If I always use "Automatically approve," does that mean I'm completely safe from any action Claude might misjudge?
No, not completely safe. The safety review built into Automatically Approve is designed to catch actions Claude itself judges to be unsafe — meaning it can effectively Block situations where Claude correctly identifies risk, but it can't guarantee catching every action that's objectively risky yet gets misjudged as safe by Claude. That's exactly why Prompt Injection attacks are dangerous: if a document or webpage contains a cleverly crafted malicious instruction that successfully convinces Claude an action is a normal part of the task, this review layer won't trigger a warning.
The more accurate way to think about it is that the safety review in Automatically Approve reduces risk rather than eliminating it — it turns a situation with no gatekeeping at all into one with an automated layer of judgment doing the gatekeeping, but that layer isn't foolproof. That's also why Anthropic's documentation specifically notes that even in Automatically Approve mode, switching to Manually Approve is still recommended whenever a task touches sensitive files, accounts, or high-risk sites.
After switching to "Skip all approvals," is deleting files the only thing that still triggers a confirmation, or is there truly nothing else at all?
This is the easiest misunderstanding when it comes to "Skip all approvals." Anthropic's exact wording is that "nothing checks its actions" — that refers to the safety-review layer being removed, not every type of prompt disappearing entirely. The specific confirmation prompt for deleting files is an independent, always-on rule that sits outside the approval mode system, separate from whether safety review runs — even under Skip All Approvals, this particular confirmation still appears, because it isn't part of the safety review mechanism at all; it's a standalone floor unaffected by the approval mode.
In other words, what Skip All Approvals removes is the entire mechanism where Claude first runs its own risk assessment and only stops to ask you when something looks off — not the rule that certain specific high-risk actions always require your explicit yes, regardless of which mode you're in. These two are designed as separate systems, so seeing a deletion confirmation still pop up occasionally shouldn't be mistaken for safety review secretly still running under the hood in that mode.
If a task starts out as low-risk routine work under Automatically Approve, but partway through it needs to touch sensitive files, does the approval mode adjust automatically?
No, it doesn't adjust automatically — the approval mode is a setting you actively choose and actively switch, and it doesn't upgrade or downgrade on its own just because the nature of a task changes mid-stream. That means if you chose Automatically Approve at the start because you judged the work low-risk, and partway through Claude determines it needs to access a sensitive file you hadn't anticipated, the safety review built into Automatically Approve may Block that specific action and pause to ask you — but that's the safety-review mechanism itself triggering a pause, not the system automatically switching your approval mode to Manually Approve.
That's also why Anthropic recommends treating "monitor the task" as an ongoing action rather than something you set once and walk away from — even with automatic review running in the background, keeping an eye on whether Claude is accessing files or sites you didn't originally mention is still part of the recommended practice. If you notice a task's scope has crept beyond what you originally intended, manually switching to Manually Approve yourself is more reliable than waiting for the system to adjust it for you.
Does computer use follow the same Automatically Approve / Skip All Approvals logic as everything else?
Computer use deserves special attention because its risk structure differs from other tools. Anthropic's documentation is explicit that, unlike file operations (which go through permission checks) or code execution (which runs in an isolated environment), computer use has no sandbox between Claude and what's on your screen. That means Claude directly clicking, typing, and interacting with your screen carries a risk profile that isn't quite the same as reading or writing files, and it's specifically called out as a category that warrants extra caution.
Anthropic's specific warning for computer use: Claude can only use apps you've given it permission to use, but if it clicks a link inside one of those apps, that link will still open — even if you never authorized Claude to access whatever app that link points to. That means the approval-mode logic still applies to computer use, but because its interaction with your screen is direct and immediate, Anthropic still recommends pairing it with extra precautions — like blocking sensitive apps such as healthcare portals, banking, and dating apps — even under Automatically Approve, rather than relying solely on the protection the approval mode itself provides.
When Claude Cowork works through a task, the screen doesn't usually pop up a "is this action okay?" prompt at every single step — that's because Cowork offers several different approval modes that let you decide whether Claude should pause and ask before every action. Two of those modes, "Automatically approve" and "Skip all approvals," sound similar — both mean you don't have to manually click yes at every step — but Anthropic's own documentation describes the difference between them in essentially one sentence, and that one sentence decides whether anything is actually watching over what happens during a task.
Anthropic's safety guide describes both modes side by side, in direct contrast: in "Automatically approve" mode, Claude still reviews each action for safety before it runs; in "Skip all approvals," nothing checks its actions. That's a short sentence, but the difference it draws is fundamental — "Automatically approve" saves you the manual step of clicking "allow" one action at a time, but a safety-review layer still runs underneath. "Skip all approvals" removes that manual step *and* the safety-review layer along with it.
According to Anthropic's documentation, in auto mode Claude evaluates safety before each action runs and blocks anything it determines to be unsafe; if an action gets blocked, Claude looks for a safer approach or pauses to ask you directly. That means "Automatically approve" isn't "wave everything through mindlessly" — it's "replace the step-by-step confirmation with Claude running its own risk screening first, and only stop to ask when something fails that screening." There's an extra automated gatekeeping layer in between — not you, but not nobody watching either.
Worth remembering specifically: regardless of which approval mode you've chosen, Cowork requires your explicit permission before permanently deleting any file — you'll see a permission prompt and must select "Allow" before Claude can carry out the deletion. This rule doesn't change with the approval mode. That means even if you've switched to "Skip all approvals" and turned off the safety review entirely, deleting a file will still surface a confirmation prompt — this is one of the few hard floors that doesn't shift with mode switching.
Anthropic's documentation is also direct about a fact that's easy to overlook: whether you're on Automatically Approve or Skip All Approvals, if Claude reads malicious content partway through a task — a prompt injection — it could act on those instructions before you notice. That means the safety review built into "Automatically approve" is designed to catch actions Claude itself judges as unsafe, but if a prompt injection is crafted well enough to make Claude misjudge a malicious action as safe, that review layer offers no guarantee of catching it. The difference between the two modes is whether review happens at all, not whether prompt injection gets fully blocked either way — that's a shared weak point, not something switching modes resolves on its own.
Anthropic recommends switching to Manually Approve in a few specific situations: when a task touches sensitive files, accounts, or sites; the first time you're working with a new tool, Plugin, or site; and when mistakes would be hard to undo, like sending messages or making purchases. That means neither "Automatically approve" nor "Skip all approvals" is meant to be a fixed default — you're meant to switch dynamically based on the nature of the task. Routine, low-risk work can run on Automatically Approve to save time; the moment a task's nature changes or the risk climbs, switching back to Manually Approve for step-by-step confirmation yourself is what Anthropic actually recommends.
If you currently default to "Skip all approvals," it's worth asking yourself one question: did you pick that mode because you genuinely trust every tool, connector, file, and app involved in this particular task — or purely to save yourself a few clicks? Anthropic's own guidance on this mode is explicit: only use it when you completely trust every action, connector, file, and app involved. If the honest answer leans toward the latter, switching to "Automatically approve" barely changes what the experience feels like — tasks still run continuously without step-by-step nods — but it buys you an extra layer that evaluates risk before an action runs. That switch costs almost nothing, while the protection it buys is real, especially any time you can't guarantee that every document and every site involved in a task is entirely clean and free of malicious content.