← Back to all drops

Drop #22: A Security Vendor Adds Guardrails for Claude Cowork

by ClaudeCowork.com

This week's news isn't from Anthropic - it's from the security vendors racing to keep up with Cowork's growing footprint. On July 31, AI governance platform Opsin announced it now covers Claude Cowork, giving enterprise security teams visibility into a tool that's been quietly expanding since its January desktop launch.

Opsin Adds Cowork to Its AI Governance Platform

Opsin, a third-party AI governance and security platform, announced on July 31 that its coverage now extends to Claude Cowork alongside Claude Enterprise and Claude Managed Agents. The reasoning: Cowork lets any employee, not just developers, connect Claude to Slack, Gmail, HubSpot, their file system, and dozens of other tools, then hand it a task and let it run - and most of that activity has been invisible to security teams.

Opsin's Cowork coverage spans three areas: full visibility into who is running sessions, what they're asking for, and every tool call the agent makes, across desktop, web, and mobile; risk alerts when a session's tool calls touch sensitive data, like reading a folder of compensation records and sending it through an external connector; and connector governance that inventories every connector in use across an organization's Cowork deployment and checks it against policy.

Why This Matters for Cowork Users

None of this changes what Cowork itself does. But it's a signal of where enterprise adoption is heading: as Cowork has spread from a desktop-only app to web, mobile, and cloud sessions, the security tooling built to watch it is starting to catch up. If your organization is piloting Cowork, this is a good moment to ask whether anyone has a full list of which connectors are actually in use, and by whom.

Tip of the Week: Ask for a Connector Inventory Before You Scale

Cowork makes it trivially easy for anyone to click "connect" on a new tool. That's the point - and also the reason a connector inventory is worth asking for before a pilot turns into org-wide adoption.

❌ Weak

Let a Cowork pilot spread team by team with no record of which connectors each group has enabled, and find out what's connected only when something breaks.

✅ Strong

Before expanding a Cowork pilot, ask an admin for a list of every connector currently in use, who enabled it, and whether it was approved - then decide what stays.

The rule of thumb: the easier a tool makes connecting to new data sources, the more often someone should be checking what's actually connected.

Worth Reading This Week

Cowork keeps getting easier to adopt one connector at a time; the tooling to see what's actually been connected is only just catching up. Worth checking your own org's connector list before next week's drop.

Until next time.

— The ClaudeCowork.com team