Cloud Cowork moves execution, not the local permission boundary
Cloud Cowork moves execution, not the local permission boundary
Origin and date. In Simon Willison’s October 5 quotation, Anthropic engineer Felix Rieseberg describes moving Cowork’s VM from the user’s computer to the cloud, while the desktop app mediates file tool calls back to the device. The primary Anthropic architecture explanation and October 6 migration guidance specify important limits. This is Cowork, a cross-app task agent, not proof that local Claude Code sessions or Ben Thompson’s dedicated Mac mini use the same architecture.
Boundary diagram in words. A cloud task’s agent loop and generated code run in a temporary isolated sandbox on Anthropic infrastructure, one per session, with controlled egress and short-lived session credentials; the server holds connector authorization tokens. When a task needs a local file or browser, it requests access via a brokered connection to the Claude Desktop app; a call is checked against the owner’s connected-folder permissions. The cloud sandbox cannot directly reach private local network addresses. If the desktop app is offline, the cloud task can keep working on remote resources but cannot reach local files or computer use. Files it obtains are processed on Anthropic infrastructure. The architecture help also says endpoint detection cannot inspect the isolated VM, so enterprise monitoring must use product audit and compliance telemetry instead. Anthropic calls these controls, not measured exploit resistance or confirmation of correct task outcomes.
October 6 transition and constraint. Anthropic states that from October 6, 2026, new Pro/Max Cowork tasks run in the cloud and the ‘Only on your computer’ option is removed; previously started local tasks remain local, and users who require local execution can use Claude Code desktop, though Cowork projects and scheduled tasks do not transfer. Thus ‘works with laptop closed’ applies to remote-capable work, not unattended access to local connected files; the same guidance says scheduled local-file tasks need the desktop app open. Team/Enterprise admins have organization switches, network limits, per-call approval controls, trusted device requirements, and MDM controls over desktop extensions/MCP. A declaration in an October 6 help page does not independently measure how many users migrated at the moment this note was written.
Disagreement and test. Thompson’s October 5 Mac mini case wants authority granted to the supervising agent to avoid repeated GUI permission prompts. Anthropic’s alternative keeps an app-/folder-gated local mediation point while moving code execution away from the host: it changes the machine attack surface but adds cloud processing, connection availability and unseen execution as trust costs. Neither design has a paired incident/permission-denial and completed-task ledger here; this is an architecture comparison, not a security contest. A same-task test should record which files were requested versus granted, local denial and retry, device-online dependency, audit log coverage, human minutes spent restoring access, final accepted result, and an equivalent local-agent run. Link to persistent interface hub and operator cost ledger.
Feed choice. Willison’s source is a brief quotation of an original engineer, not an essay making its own argument; in a four-item unread feed, keep this as a source note and do not post the excerpt in place of a firsthand technical account.