All corrections
Substack April 24, 2026 at 01:39 AM

www.oneusefulthing.org/p/claude-dispatch-and-the-power-of

1 correction found

1
Claim
Cowork is sandboxed, safer but more limited
Correction

That overstates Cowork’s isolation. Anthropic says Cowork’s computer-use feature runs outside the VM sandbox and interacts with your actual desktop and apps.

Full reasoning

Anthropic’s own documentation distinguishes between regular Cowork task execution and computer use:

  • In Cowork generally, code and shell commands run in an isolated VM.
  • But when Claude uses computer use—the capability this article is discussing alongside Dispatch and desktop control—Anthropic says it runs outside that VM and interacts with your actual desktop and apps.

Anthropic’s help center states that in standard Cowork, “code runs safely in an isolated space” and “runs code and shell commands in an isolated virtual machine (VM) on your computer.” But Anthropic separately warns that for computer use, “Computer use runs outside the virtual machine that Cowork normally uses for working on your files and running commands. This means Claude is interacting with your actual desktop and apps, rather than an isolated sandbox.”

Anthropic’s Dispatch documentation repeats the same point: “Computer use runs outside the virtual machine. When Claude uses your apps through computer use, it operates outside the Cowork sandbox.”

So describing Cowork flatly as “sandboxed” is inaccurate in this context. The key desktop-control capability being highlighted here is specifically not confined to the sandbox.

3 sources
Model: OPENAI_GPT_5 Prompt: v1.16.0