Claude Cowork for Accounting Firms: A Rollout Guide

Bobby Huang

Partner, SDO CPA LLC / CEO, Growthy

September 3, 2026
8 min read
AI for Accountants
Claude Cowork for Accounting Firms: A Rollout Guide

Rolling out Claude Cowork at a firm is not like one bookkeeper trying a new tool. A firm has to answer three questions first. Who gets a seat? Who reviews the output? Where does the client's data go? Answer those first. The day-to-day workflow can wait.

This guide covers Claude Cowork for accounting firms at the firm level only. It covers seats, review, and data handling. Want the day-to-day workflow a bookkeeper runs inside Cowork? Read our individual-workflow guide instead. Month-end close steps live in a separate guide too. This piece stays at the firm level on purpose.

What is Claude Cowork, and does a firm need a special plan for it? Cowork sits on paid Claude plans only: Pro, Max, Team, and Enterprise. It runs on the same agent system as Claude Code, but with no terminal. You describe a task. Claude plans the work, breaks it into steps, and returns a finished result. Desktop access, on Mac or Windows, ships on every paid plan. Web and mobile ship on Pro, Max, and Team. On Enterprise, those surfaces stay off until an admin turns them on. A firm's rollout call is really an admin call, not just a plan choice.

Key Takeaways

  • Cowork sits on paid plans only: Pro, Max, Team, Enterprise. There is no free-tier seat.
  • Desktop access comes with every paid plan. Web and mobile are on by default for Pro, Max, and Team, but admin-enabled on Enterprise.
  • Cowork does the work and hands back a result. A person still checks it. Nothing in Cowork signs off on a client engagement.
  • Cloud work runs on Anthropic's servers. A local file or browser task routes through the Claude Desktop app on that machine.
  • Network rules do not cover web fetch, web search, or connectors like Claude in Chrome. That gap matters for locked-down firm networks.
  • Admins get real levers: access by team, spend limits, tool permissions by department, and an activity feed to your SIEM.

Seats and who gets them

Cowork is a paid-plan feature only. It is not on a free Claude account. So a firm's first choice is which plan tier covers the people who need it. Desktop access, on Mac or Windows, comes with every paid plan: Pro, Max, Team, and Enterprise.

Web and mobile access work a bit differently. On Pro, Max, and Team, they are on by default. On Enterprise, they stay off until an admin turns them on for a team. That is a real design choice. An Enterprise firm opts in to each surface. It does not get everything at once.

The Chrome side panel version of Cowork sits on Max and Team today. It is rolling out to Pro. On Enterprise, an admin has to turn it on, the same as web and mobile.

In practice, do not hand out the same access to every staff member on day one. A partner reviewing output on a laptop needs different surfaces than a bookkeeper working inside a browser tab. Map roles to surfaces first. Hand out seats second. Not every firm needs the same setup either. Claude Cowork for accountants at a two-person shop looks different than it does at a firm with a dozen staff across three departments.

Who reviews and who signs off

Categorizes the routine. Flags what needs you.

See Growthy on a sample book. Read-only bank access.

Get started

Cowork plans a task, runs the steps, and hands back a finished output. That is the loop: plan, run, return. Nothing in that loop reviews the work for you. Nothing in it signs off on a client engagement.

The real control here is Claude's permission modes. Three modes govern when Claude asks before it acts. Each mode is crossed with a per-connector setting: Always allow, Needs approval, or Blocked. A firm can set a connector to Needs approval, so a person has to say yes first. Or set it to Blocked, so Claude cannot reach it at all. That is the actual lever a firm has. It is not a claim about automatic quality control.

To be direct: nothing here says Cowork, or any AI tool, replaces a reviewer's sign-off on a client's books. A person still reviews the output. A person still signs off. Growthy is bookkeeping software, not a CPA firm. This guide does not say otherwise about Cowork either.

Where client data goes

This is the question that matters most for an engagement. Cowork runs tasks in the cloud, currently in beta, on Anthropic's own servers, inside an isolated space. Sessions and files save to the user's Claude account. They follow that person across desktop, web, and mobile. Close the laptop, and the task keeps running.

When a task needs something local, a file or the browser itself, Claude reaches it through the Claude Desktop app on that machine. That app is the bridge between the cloud session and anything sitting locally.

Here is the part every firm should know before rollout. Cowork follows a firm's existing network egress rules, but those rules do not cover everything. Web fetch, web search, and connectors including Claude in Chrome sit outside them. Web fetch itself runs server-side. It is limited to search results and shared URLs. If your firm has locked down its network rules, do not assume those rules quietly cover Cowork's web tools too. They do not.

