AccuroAI
Products
What We Do
Solutions
Company
Resources
Book a demo
← Blog·Enterprise AI8 min read

Claude Cowork vs Claude Enterprise: Which Plan Fits Your Org?

Cowork is the agent; Enterprise is the leash. The same file-reading, browser-driving agent ships on a $20 personal plan and a governed enterprise one, and the deltas that matter are a BAA that covers neither, a local-history gap, and a browser default that flips September 10.

S
Sofia Reyes
Head of Compliance
2026-09-02

Claude Cowork is the agent; Claude Enterprise is the plan that governs it. The same agent runs on both. Enterprise adds SSO, audit logs, retention controls, and an org-wide kill switch. Neither plan puts Cowork under Anthropic's BAA.

That last sentence carries most of the weight in this comparison, so we'll come back to it. First, the naming problem, because half the confusion here comes from treating Cowork and Enterprise as rival products when one is a capability and the other is a contract.

A capability versus a contract

Cowork launched on January 12, 2026 as a research preview inside the Claude desktop app, pitched by Anthropic as bringing Claude Code's agentic abilities to knowledge work beyond coding. TechCrunch described it at launch as "similar to a sandboxed instance of Claude Code, but requires far less technical savvy to set up": you point Claude at a folder and it reads, writes, and executes multi-step work inside it. It reached web and mobile in July 2026, and Anthropic now lists it as available on every paid plan — Pro, Max, Team, and Enterprise — across desktop, web, mobile, and a Chrome side panel.

The agent can read and write local files without uploads, drive a browser, control the computer for local tasks, connect to outside services over MCP, and run scheduled tasks on a cadence the user sets. It has three permission modes: Manual, which pauses for approval; Auto, which works independently with automatic safety checks; and Skip, which does neither.

Read that list as a security person and the plan question mostly answers itself. This is an agent with file access, a browser, scheduled persistence, and a no-approvals mode. On Pro and Max, every one of those decisions belongs to the individual user. So the real comparison isn't features. It's custody.

What Enterprise wraps around the same agent

Anthropic's Enterprise page lists the governance stack by name: single sign-on with SAML and domain capture, SCIM provisioning, role-based access control, audit logs with OpenTelemetry monitoring, a Compliance API, data retention controls, spend controls, and usage analytics, on top of SOC 2, ISO 27001, GDPR and CCPA compliance and a HIPAA-ready offering. Chat, Cowork, Claude Code, and company connectors are all included in the plan.

For Cowork specifically, Team and Enterprise admins get an org-wide switch under Organization settings that disables the agent for every user, a separate toggle for running Cowork in the cloud, and per-team enablement through Enterprise groups and custom roles. Admins decide whether users may select "Automatically approve" mode and whether connector tools can be set to "Always allow." Plugins install through curated marketplaces with default, available, required, and hidden states.

Consumer plans have none of this. Same agent, whatever the user approves, twenty dollars a month, no procurement meeting. Which is why the useful framing isn't "should we buy Cowork" but "Cowork is probably already in the building; who holds its leash." Our earlier security review of Cowork and Claude Code examines the agent itself; this piece is about the plan decision sitting on top of it.

Plan against plan

Last verified: September 5, 2026. Consumer and Team prices come from public price pages. Anthropic does not publish Enterprise pricing, so treat any per-seat figure you read elsewhere as a third-party report.

ControlPro / Max (personal)TeamEnterprise
Cowork accessYes, governed by the user aloneYesYes
Org-wide Cowork kill switchNoneYes (Capabilities toggle)Yes, plus per-team enablement via groups and custom roles
Identity and provisioningPersonal loginWorkspace member managementSSO/SAML, domain capture, SCIM, RBAC
Audit and monitoringNoneOrg admin settings; full audit stack sits on EnterpriseAudit logs, OpenTelemetry streaming, Compliance API
Built-in browser defaultUser's choiceOn by default; owners can disableOff by default until September 10, 2026, then on unless disabled
Auto-approve and connector governanceUser's choiceOrg settings for auto-approve and "Always allow"Same org settings, scoped further by roles
BAA coverage for CoworkNoNoNo
Published pricePro $20/mo; Max $100 or $200$25 to $125 per seat monthly, less on annualNot published; contact sales

The audit question, answered from the current docs

Start with Anthropic's official position, because it has changed and older analyses haven't caught up. Per the current support documentation, OpenTelemetry streaming to your SIEM captures Cowork's "tool calls, file access, human approval decisions," and "Cowork via Claude, Claude Desktop, and Claude Mobile is captured in the Compliance API." Several vendor write-ups earlier this year described Cowork as wholly invisible to enterprise audit on every tier. The docs have moved past them.

