Can Team or Enterprise plan users get early access to this feature somehow?
There's currently no official path to unlock it early. Anthropic's documentation explicitly limits this feature to Pro and Max plans — Team and Enterprise plans have no access at all right now. This isn't a hidden setting waiting to be manually turned on; it's a plan-tier limitation, unrelated to account configuration or usage habits.
If your organization is on a Team or Enterprise plan, the more practical approach is watching for future official announcements about whether this expands to those plans, rather than trying to unlock it early through any unofficial route — especially given that this particular feature involves direct control over your computer screen, enabling an untested feature that hasn't been officially tuned for that plan tier through unofficial means carries higher risk than it would for an ordinary feature.
In background mode, if Claude is operating one app while I open another window to do my own work, could that cause interference or operation errors between us?
Anthropic's design accounts for this scenario — Claude works in a background window and, in principle, doesn't take over whatever window you're currently using, so you can keep working in your own window. Worth noting, though: the documentation's phrasing that it "generally waits" if you're mid-typing uses "generally," not "always," meaning this avoidance mechanism isn't a 100% guarantee against any timing overlap — it just avoids the moment you're actively typing in most cases.
If the work you're doing genuinely requires precise timing or uninterrupted operation (a sequence of continuous keystrokes that can't be broken, say), the more conservative approach is not running Claude in the background during that specific window when you genuinely need uninterrupted focus, rather than fully trusting that the "generally waits" mechanism applies to every situation.
Anthropic recommends not granting access to banking, healthcare, or government apps. If I use an app not explicitly named in those categories but that still contains sensitive information (an internal HR system, say), does this recommendation still apply?
Yes, and Anthropic's own wording uses an open-ended phrase like "including but not limited to," meaning banking, healthcare, and government are examples of high-risk categories, not an exhaustive list. The more accurate standard for judging whether an app should be excluded from computer use authorization isn't "was it explicitly named by Anthropic" — it's "how severe would the consequences be if this app's content got mishandled or misread." An internal HR system might contain employee salaries, personal information, and performance review records — information no less sensitive than what's found in the categories Anthropic explicitly named.
The more solid approach in practice is treating Anthropic's three named categories as a floor of what must be excluded at minimum, not the only scope that needs excluding — and separately taking stock of which other apps on your computer sit at a comparable sensitivity level. Anything meeting the test of "content leaking or being mishandled would cause real damage" is worth proactively excluding from authorization scope, held to the same standard as banking, healthcare, and government apps.
If I follow Anthropic's advice and start with simple tasks, how do I judge when it's safe to hand over more complex, multi-step work?
Anthropic's documentation doesn't give a clear time threshold or number of successful runs, meaning this judgment is inherently subjective and needs to be calibrated by you based on what you actually observe. A more practical basis for the judgment is whether Claude's performance on simple tasks consistently matches your expectations — did it take any action beyond the scope of what you instructed, did it stop to ask in places you didn't expect, how large was the gap between the result and what you wanted. The patterns you observe during these simple tasks help build an understanding of its actual capability boundaries, rather than just checking whether it "succeeded."
Even if performance on simple tasks has been consistently solid, Anthropic's advice to "make sure your prompts are specific and carefully tailored" only becomes more important as you hand over more complex, multi-step work — it isn't something that can be relaxed as trust accumulates. Every additional step in a complex task adds one more opportunity for ambiguity to creep into the instructions, so it's worth raising how specific your instructions are in step with increasing task complexity, rather than building trust first and letting precision slide afterward.
Anthropic announced on September 2, 2026, that Claude Cowork and Claude Code gained background computer use — on macOS 15 or later, Claude can now click, type, and open apps in a background window to complete desktop tasks you've assigned, while you keep using your computer for something else, without having to hand over your entire screen. This is a meaningful upgrade to computer use: earlier versions required giving Claude your full screen to work with, and there's now an option that doesn't interrupt what you're doing. It's currently limited to Pro and Max plans — Team and Enterprise plans don't have this feature yet.
Anthropic's documentation is explicit: on macOS 15 and later, Claude works in background windows so you can keep using your computer while it runs. Claude doesn't take over your pointer or keyboard, and it generally waits if you're in the middle of typing. Working in the background is the default on macOS 15 and later; if you'd rather watch Claude actually operate the screen, you can go into settings and change "when Claude requests access to an app" to "full control," switching back to the mode where your screen gets taken over. The first time in each session that Claude needs the full screen, it still asks for your permission before taking over.
One design detail worth noting: screen control sits relatively far down the list when Claude decides which tool to reach for. If an MCP Server, a Bash command, a native connector, or the browser can accomplish the same thing, Claude prioritizes those channels; only when there's genuinely no other way to reach a particular app — legacy desktop software, an internal tool with no automation surface at all — does it fall back to operating the screen directly. That means background computer use fills a specific gap: work that has no path in other than "click and type the way a person would" — not a replacement for the more precise, more stable connectors or command-line tools that already exist.
This is the line from the announcement most worth taking seriously. Anthropic's documentation states plainly that these guardrails are part of how Claude is trained and instructed, but they aren't absolute, and shouldn't be relied on as a substitute for blocking access to sensitive apps. The documentation goes further with concrete advice: don't grant computer use permission access to sensitive apps like banking, healthcare, or government; start with simple tasks like research or organizing rather than handing it a complex multi-step workflow right away; make sure your prompts are specific and carefully tailored to avoid Claude doing things you didn't intend. That's not boilerplate legal language — it draws a clear line: the safeguards reduce risk, but they're probabilistic in nature, not a guarantee.
Computer use carries a different kind of risk than Cowork's usual file reads/writes or connector-based data access. File operations go through permission checks; code execution runs in an isolated environment. Computer use, by contrast, runs directly on your actual desktop, and its reach is bounded by whichever apps you've already approved access to — meaning once an app is authorized, what Claude can do within that app is closer to "what a person actually sitting at your computer could do" than to something confined within a security sandbox. That's also why Anthropic specifically emphasizes that computer use's trust boundary is different from its other tools, and needs to be treated with a different degree of caution.
This feature currently only supports macOS 15 and later, and is limited to Pro and Max plans — Team and Enterprise plans can't use it yet. The desktop app supports both macOS and Windows, but this specific background-window mechanism is currently macOS-only; if you use Claude Code via the command line, computer use there is also currently macOS-only. Your computer needs to stay powered on and the Claude Desktop app needs to remain open while it runs — consistent with the logic of any other Cowork task that needs a local environment.
If you have a piece of work stuck on "this system is GUI-only, no API, no CLI, the only way in is clicking around like a person," background computer use fills exactly that gap, and without tying up your entire afternoon on a machine you can't otherwise use. But before turning this on, it's worth honestly taking stock of the apps installed on your computer — particularly anything touching money, medical records, or government filings. Not because Claude will necessarily go near them, but because Anthropic itself says the trained-in guardrails aren't foolproof. The genuinely reliable line of defense is excluding those apps from the granted scope yourself upfront, rather than trusting after the fact that Claude will know on its own what to avoid. Starting with simple, redoable tasks, rather than handing it a multi-step workflow with little room for error right out of the gate, matches the order of priorities Anthropic's own guidance actually recommends.