Anthropic says this plainly in its own documentation: Cowork "has unique risks due to its agentic nature and internet access." That is Anthropic's own language, not a marketing gloss. It belongs in any honest rollout talk. Whether that risk works for a given engagement, and a given client's data, is a call for your firm and its own policy. This guide lists the controls. It does not make that call for you.

Put plainly, a firm weighing Claude Cowork for accounting firms is not weighing one tool against no tool. It is weighing a specific set of published controls against a specific set of published gaps, for a specific engagement. That framing changes the conversation from "is this safe" to "which controls does this engagement actually require," which is a question your firm can answer.

Admin controls for the firm

A firm rolling out Cowork gets more than an on/off switch. Here is Anthropic's own line on Teams and Enterprise controls: "Admins set access by team, manage spend limits, and control tool permissions by department. Activity streams to your SIEM through OpenTelemetry."

Break that into plain terms. Access by team means a bookkeeping team and an admin team do not share the same permissions. Spend limits cap what a team can run up. Tool permissions by department mean one team's connectors do not become another's. The SIEM stream means your security team can watch what happens. They do not just have to trust it.

One more lever worth knowing. A Team or Enterprise plan owner can turn off web search for both Cowork and Chat. Find it in Organization settings under Capabilities. For a firm that wants Cowork's task work without the open internet attached, that is the switch.

This guide will not tell you Cowork carries a specific compliance badge, a data-retention window, or that it is cleared for client financial data. Those facts are not public anywhere we could check as of this writing. Confirm them with Anthropic directly, or through your own firm's compliance process, before you decide what data touches Cowork.

Rolling this out at your firm

Rolling out Claude Cowork for accounting firms comes down to these same four decisions every time, whether your firm has three people or thirty. None of this replaces your firm's own policy work. It gives you the real controls Anthropic has published. Build your policy on what is real, not on what sounds reasonable. Start with seats mapped to roles. Set connector permissions to Needs approval where you want a person in the loop. Confirm your admin turned on the SIEM stream before anyone starts a client task.

A simple rollout checklist for a partner or IT lead: pick which plan tier covers your staff, decide which roles get web and mobile access versus desktop only, set connector permissions to Needs approval for anything touching client data, and confirm the SIEM stream is live before day one. Write those four decisions down. A firm that skips this step ends up making the same calls one seat at a time, under pressure, after something has already gone wrong.

Weighing how Cowork fits next to a wider AI rollout at your firm? Our guide to Claude's accounting skill covers a related surface, and the AI for accountants hub collects the rest. If the real problem your firm is solving is a client-count ceiling, not a single tool, our piece on how many clients one bookkeeper can handle is the better place to start.

Ready to see what a modern bookkeeping stack looks like for a growing firm? Start your Growthy signup and bring your books into one place before you decide what AI tools sit around them.


Growthy is bookkeeping software, not a CPA firm. This content is educational, not professional advice.

See It Work on Your Data

See Growthy on a sample book. Read-only bank access.

✓ No credit card✓ Works with QuickBooks Online✓ 85% accuracy
Get started

Bobby Huang Partner, SDO CPA LLC / CEO, Growthy

Partner at SDO CPA. 18 years of hands-on bookkeeping. Bobby still reconciles real client books and builds Growthy from that operating work.

View author profile

Growthy content is written and reviewed by people who keep real books. Worked examples come from real bookkeeping scenarios, and product claims are checked against what the product does today. Our editorial guidelines cover how we source, verify, and update every article.

Keep reading

Claude Bookkeeping Skill: What It Can and Cannot Do
Close-up of a laptop screen showing the Claude AI chat interface
AI for Accountants

Claude Bookkeeping Skill: What It Can and Cannot Do

A Claude Skill is instructions, not a ledger connection. What it can and cannot do for real bookkeeping, and where a purpose-built tool has to own the ledger.

Growthy vs Pilot for CPA Firms: An Honest Breakdown
CPA firm professionals reviewing financial data on screens
AI for Accountants

Growthy vs Pilot for CPA Firms: An Honest Breakdown

Pilot is real and capable. So is Growthy. They're built for different jobs. Here's the practitioner framing you need before you decide.

Will AI Replace Accountants? An Honest Answer
Accountant reviewing reports on a tablet in a modern office
AI for Accountants

Will AI Replace Accountants? An Honest Answer

No. AI automates transaction coding, receipt matching and anomaly flags. It does not automate sign-off, tax strategy or client trust. A working firm partner on what actually changes at a 5-20 staff firm in 2026-2027.