Domain 612%

Quick Reference: Team Deployment, Security & Enterprise Readiness

TL;DR

One-page cheat sheet for Team Deployment, Security & Enterprise Readiness

Plan Comparison Matrix

FeatureFreePro ($20/mo)Max ($100-200/mo)Team Std ($25/seat)Team Prem ($100-150/seat)Enterprise
Cowork accessLimitedFullFullFullFullFull
Computer UseNoYesYesNoNoNo
DispatchNoYesYesNoNoNo
Conversation memoryNoNoYesNoNoVaries
SSONoNoNoYesYesSAML SSO
No-training defaultNoManual opt-outManual opt-outYesYesYes
Tenant restrictionsNoNoNoNoNoYes
Audit logs (Cowork)NoNoNoNoNoNo
Admin toggle (org-wide)N/AN/AN/AYesYesYes

Key takeaway: Cowork audit logging does not exist on any tier. Computer Use and Dispatch are individual plan features (Pro/Max), not team features.

Security Model — The Five Boundaries

  1. VM Sandbox — Cowork runs in an isolated local environment; file processing stays on your device
  2. Folder Scoping — Claude sees only the explicitly shared directory and its subfolders
  3. Deletion Protection — File removal requires explicit "Allow" click (edits and overwrites do not)
  4. Per-App Permissions — Computer Use requires approval for each individual application
  5. Network Egress — Configurable allowlist, but web search bypasses it

The audit gap (know this cold):

  • Cowork excluded from Audit Logs on all tiers
  • Cowork excluded from Compliance API on all tiers
  • Cowork excluded from Data Exports on all tiers
  • History stored locally on each user's machine — no central access
  • Cannot satisfy HIPAA, SOX, PCI-DSS, or SOC 2

Compliance Decision Table

If the workload involves...Can you use Cowork?Why / Why not
General document summarisationYesLow-risk, no regulatory requirement for audit trail
Internal report generationYesKeep in dedicated workspace folder
HIPAA-regulated patient dataNoAudit gap makes logging requirements impossible
SOX financial reportingNoCannot produce chain-of-custody documentation
PCI-DSS payment card dataNoNo compliant audit trail available
Client-facing financial analysisCautionNo audit trail; review output manually before sharing
Competitive intelligence gatheringYesMonitor output quality; web search bypasses egress

Compensating controls: OpenTelemetry for partial observability, defensive global instructions, dedicated workspace folders, manual output review.

Team Onboarding Checklist

Phase 1 — Pre-enablement:

  • Write Acceptable Use Policy (approved use cases, prohibited data, incident reporting)
  • Define dedicated workspace folder structure (/cowork-workspace)
  • Complete mandatory training (prompt injection, folder hygiene, plan review)
  • Select pilot group for controlled rollout
  • Check default settings for your plan tier (Chrome on by default for Team; off for Enterprise)
  • Honestly disclose the audit gap to leadership

Phase 2 — Rollout day:

  • Enable the admin toggle (remember: all-or-nothing, org-wide)
  • Confirm access for pilot group
  • Run a supervised first task with the pilot group
  • Verify folder scoping works as expected

Phase 3 — Ongoing operations:

  • Monitor usage patterns and review scheduled task outputs
  • Update Acceptable Use Policy based on real-world findings
  • Run periodic security refreshers
  • Audit which connectors are installed across the team

ROI Framework

Measuring value:

  1. Time a recurring task manually (baseline measurement, not estimate)
  2. Automate it with Cowork (time the full process including review)
  3. Calculate: (Time saved/week) x (Hourly rate) x (52 weeks) = Annual value per task
  4. Compare against: Annual plan cost (e.g., Pro at ~$240/month = ~$2,880/year)

Published benchmarks:

OrganisationResult
Novo NordiskRegulatory process: 10+ weeks → 10 minutes
Cox AutomotiveDoubled lead follow-ups
IBM45% increase in developer productivity
DeloitteDeployed to 15,000 practitioners

Business case rules:

  • Use your own measured data, not just industry benchmarks
  • Disclose the audit gap honestly — burying it destroys credibility when discovered
  • Factor in total cost of ownership (seat fee + projected token consumption)
  • Include governance value when comparing Pro ($20) vs Team ($25) — the $5 premium buys centralised no-training defaults

Common Exam Traps — Domain 6

TrapCorrect Answer
"Enterprise audit logs cover Cowork"Cowork excluded from audit logs on all tiers
"Compliance API captures Cowork sessions"Explicitly excluded — no configuration enables it
"Team plan admins can enable Cowork per department"Admin toggle is all-or-nothing, org-wide
"Tenant restrictions work on Team plans"Enterprise-only feature
"ZDR policy applies to Cowork conversations"ZDR governs Anthropic server data; Cowork stores locally
"Pro is cheaper than Team so it is better for organisations"Team's centralised no-training default justifies the premium
"The VM sandbox prevents all data exfiltration"cURL, MCP calls, and Chrome can send data externally
"Cowork is HIPAA-ready on Enterprise"No plan can provide the required audit trail
"Corporate proxy blocks all Cowork web traffic"Web search bypasses network egress restrictions