❮ Back to all resources
Webinar

Agents Don’t Ask Twice: Governing High-Risk Actions in Claude Code & Cowork

See how to govern the high-risk actions Claude Code and Cowork can take across local files, MCP tools, and third-party apps without blocking approved work.

Claude agents become more useful when they can work in GitHub, Snowflake, Salesforce, Slack, and other business systems. That access may come through service accounts, OAuth grants, MCP servers, local files, and user permissions, often giving the agent more reach than the task requires.

A harmful action does not require harmful intent. An ambiguous instruction or overly broad folder grant can lead an agent to read sensitive configuration files, expose data, or take a destructive action while doing what it believes it was asked to do.

In this 20-minute session, Scott Young and Viet Tran examine the limits of Anthropic’s native controls, the Claude Code and Cowork actions security teams need to govern, and the policies that can stop risky behavior without disrupting allowed workflows.

Watch to learn:

  • Where Anthropic’s native controls stop when Claude Code and Cowork interact with local files, MCP tools, and third-party apps
  • Which actions require tighter governance, from reading environment files and broad folders to running destructive database commands
  • How to enforce policies that alert, require user approval, or block specific actions while allowed agent workflows continue

Speakers

Scott Young, Obsidian Security

Viet Tran, Obsidian Security