Domain 2File Management, Data Processing & Output
Dedicated Workspace
TL;DR
A purpose-built folder containing only the files you want Claude to work with, following the principle of least privilege.
Definition
A purpose-built folder containing only the files you want Claude to work with, following the principle of least privilege. Instead of pointing Cowork at your entire Documents folder, you create a folder like "Q2-Expenses-Processing" and copy only the relevant files into it. This limits the blast radius of any security incident.
Exam Context
The "dedicated workspace" best practice appears in nearly every security question. The correct answer almost always involves creating a scoped folder rather than granting broad access.