Product names, plans and features change often. Check the vendor’s current documentation before relying on any detail here, and apply your own jurisdiction’s professional-conduct rules.
Most lawyers meet AI as a chat box. You copy something out of a document, paste it into a browser tab, read the answer, copy the useful part back. The copying is not incidental friction, it is most of the cost. It is also where confidentiality slips happen, because the thing you paste is decided in a hurry.
Cowork removes the copying. You point Claude at a folder, describe the task, and it works on the actual files.
What Cowork actually is
Cowork is Claude running as an agent rather than a correspondent. Instead of answering one prompt at a time, it takes a multi-step task, plans an approach, shows you the plan, and then executes: reading and writing files in folders you have connected, driving a browser, spawning sub-agents to work in parallel, and producing real outputs such as a spreadsheet with working formulas or a deck built from a transcript.
It arrived as a research preview in January 2026 and sits on the paid plans. Desktop, on macOS and Windows, covers Pro, Max, Team and Enterprise. Web and mobile cover Pro, Max and Team. Enterprise gets it where an administrator has switched it on.
One detail matters more than the rest of that list: local file access is desktop only. If you want Claude working on your matter folders, you need the desktop app on the machine those folders live on.
Read this before you connect a folder
There is a sentence circulating about Cowork that says your files stay on your computer. It is true, and it is routinely misread.
What stays local is the project definition: the folder link, your instructions, the files sitting on your disk. Projects created locally do not even sync to your Claude account. But Cowork sessions execute in the cloud, which is precisely why a task keeps running after you shut the lid. For Claude to summarise a deposition, it has to read the deposition. The contents go to the model.
Local folder access controls which files Claude can reach. It does not mean the contents never transit. Those are different questions, and only one of them is answered by connecting a folder.
For most firm work this is fine, on the same basis that using a cloud practice management system or Microsoft 365 is fine: a business or enterprise plan, training on your data switched off, and a written policy about what goes where. It is not fine for the small set of matters that genuinely cannot leave the building. Those need an open model running on your own hardware, which is a different setup and a different post.
Decide which bucket a matter is in before you connect its folder, not after.
Local folder access
Claude reads and writes only in folders you have explicitly connected. Nothing else on the disk is visible, so connecting your Matters/Ferguson folder does not expose Matters/Whitlock, and it certainly does not expose your tax returns.
Permissions are granted per folder, and read, edit and delete are separate. You can grant for one time or always.
Our default for a live matter folder is read and edit, never delete. The upside of delete is that Claude can tidy up after itself. The downside is a deleted exhibit. That trade is not close. Keep the folder backed up somewhere Claude has no access to, and you have removed the only genuinely expensive failure mode.
Separately from folders, connectors have their own three permission modes, and they are worth knowing by name because the difference is real:
- Manual. Claude pauses and asks before each action. Slow, and correct for anything that writes to a system of record.
- Auto. Claude reviews its own planned actions for safety concerns and proceeds. Reasonable for read-heavy research work.
- Skip. No automatic checks. We do not use this on anything touching client data, and neither should you.
Start everything on Manual. Move a workflow to Auto only once you have watched it run correctly a dozen times and you know what its failure looks like.
Projects, one per matter
A project is a workspace that holds context, instructions, files and memory together, so you are not re-explaining the matter every morning. Projects work the same way in Cowork as they do in Claude.
There are three ways to start one:
- From scratch. A new folder, custom instructions, files you attach.
- Import an existing Claude project. Brings over the files and instructions from a chat project you already built.
- Point it at a folder you already have. This is the one that matters for a firm, because your matters are already folders.
That third route is the whole argument. You do not restructure your filing to suit the tool. You link Matters/Ferguson and the project is the matter.
Each project carries four things: instructions that shape how Claude behaves inside it, scheduled tasks that belong to it, context from the linked folder plus any chat project or URL you add, and memory.
On Team and Enterprise you can give colleagues Can view or Can edit on a project, which is how a supervising partner stays across an associate's workspace without taking it over.
Memory and conflicts
Memory is on by default. Claude retains what it learned from earlier tasks in a project and applies it to later ones, so the second time you ask for a chronology it already knows who the parties are and which naming convention you use.
The part that matters professionally is the boundary: what Claude learns in one project does not carry into another. Memory is scoped to its project.
That isolation is what makes project-per-matter the right structure rather than just a tidy one. One project per matter gives you a memory boundary that maps onto a matter boundary. One giant project called "Work" does not, and you should not build it.
A worked example
A real shape, lightly anonymised, for a small US immigration practice.
Folder on disk:
Matters/
Ferguson-EB1A/
01-intake/
02-evidence/
03-drafts/
04-filed/
_matter.md
_matter.md is a plain text file holding the facts that never change: petitioner, beneficiary, criteria being argued, filing deadline, attorney of record, and the firm's citation and naming conventions. It costs ten minutes to write once.
Project instructions, kept short:
This project is one EB-1A petition. Read _matter.md before any task.
- Draft into 03-drafts/ only. Never write to 04-filed/.
- Name files YYYY-MM-DD-short-description.docx
- Every factual claim about the beneficiary must cite an exhibit in
02-evidence/ by filename. If no exhibit supports it, flag it and stop.
- Do not characterise the strength of any criterion. That is the
attorney's call, not yours.
- US spelling. No em dashes.
That last block is doing the real work. It is not prompt decoration, it is the instruction that turns a confident drafting assistant into one that surfaces evidentiary gaps rather than writing over them.
Then the day-to-day is ordinary: "index everything in 02-evidence and tell me which criteria are thin", "draft the cover letter from _matter.md and the current exhibit index", "read the RFE in 01-intake and list every factual assertion we have not yet answered".
The output still gets read, checked and signed by a lawyer. Nothing here changes that.
Where it breaks down
Honest list, because you will hit all of these.
- Scheduled tasks cannot be tied to a local folder. This surprises people. Recurring tasks run in the cloud against your connectors and the files saved to your Claude account, which means the matter-folder workflow above cannot simply be put on a daily timer. You either move that data into a connected system, or you run the task manually.
- Projects do not exist in Claude Code. If your team works across both, the project lives in one place only.
- Locally created projects do not sync. Two machines means two projects unless the folder sits on a synced drive.
- Sessions cannot be shared. You can share an individual artifact, not the session that produced it. Handover is still a conversation.
- It will be confidently wrong. Cowork is more autonomous, which means a wrong turn goes further before you notice. The verification habit matters more here, not less.
None of that is a reason to stay in the copy-and-paste loop. It is a reason to start with a low-stakes folder, watch what it does for a fortnight, and expand from there.
If you want this set up properly, with the folder structure, the permission model and the instruction files written around how your firm actually files things, that is what we do.