How to set up Claude Cowork in your accounting firm: the practical guide
A practical, step-by-step walkthrough for accounting and bookkeeping firm owners setting up Claude Cowork: from choosing the right plan and settling your client-data policy to connecting the first folders and connectors. Includes the first five jobs to hand it, what to skip until later, and a pilot-to-rollout plan for the team.
Trent McLaren · 22 July 2026 · 9 min read
In this article
- Before you start: plan, cost and the security questions
- What plan you need
- Settle these three questions first
- Setup walkthrough
- The first five jobs to give it
- What to skip until later
- Rolling it out to the team
- Frequently asked questions
- What plan do I need for Claude Cowork, and what does it cost?
- Is client data safe in Cowork?
- Which integrations should an accounting firm connect first?
- How long does setup actually take?
- Is Cowork a replacement for hiring an admin?
Part of our AI in accounting coverage. See the full AI for accounting firms guide →
You've read the benefits and costs piece and decided Cowork is worth a proper trial. Good. This is the how-to: what plan to buy, what to connect, what to deliberately not connect, and the first five jobs to hand it. By the end you'll have a working setup (Cowork running against a dedicated folder, one or two safe connectors attached, and a short list of jobs it's actually doing) without having handed an AI agent the keys to your client files on day one.
One framing note before we start. Cowork is not a chatbot with a new name. It's Claude working as an agent: you give it a task, it works through files, browsers and connected apps in a session, and it comes back with finished work. That's the whole appeal, and the whole reason setup deserves more care than "sign up and go." No AI is ever going to jail for you. You're still the registered agent, the licensed CPA, the one whose name is on the engagement letter. Set it up accordingly.
Before you start: plan, cost and the security questions
What plan you need
Cowork is included on every paid Claude plan: Pro, Max, Team and Enterprise. It runs on macOS and Windows via the Claude desktop app, plus web and mobile, though tasks that need local file access or browser use require the desktop app open.
At the time of writing, Anthropic's published pricing is roughly: Pro at US$20/month (about US$17 on annual billing), Max from US$100/month for heavier usage, and Team at around US$25-30/seat monthly equivalent with premium seats available for power users. Enterprise is custom. Check current pricing before you buy: these numbers move.
Two practical notes from firms already running it. First, Cowork sessions burn dramatically more usage than chat: a Pro subscription is fine for testing, but anyone using it daily will bump into limits and want Max or a premium Team seat. Second, if you're setting this up for a firm rather than yourself, go straight to Team or Enterprise. Pro and Max are personal accounts: no central admin, no connector governance, no way to see what your staff have connected. Team gives you an admin console where owners control which connectors are enabled org-wide. For a firm handling client data, that control is not optional.
Settle these three questions first
- What's your client-data position? On Team and Enterprise plans, Anthropic's commercial terms apply to your data; on individual consumer plans, check your training-data settings in your account before you paste anything client-related. Read the current terms yourself and, if you're in the US, think about whether your engagement letters and privacy policy cover third-party processing. AU and UK firms should map this against the Privacy Act and UK GDPR respectively. This is an hour of reading that prevents a very bad conversation later.
- What folders may it touch? Anthropic's own safety guidance says it plainly: don't grant access to folders containing credentials, sensitive financial documents or personal records: create a dedicated working folder instead. That's your model. Cowork sees what you connect, nothing else.
- Who approves actions? Cowork has three permission modes: manual approval for every action, auto (Claude checks its own actions for safety), and skip. Start on manual. You can loosen later; you can't un-send an email.
Setup walkthrough
- Buy the plan and install the desktop app. Sign up at claude.ai (Team plan if it's for the firm), then install Claude Desktop on macOS or Windows. Cowork sessions run in an isolated environment on Anthropic's servers, but local file access needs the desktop app open.
- Create a dedicated working folder. Something like ~/Cowork or a scoped subfolder of your document drive. Copy work into it; don't point Cowork at the root of your client file server. This one habit does more for your risk position than anything else in this guide.
- Start your first session. In the Claude app, switch the message box from Chat to Cowork, connect your working folder when prompted, and give it a real task: "read these three PDFs and build me a comparison table" is a good first run. Watch what it does. Manual approval mode means it pauses before actions; get a feel for that rhythm.
- Add connectors deliberately. Connectors live under Settings → Connectors (admin-controlled on Team/Enterprise). Anthropic's directory now covers hundreds of tools: Xero is in there, along with Gmail, Google Drive, calendar and Slack-type tools. Start with calendar and a scratch drive folder. Note the golden rule: a connector inherits your permissions in that system. Connect Xero as a user who can see everything and Claude can see everything.
- Add one or two skills. Skills are reusable instruction packs: think of them as SOPs Claude loads for specific jobs. Browse the directory for document and spreadsheet skills first, and look at our agent templates for accounting firms for prompts and workflows you can adapt into your own.
