Claude Cowork Enterprise Deployment Guide: Plans, Admin Controls, and Rollout
Claude Cowork is easy for one person to start using. Rolling it out to a company takes more thought: which plan, which settings to change from their defaults, how plugins and connectors are governed, and how security teams see what the agent does.
This guide is for IT admins and team leads deploying Cowork on Claude Team and Enterprise plans. It covers plan and billing models, every Cowork setting in Organization settings, private plugin marketplaces, monitoring and compliance, and a phased rollout plan you can adapt.
Updated October 5, 2026
Team vs Enterprise: plans and billing
Both Team and Enterprise plans include Cowork alongside Claude on web, desktop, and mobile, and Claude Code. The main differences are billing, controls, and compliance features.
| Team | Enterprise | |
|---|---|---|
| Who it suits | Small and mid-size teams | Larger or regulated organizations |
| Billing | Per seat with usage limits per seat | Seat fee for access, with usage billed separately at standard API rates (usage-based plans) |
| How to buy | Self-serve | Self-serve (20-seat minimum) or through sales (50-seat minimum) |
| Cloud Cowork sessions | On by default | Admin choice; defaults changed on September 10, 2026 |
| Compliance features | Core admin controls | Audit logs, SCIM, custom data retention, Compliance API, customer-managed keys, US-only inference |
On usage-based Enterprise plans, the seat fee covers access only. All usage across Claude, Claude Code, and Cowork is billed at standard API rates with no per-seat caps, so heavy agent users cost more than light chat users. Older Enterprise contracts with Standard and Premium seats move to the usage-based model at renewal. For the consumer side of pricing, see our Cowork pricing guide.
Enable Cowork for your organization
Owners manage Cowork in Organization settings → Cowork. The two most important switches:
- Enable for your organization is the master switch for Cowork access.
- Run Cowork in the cloud lets sessions run on Anthropic's servers so they continue when laptops close and can be picked up on web and mobile. It is on by default for Team. For Enterprise it was off by default until September 10, 2026. Claude Design is a separate switch that Enterprise admins also turn on.
Where members can use Cowork depends on the plan and these settings: the desktop app on macOS and Windows for all paid plans, and web, mobile, and the Chrome side panel where the admin has enabled them on Enterprise. If Cowork doesn't appear for a user, check these switches before anything else; our troubleshooting guide covers the other common causes.
Admin controls worth reviewing on day one
| Setting | Where | Default | What to consider |
|---|---|---|---|
| Built-in browser | Organization settings → Cowork | On for Team; on for Enterprise from Sept 10, 2026 | Needed for web research tasks; Claude in Chrome is a separate extension |
| Allow “Automatically approve” mode | Organization settings → Cowork | On | Turn off to force manual approvals for every sensitive action |
| Allow “Always allow” for connector tools | Organization settings → Cowork | Off | Keeping it off means write-capable connector actions need approval each task |
| Network egress for code execution | Organization settings → Capabilities → Code execution | Plan default | Applies at session start; web search, fetch, and MCP connectors are controlled separately |
| Plugins | Organization plugin marketplaces | Varies | Mark each as installed by default, available, required, or not available |
| Branding | Organization settings | Not set | Shows your company identity on the home screen |
A sensible starting posture for regulated teams: cloud sessions on only after security review, automatic approval off, “always allow” off, and a short list of approved connectors. Loosen settings as you gain confidence. Our security overview explains how Cowork's sandbox and permissions work.
Private plugin marketplaces
Plugins are how you turn Cowork from a general assistant into a set of role-specific tools. Since February 2026, admins can run organization-specific marketplaces, use private GitHub repositories as plugin sources, and provision plugins per user with auto-install. Each plugin can be marked:
- Installed by default for everyone, but removable.
- Available to install from the marketplace.
- Required, installed automatically and impossible to turn off.
- Not available to members.
Start from Anthropic's open source plugins for roles like sales, finance, legal, HR, and engineering, customize them with your company's terminology and tools, and publish them from a private repository. Enterprise admins can also limit which groups see which plugins, and plugins are scanned for malicious content when installed or updated. Our Cowork plugins directory lists what's available.
Connectors and data access
Connectors decide what company data Cowork can reach. Enterprise plans include workplace connectors for Google Workspace, Microsoft 365, GitHub, and Slack, and many more are available. Each connector has its own admin setup; for example, the Microsoft 365 connector needs one-time consent from a Microsoft Entra Global Administrator, respects existing permissions, and has write tools that admins can enable separately. See our Microsoft 365 integration guide and connectors overview.
Two principles keep access manageable: approve connectors centrally rather than letting each team add its own, and start with read access before enabling tools that send email, post messages, or change records.
Monitoring, audit, and compliance
- OpenTelemetry. Cowork can stream events such as tool calls, file access, and approvals to your security and observability tools, which also helps track usage and cost.
- Compliance API. Enterprise organizations can programmatically access usage data, including remote Cowork sessions on web, desktop, and mobile.
- Audit logs. Enterprise audit logs capture user actions, system events, and data access.
- Local session data. Sessions that run locally store data on the member's computer and aren't covered by standard retention policies; Enterprise can retrieve them through the Compliance API.
- Cloud session isolation. Each cloud session gets its own sandbox with restricted network access, created at start and destroyed at the end, and connector tokens never enter the sandbox.
Before launch, agree with your security team which events they need, where they will be stored, and who reviews alerts, so monitoring is in place on day one rather than added after an incident.
