By Thomas Echezabal, AI Automation Coach, thomasknows.ai
A small business can use Claude's built-in browser to visit approved websites, collect information, fill draft forms, and return a reviewable result inside Claude Cowork. Start with a low-risk recurring task, name the sites Claude may use, require a visible source for every fact, and keep sending, submitting, purchasing, deleting, and other consequential actions behind your approval.
This guide explains how the browser works, how it differs from Claude in Chrome, and how to test one workflow without handing over your whole browser. The feature is useful because it removes repetitive clicking. It is risky for the same reason.
Key Takeaways
- Claude Cowork now has a browser inside the Claude Desktop app for paid plans as the rollout reaches each account.
- The built-in browser is separate from your normal browser, tabs, bookmarks, and history.
- Claude in Chrome works in the browser session you already use; the built-in browser is better for handing off a complete web task.
- The desktop app must remain open and online when the built-in browser is used from Claude on web or mobile.
- Start with public research or read-only reporting before using imported logins or write actions.
- Treat the open web as untrusted input. A page can contain instructions designed to manipulate a browser agent.
- A successful workflow leaves evidence: source links, dates, a reviewable output, and no unapproved live action.
What Is Claude's Built-In Browser?
Claude's built-in browser is a separate browser that Claude Cowork can open, read, click, type in, and use to complete web-based steps while you watch from the task panel. It lives inside the Claude Desktop app and does not require the Claude in Chrome extension.
Anthropic announced the feature on August 26, 2026 and says it is rolling out to Cowork on macOS, Windows, and Linux beta for Pro, Max, and Team plans. Enterprise owners can control access. Availability can still depend on the rollout, plan, organization policy, and current desktop version.
The browser opens next to the Cowork task. Claude can move through pages, follow links, enter text, and gather information without taking over the tabs you are using for your own work. According to Anthropic's built-in browser documentation, it has the same browsing capabilities and safeguards as Claude in Chrome but runs in its own environment.
That separation is the main benefit. You can hand Claude a website task while your regular browser remains available. It is not a reason to grant broad access. A separate browser can still reach sensitive information after you import a login or open an authenticated site.
Built-In Browser or Claude in Chrome?
Use the built-in browser when you want Claude to handle a complete website task in its own browser. Use Claude in Chrome when you want help with the page already open in your signed-in Chrome session. Both can read, click, type, and navigate, but they begin from different contexts.
| Choice | Best for | What it can see by default | Main limit |
|---|---|---|---|
| Built-in browser | Handing off a bounded web task while you keep working | Its own new browser session | The desktop app must stay open and sites may require a separate login |
| Claude in Chrome | Working with the tab and login you already have open | Your active Chrome page and allowed browser context | It touches the browser session you use for daily work |
| Standard web search | Finding and summarizing public information | Search results and public pages | It does not operate a live site or complete form steps |
If you already use Claude in Chrome, Cowork may continue to prefer it until you change the browser setting. Open Claude Desktop > Settings > Cowork > Preferred browser to choose the built-in browser.
Anthropic's official demo below shows Claude reading pages, pulling dashboard data, and completing browser steps through Claude in Chrome. The built-in browser uses the same browser-control capabilities, but in Claude's separate side-panel browser.
Video: Let Claude handle work in your browser, from Anthropic
Which Browser Tasks Should a Small Business Try First?
The best first task uses trusted sites, produces a result you can inspect, and stops before an action that is difficult to undo. Public vendor research, read-only dashboard reporting, and draft preparation are stronger starting points than outreach submissions, customer-record changes, purchases, or financial work.
I applied a four-part screen to five common browser tasks. This is original analysis based on Anthropic's current browser and Cowork safety documentation.
| Browser task | Trusted source? | Reversible action? | Visible evidence? | First-test decision |
|---|---|---|---|---|
| Compare three public vendor pricing pages | Yes, when you name the vendors | Yes, no live change | Source URL and checked date | Start here |
| Pull last week's numbers from a dashboard | Yes, if it is your approved account | Yes, when the task is read-only | Metric name, date range, dashboard page | Test after login setup |
| Prepare an intake form without submitting | Yes, if you own or approve the form | Yes, while it remains a draft | Completed fields and source document | Good second workflow |
| Update customer records in a CRM | Yes, but the data is sensitive | Sometimes | Before-and-after record log | Require manual approval |
| Make a purchase or manage banking | High stakes even on a trusted site | Often difficult to undo | A receipt appears after the risk | Do not delegate |
A task can fail this screen in more than one way. Public pages can contain manipulated or stale information. A trusted portal can still expose sensitive data. A reversible click can still create a customer-facing mistake if Claude selects the wrong record.
