How do you govern Claude Cowork?
Blog post from Speakeasy
Claude Cowork, launched in 2026 as an agentic work assistant for nontechnical business functions, can access local files, enterprise connectors, plugins, browsers, cloud sessions, and scheduled tasks to execute multistep work across Claude applications. The article argues that these capabilities create governance risks including prompt injection in untrusted documents, excessive read and write permissions, unattended automation, unapproved custom MCP connectors, and limited audit visibility. Anthropic provides Team and Enterprise controls such as role-based access, connector and plugin management, approval settings, OpenTelemetry exports, and, for Enterprise, compliance transcripts and Inference hooks that can submit prompts to external security services for allow-or-deny decisions. It presents Speakeasy as a complementary security layer: Inference hooks inspect prompts, attachments, and tool responses for sensitive data and malicious instructions, while an MCP gateway evaluates tool calls before execution, restricts tools by role, logs activity, and identifies unmanaged “shadow MCP” servers. The recommended rollout begins with visibility, role and connector configuration, telemetry and shadow-mode monitoring, followed by policy tuning and eventual enforcement once approved services and false-positive rates are understood.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 21 | 2,241 | 148 | 72 | -74% |
| OpenTelemetry | 5 | 125 | 18 | 15 | -83% |
| Observability | 3 | 472 | 102 | 54 | -85% |
| Secrets Management | 2 | 451 | 99 | 43 | -80% |
| LLM | 1 | 747 | 162 | 79 | -85% |
| Real-time | 1 | 649 | 155 | 80 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.