Rolling out Claude Cowork at a firm is not like one bookkeeper trying a new tool. A firm has to answer three questions first. Who gets a seat? Who reviews the output? Where does the client's data go? Answer those first. The day-to-day workflow can wait.
This guide covers Claude Cowork for accounting firms at the firm level only. It covers seats, review, and data handling. Want the day-to-day workflow a bookkeeper runs inside Cowork? Read our individual-workflow guide instead. Month-end close steps live in a separate guide too. This piece stays at the firm level on purpose.
What is Claude Cowork, and does a firm need a special plan for it? Cowork sits on paid Claude plans only: Pro, Max, Team, and Enterprise. It runs on the same agent system as Claude Code, but with no terminal. You describe a task. Claude plans the work, breaks it into steps, and returns a finished result. Desktop access, on Mac or Windows, ships on every paid plan. Web and mobile ship on Pro, Max, and Team. On Enterprise, those surfaces stay off until an admin turns them on. A firm's rollout call is really an admin call, not just a plan choice.
- Cowork sits on paid plans only: Pro, Max, Team, Enterprise. There is no free-tier seat.
- Desktop access comes with every paid plan. Web and mobile are on by default for Pro, Max, and Team, but admin-enabled on Enterprise.
- Cowork does the work and hands back a result. A person still checks it. Nothing in Cowork signs off on a client engagement.
- Cloud work runs on Anthropic's servers. A local file or browser task routes through the Claude Desktop app on that machine.
- Network rules do not cover web fetch, web search, or connectors like Claude in Chrome. That gap matters for locked-down firm networks.
- Admins get real levers: access by team, spend limits, tool permissions by department, and an activity feed to your SIEM.
Cowork is a paid-plan feature only. It is not on a free Claude account. So a firm's first choice is which plan tier covers the people who need it. Desktop access, on Mac or Windows, comes with every paid plan: Pro, Max, Team, and Enterprise.
Web and mobile access work a bit differently. On Pro, Max, and Team, they are on by default. On Enterprise, they stay off until an admin turns them on for a team. That is a real design choice. An Enterprise firm opts in to each surface. It does not get everything at once.
The Chrome side panel version of Cowork sits on Max and Team today. It is rolling out to Pro. On Enterprise, an admin has to turn it on, the same as web and mobile.
In practice, do not hand out the same access to every staff member on day one. A partner reviewing output on a laptop needs different surfaces than a bookkeeper working inside a browser tab. Map roles to surfaces first. Hand out seats second. Not every firm needs the same setup either. Claude Cowork for accountants at a two-person shop looks different than it does at a firm with a dozen staff across three departments.
Categorizes the routine. Flags what needs you.
See Growthy on a sample book. Read-only bank access.
Get startedCowork plans a task, runs the steps, and hands back a finished output. That is the loop: plan, run, return. Nothing in that loop reviews the work for you. Nothing in it signs off on a client engagement.
The real control here is Claude's permission modes. Three modes govern when Claude asks before it acts. Each mode is crossed with a per-connector setting: Always allow, Needs approval, or Blocked. A firm can set a connector to Needs approval, so a person has to say yes first. Or set it to Blocked, so Claude cannot reach it at all. That is the actual lever a firm has. It is not a claim about automatic quality control.
To be direct: nothing here says Cowork, or any AI tool, replaces a reviewer's sign-off on a client's books. A person still reviews the output. A person still signs off. Growthy is bookkeeping software, not a CPA firm. This guide does not say otherwise about Cowork either.
This is the question that matters most for an engagement. Cowork runs tasks in the cloud, currently in beta, on Anthropic's own servers, inside an isolated space. Sessions and files save to the user's Claude account. They follow that person across desktop, web, and mobile. Close the laptop, and the task keeps running.
When a task needs something local, a file or the browser itself, Claude reaches it through the Claude Desktop app on that machine. That app is the bridge between the cloud session and anything sitting locally.
Here is the part every firm should know before rollout. Cowork follows a firm's existing network egress rules, but those rules do not cover everything. Web fetch, web search, and connectors including Claude in Chrome sit outside them. Web fetch itself runs server-side. It is limited to search results and shared URLs. If your firm has locked down its network rules, do not assume those rules quietly cover Cowork's web tools too. They do not.
Anthropic says this plainly in its own documentation: Cowork "has unique risks due to its agentic nature and internet access." That is Anthropic's own language, not a marketing gloss. It belongs in any honest rollout talk. Whether that risk works for a given engagement, and a given client's data, is a call for your firm and its own policy. This guide lists the controls. It does not make that call for you.
Put plainly, a firm weighing Claude Cowork for accounting firms is not weighing one tool against no tool. It is weighing a specific set of published controls against a specific set of published gaps, for a specific engagement. That framing changes the conversation from "is this safe" to "which controls does this engagement actually require," which is a question your firm can answer.
A firm rolling out Cowork gets more than an on/off switch. Here is Anthropic's own line on Teams and Enterprise controls: "Admins set access by team, manage spend limits, and control tool permissions by department. Activity streams to your SIEM through OpenTelemetry."
Break that into plain terms. Access by team means a bookkeeping team and an admin team do not share the same permissions. Spend limits cap what a team can run up. Tool permissions by department mean one team's connectors do not become another's. The SIEM stream means your security team can watch what happens. They do not just have to trust it.
One more lever worth knowing. A Team or Enterprise plan owner can turn off web search for both Cowork and Chat. Find it in Organization settings under Capabilities. For a firm that wants Cowork's task work without the open internet attached, that is the switch.
This guide will not tell you Cowork carries a specific compliance badge, a data-retention window, or that it is cleared for client financial data. Those facts are not public anywhere we could check as of this writing. Confirm them with Anthropic directly, or through your own firm's compliance process, before you decide what data touches Cowork.
Rolling out Claude Cowork for accounting firms comes down to these same four decisions every time, whether your firm has three people or thirty. None of this replaces your firm's own policy work. It gives you the real controls Anthropic has published. Build your policy on what is real, not on what sounds reasonable. Start with seats mapped to roles. Set connector permissions to Needs approval where you want a person in the loop. Confirm your admin turned on the SIEM stream before anyone starts a client task.
A simple rollout checklist for a partner or IT lead: pick which plan tier covers your staff, decide which roles get web and mobile access versus desktop only, set connector permissions to Needs approval for anything touching client data, and confirm the SIEM stream is live before day one. Write those four decisions down. A firm that skips this step ends up making the same calls one seat at a time, under pressure, after something has already gone wrong.
Weighing how Cowork fits next to a wider AI rollout at your firm? Our guide to Claude's accounting skill covers a related surface, and the AI for accountants hub collects the rest. If the real problem your firm is solving is a client-count ceiling, not a single tool, our piece on how many clients one bookkeeper can handle is the better place to start.
Ready to see what a modern bookkeeping stack looks like for a growing firm? Start your Growthy signup and bring your books into one place before you decide what AI tools sit around them.
Growthy is bookkeeping software, not a CPA firm. This content is educational, not professional advice.