The gap that survives is local-session history. Anthropic's own article is plain about it: for local sessions, Cowork "stores conversation history locally on users' computers," data that "cannot be centrally managed or exported by admins," and deletion endpoints for local sessions aren't available yet. So the record of what the agent did reaches your SIEM while the conversation that steered it can sit on a laptop outside every retention policy you have. A narrower hole than advertised, but a real one, and a forensic problem the day something goes wrong. This documentation is moving fast; re-verify against the support pages the week you decide.

HIPAA, without the hedging

Anthropic's privacy documentation says of Cowork: "Available to use but feature is not covered under Anthropic's BAA." Not on Pro, not on Team, not on Enterprise, not behind any toggle. The BAA also excludes the Claude Console and features in beta, and it covers Claude Code only with Zero Data Retention enabled, with the remote and web Claude Code modes excluded outright. Coverage lists differ by which BAA version your org accepted — there are separate lists for agreements signed after December 2, 2025 and after April 1, 2026 — so pull your own agreement rather than trusting a blog table, ours included.

The practical consequence for healthcare orgs is short. There is currently no configuration in which Cowork touches PHI compliantly. Enterprise's HIPAA-ready offering is real and it does not extend to this feature. If clinicians or claims staff are pointing the agent at patient files, your plan tier is irrelevant. We go deeper in Is Claude HIPAA compliant?.

September 10, and other defaults that change without asking

One date deserves a calendar entry. Cowork's built-in browser has been off by default on Enterprise since launch; per Anthropic's admin documentation it turns on by default starting September 10, 2026 unless an admin has already switched it off. On Team it's on by default today. Defaults are policy. If your risk assessment assumed no browser, it expires on September 10.

The browser matters because it operates with the user's real session cookies, outside the file sandbox. The Cloud Security Alliance's July 2026 analysis of Cowork, written by Krishanu Borah, ranks that among six risks worth watching, alongside prompt injection (with a roughly 1% attack success rate even with Anthropic's mitigations in place, a figure CSA attributes to Anthropic), the audit gap, scheduled tasks as a persistence mechanism, MCP servers widening the attack surface, and computer use without org permission checks on consumer plans. Borah's summary line is the one to keep: "When something goes wrong, the impact depends on what Claude can read and what Claude is allowed to do."

Five checks before you sign anything

Mapped against that CSA list, the assessment comes down to five questions. Can you kill the agent org-wide and per team, and does that control cover the personal accounts your staff already hold? Is OpenTelemetry streaming plus the Compliance API wired into your SIEM, and does the local-session gap matter for your forensics? Have you decided the browser default before September 10 decides it for you? Who is allowed to enable Skip mode, auto-approve, and scheduled tasks, and who reviews what's scheduled? And does any workflow put regulated data near the agent, because the BAA exclusion answers that one for you.

Plan controls govern the account. They don't inspect the content. That second layer is where accuroai sits: inline screening with 40+ data classifiers at under 38ms p99, running across 14M+ prompts a day for enterprise customers, in front of whatever assistant or agent the org has approved. Details on the workforce AI governance page.

If you're running this comparison across vendors, we've done the same exercise on Cursor and ChatGPT Work, and for orgs weighing managed-agent platforms instead, the Agent 365 and managed Claude agents field guide covers that fork in the road.

The questions that decide the purchase

Is Claude Cowork HIPAA compliant?

No. Anthropic's BAA documentation states the feature is "not covered under Anthropic's BAA," and that holds on every plan, Enterprise included. No toggle changes it. Keep PHI away from the agent entirely.

Can admins actually see what Cowork does?

On Enterprise, yes, with one gap. OpenTelemetry streams tool calls, file access, and approval decisions to your SIEM, and Cowork sessions via web, desktop, and mobile land in the Compliance API. Local-session conversation history stays on the user's machine, outside admin reach and outside retention policy.

Can we block Cowork for the whole org?

On Team and Enterprise, one toggle under Organization settings does it. On the personal Pro and Max accounts your staff may hold there is no admin, so blocking means network and endpoint controls, not a setting.

What does Claude Enterprise cost?

Anthropic doesn't say; the page offers contact sales. Third-party compilations report roughly $20 per seat per month billed annually plus usage at API rates, but we couldn't verify that against any first-party source. Treat it as a rumor with a spreadsheet.

Is Cowork just Claude Code renamed?

No. Same agentic lineage, different audience. Cowork trades the terminal for a folder picker and adds browser use, computer use, and scheduled tasks aimed at general knowledge work. The BAA treats them differently too: Claude Code can be covered with Zero Data Retention enabled, while Cowork can't be covered at all.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security