Smartflow for Claude Cowork

Smartflow for Claude Cowork governs what Cowork does in your systems. Connectors reach your applications through Smartflow, consequential writes pause for a person with authority to approve them, and every action lands in a tamper-evident record on your infrastructure.

Smartflow for Claude Cowork governs what Cowork does in your systems. Connectors reach your applications through Smartflow, consequential writes pause for a person with authority to approve them, and every action lands in a tamper-evident record on your infrastructure. When Cowork runs on third-party inference, Smartflow can also sit in the model path.

What is Claude Cowork?

Claude Cowork is the agent inside the Claude desktop app. It works across a user's files, connectors and browser to complete multi-step tasks: assembling a board pack, reconciling a spreadsheet, updating an account plan. Anthropic made it generally available on April 9, 2026. It is on by default for Team and Enterprise organizations until an owner turns it off.

Cowork acts with the access the user gives it. Connected to email, a CRM, a marketing platform or a code repository, it can send, publish, update and delete on that user's behalf.

Why do most rollouts stop at read-only?

The common advice for a safe Cowork rollout is to restrict risky access paths and block writes: no sends, no publishing, no changes to deals, renewals or production. That advice is sound for the first week. As a steady state it produces an assistant that can read and summarize everything and change nothing. The productivity case for agents sits in the writes.

Smartflow gives each write an outcome between allow and block. The agent prepares the action. The action pauses as an approval ticket, and a person with approval rights decides, stepping up to re-verify their identity where you require it. The record shows who decided.

Where does Smartflow sit?

Cowork runs in two deployment modes, and the control points differ.

Cowork on a Claude Team or Enterprise plan. Model traffic goes from the desktop app to Anthropic. Anthropic's feature matrix lists gateway configuration as unavailable in this mode, so govern the tools. Every connector that reaches your systems is an MCP server. Point those connectors at Smartflow's MCP gateway and each tool call arrives through it, with the tool name and arguments checked against policy. Remote connectors call MCP servers from Anthropic's cloud rather than from the laptop, so each call carries the credential configured on the connector, not the identity of the person at the laptop. Calls are attributable to a person only when each user's connector holds that user's own Smartflow key. Anthropic's Compliance API has captured Cowork sessions since August 2026, in beta, and Cowork exports OpenTelemetry events. Send both to the SIEM that receives Smartflow's record.

Claude Desktop on third-party inference. Anthropic offers a mode that routes all inference, Cowork included, through a provider the enterprise configures, including a gateway you operate. Set inferenceProvider to gateway and point inferenceGatewayBaseUrl at Smartflow's Anthropic-compatible endpoint, which supports streaming and tool use and passes cache_control through unchanged. APERION has not yet validated Claude Desktop against it, so run this mode as a pilot before you depend on it. In this mode every prompt and response passes through your infrastructure, where Smartflow redacts personal identifiers, applies routing policy and records each turn. It runs as a separate Anthropic organization with token billing, and some features differ, including the Compliance API.

Which actions pause for a person?

The actions read-only rollouts block become approvals.

Function Action Cowork prepares
Marketing Publish a page, send a campaign, post to a company account
Marketing Export a customer list, change an audience or budget
Go-to-market Change a close date, amount or forecast category
Go-to-market Issue a quote or a discount above your policy line
Customer success Change a renewal, entitlement or account health score
Engineering Merge, deploy, or change production configuration
Finance Post a journal entry or release a payment
HR Update an employee record or compensation

Grant approval rights to the people who own these decisions. Reading, drafting, summarizing and research pass through and are recorded.

Anthropic's controls, and where they stop

Use Cowork's admin settings first. Give Cowork a dedicated working folder, which Anthropic's own safety guidance recommends. Keep the built-in browser off unless a team needs it. Limit connectors and plugins to an approved set. On Enterprise, restrict Cowork to specific groups.

Know the limits. Anthropic's documentation states that network egress settings do not apply to web fetch, web search or MCP connectors. It also states that local session history is stored on the user's computer, where admins cannot centrally manage or delete it. A record your firm is required to keep belongs on infrastructure your firm controls.

Rollout in five phases

  1. Scope. Enable Cowork for one group, with a dedicated folder, approved connectors and the browser off.
  2. Route the tools. Point every connector that reaches an internal system at Smartflow, holding each user's own key where you need per-person attribution. Record everything with approvals off for two weeks.
  3. Choose the approvers. For each function, list the consequential writes and grant approval rights to the people who own them.
  4. Turn on approvals. Start with sends, publishing and payments. Add CRM and HR writes next.
  5. Join the records. Stream Smartflow, the Compliance API and OpenTelemetry into one SIEM view.

Related: Smartflow for HR and Smartflow for Payroll cover two functions in depth.

Quick answers

Can Cowork traffic go through our own gateway?

On a standard Claude Team or Enterprise plan, Anthropic lists gateway configuration as unavailable. Claude Desktop on third-party inference routes all inference, Cowork included, through a provider or gateway you configure; APERION has not yet validated that mode with Smartflow. In both modes, connectors to your systems can run through Smartflow.

Does Anthropic record what Cowork does?

Since August 2026 the Compliance API captures Cowork sessions, in beta, including prompts, responses and tool call content. Cowork also exports OpenTelemetry events, metadata-only by default. Local session history stays on the user's device, outside central retention.

Is a read-only rollout enough?

It is safe and limited. Read-only prevents harmful writes and useful ones alike. Approvals let Cowork prepare the send, the update or the payment while a person with authority decides whether it runs.

Download the full guide

The PDF adds configuration for both deployment modes, the full decision map across eight functions, a phase-by-phase checklist, and the questions to ask any vendor that proposes to govern Cowork.

Sources

Verified as of September 25, 2026.

Claude, Claude Code and Claude Cowork are products of Anthropic. OpenClaw is maintained by the OpenClaw Foundation. Hermes Agent is a project of Nous Research. APERION is not affiliated with or endorsed by these organizations.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs