CLAUDE LABJP
2.1.280 — Claude Code reached 2.1.280 on September 22, adding Claude Opus 5.5 (claude-opus-5-5) as the new default Opus model: 1M context, $4/$20 per Mtok, and $0.20/Mtok cache reads10/07 — The old spellings of the Claude Desktop and Cowork managed config keys stop being accepted at 12:00 PT on October 7, fourteen days out. After that the check fails closed0X80070020 — On Windows, updates can silently fail to land and leave the old build running. A lingering git fsmonitor--daemon blocks the new version, and the report includes a workaround that needs no rebootNEW — Auditing the worktrees that were supposed to clean themselves up, and deciding what to hand to isolationBING73 — Bing accounts for 73.6% of this site's real traffic. What gets read is strictly troubleshooting — billing errors, PowerShell, file attachments — and not one explainer sits near the topCOWORK — Handing over write access in three stages — read-only, one scoped folder, then writes — keeps the places you cannot undo out of reach until last2.1.280 — Claude Code reached 2.1.280 on September 22, adding Claude Opus 5.5 (claude-opus-5-5) as the new default Opus model: 1M context, $4/$20 per Mtok, and $0.20/Mtok cache reads10/07 — The old spellings of the Claude Desktop and Cowork managed config keys stop being accepted at 12:00 PT on October 7, fourteen days out. After that the check fails closed0X80070020 — On Windows, updates can silently fail to land and leave the old build running. A lingering git fsmonitor--daemon blocks the new version, and the report includes a workaround that needs no rebootNEW — Auditing the worktrees that were supposed to clean themselves up, and deciding what to hand to isolationBING73 — Bing accounts for 73.6% of this site's real traffic. What gets read is strictly troubleshooting — billing errors, PowerShell, file attachments — and not one explainer sits near the topCOWORK — Handing over write access in three stages — read-only, one scoped folder, then writes — keeps the places you cannot undo out of reach until last
Articles/Cowork
Cowork/2026-09-23Beginner

Write Access Came Third: The Order I Hand Folders to Cowork

When I connect a folder to Cowork I open it in three steps: read-only, a place where new files may appear, then write access. Here is the line I drew with a client's asset folder, and the three things I settle before connecting.

Cowork42Connected foldersPermissions6Non-engineersOperations19

One morning I opened the connection screen to hand Cowork a folder of assets a client had sent me, and my hand stopped. It was the working folder for a site I was building — photos, draft copy, and reference documents the client had shared, all sitting at the same level. I only meant to ask for some tidying up. Then I read the line that said Cowork would be able to read and write everything inside, and my finger would not move.

What I was doing in that moment was trying to list the things I could not afford to lose. Looking back, that was the long way round. You can count the files that matter, but there will always be one you failed to count.

Open the places you can undo, first. Once I turned it into a question about order rather than a question about risk, my hand started moving again. Read-only for a week. Then one folder where new files may appear. Then, and only then, write access to what already exists. Three steps, opened from the top. I would like to write down that order here, along with the three things I settle before I touch the connection screen. None of it requires a terminal.

Step one: read-only, for a full week

In the first step I make no request that involves writing. Summarize, find, list, compare — everything comes back inside the conversation and nowhere else.

What that week reveals is not how capable Cowork is. It is how I ask. By the third day I had started typing "and while you're at it, go ahead and tidy those up." If the connection had not been read-only, that request would simply have gone through.

Three things I noticed during that read-only week:

  • I have a habit of tacking write requests onto the end of read requests
  • The asset folder contained files I had not created myself
  • Asking for a plain listing surfaced two drafts I had forgotten about

The third one mattered most. Granting write access to a folder you have not fully accounted for is close to asking someone to tidy a desk drawer that is not yours. Look at what is in there with your own eyes first. That is what the read-only week is for.

Names alone will not tell you what is inside, by the way. I counted the gap between what a filename search finds and what a content search finds in I counted the keys in a folder before handing it to an AI: only 5 of 18 were findable by filename.

There is one more reason the read-only week is worth the wait. A folder you have been using for months feels familiar, and familiarity is exactly what hides the odd file. Mine held a PDF a client had sent as a reference, which I had never opened and could not have replaced. I would not have found it by worrying about it. I found it because I asked for a list and read the list.

Step two: exactly one place where new files may appear

Once I can see my own habits, I move to the second step. What I open here is not permission to change existing files. It is one place where new files are allowed to appear.