- Write your first firm skill. Once one job works reliably, capture how you want it done (your workpaper naming convention, your file-note format) as a skill so every session does it your way. This is where Cowork stops being a toy and starts being infrastructure.
The first five jobs to give it
Pick jobs that are document-heavy, low-stakes and easy to review. Five that work in practice:
- Month-end prep. Drop last month's close checklist and this month's exports into the working folder and have Cowork build the prep pack: outstanding items list, variance summary, queries to chase. It won't reconcile the bank for you, but it kills the two hours of assembly before the real work starts.
- Workpaper summaries. "Read this workpaper file and give me a one-page summary of positions taken, open items and anything unusual" is a genuinely great reviewer's assistant, especially on jobs you're cold-reviewing.
- Meeting notes into file notes. Paste a transcript or your rough notes; get back a structured file note plus a draft follow-up email in your voice. Five minutes of review versus thirty of writing.
- Template and letter drafting. Engagement letter variants, fee-increase letters, new-client onboarding packs, position papers. Cowork drafting against your existing templates in the working folder beats a blank page every time.
- Client email triage: drafts only. Once you're comfortable, connect email read-only or forward batches into the working folder, and have Cowork categorise and draft responses for you to send. Do not give it send permissions in month one. Possibly ever.
What to skip until later
- The practice-management system. Don't connect your practice management system (Karbon, FYI, Kloud Connect, AccountKit or XPM) on day one. That's your whole client base, deadlines and correspondence in one credential. There's no verified first-party Karbon connector in Anthropic's directory at the time of writing anyway; if you get there later, do it via a scoped integration and a restricted user account.
- Write access to the ledger. The Xero connector can be genuinely useful for pulling reports and querying data, but read-only first. An agent posting journals unsupervised is how you end up starring in a conference talk for the wrong reasons.
- Anything unattended during deadline season. Scheduled, unmonitored tasks are the highest-risk mode of any agent. Earn trust on supervised work first, and know where these tools still fall over, because they do.
- Firm-wide rollout. Resist the urge to buy 15 seats in week one.
Rolling it out to the team
Weeks 1-4: pilot. Two people (one partner or manager, one senior) on two or three of the jobs above. Keep a shared doc of what worked, what didn't, and actual time saved. Real numbers, not vibes.
Week 5: policy. One page, max: what data may go in, which connectors are approved, approval mode required, and the review rule: nothing Cowork produces reaches a client without a human reading it end to end. Boring, essential, and much easier to write once the pilot has surfaced the real questions.
Weeks 6-8: training. Onboard the rest of the team on the jobs the pilot proved, with the skills you've built doing the heavy lifting on consistency. Expect a spread: some staff will run with it immediately, some will need the "watch me do it" session. That's normal: it's the same curve as every practice-tool rollout you've done, just faster. If you're still working out where agents fit in your broader stack, our AI for accounting firms hub covers the wider landscape.
Frequently asked questions
What plan do I need for Claude Cowork, and what does it cost?
Any paid Claude plan includes Cowork: Pro starts at US$20/month. But firms should use Team (roughly US$25-30/seat) or Enterprise for admin controls and connector governance, and heavy daily users will want Max or a premium seat because Cowork consumes usage far faster than chat. Verify current pricing at claude.com before committing.
Is client data safe in Cowork?
Safe-ish, if you set it up properly, which is the point of this guide. Cowork only accesses folders and connectors you explicitly grant, sessions run in an isolated environment, and commercial plans carry Anthropic's business data terms. The residual risk is mostly self-inflicted: over-broad folder access, over-permissioned connectors, and skipping human review. Use a dedicated working folder, manual approval mode, and read the current terms against your engagement letters.
Which integrations should an accounting firm connect first?
Calendar and a scoped document folder first, then Xero read-only once you're comfortable, then email in draft-only mode. Leave your practice-management system, ledger write access and anything with send/post permissions until the team has months of supervised use behind it.
How long does setup actually take?
The technical setup (account, desktop app, working folder, first session) is an afternoon. The parts that matter take longer: settling your data policy (a few hours of reading and one partner conversation) and the pilot (about a month). Budget six to eight weeks from purchase to confident team-wide use.
Is Cowork a replacement for hiring an admin?
No, and firms that frame it that way set themselves up for disappointment. It's closer to giving everyone on the team a very fast assistant for document work: drafting, summarising, assembling, tidying. It doesn't answer phones, chase clients with judgment, or take responsibility for anything. What it does do is claw back the hours your qualified staff currently spend doing admin-shaped work, which is usually worth more than an admin salary anyway. The maths is in our benefits and costs breakdown.
AIClaudePractice Technology