Home / Blog / Anthropic Details How It Contains Claude Across Web, Code,…
Tech News

Anthropic Details How It Contains Claude Across Web, Code, and Cowork

By Dillip Chowdary • Jul 22, 2026 • Source: InfoQ

Anthropic detailed the containment architectures it uses for Claude across its Web, Code, and Cowork products, as reported by InfoQ. The company frames agent safety as a systems problem: control comes from hard limits on what an agent can touch, not from asking the model to behave.

The core argument is that effective containment rests on deterministic limits on the agent’s filesystem, network, and execution environment. Permission prompts and model-level safeguards are treated as secondary. Anthropic’s write-up focuses on how those hard boundaries are drawn for each product surface and what happens when work crosses from one controlled domain into another.

It pays special attention to failures at trust boundaries and along permitted egress paths. Those are the places where an agent is still inside an allowed channel yet can still cause harm—for example by reading or writing more than intended, or by using approved network access in an unexpected way. The analysis treats those paths as first-class design targets rather than rare edge cases.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

For engineers building agents, the practical claim is architectural: put the agent in a constrained runtime first, then layer product UX and model instructions on top. If the filesystem, network, and execution scope are not bounded by construction, prompts and approval dialogs will not close the gap under real tool use.

That stance sits against a market where many agent products still lean on permission UIs, tool allowlists in the model, or soft policy text. Anthropic is arguing that competitive safety claims should be judged by the isolation model of Web, Code, and Cowork-style surfaces—what the process can open, reach, and run—rather than by how often the model is asked to confirm.

What to watch next is whether other agent platforms publish comparable containment models: explicit filesystem and network envelopes, execution sandbox rules, and postmortems of trust-boundary and egress failures. Builders evaluating Claude or peer agents should ask for those controls in product docs and runbooks, not only for safety copy around prompts.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →