Anthropic Shipped an Agent With No Sandbox. Team and Enterprise Plans Can't Get It.

· CX Pulse

Claude can now click around your desktop with no sandbox. Anthropic's own doc says the plans with an admin console can't have it.

Anthropic turned on background computer use in the Claude desktop app this week. Claude clicks, types and opens applications on your machine while you keep working in another window. It doesn't grab your pointer, and it waits if you're mid sentence. On macOS 15 and later, running in the background is the default rather than an option you go find.

Most of the coverage landed in the same place: Claude can drive your Mac now. That's true and it's the least interesting thing about it. The part worth reading sits in Anthropic's own help article, in two sentences about four paragraphs apart.

"Computer use has no sandbox between Claude and your applications."

And then, further down, under Current limitations:

"Available for Pro and Max plans only. Team and Enterprise plans don't have access to computer use at this time."

Read those together. The capability with no isolation layer between a model and every application on a machine is shipping to the two personal plans, and it isn't shipping to the two plans that come with an admin console.

What it does on the machine

Claude works down a ladder. Connector first, Gmail or Slack or Microsoft 365, because that path is fastest. If there's no connector it moves to a browser. If neither works it goes to your screen and clicks around the desktop like a person would.

To do that it takes screenshots continuously. Anthropic is direct about what that means: Claude "can see any information visible on your screen or those apps, including personal data, sensitive documents, or private information belonging to you or others."

The controls are real. Permission is requested per application. Investment, trading and cryptocurrency apps are blocked by default. There's a blocklist you can add to, a scanner watching for prompt injection, and you can stop a run at any point.

There's also a leak in the boundary that Anthropic documents rather than hides. Clicking a link inside your mail app can open Chrome even when Chrome was never approved. In their words, they can prevent Claude from seeing that window but "can't stop the link from opening."

Their own advice on where not to point this includes a line that matters for anyone serving customers: avoid apps holding financial records, legal documents, medical information, or the personal information of other people.

A support queue is a list of other people's personal information. So is a CRM, a billing portal and a returns dashboard.

The enterprise problem is that there's nothing to look at

Everything a large organization uses to govern this lives on the Enterprise plan. Single sign on, SCIM provisioning, audit log access, IP allowlisting, tenant restrictions, model access management, the Compliance API. All of it exists and none of it applies here, because the feature isn't on that plan.

So it arrives through personal subscriptions on managed laptops. Somebody in support pays for Pro themselves, updates the desktop app, and turns on a toggle in Settings. There's no admin relationship with that account, so there's no switch to flip and no report to run.

The approval governing all of it is a prompt shown to whoever is sitting at the desk, per application, with full screen access approved once per session. That person is a support rep or a billing analyst, making an access control decision in the middle of doing their job.

Existing tooling won't help much. The activity is a legitimate logged in session performing ordinary clicks, so a DLP or SIEM rule watching for exfiltration sees a user working. The record of what the agent looked at is a series of screenshots held outside your environment.

Four questions have answers today:

Smaller operations have the opposite problem

Run a ten person company and there's no MDM fleet to inventory and no policy to amend. You're the admin, which makes this easier to control and easier to leave alone entirely.

The upside is bigger here than at scale. This is the first version of an agent that can work an internal tool with no API, no integration budget and no vendor conversation. The scheduling system nobody ever automated is suddenly reachable.

Two things are worth doing before the first run, and they take ten minutes. Put your customer systems on the blocklist so the decision isn't made in a prompt while you're busy. Then close the tabs and files you wouldn't hand to a contractor, because everything left open is in the screenshots.

The gap is the story

Anthropic wrote these warnings itself, plainly, in a public document, and added that no safeguards are perfect. More candor than most vendors offer.

The organizations with the controls to act on those warnings can't turn the feature on. The people who can turn it on are approving app access one prompt at a time, on a laptop with a customer record open behind the window.

Source: Anthropic Help Center, Let Claude use your computer in Cowork