The reason it is useful is the reason it needs care
Everything that makes Cowork worth using comes from the same fact: it works with your own files, folders and applications rather than with whatever you can be bothered to paste into a box. That is why it can produce something specific to your actual work instead of generic advice. It is also why this lesson exists.
Start with the easy half. Point it at a named folder rather than gesturing at your work in general. A named folder gives the job a boundary, makes the run reviewable, and means you know what was in scope when you check the result. My files is not a location. Northgate slash Q2 is.
In plain English
- Folder scope:
- The specific, named set of files a job is allowed to look at.
- Anonymising:
- Removing the identifying details from information while keeping its shape and meaning.
- Placeholder:
- A stand-in like CLIENT A or CONTACT 1 that holds the position of a real name without being one.
- Derived file:
- A new document created from your material. It carries whatever was in the original.
- Acceptable use policy:
- Your employer's rules about which tools may touch which information. They apply whether or not you have read them.
What to keep away from it
This section matters more than the rest of the lesson, so read it slowly.
Client and customer data. Names, contact details, account numbers, case details, anything you hold because someone trusted you with it rather than because it is yours. The obligations attached to that material do not pause because a tool is convenient.
Anything covered by an employer policy or a signed agreement. Most organisations have rules about which systems may hold which information, and those rules apply to you whether or not you have read them. A non-disclosure agreement does not carve out an exception for tools you find helpful. If you do not know your organisation's position, that is the thing to resolve before you widen the folder, not after.
Anything you would not want summarised into another file. This is the test specific to this product and it deserves its own paragraph.
Why the summarised into another file test matters here
Pasting something into a chat window puts it in one conversation. Handing a folder to a job that produces output does something different: the material comes out the other side as new documents, sitting in your file system, now containing the sensitive parts in a fresh arrangement that no longer looks sensitive.
A summary of forty appraisal documents does not look like forty appraisal documents. It looks like a tidy one page summary. It is far more likely to get attached to an email, dropped into a shared folder, or reused six months later by someone who has no idea what it was distilled from. Anthropic is also unifying Claude chat and Cowork into one space with access to the same files, so the material and everything derived from it becomes reachable from more places, not fewer.
So the question is not only what am I comfortable handing over. It is what am I comfortable existing as a new document afterwards.
There is a second reason to be careful about what you point it at. Our agents course explains that a system reading a document has no reliable way to distinguish your instructions from text it finds inside that document. If you point a job at material that arrived from outside your organisation, treat it as content to be read rather than trusted, and keep the job read only.
โ Weak prompt
Prompt
Look across my whole drive and summarise the themes in this year's client feedback. Full names and account numbers are fine, it is easier to read that way.
Output
A themed summary quoting eleven named clients, three account references and one detailed complaint that identifies a specific individual and their circumstances.
Unbounded scope, real identities, and a new document that now holds all of it in a form that looks harmless enough to forward. Every one of those is a separate problem.
โ Good prompt
Prompt
Use only the files in Feedback slash 2026. Before writing anything, replace every client name with CLIENT A, CLIENT B and so on, and every account number with ACCOUNT 1, ACCOUNT 2. Do not keep a mapping. Summarise the recurring themes, with counts. Do not quote any passage that would identify a person even without their name. Create nothing outside this folder.
Output
A themed summary with counts, referring throughout to CLIENT A, CLIENT B and CLIENT C, quoting nothing identifying.
The analysis is just as useful because the themes were never in the names. The derived file is now safe to keep, share and forget about.
Checkpoint
Ask what you are comfortable existing as a new document afterwards, not just what you are comfortable handing over. Output becomes files, and files travel.
Anonymising is the middle path
The choice is rarely between handing over everything and handing over nothing. Most of the value in your material is in its shape, not in the identities attached to it. Patterns, counts, recurring complaints, timings and structures all survive anonymising completely intact.
Swap the identities out before the job starts, keep no mapping in the same place as the output, and you get the analysis without the exposure.
NEVER HAND OVER
client or customer records, case files, contact details
anything under an NDA or a confidentiality clause
pay, contracts, disciplinary or medical information
anything your employer's policy places off limits
anything you would not want to exist as a new tidy document
ASK FIRST
material belonging to a client rather than to you
anything that arrived from outside your organisation
anything where you do not know your organisation's position
REAL THING REPLACE WITH
person's name PERSON A, PERSON B
company name CLIENT A, CLIENT B
account or case number ACCOUNT 1, ACCOUNT 2
email address CONTACT 1
exact salary figure BAND 2
precise date of birth AGE RANGE
full address REGION
Keep the mapping somewhere separate from the output, or keep none at all.
Check free text as well as fields. Names hide inside complaint descriptions.
Use only the files in [named folder]. Do not read anything outside it,
including subfolders I have not named.
Before producing anything, replace all names, account numbers and
email addresses with placeholders. Do not reproduce them anywhere
in the output, including in examples and quotations.
Create your output as a single new file inside [named folder].
Do not create, rename, move or delete anything else.
Do not send, share or publish it.
Finish by listing which files you read, which you could not open,
and anything you assumed. Then wait for my approval.
Before widening a job's folder scope, open the folder and actually look at what is in it. Most people are surprised at least once. Old attachments, forwarded documents and someone else's spreadsheet have a way of accumulating in places you think you know.
๐ Quiz
Question 1 of 4Why is pointing a job at a specific named folder better than gesturing at your files in general?