing, sales, legal and finance examples such as reports, account research, contract review and reconciliation. | Software engineering: building features, fixing bugs, git workflows, tests and automation, in a terminal, IDE, desktop app or browser. |
| Where it runs | Claude desktop app on macOS and Windows, with web and mobile in beta or rolling out. Sessions run in the cloud by default; local execution remains for existing desktop deployments. | Terminal, IDE extensions, the Code tab in the desktop app, and the web. Local sessions run on your machine, and cloud sessions run in Anthropic-managed virtual machines. |
| What it can touch | Folders you connect, connectors to apps such as Slack and Google Drive, a built-in browser, plugins and skills, and computer use (beta). The product page says you choose the folders and tools and Claude cannot reach anything else. | Your repository and working directory, shell commands, git, MCP servers and, with Chrome integration, web pages. Which actions need approval depends on the permission mode. |
| Plans | Paid plans: Pro, Max, Team and Enterprise, with web, mobile and cloud sessions varying by plan and, on Enterprise, admin enablement. | Included in all paid Claude plans, per claude.com/pricing. The desktop app requires a paid subscription. |
| Approvals | Cowork asks before permanently deleting files. A 'Manually approve' mode asks about actions, and an 'Automatically approve' mode lets Claude review each action for safety before it runs. Computer use asks before accessing each app. | Permission modes from default (asks before edits and commands) to bypassPermissions, with allow, ask and deny rules and an opt-in Bash sandbox. |
| Admin controls | Organisation settings let owners enable or disable Cowork, cloud sessions, the built-in browser, auto mode and connector approvals. | Managed settings, managed MCP configuration and OpenTelemetry usage metrics. |
What do Anthropic's safety and approval statements say?
| Question | Claude Cowork | Claude Code |
|---|---|---|
| Where does code or file work execute? | In cloud sessions, in an isolated, temporary environment on Anthropic's servers, with a sandbox per session that is destroyed when the session ends. The sandbox cannot reach private, internal, link-local or cloud-metadata addresses. In legacy local sessions, shell commands run in a dedicated Linux VM isolated by the platform hypervisor. | Locally, on your machine, with an opt-in Bash sandbox that covers shell commands only. In cloud sessions, in an isolated Anthropic-managed VM with limited network access by default. |
| What is the stated main risk? | Prompt injection: malicious instructions in content Claude reads. Anthropic says it trains Claude to refuse them, scans untrusted content and flags injections, and tells users to avoid granting access to sensitive local files. | Anthropic lists prompt injection safeguards too, including the permission system and network command approval, and says no system is completely immune to all attacks. |
| Who reviews actions? | You do, or in Automatically approve mode a safety review by Claude. Anthropic advises switching to Manually approve for sensitive files, accounts or sites. | You are responsible for reviewing proposed code and commands before approval, per Anthropic's security page. In Auto mode a classifier model reviews actions instead of you. |
| What is blocked by default? | Computer use blocks some sensitive app types by default, such as investment and trading platforms and cryptocurrency apps. Anthropic says not to grant it access to banking, healthcare or government apps. | Reads outside the working folder prompt in Manual mode, and commands such as curl and wget are not auto-approved by default. |
What does Anthropic say about data handling for each?
For Claude Code, Anthropic publishes retention and training terms by plan. Free, Pro and Max users choose whether data improves future models, with 5-year retention if allowed and 30 days if not. Commercial users (Team, Enterprise, API) are not trained on under commercial terms unless they opt in, with standard 30-day retention. Session transcripts are also stored locally for 30 days by default.
For Cowork, the pages we read say deleting a session deletes the copies of files Claude fetched, and that the data improvement setting in Privacy settings governs training use. On Team and Enterprise, the architecture page says conversation data is handled under the same commercial commitments as other Team and Enterprise data and is not used to train Claude. Cowork sessions are captured in the Compliance API. For local sessions, the Team and Enterprise article says admins cannot centrally manage or delete stored conversation history.
Retention periods specific to Cowork on consumer plans were not stated on the pages we read, so this page states none.
When should you pick Cowork, and when Claude Code?
These are decision rules from documented differences, not a ranking.
| Your task | Lean towards | Reason |
|---|---|---|
| Turn a folder of contracts into a tracker, or draft a variance memo | Cowork | Built for multi-step knowledge work across files and apps, without a terminal. |
| Fix a failing test and open a pull request | Claude Code | Works with your repository, shell and git, and fits CI. |
| Run a task while your laptop is closed | Either, check the surface | Cowork cloud sessions and Claude Code cloud sessions both run on Anthropic servers. Cowork needs the desktop app open for local folders. |
| Work in apps that have no connector | Cowork | Computer use (beta, Pro and Max) can interact with apps, with approval per app. |
| Script an agent in CI or pipe logs into it | Claude Code | The CLI supports non-interactive use with the -p flag. |
| Keep an org-wide record of agent sessions | Check both | Cowork sessions appear in the Compliance API. For Claude Code, Anthropic points to OpenTelemetry usage metrics. Compare against your own audit needs. |
Where Swfte fits
The governance questions are the same for both agents: who approved what, with which data, and where the record is. Anthropic gives each agent its own approval modes and its own admin controls, so a team that uses both keeps two sets of rules.
