Domain 1Cowork Foundations & Agentic Architecture
Directory Scoping
TL;DR
The primary security mechanism in Cowork.
Definition
The primary security mechanism in Cowork. When you start a session, you select which folder Claude can access. Claude operates only within that folder and its subfolders — it cannot traverse upward to parent directories, access your Desktop, or read files elsewhere, even if you type the full file path in your prompt.
Exam Context
This is the single most important security concept in Domain 1. Questions test whether you know that scoping is per-session, that it cannot be bypassed via prompt instructions, and that broad folder grants (like your entire Documents folder) are a security anti-pattern.