See how to govern the high-risk actions Claude Code and Cowork can take across local files, MCP tools, and third-party apps without blocking approved work.
Claude agents become more useful when they can work in GitHub, Snowflake, Salesforce, Slack, and other business systems. That access may come through service accounts, OAuth grants, MCP servers, local files, and user permissions, often giving the agent more reach than the task requires.
A harmful action does not require harmful intent. An ambiguous instruction or overly broad folder grant can lead an agent to read sensitive configuration files, expose data, or take a destructive action while doing what it believes it was asked to do.
In this 20-minute session, Scott Young and Viet Tran examine the limits of Anthropic’s native controls, the Claude Code and Cowork actions security teams need to govern, and the policies that can stop risky behavior without disrupting allowed workflows.
Watch to learn:
Speakers
Scott Young, Obsidian Security
Viet Tran, Obsidian Security