The short answer
Claude Cowork has no separate price. It is included on every paid Claude plan. Pro is $17 per month billed annually ($200 up front) or $20 monthly. Max starts at $100 per month. Team is $20 per seat per month billed annually ($25 monthly) for a standard seat and $100 annually ($125 monthly) for a premium seat, and Anthropic documents the Team plan as being for teams of 2 to 150. Enterprise is $20 per seat plus usage billed at API rates, so the seat is the smaller half of the bill. The two things to settle before you roll it out are that Cowork is all or nothing on Team plans, and that local session history cannot be centrally deleted by admins.
Last updated: September 2026. Every figure read from claude.com/pricing and Anthropic's own help center and product announcements on September 1, 2026.
Anthropic priced Claude Cowork in a way that makes it easy to buy and harder to budget. There is no Cowork SKU, no per-agent fee and no add-on line. If you already pay for Claude, you already have it. That removes the usual procurement conversation entirely, which is genuinely good, and it replaces it with a different one about usage, governance and what your admins can actually switch off.
This page covers what Cowork costs on each plan, where the plan boundaries sit, and the admin settings that decide how it behaves in a company. It is written for someone deciding whether Cowork covers the job they were about to buy a separate tool for, so the last section is an honest comparison against dedicated workplace search rather than a sales pitch.
How much does Claude Cowork cost?
Nothing on top of your Claude subscription. Cowork is bundled into every paid plan, so the question is really which Claude plan you need. Anthropic publishes real numbers for everything except Enterprise usage, which is unusual in this category and worth crediting. Here is the full table as published on September 1, 2026.
| Plan | Published price | Cowork included | The catch worth knowing |
|---|---|---|---|
| Free | $0 | No | Cowork is documented as available on paid plans only |
| Pro | $17 per month with the annual discount, billed as $200 up front. $20 if billed monthly | Yes | Individual plan. No admin console, no org policy, no central visibility |
| Max | From $100 per month. Choose 5x or 20x more usage than Pro | Yes | Still an individual plan. Buying Max for a team gives you no governance |
| Team, standard seat | $20 per seat per month billed annually. $25 if billed monthly | Yes | Documented as "For teams of 2 to 150". Cowork controls are all or nothing |
| Team, premium seat | $100 per seat per month billed annually. $125 if billed monthly | Yes | Buys 5x the usage of a standard seat, not extra features |
| Enterprise | $20 per seat plus usage at API rates. Anthropic states usage cost scales with model and task | Yes | The seat is not the bill. Only Enterprise gets role based access control for Cowork |
Two rows on that table deserve more than a cell. The Team plan carries a documented ceiling of 150 people, which puts it in the same bracket as several products in this category that quietly stop at a headcount rather than a price. The Enterprise row is the more consequential one, because it is the only plan here where the published number does not tell you what you will pay.
Why is Enterprise priced at $20 a seat when nobody quotes that?
Because the seat is only the access fee. Anthropic's pricing page describes Enterprise as a seat price plus usage at API rates, with usage scaling by model and by task. A seat entitles a person to use Claude. What they then do with it is metered against the same token rates a developer pays, and an agent running a multi step task consumes far more than someone asking a question in chat.
That matters for Cowork specifically, because Cowork is the surface designed to consume the most. It runs multi step work across files and connectors rather than answering a single question, so a heavy Cowork user and a light chat user on identical $20 seats can produce very different invoices. If you are modelling this, model the usage, not the headcount, and ask your account team for a consumption estimate based on the workflows you actually intend to run.
Anthropic has clearly anticipated the problem. Alongside the general availability announcement on April 9, 2026, it shipped group spend limits so admins can set per team budgets from the console, plus usage analytics in the admin dashboard and an Analytics API that reports per user Cowork activity, skill and connector invocations, and daily, weekly and monthly active users. Those are the controls of a product that knows its costs are variable. Use them from day one rather than after the first surprising month.
What can admins actually control?
More than most people expect, but the depth of control depends entirely on whether you are on Team or Enterprise. This is the single biggest functional difference between the two plans for Cowork, and it is not a pricing difference.
Anthropic's help center is direct about it: the Cowork toggle is organization wide, so either all members have access or none do. On Enterprise plans, admins who need per team control can use groups and custom roles to selectively enable Cowork or grant the capability to run Cowork in the cloud to specific users or teams. Team plans do not have access to those controls, so Cowork stays all or nothing.
If your intention was to pilot Cowork with the operations team before letting it near legal or finance, that plan requires Enterprise. On Team you are choosing between everybody and nobody.
The controls that do exist across both plans are worth listing, because several are off by default and several are on:
- Cowork itself is on by default. Owners disable it under Organization settings, Cowork.
- Running sessions in the cloud is a separate toggle. It is on by default on Team and off by default on Enterprise, where an owner must turn it on and then grant the capability through custom roles.
- Automatically approve mode is on by default, so members can let Claude act without per step approval unless you turn it off.
- Always allow for connector tools is off by default, which means write capable connector tools need approval on every task. Turning it on is a deliberate loosening.
- Per tool connector permissions let admins allow reads while blocking writes, applied org wide from the admin console.
- OpenTelemetry streaming to a SIEM such as Splunk or Cribl is available on Team and Enterprise, covering tool calls, file access and whether each action was approved manually or automatically. Anthropic notes plainly that it does not replace audit logging for compliance purposes.
What changes on September 10, 2026?
The built in browser in Cowork switches from off by default to on by default for Enterprise plans on September 10, 2026, unless an admin has already turned it off. On Team plans it is already on by default. This is a live deadline rather than a roadmap item, and it changes the security posture of an agent that can already read your files.
