# CellCog Cowork Guide

Connect your own computer to CellCog so agents can read, edit, and run commands in your real projects, with every action classified by risk and gated by your approval settings.

---

## What is Cowork?

Cowork (also called "Cowork on my PC") lets a CellCog agent work directly on your computer during a chat. Instead of working only in its cloud workspace, the agent can:

- Read and edit files on your machine
- Run terminal commands in your local shell
- Use the tools, SDKs, and dependencies you already have installed
- Work with your actual codebase in its real environment

**Key principle:** you stay in control. The agent classifies every command as safe, moderate, or dangerous, and your auto-approve threshold decides which of those run without asking. Everything above the threshold waits for your decision in chat.

---

## Getting Started

### Step 1: Download the Desktop App

1. Open the Cowork page at `cellcog.ai/cowork`. You can also reach it from the Cowork chip in the chat editor (the "Cowork settings" link) or from your profile page.
2. Click **Download for <your OS>**. The page detects your operating system and lists the other builds under "Also available for":
   - **macOS** (.dmg)
   - **Windows** (.exe)
   - **Linux** (.AppImage)

### Step 2: Install and Sign In

1. Install the downloaded app
2. Open CellCog Desktop
3. Sign in with your CellCog account (the same account you use on the web)
4. The app runs in the background with an icon in your menu bar or system tray

### Step 3: Verify the Connection

1. Return to the Cowork page in the web app
2. You should see **Connected** with your machine's hostname, operating system, shell, and detected tools
3. If it says **Not connected**, make sure the desktop app is running and you are signed in

---

## Using Cowork in Chats

### Enabling Cowork for a Chat

1. Start a new chat or open an existing one
2. In the message editor toolbar, click the **Cowork** chip
3. Set a **working directory**: the folder the agent will primarily work in, such as your project root. Recent directories are listed for quick reuse.
4. Send your message

The chip also shows the connection state: whether the desktop app is connected, whether it needs an update, and whether more than one desktop app is signed in with your account.

**Tip:** the working directory gives the agent your project context and is an input to how it classifies risk (see below).

### What Happens Next

When the agent needs your machine, it sends one or more commands (terminal commands, file reads, file writes, file edits). Each command is classified by risk:

1. Commands at or below your auto-approve threshold run immediately
2. Commands above it appear in the approval panel on the right side of the chat
3. Approved commands run on your machine through the desktop app, in the order the agent sent them
4. Results go back to the agent, which continues working

### Several chats at once

Different chats run on your computer in parallel: each chat gets its own lane, and commands inside one chat still run one at a time, in order. The desktop app shows one "Running on this computer" card per active chat. The **Parallel chats** setting in the desktop app's footer caps how many chats may run at the same time (default 8, from 1 to 16); chats beyond the cap wait their turn, and the app shows how many are waiting. Set it to 1 if you prefer one chat at a time. An agent whose chat is waiting behind others keeps waiting for its results instead of failing while the app is still going to run them.

---

## Approvals in Cowork

The approval panel shows each pending command with:

- **Command type**: terminal command, file read (marked "Read-only file access"), file write, or file edit
- **Threat level**: safe, moderate, or dangerous, with the agent's one-sentence reason when elevated
- **Summary**: a plain-language description of what the command does
- **Details**: the exact command, script, or file change

You can **Approve** or **Deny** each command (optionally with a reason the agent will read), or use **Approve All** / **Deny All** for the whole batch. A batch starts executing once every command in it has been decided. In a regular chat the agent waits for you as long as it takes.

Everyday Cowork examples:

| Level | Cowork examples |
|-------|-----------------|
| **Safe** | Listing files, running tests or builds, reading and editing files inside a version-controlled working directory |
| **Moderate** | Reading files outside the working directory, reading environment variables or shell history, editing files in a project with no version control and no backup |
| **Dangerous** | Installing packages, deleting files, editing shell profiles or system files, pushing to remote repositories, anything touching production |

The full model, including how AI employees handle approvals, is in the [Approvals & Safety Guide](./CellCog_Approvals_and_Safety_Guide.md).