Rather than working inside the client's folder, I made a separate working folder next to it and connected that instead. The original assets stayed read-only. Every output went into the working folder. If I dislike the result, I can throw away the whole folder and nothing has moved.

Three things worth putting in place at this step:

  • A dated output folder (something like 2026-09-23_cleanup-proposal)
  • A one-line promise not to touch the originals, written into the project instructions
  • A rule for myself: do not ask for the next thing before reviewing the last output

The third is a habit rather than a setting, and it turned out to be the one that mattered. When you believe new files cannot do any harm, you stop reading them, and outputs pile up. A week later you cannot remember what any of the proposals were for.

Step three: finally, write access

The third step is permission to change files that already exist. It took me about two weeks to get there.

Before I open it I always duplicate the whole folder somewhere else. The word "backup" makes people brace themselves, so I call mine the "way back." It is tempting to think cloud sync history covers this — but history restores one file at a time. Picture the morning after twenty files changed at once, restoring each one by hand, and ten minutes of copying starts to look cheap.

I should add that the duplicate is not only insurance against Cowork. It is insurance against me. Twice now the thing I wanted to undo was a change I had approved too quickly while reading on my phone, and the way back was what let me take an afternoon to decide properly rather than deciding in ten seconds.

Here are the three steps side by side.

Step What is granted Where output lands How you undo a mistake
One Read only The conversation Nothing to undo
Two Create inside a working folder A dated new folder Delete the folder
Three Modify existing files The original location Restore from the duplicate

Even at step three, the places I cannot undo — original files a client entrusted to me, anything tied to a contract — stay closed. Keeping one folder permanently off the table makes the rest of the handover feel much lighter.

The three things I settle before connecting

Folded back into a checklist you run before opening the connection screen:

First, is there a way back? If not, I make one and then connect. Do it in the other order and the morning you want to restore is the morning you have nothing to restore from.

Second, where does output land? If I do not say, Cowork will choose somewhere reasonable — but "reasonable" may not match the map in my head. One line up front saves a search later.

Third, can this request be done read-only? If it can, there is no reason to open writing at all. I connected that folder intending to have it reorganized, and in the end everything I actually needed that first week was read-only.

That said, stopping before step three means the amount you can hand over never grows. The comfort of read-only and the lightness of delegating — what holds those two together, I think, is the order itself.

One thing to try

If you do one thing today, make it this: pick one folder you have connected right now and write down which step you are actually on. You may find, as I did, that you connected it read-only in your mind and have been using it like step two ever since.

If you get as far as running things unattended, the next question becomes not what you hand over but how far it is allowed to walk — I measured that in A connected folder is defined less by what you hand over than by what you keep it from walking through.

Thank you for reading this far. Settling the order in advance has meant my hand stops at that connection screen far less often. If you have been hesitating in the same place, I hope these three steps give you something to start from.

Share

Thank You for Reading

Claude Lab is ad-free, supported entirely by members like you. We publish practical guides daily with implementation code, benchmarks, and production-ready patterns. If you've found it useful, we'd love to have you on board.

  • Copy-paste ready implementation code
  • New advanced guides published daily
  • $5/mo or $15 for lifetime access
View Membership →

If you found this article helpful, a small tip ($1.50) would mean a lot to us. Your support helps keep this site ad-free and covers server and hosting costs.

Related Articles

Cowork2026-09-18
How I decide between Cowork and Claude Code: by where approvals land
Cowork and Claude Code run the same Claude, so I stopped comparing features and started sorting work by one question: can a human approval interrupt this step, or not? Here is the line I draw and the code I keep on the unattended side.
Cowork2026-07-11
Make Your Nightly MCP Connectors' Health Visible — A Lightweight Ledger for Solo Operators
You don't need Enterprise connector observability to see your MCP connectors' error rate and latency. Append one line per tool call, roll it up weekly, and let regressions ring a bell. A working health ledger for anyone running scheduled tasks solo.
Cowork2026-09-16
The scheduled task that only ran on days my desk was awake
Cowork scheduled tasks run remotely by default, but the moment one needs a local file or app, it runs only on your machine. Here is how the last field in the setup dialog decides that, and the three questions I now answer before creating a task.
📚RECOMMENDED BOOKS
Build a Large Language Model (From Scratch)
Sebastian Raschka
LLM Dev
Prompt Engineering for LLMs
Berryman & Ziegler
Prompting
AI Engineering
Chip Huyen
AI Eng
* Contains affiliate links