One read of Claude Documentationclaude-docs-20261006T030712Z
2 pages moved out of 262 read.
Pages moved
2
significant first
Pages read
262
in this capture
Captured
03:07 UTC
Corpus hash
2d468160f7f5
corpus-hash
What this read moved
1-2 of 2cowork/hipaa-setup Changed · +5 / -5 lines
from line 52
5252
5353### Allow network access for Claude Desktop
5454
55Allow the hosts in this table through your proxy and firewall, over HTTPS on port 443. The table lists the hosts that the tasks on this page depend on, and leaves out the rest.
55Allow the Anthropic hosts listed in [Desktop network access requirements](https://code.claude.com/docs/en/desktop#network-access-requirements) through your proxy and firewall. Claude Desktop reaches them over HTTPS on port 443. The table shows what Claude Desktop uses three of those hosts for. The setup on this page depends on all three.
5656
5757| Host | Needed for |
5858| :- | :- |
from line 60
6060| `api.anthropic.com` | Claude API requests, update checks, and the status that tells Claude Desktop the HIPAA configuration is on |
6161| `downloads.claude.ai` | The virtual machine image that Cowork runs shell commands in, the Claude Code binary, and app updates |
6262
63[Desktop network access requirements](https://code.claude.com/docs/en/desktop#network-access-requirements) lists the Anthropic hosts to allow for Claude Desktop.
64
6563### Deploy the Claude Desktop policy
6664
6765A Claude Desktop policy is a set of settings that your device management tool installs on each computer, as a configuration profile on macOS or as registry values on Windows. You can use one to restrict sign-in to your organization, turn off local MCP servers and desktop extensions, and keep session content out of [Cowork monitoring](/docs/cowork/monitoring) events.
from line 179
181179* **Domain allowlist**: the Owner selects a preset list of domains. With the HIPAA configuration applied, the **All domains** option is unavailable
182180* **Additional allowed domains**: the Owner adds each domain your organization needs
183181
182If **All domains** is still selected when your organization applies the HIPAA configuration, the VM reaches only `anthropic.com` and `claude.com` hosts, plus your OpenTelemetry collector if Cowork monitoring is set up. Entries in **Additional allowed domains** have no effect. To avoid or undo this, ask the Owner to select a different **Domain allowlist** option.
183
184184### Turn off web search in Cowork
185185
186186Web search in Cowork follows your organization's web search setting. Applying the HIPAA configuration doesn't change it. If web search is on and your organization's own policy forbids it, turn it off at one of these levels:
from line 254
254254
255255| Location | What it holds | Deleted automatically |
256256| :- | :- | :- |
257| Task folders in `local-agent-mode-sessions`, in the Claude Desktop data folder | One folder per Cowork task, with the task's transcript, uploaded files, and outputs | Yes, [after `cleanupPeriodDays`](#when-claude-desktop-deletes-cowork-tasks), except for the background sessions that Dispatch creates |
257| Task folders in `local-agent-mode-sessions`, in the Claude Desktop data folder | One folder per Cowork task, with the task's transcript, uploaded files, and outputs | Yes, [after `cleanupPeriodDays`](#when-claude-desktop-deletes-cowork-tasks), with one exception |
258258| Everything else in `local-agent-mode-sessions`, in the Claude Desktop data folder | Data that Cowork keeps between tasks, such as memory and plugins | No |
259259| `vm_bundles`, in the Claude Desktop data folder | The disk images of the virtual machine that runs shell commands | No |
260260| The Cowork files folder, `~/Claude` by default | Artifacts, scheduled tasks, and project files | No |
from line 270
270270
271271If your organization also uses [server-managed settings](https://code.claude.com/docs/en/server-managed-settings), have an Owner set `cleanupPeriodDays` there too. Claude Desktop reads server-managed settings for this check, and [uses one managed source at a time](https://code.claude.com/docs/en/managed-settings#how-claude-code-combines-managed-sources).
272272
273With the HIPAA configuration applied, Claude Desktop deletes Cowork tasks that have been inactive for longer than `cleanupPeriodDays`, including starred and archived ones. Running or opening a task counts as activity.