The reason to care is the one Anthropic states itself. Cowork carries what the help center calls unique risks due to its agentic nature and internet access, and it says the risk of prompt injection attacks is non zero despite model training and content classifiers. An agent with file access and a browser is a broader surface than an agent with file access alone. There is also a specific gap worth reading twice: network egress permissions do not apply to the web fetch or web search tools, or to MCP connectors, because web fetch runs server side.
None of that makes Cowork unsafe to deploy. It makes the default worth an explicit decision before the tenth rather than after. If your security review has not covered browser use, turn it off now and turn it on when the review is done.
Where does Cowork data live, and can admins delete it?
Cloud sessions are saved to the member's Claude account and are covered by the Compliance API. Local sessions are stored on the user's own computer, and Anthropic states this data is not subject to its standard data retention policies and cannot be centrally managed or exported by admins. Enterprise admins can retrieve local session content through the Compliance API, but the documentation says deletion endpoints for local sessions are not available yet.
For most teams this is a footnote. For anyone operating under a records retention schedule or a legal hold process, it is the paragraph that governs whether Cowork can be approved at all, and it is the kind of detail that does not appear in pricing comparisons. Ask about it during procurement, because "we can retrieve it but not delete it" is a specific and answerable question.
Is Claude Cowork an enterprise search tool?
No, and treating it as one is where the evaluation usually goes wrong. Cowork is an agent that does multi step work using the sources a person connects. Enterprise search is an index over everything the company holds, scoped per person at query time. They overlap on the demo and diverge in production.
The distinction is architectural. Connectors in Cowork use a two gate model: an admin enables a connector across the organization, then each user individually authorizes their own account. Claude then inherits that person's permissions from the source system, which is exactly the right security behaviour. The consequence is that coverage is per person and opt in. Someone who has connected Google Drive and Slack gets answers from Drive and Slack. Someone who never finished the setup gets answers from nothing, and neither of them can tell you what exists in the company that they have not connected.
That is a fine model for doing work and a poor one for finding things. Anthropic's own examples make the intended job clear: Zapier connected Cowork to a database, Slack and Jira and got back engineering bottleneck analyses and a prioritized roadmap; Jamf turned a seven facet performance review into a 45 minute guided self evaluation; the venture firm Airtree built a board preparation workflow pulling from a portfolio company's Drive, Slack updates and competitor news. Those are tasks, not lookups. Anthropic also reports that the vast majority of Cowork usage comes from outside engineering teams, which fits: this is a tool for the work that surrounds someone's core job. A board prep workflow of that kind still depends on somebody tracking what competitors announce in the first place, because an agent can only reason over sources it has been pointed at.
Where dedicated workplace search earns its place is the question with no known starting point. "What did we agree with this customer about the renewal date" has an answer sitting in a thread the person asking has never seen, in a tool they may not have connected, written by someone who left. Answering that needs a permission aware index across the company's systems, maintained centrally, that returns a cited answer scoped to what the person asking is allowed to see. That is a different product, and it is the one we build.
In practice a lot of companies will run both, and that is a reasonable outcome rather than a failure to decide. The mistake is buying one expecting the other. If your users ask questions, you need search. If they hand over tasks, you need an agent. Most organizations discover they do both, in roughly a nine to one ratio in favour of questions.
How does the price compare to the rest of the category?
Favourably, with a caveat. At $20 a seat on Team, Cowork lands at the bottom of the range for anything in this space, and it includes chat and Claude Code in the same subscription. Microsoft 365 Copilot is a $30 add on that requires a base plan underneath it, making the honest seat $69 on E3. Dropbox Dash is $15 for teams up to 100 users and $35 above that. Glean publishes no price at all.
The closest comparison is OpenAI, which prices the same way at the entry point and diverges sharply above it. ChatGPT Business is also $20 a seat billed annually, but it stops at 200 paid seats, and OpenAI states support cannot raise that limit, so growth forces you into a quote-only Enterprise contract. Anthropic's Team ceiling of 150 works the same way. Both are covered in ChatGPT Enterprise pricing and what crossing the 200 seat cap costs.
The caveat is that these are not the same purchase. The per seat products above are priced for unlimited use of a search index; Enterprise Cowork is priced per seat plus consumption. A cheap seat with a variable meter behind it can end up costing more than an expensive seat with none, and which way it lands depends entirely on how heavily your team uses agentic workflows. Run the numbers on your own expected usage before treating $20 as the comparison figure.
Should you buy it?
If you already pay for Claude, there is nothing to buy and the only real decisions are governance ones. Set the group spend limits, decide the built in browser question before September 10, choose whether automatic approval mode stays available, and confirm your retention obligations against the local session storage limitation. Those four take an afternoon and prevent every common problem with this rollout.
If you are choosing between Cowork and a workplace search tool, the honest test is what your people actually type. Count a week of questions in your busiest internal help channel. If most of them are requests to produce something, an agent is the right purchase. If most are requests to find something that already exists somewhere in the company, an index is, and no amount of per user connector setup will substitute for one.
For the wider shortlist, enterprise search tools compares sixteen products on coverage, citations and published price, and unified search explains the category itself. On pricing specifically, Microsoft Copilot pricing untangles the add on and the 300 user cap, Gemini Enterprise pricing covers the editions and the 25 seat self serve cap, Coveo alternatives documents a plan that entitles you to pick three cloud connectors, and Glean pricing explains what can and cannot be said about a vendor that publishes nothing. If seat thresholds are what you are really shopping for, best enterprise search software for teams over 100 users collects every documented one in the category, and permission aware AI search covers the access control model that separates an index from an agent.