Anthropic
Security configuration, governance controls, and risk guidance for Claude Cowork, Claude Code, and Claude Tag.
Products covered in this handbook
Security considerations specific to Anthropic
Cowork is not a chatbot. Treat it as an agentic work surface that can read and write files, run code, browse with user context, invoke MCP and plugins, and continue unattended work. Approve local, remote, browser, MCP, plugin, and Computer Use paths separately.
OTel is the practical Cowork evidence path today. Cowork activity is not currently covered by Anthropic audit logs, the Compliance API, or data exports. Route OpenTelemetry to a protected collector and SIEM, then test whether the fields needed for investigations arrive with the right redaction.
Claude Code needs code-review-grade governance. Repository instructions, hooks, MCP servers, shell commands, local credentials, and generated changes can all influence outcomes. Keep unmanaged hooks and broad filesystem access out of ordinary use.
Claude Tag is a Slack agent with its own identity and memory model. Scope workspace, channel, repository, service-account, credential, and spend access. Preserve Slack threads, Agent Proxy evidence, downstream system logs, and revocation paths before broad rollout.
Current provider documentation
Last reviewed: August 18, 2026
Applicable Harmonic guidance
Related handbook guidance
Was this helpful?