273With the HIPAA configuration applied, Claude Desktop deletes Cowork tasks that have been inactive for longer than `cleanupPeriodDays`, including starred and archived ones. Running or opening a task counts as activity. Task folders for background sessions that Dispatch created before your organization applied the HIPAA configuration stay until you delete them.
274274
275275Claude Desktop checks for tasks to delete after it starts, and every six hours while it stays open. The check needs all of these conditions:
276276
cowork/monitoring Changed · +10 / -4 lines
from line 44
4444
4545| `otlpContentCapture` on the device | Content that events carry |
4646| - | - |
47| Not set, on a first-party deployment | User prompt text, model response text, and tool inputs |
47| Not set, on a first-party deployment | User prompt text, model response text, and the [`toolDetails` content](#security-and-privacy) |
4848| Not set, on a [third-party deployment](/docs/third-party/claude-desktop/overview) | No content. Events carry metadata only |
4949| Set to a list of [categories](/docs/third-party/claude-desktop/telemetry#content-capture) | The content in the listed categories. Listing `userPrompts` also includes model response text |
5050| Set to an empty list, `[]` | No content. Events carry metadata only |
5151
52Metadata includes `workspace.host_paths` and, on first-party deployments, `user.email`. The key doesn't control either one. See [Security and privacy](#security-and-privacy).
53
5254### Event correlation
5355
5456When a user submits a prompt, Cowork may make multiple API calls and run several tools. The `prompt.id` attribute links all events back to the single prompt that triggered them.
from line 75
7375| `user.account_id` | Account ID in tagged format matching Anthropic admin APIs (for example, `user_01BWBeN28...`) |
7476| `user.id` | Anonymous device/installation identifier |
7577| `user.email` | User email |
76| `workspace.host_paths` | Host workspace directories selected in the desktop app (string array) |
78| `workspace.host_paths` | Paths of the folders the user connected to the task (string array) |
7779| `terminal.type` | Terminal type (`non-interactive` for Cowork) |
7880
7981<Note>
from line 246
244246## Security and privacy
245247
246248* Events are only exported when an admin configures the OTLP endpoint
247* Which content events carry is set per device by the [`otlpContentCapture`](#content-capture) key: `userPrompts` for user prompt text, `assistantResponses` for model response text, and `toolDetails` for the `tool_input` attribute (file paths, URLs, search patterns, and other arguments)
249* The [`otlpContentCapture`](#content-capture) key on each device sets which content events carry. Each category you list in the key adds its content. The [full category list](/docs/third-party/claude-desktop/telemetry#content-capture) has two more than these three:
250 * `userPrompts`: user prompt text
251 * `assistantResponses`: model response text
252 * `toolDetails`: the arguments a tool was called with, in `tool_input` and `tool_parameters`, such as shell commands, file paths, URLs, and search patterns. It also covers the text of a failed tool's error message, in `error` on the [tool result event](#tool-result-event)
248253* On Claude Desktop version 1.17377 or later, events that carry user prompt text also carry model response text, even when the key doesn't list `assistantResponses`
249* On Claude Desktop version 1.17377 or later, when `otlpContentCapture` isn't set on a device in a first-party deployment, events carry user prompt text, model response text, and tool inputs. To export metadata only, set the key to an empty list, `[]`
254* On Claude Desktop version 1.17377 or later, when `otlpContentCapture` isn't set on a device in a first-party deployment, events carry user prompt text, model response text, and the `toolDetails` content. To export metadata only, set the key to an empty list, `[]`
255* Metadata includes `workspace.host_paths`, the paths of the folders a user connects to a task. `otlpContentCapture` doesn't control this attribute, so events carry the paths even when the key is `[]`. If folder names can be sensitive, configure your telemetry backend to filter or redact it
250256* On first-party deployments, `user.email` is always included in event attributes, so configure your telemetry backend to filter or redact it if this is a concern
251257* On third-party deployments, `user.email` is absent; the export identifies users with the `enduser.id` resource attribute, controlled by the [`endUserAttribution`](/docs/third-party/claude-desktop/configuration#enduserattribution) setting
252258