Claude Cowork Security Guide
·2026.05.02 05:48
Key point
The guide outlines security practices for monitoring and controlling Claude Cowork through a proxy.
Details
This presents a deployment guide that places Claude Cowork behind a middleman control plane.
The key points are as follows.
- Use managed devices and restricted working folders.
- Route Claude Desktop, Claude Code, browser, and local tool traffic through an on-device proxy or LLM gateway.
- Install the enterprise CA only on managed devices, and provide an example of connecting Claude Code to
mitmproxyviaHTTP_PROXY/HTTPS_PROXY/NO_PROXYsettings. - browser use and computer use require separate policies, paired with managed browser profiles, app blocking, approval flows, and endpoint telemetry.
- Treat plugins and MCP like a supply chain, recommending approved marketplaces, least privilege, tool-call logging, and secret masking.
Since the proxy cannot see every path, flows such as server-side web fetch/search, remote MCP, and local screen clicks must be supplemented with separate telemetry.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.