| When to leave chat | OpenAI describes Chat for quick questions and conversation, and Work for longer multi step tasks and finished deliverables. Work is unnecessary overhead for a small reversible request. | Cowork is useful when Claude must carry out a process across files or tools rather than merely explain it. Ordinary Claude chat remains the simpler route for a contained answer or draft. | Use an agent only when planning, tool use, file creation or repeated steps are a material part of the job. More autonomy is not a reward for an important sounding task. | What work must happen between the request and the final result that ordinary chat cannot complete cleanly? |
| Starting context | Work can start from a ChatGPT Project, using its related chats, files and instructions as context, or from a fresh task with uploaded and connected material. | Cowork can start from projects, account files, connectors or selected local folders. Local folder access and some local tools depend on Claude Desktop being available. | Choose the environment where the authoritative context can be made clear and kept current without exposing unrelated material. | Which version is authoritative, which files are irrelevant or stale, and who owns keeping the project context accurate after this run? |
| Files on your computer | Desktop Work can use local folders and desktop apps with permission. Local chats remain on that computer, while cloud Work behaves differently across web, mobile and desktop. | Cowork can reach selected local folders through Claude Desktop. Remote sessions can only use those local files while the desktop app is open and within the permissions already granted. | Prefer a dedicated working folder containing copies of only the material needed for the task, regardless of product. | Would an accidental read, overwrite or deletion inside the granted folder be acceptable and recoverable? |
| Connected apps | Work can use connected apps and files as part of a longer process, subject to plan, workspace and connection settings. | Cowork can use connectors, Skills and plugins, and may use the browser or computer when a direct connector is not available. | Use the most precise reliable integration first. Screen control should not replace a supported connector merely because it looks more autonomous. | Does every connected system contribute to the outcome, and can the agent move information between systems in a way the affected people did not expect? |
| Finished outputs | Work is explicitly designed to create editable documents, spreadsheets, presentations, reports and Sites from instructions, templates and source material. | Cowork can create finished files and organise outputs, while Claude also supports Office file creation and Live Artifacts on supported surfaces. | Compare the editable result in its final application. File generation is useful only when the content, calculations, layout and handover survive outside the agent interface. | Who checks formulas, links, source notes, accessibility, branding and the assumptions that the file now makes look final? |
| Progress and steering | Work lets the user follow progress, answer questions, change direction and approve important actions as the task runs. | Cowork sessions can be started, steered and reviewed across supported surfaces, with notifications when work finishes or needs input. | Choose the route whose progress view helps you catch a wrong plan early and whose questions arrive before a consequential action, not after it. | What signal tells you the agent misunderstood the task, and at what point does continuing become more expensive than restarting? |
| Permissions and approvals | Work should receive only the files, apps and actions the task needs, with important actions held for approval. Product and workspace controls determine what is available. | Cowork distinguishes read and write tools and recommends human oversight for high stakes work. Approval modes change how much can happen before the user intervenes, while permanent deletion still requires permission. | Select the narrowest permission mode that can complete the task. Write access, browser control and automatic approvals need a stronger reason than read only preparation. | List every action the agent may take without asking and decide whether each is reversible, observable and appropriate for this material. |
| Scheduled work | Work can use Scheduled Tasks that run once, on a schedule or trigger, or monitor for changes. Exact access and active task limits depend on plan and workspace. | Cowork scheduled tasks can run remotely, use approved connectors and account files, and return reports or summaries even when the computer is off. They cannot use a local computer folder while running remotely. | Start with low risk information preparation, keep the result waiting for review and choose by approved source access and run history visibility. | Who reviews every run, what missing source must be reported, and which condition automatically pauses the schedule? |
| Security and prompt injection | Any agent using connected material or the open web can encounter instructions embedded in content. Broad tools and permissions increase the possible impact of following them. | Anthropic explicitly warns that malicious content can steer Cowork and that risk depends on what it can see and do. Manually approve higher stakes tasks and use dedicated folders. | Treat all external content as untrusted input. Keep access narrow, prevent irreversible action and design the workflow so a hostile instruction cannot silently become authority. | Could a document, email or webpage tell the agent to access another system, reveal information or take an action outside the user's stated goal? |
| Choosing the model inside the agent | Eligible Work users can choose among GPT-5.6 Sol, Terra and Luna and set effort. Use a lighter model for stable routine work and Sol when complexity earns it. | Cowork can use Claude models within the product experience. Sonnet is a practical default and Opus should be reserved for tasks whose complexity or failure rate justifies it. | First choose the agent workflow, sources and permissions. Then use the least expensive model and effort level that repeatedly passes the output review. | Is the agent failing because the model needs more capability, or because the task, source pack and approval boundary were never made clear? |
| Review and audit | The finished output, progress history, cited sources and connected context should support a reviewer in understanding what happened and correcting the result. | Cowork exposes session progress and scheduled run history, but the user should monitor task level patterns rather than assume every command can be individually validated. | Choose the route that leaves enough evidence for the accountable person to verify the result without replaying the entire job from memory. | Can a reviewer identify the sources, transformations, exceptions, approvals and unresolved decisions that produced the final output? |