Domain 1Cowork Foundations & Agentic Architecture
Computer Use Boundary
TL;DR
The distinction between tasks running inside the sandboxed VM (file processing, data analysis) and tasks running outside it via Computer Use (screen interaction, mouse/keyboard control).
Definition
The distinction between tasks running inside the sandboxed VM (file processing, data analysis) and tasks running outside it via Computer Use (screen interaction, mouse/keyboard control). Computer Use operates on your actual desktop with direct access to applications, representing a fundamentally different risk level that requires separate per-application permissions.
Exam Context
This boundary is tested in security questions. Know that most Cowork tasks run inside the VM, but Computer Use steps outside it — and that this changes the threat surface entirely.