Smart reports (beta): what your teams actually use Claude for
Since September 10, 2026, Enterprise organizations can run smart reports, a beta feature in which Claude analyzes how a team uses Claude and reports back in plain language. Claude reads a sample of up to 28 days of activity across chat, Claude Code, and Cowork, and groups it into:
- Workstreams and deliverables: what kinds of work get done, such as analysis, documentation, or code.
- Cost: spend attached to each workstream.
- Friction: where sessions run into trouble, such as failing connectors, rework loops, or tool errors.
- Shared skill candidates: repeated patterns worth packaging as a skill the whole team can use.
Reports can be scoped to teams, groups, departments, or cost centers, and you can ask custom questions. During the beta, each organization can create up to 10 reports a month at no charge. A monthly smart report per pilot team is a cheap way to find which connectors need fixing and which workflows deserve a shared skill or plugin.
Deploying the desktop app
Most Cowork capabilities that touch local files, the browser, or the screen need the Claude desktop app. For managed fleets:
- On Windows, deploy the
.msixpackage; machines installed with the legacy.exeget Claude Desktop without Cowork. Cowork also needs hardware virtualization and the Virtual Machine Platform feature, and users without admin rights can't use Cowork on the desktop. - On macOS, distribute the
.dmgthrough your MDM. - Run Anthropic's Cowork readiness check on one device of each hardware model before a broad rollout.
- If you use web filtering or EDR, allow the app to download its workspace bundle from
downloads.claude.aiand allowlist the agent helper by its publisher, Anthropic, PBC. - Virtual desktops without nested virtualization can't run the local workspace; cloud sessions are the alternative.
Our download guide and Windows guide cover individual installs.
A phased rollout plan
- Week 1 to 2, pilot. Pick 10 to 20 people in two teams with clear, repeatable work, such as sales prep and finance reporting. Enable Cowork for them, one or two connectors, and one plugin each.
- Week 3 to 4, measure. Track tasks completed, time saved, and corrections needed. Collect prompts that worked and failure cases.
- Week 5 to 6, package. Turn the best prompts into skills and customized plugins in your private marketplace. Write short internal guidance on approved uses and data rules.
- Week 7 onward, expand. Add teams in waves, each with a named champion, office hours, and a feedback channel. Review settings and usage monthly.
If you already run bots for back-office work, map which steps stay with them using our Cowork vs RPA guide. Pair the rollout with basic training on reviewing agent output and spotting prompt injection. Our prompt injection guide is a good primer for all users.
Write a short acceptable-use policy
People adopt an agent faster when they know the rules. A one-page policy is enough if it answers the questions employees actually ask:
- What data is allowed. Which folders, systems, and data classes may be shared with Cowork, and which never may, such as health records or payment card data unless your agreement covers them.
- Who reviews output. Anything sent to customers, regulators, or the public needs a human check, and the person who sends it owns it.
- Which actions need approval. Deleting files, sending email, posting to shared channels, and changing records should always be confirmed.
- How to report problems. A named channel for bad outputs, suspected prompt injection, or access that seems too broad.
- Where approved tools live. Point to the internal plugin marketplace and the list of approved connectors.
Keep the policy short and link it from your internal wiki and onboarding. Revisit it each quarter as features and settings change.
Support after launch
The first month after each wave decides whether usage sticks. Three habits help. First, give every team a champion who collects questions, shares good examples, and escalates problems. Second, hold short weekly office hours where people bring a real task and solve it live; this surfaces missing connectors and unclear rules quickly. Third, keep a living page of known issues and fixes, such as app version problems or folder access questions, so the help desk isn't answering the same ticket repeatedly.
Measure adoption by active users and repeated use cases, not by seat count. A team that runs the same three tasks every week is getting more value than a team that tried twenty things once.
Keeping costs predictable
Because agent tasks take many steps, Cowork usage grows faster than chat usage. To avoid surprises on usage-based billing:
- Use OpenTelemetry, the usage reports, and smart reports to see which teams and tasks drive consumption.
- Teach people to scope tasks: a specific folder and a clear output use far less than “look through everything.”
- Prefer skills over long pasted prompts; they make runs shorter and more consistent.
- Review scheduled tasks regularly and retire ones nobody reads.
- Estimate value with our ROI calculator before scaling a use case.
Frequently asked questions
Is Cowork included in Claude Enterprise?
expand_more
Yes. Enterprise and Team plans include Cowork, Claude Code, and Claude on web, desktop, and mobile. On usage-based Enterprise plans, usage is billed separately at API rates.
How do admins turn on Cowork?
expand_more
Owners go to Organization settings → Cowork and turn on Enable for your organization, then decide whether to allow cloud sessions and adjust browser and permission settings.
Can we run a private plugin marketplace?
expand_more
Yes. Admins can add organization marketplaces, including private GitHub repositories, and mark each plugin as installed by default, available, required, or not available.
How do security teams monitor Cowork?
expand_more
With OpenTelemetry event streaming, the Compliance API, and Enterprise audit logs. Cloud sessions run in isolated sandboxes with restricted network access.
Should Enterprise turn on cloud sessions?
expand_more
Cloud sessions let tasks keep running when laptops close and work on web and mobile. Review the architecture and data handling with your security team first, then enable them for a pilot group before the whole Enterprise organization.
Can we buy Enterprise without talking to sales?
expand_more
Yes. Self-serve Enterprise has a 20-seat minimum and is paid by card or ACH in USD. Sales-assisted plans start at 50 seats.