---

## Auto-Approve Threshold

Cowork uses the same risk model as Browse my Chrome and connected Tools: the agent classifies, your threshold gates.

### Setting Your Account Default

On the Cowork page, find the **Auto-approve threshold** section and pick a level:

| Threshold | What it auto-approves |
|-----------|----------------------|
| **None** | Nothing. Every terminal command requires your approval. |
| **Safe** | Reads and edits inside your working directory when the file is git-tracked, plus side-effect-free terminal commands. This is the default. |
| **Moderate** | Also reads of files outside your working directory, modifications to non-git-tracked files, and dev-mode database operations. |
| **Dangerous** | Also writes outside your working directory without git, package installs, deploys, and production-touching commands. The most permissive setting. |

### Per-Chat Override

Each chat can override the account default. Hover the Cowork chip in the editor and click the colored dot to pick a level for **this chat** only; **Reset** returns the chat to your account default. New chats always start at the account default.

Your profile page shows all three thresholds (terminal, browser, connected app actions) side by side under **Auto-approve up to**, with links to the page where each one is changed.

---

## Working Directory and Recovery

The working directory tells the agent where your project lives, and recoverability decides how edits are classified.

- Edits **inside** a working directory that is under version control are recoverable and classified **safe**
- If the directory is not a git repository, the agent looks for a documented backup strategy in the project's `AGENTS.md`. If there is none, it asks how you back the project up and offers to record your answer there. Without a recovery story, in-directory edits are classified **moderate**.
- Reads or changes **outside** the working directory are classified higher (**moderate** or **dangerous**)
- Shell profiles and system files (for example `~/.zshrc`, `/etc/hosts`) are always **dangerous** to modify, and anything touching production is always dangerous

You can change the working directory mid-chat from the Cowork chip.

---

## Security and Privacy

### What's Protected

- **Blocked paths**: credential locations are never readable, even under auto-approve. This includes `~/.ssh`, `~/.gnupg`, `~/.aws`, `~/.kube`, cloud CLI configs, `~/.npmrc`, `~/.pypirc`, `~/.netrc`, `.env` files in your home directory, and your shell profiles.
- **Secret redaction**: command output is scanned for API keys, access tokens, private keys, and similar patterns, which are redacted before leaving your machine
- **Encryption**: all traffic between the desktop app and CellCog is encrypted in transit (TLS)
- **Session-scoped access**: the agent can only reach your machine during chats where Cowork is enabled and the desktop app is running

### Your Controls

- **Per-command approval** for anything above your threshold
- **Threshold per account and per chat**
- **Instant disconnect**: quit the desktop app to cut all access
- **Per-chat toggle**: enable Cowork only in the chats that need it
- **Working directory scope**: everything outside it is classified more strictly

### Data Handling

- File contents and command output you approve are sent to CellCog for the agent to work with, and become part of that chat's context
- Data is encrypted in transit
- The desktop app keeps a local history of executed commands on your machine and clears entries older than 90 days

---

## Desktop App Updates

- The desktop app checks for updates automatically, downloads them in the background, and installs them when it restarts
- When CellCog requires a newer version, the Cowork page and the editor chip show **Update Required**; pending commands show "Waiting for update" until the app has updated
- If an update gets stuck, quit the app completely and reopen it, or download the latest version from the Cowork page

---

## Browse my Chrome: the Browser Companion

Cowork is the foundation; Browse my Chrome extends the same desktop app to your real Chrome browser. With a small Chrome extension, your agent can use the sites you are already logged into, gated by the same approval model. Instead of a working directory on disk, the trust boundary is a cyan **"CellCog" tab group** in your Chrome window.

See the [Browse my Chrome Guide](./CellCog_Browse_my_Chrome_Guide.md) for setup. AI employees can also browse without your machine through their own [Cloud Browsers](./CellCog_Cloud_Browsers_Guide.md).