Swfte Nexus wraps Claude Code and Codex (Built). It does not wrap Cowork. If you want a policy gate and audit record for coding sessions, see Claude Code security and Nexus. For Cowork you rely on Anthropic's admin settings and Compliance API.
Swfte Cortex is a governed desktop assistant (Built) with on-device knowledge bases, MCP servers and tool approvals bound to the exact call. It is a different product from Cowork, and this page does not compare their features. If you want to see how approvals work in practice, read human in the loop AI.
You do not need Swfte if one person uses Cowork or Claude Code on an individual plan and the vendor controls are enough for your risk.
Which governance questions should you ask about either agent?
- Which folders, connectors and apps can it reach, and who set that list?
- Which actions run without a person approving them, and can you turn that off for the whole organisation?
- Where does the work execute: your machine, a local VM or a cloud sandbox?
- Which untrusted content can it read, such as web pages, emails and documents, and what could that content make it do?
- Where is the record of what it did, who can read it, and how long is it kept?
- What does the vendor say about training on your data on your plan, in writing?
Sources and last verified
Every dated or technical fact on this page was read from the pages below on 2026-10-07. Anything that could not be confirmed is left out or marked as not verified.
- Claude Cowork product page. Who it is for, where it runs, what it can access and approval statements. The anthropic.com/product/claude-cowork address redirects here.
- The Claude Cowork product guide. Positioning against chat and Claude Code, dated 2026-06-05.
- Get started with Claude Cowork. Same architecture as Claude Code, plan requirements and the naming note.
- Use Claude Cowork on web, desktop and mobile. Cloud sessions, the 2026-10-06 change and local folder access.
- Use Claude Cowork safely. Safety measures, prompt injection and user responsibilities.
- Claude Cowork architecture overview. Cloud and local session isolation, data handling and Compliance API.
- Use Claude Cowork on Team and Enterprise plans. Admin controls and local history statement.
- Let Claude use your computer in Cowork. Computer use availability, per-app approval and blocked apps.
- Claude Code overview. Claude Code surfaces and plan requirements.
- Claude Code security. Permission modes, prompt injection safeguards and cloud isolation.
- Claude Code data usage. Training and retention terms for Claude Code.
- Claude pricing. Claude Code inclusion in paid plans.
Frequently asked questions
Is Claude Cowork an Anthropic product?
Yes. Cowork has a product page on claude.com, a product guide on the Claude blog dated 2026-06-05 and several Claude help centre articles. We read them on 2026-10-07. Anthropic describes it as a knowledge work agent that works across your files and tools. Its status and name are changing, so check the pages again before you decide.
Is Cowork just Claude Code without the terminal?
Partly. Anthropic says Cowork uses the same agentic architecture that powers Claude Code, with no terminal required, but positions it for knowledge work such as research briefs, meeting prep and recurring reports, while Claude Code targets software engineering. They are separate products with different audiences, surfaces and admin controls.
Where does Claude Cowork run?
By default in the cloud: the agent loop and code execution run on Anthropic servers, in a sandbox per session. Local execution remains for existing desktop deployments, and tasks on Pro and Max plans started before 2026-10-06 remain local, per Anthropic. Cloud sessions can read connected local folders only while the desktop app is open.
Does Claude Cowork need approval before it acts?
Anthropic says Cowork asks permission before permanently deleting files, and offers a Manually approve mode and an Automatically approve mode in which Claude reviews each action for safety. Computer use asks before accessing each app. Organisations can turn auto mode off. Anthropic also warns that prompt injection is a real risk and advises care with sensitive files and sites.
Can Swfte Nexus govern Cowork?
No. Nexus wraps Claude Code and Codex. It does not wrap Cowork, so use Anthropic's admin settings and the Compliance API for Cowork sessions. The governance questions are the same for both agents, and this page lists them so that you can ask them of either one, whichever tool you adopt.
Which plans include Cowork and Claude Code?
Claude Code is included in all paid Claude plans, per claude.com/pricing. Cowork is available on Pro, Max, Team and Enterprise, with web, mobile and cloud sessions varying by plan and admin settings. See claude.com/pricing for current prices, because we do not restate them here.