A short, prescriptive policy for which folders Claude Cowork should have access to. Three-tier model, joiner/mover/leaver process, backup posture.
TL;DR. One folder per function, per workspace. Never the home directory, never Documents root, never a network drive without controls. The three-tier policy below is what we hand to mid-market IT teams as a starting template — most companies adopt it with two or three edits.
One folder per function, per workspace. The principle is small and absolute. Every Cowork failure mode in folder permissions starts with someone wanting to grant a "convenient" parent folder, then discovering six months later that Cowork has been seeing the CEO's personal pipeline.
| Tier | Folder type | Access pattern |
|---|---|---|
| Tier 1 — Personal pilot | A personal ~/cowork-{role} workspace | Single-user, non-shared, low-risk experimentation |
| Tier 2 — Shared function | Cloud-synced ~/cowork-{function} via OneDrive / GDrive / Dropbox | Multiple operators, governed by CLAUDE.md |
| Tier 3 — Regulated function | Access-controlled folder with audit logging | Head-of-function approval; regulated data only with Enterprise plan |
Most pilot work starts at Tier 1 and moves to Tier 2 when the team is ready. Tier 3 is for healthcare, regulated financial, and government work; it is not the default.
The monthly review is the part most teams forget. Add it to the function's calendar.
Encode the following in IT policy:
cowork-{function}. Lowercase, hyphens, no spaces.CLAUDE.md.The naming convention sounds trivial. It is the policy clause that breaks ties when two operators disagree about how to organise a sub-folder.
A short policy block, written for an IT lead to copy:
CLAUDE.md ownership entry. Treat as a tier-one offboarding action.The leaver step is the one most teams under-execute. A revoked Anthropic account is not enough — the workspace folder may still be on the laptop and may still be syncing. Off-boarding has to touch both.
CLAUDE.md. Test it once before scaling beyond the pilot team. Untested rollback is wishful rollback.Folder policy is unsexy and decisive. The deployments that scale cleanly past 20 users have a written policy from week one; the deployments that stall do not. We hand clients a template policy and ask IT to red-line it during pre-flight — that is faster than asking them to write one from scratch, and it produces a better policy because the conversation is about edits, not blank pages.
Open IT's existing SaaS access policy. Add a Cowork section using the three-tier table above. Send it to your security partner with one question: "is this consistent with our DLP and DPA stance?" Iterate from there. You will be done in a week.
Book a 30-minute call. We'll ask where you are, what your team needs, and which systems Cowork should touch.