---

## Cowork with AI Employees

AI employees can use Cowork when you enable it for their chat. Because employees work autonomously, their auto-approve level is at least **Moderate** (the default) and can be raised to **Dangerous** per surface, at hire time or later. Actions above that level run only with a standing approval you have granted, or with your live approval while you are present; if you do not decide within 15 minutes the action fails and the employee's shift continues. Details are in the [Approvals & Safety Guide](./CellCog_Approvals_and_Safety_Guide.md).

---

## Troubleshooting

### Desktop App Not Connecting

1. **Verify the app is running**: check your menu bar or system tray for the CellCog icon
2. **Check sign-in**: make sure you are signed in with the same account as the web app
3. **Restart the app**: quit and reopen CellCog Desktop
4. **Check network**: make sure your machine has internet access
5. **Firewall**: make sure CellCog Desktop is not blocked

### Commands Not Executing

1. **Check the approval panel**: a batch runs only after every command in it is approved or denied
2. **Check the connection**: the Cowork page should say **Connected**
3. **Check for a second desktop app**: if CellCog Desktop is running on two computers with your account, the editor chip shows "Two desktop apps connected" and commands pause. Quit the app on the computer you are not using and they resume automatically.
4. **Check the app version**: if the chip says **Update Required**, let the app update

### "Update Required" Message

1. The desktop app downloads the update automatically
2. If it does not restart on its own, quit the app completely and reopen it
3. As a last resort, download the latest version from the Cowork page

### Agent Can't Find Tools or SDKs

Commands run in your login shell, so tools configured in your shell profile (nvm, pyenv, conda, and similar) are normally found. If a tool is missing:
1. Make sure it is installed and on your shell PATH
2. Check that it is initialized in your shell profile (`~/.zshrc` or `~/.bash_profile`)
3. Run the command yourself in a terminal to confirm it works

Each command runs as a separate process, so `cd` and environment changes do not carry over between commands.

### Working Directory Issues

- The path must exist on your machine
- Use absolute paths (`/Users/me/projects/app`, not `~/projects/app`)
- The directory must be accessible to your user account

---

## Frequently Asked Questions

### Can the agent access my machine without my permission?
No. You must install the desktop app, sign in, and enable Cowork for a chat. Within a chat, only commands at or below your threshold run without a click.

### What happens if I close the desktop app mid-session?
The agent loses access immediately and pending commands fail. Reopen the app to resume.

### Is my code sent to CellCog servers?
Files the agent reads and command output it receives are sent to CellCog so the agent can work with them, and become part of that chat's context. Data is encrypted in transit; credential paths are blocked and secrets in output are redacted.

### Can I use Cowork with multiple machines?
You can install the desktop app on several computers, but commands run only when exactly one is connected to your account. With two connected at once, commands pause until you quit one.

### Does Cowork work on all operating systems?
The Cowork page offers builds for macOS, Windows, and Linux.

### Can the agent install software on my machine?
Only if the command is approved. Installing software is classified **dangerous**, so unless your threshold is Dangerous you review it first.

### How do I completely remove Cowork access?
Quit CellCog Desktop, and optionally uninstall it. No further access is possible.

### Can other people in my organization see my machine?
No. Cowork connects your machine to your own CellCog account. Organization members cannot reach your machine through CellCog.

---

## Related Guides

- [Approvals & Safety Guide](./CellCog_Approvals_and_Safety_Guide.md)
- [Browse my Chrome Guide](./CellCog_Browse_my_Chrome_Guide.md)
- [Cloud Browsers Guide](./CellCog_Cloud_Browsers_Guide.md)
- [Getting Started Guide](./CellCog_Getting_Started.md)
- [Chat Guide](./CellCog_Chat_Guide.md)
- [Connectors Guide](./CellCog_Connectors_Guide.md)

---

Markdown alternate of https://cellcog.ai/support/cowork-guide (CellCog support guide, category: Features). All guides for agents: https://cellcog.ai/support/llms.txt. Site index: https://cellcog.ai/llms.txt. Try CellCog free, no credit card needed: https://cellcog.ai/signup
