Connect your own computer to CellCog so agents can read, edit, and run commands in your real projects, with every action classified by risk and gated by your approval settings.
Cowork (also called "Cowork on my PC") lets a CellCog agent work directly on your computer during a chat. Instead of working only in its cloud workspace, the agent can:
Key principle: you stay in control. The agent classifies every command as safe, moderate, or dangerous, and your auto-approve threshold decides which of those run without asking. Everything above the threshold waits for your decision in chat.
cellcog.ai/cowork. You can also reach it from the Cowork chip in the chat editor (the "Cowork settings" link) or from your profile page.The chip also shows the connection state: whether the desktop app is connected, whether it needs an update, and whether more than one desktop app is signed in with your account.
Tip: the working directory gives the agent your project context and is an input to how it classifies risk (see below).
When the agent needs your machine, it sends one or more commands (terminal commands, file reads, file writes, file edits). Each command is classified by risk:
Different chats run on your computer in parallel: each chat gets its own lane, and commands inside one chat still run one at a time, in order. The desktop app shows one "Running on this computer" card per active chat. The Parallel chats setting in the desktop app's footer caps how many chats may run at the same time (default 8, from 1 to 16); chats beyond the cap wait their turn, and the app shows how many are waiting. Set it to 1 if you prefer one chat at a time. An agent whose chat is waiting behind others keeps waiting for its results instead of failing while the app is still going to run them.
The approval panel shows each pending command with:
You can Approve or Deny each command (optionally with a reason the agent will read), or use Approve All / Deny All for the whole batch. A batch starts executing once every command in it has been decided. In a regular chat the agent waits for you as long as it takes.
Everyday Cowork examples:
| Level | Cowork examples |
|---|---|
| Safe | Listing files, running tests or builds, reading and editing files inside a version-controlled working directory |
| Moderate | Reading files outside the working directory, reading environment variables or shell history, editing files in a project with no version control and no backup |
| Dangerous | Installing packages, deleting files, editing shell profiles or system files, pushing to remote repositories, anything touching production |
The full model, including how AI employees handle approvals, is in the Approvals & Safety Guide.
Cowork uses the same risk model as Browse my Chrome and connected Tools: the agent classifies, your threshold gates.
On the Cowork page, find the Auto-approve threshold section and pick a level:
| Threshold | What it auto-approves |
|---|---|
| None | Nothing. Every terminal command requires your approval. |
| Safe | Reads and edits inside your working directory when the file is git-tracked, plus side-effect-free terminal commands. This is the default. |
| Moderate | Also reads of files outside your working directory, modifications to non-git-tracked files, and dev-mode database operations. |
| Dangerous | Also writes outside your working directory without git, package installs, deploys, and production-touching commands. The most permissive setting. |
Each chat can override the account default. Hover the Cowork chip in the editor and click the colored dot to pick a level for this chat only; Reset returns the chat to your account default. New chats always start at the account default.
Your profile page shows all three thresholds (terminal, browser, connected app actions) side by side under Auto-approve up to, with links to the page where each one is changed.
The working directory tells the agent where your project lives, and recoverability decides how edits are classified.
AGENTS.md. If there is none, it asks how you back the project up and offers to record your answer there. Without a recovery story, in-directory edits are classified moderate.~/.zshrc, /etc/hosts) are always dangerous to modify, and anything touching production is always dangerousYou can change the working directory mid-chat from the Cowork chip.
~/.ssh, ~/.gnupg, ~/.aws, ~/.kube, cloud CLI configs, ~/.npmrc, ~/.pypirc, ~/.netrc, .env files in your home directory, and your shell profiles.Cowork is the foundation; Browse my Chrome extends the same desktop app to your real Chrome browser. With a small Chrome extension, your agent can use the sites you are already logged into, gated by the same approval model. Instead of a working directory on disk, the trust boundary is a cyan "CellCog" tab group in your Chrome window.
See the Browse my Chrome Guide for setup. AI employees can also browse without your machine through their own Cloud Browsers.
AI employees can use Cowork when you enable it for their chat. Because employees work autonomously, their auto-approve level is at least Moderate (the default) and can be raised to Dangerous per surface, at hire time or later. Actions above that level run only with a standing approval you have granted, or with your live approval while you are present; if you do not decide within 15 minutes the action fails and the employee's shift continues. Details are in the Approvals & Safety Guide.
Commands run in your login shell, so tools configured in your shell profile (nvm, pyenv, conda, and similar) are normally found. If a tool is missing:
~/.zshrc or ~/.bash_profile)Each command runs as a separate process, so cd and environment changes do not carry over between commands.
/Users/me/projects/app, not ~/projects/app)No. You must install the desktop app, sign in, and enable Cowork for a chat. Within a chat, only commands at or below your threshold run without a click.
The agent loses access immediately and pending commands fail. Reopen the app to resume.
Files the agent reads and command output it receives are sent to CellCog so the agent can work with them, and become part of that chat's context. Data is encrypted in transit; credential paths are blocked and secrets in output are redacted.
You can install the desktop app on several computers, but commands run only when exactly one is connected to your account. With two connected at once, commands pause until you quit one.
The Cowork page offers builds for macOS, Windows, and Linux.
Only if the command is approved. Installing software is classified dangerous, so unless your threshold is Dangerous you review it first.
Quit CellCog Desktop, and optionally uninstall it. No further access is possible.
No. Cowork connects your machine to your own CellCog account. Organization members cannot reach your machine through CellCog.