The first workflow should make the evidence easy to inspect. If Claude compares vendor prices, require the exact page, plan name, amount, billing period, and date checked. If it pulls a weekly metric, require the dashboard section and date range. A summary without traceable sources is not finished work.
How to Set Up the Built-In Browser
Set up the browser by updating Claude Desktop, selecting the built-in browser under Cowork settings, and running one task that names the allowed sites, expected output, and approval boundary. Do not import every login before the first test.
Choose the task before opening the browser
Write the finished result in one sentence. For example: "Compare the current monthly prices and cancellation terms for these three approved scheduling tools, then return a table with source links and the date checked."
That sentence gives Claude a bounded outcome. "Research scheduling tools" does not. It leaves the number of sites, stopping point, evidence, and comparison standard undefined.
Select the browser in Claude Desktop
Open the current Claude Desktop app. Go to Settings, choose Cowork, and find Preferred browser. Select Built-in browser.
If the option is missing, check that the desktop app is current and that the feature has reached your plan and account. Team and Enterprise access may also depend on an organization owner. Do not describe a missing rollout as a prompt problem.
Give Claude a source boundary
Name the sites Claude may use. For a public research task, provide the exact domains or starting URLs. For an account task, name the approved portal and the page or report Claude should open.
A useful instruction has four parts:
- Task: the exact result you need.
- Sources: the approved sites, pages, and date range.
- Evidence: the links, labels, numbers, and dates Claude must return.
- Stop point: the action Claude must not take without approval.
For example:
Visit the pricing pages for the three scheduling tools below. Compare the entry-level paid plan, monthly price, annual-billing price, cancellation terms, and one limitation relevant to a five-person service business. Use only the official sites I provide. Return a table with the source URL and date checked for every row. If a price or term is unclear, mark it unclear. Do not start a trial, create an account, accept cookies beyond what is required to view the page, or submit any form.
Watch the first run
Keep the task visible. Claude's Cowork safety guidance recommends monitoring for unexpected sites or actions. Stop the task if it opens a source you did not approve, requests unnecessary access, or begins work outside the result you defined.
The goal of the first run is not speed. It is learning where the workflow breaks. Record the source it missed, the page it misunderstood, the login step it could not complete, and any place where it tried to widen the task.
Verify the result against the source
Open at least one source yourself and compare the result. Check dates, prices, account names, and any statement that will affect a customer or purchase. If the result is wrong, narrow the instruction before adding more access.
A workflow is ready to repeat when it produces the same evidence on two real examples and stops at the stated boundary. One successful demonstration is not enough for a live customer process.
How Should You Handle Logins?
Begin without imported logins, then add one approved site only when the workflow needs account data and the read-only result already works. The built-in browser starts as a separate session. Anthropic supports bringing logins from some browsers, but an imported login gives Claude access to whatever that account can reach.
Use a dedicated business account when the service allows it. Prefer a role with the minimum access needed for the task. If a dashboard can provide read-only reporting access, do not use an administrator account.
Before adding a login, answer four questions:
- What exact information must Claude read?
- Can the account send, publish, delete, purchase, or change records?
- What action will remain behind manual approval?
- How will you review the task history and reverse a mistake?
Do not use the built-in browser for banking, healthcare portals, payroll changes, password management, or other work where a mistaken click can expose sensitive data or move money. Anthropic specifically warns that browser agents face prompt-injection risk and that its safeguards reduce risk without removing it.
What Is Prompt Injection?
Prompt injection is hidden or visible content on a page that tries to make Claude follow the page's instructions instead of yours. A browser agent is exposed because reading the page is part of its job.
A malicious page could tell the agent to ignore your request, reveal information, visit another site, or perform an unrelated action. The wording may be placed in page text, a document, an email, or another source Claude reads during the task.
Risk rises when two conditions appear together: Claude can read untrusted content, and Claude can take consequential actions. Reduce one or both.
- Limit the task to approved sites.
- Keep the first workflows read-only.
- Do not mix public browsing with sensitive local files or broad account access.
- Require manual approval before sending, submitting, deleting, purchasing, or changing a live record.
- Stop when Claude leaves the expected path.
The built-in browser's separate environment protects your normal tabs from casual interference. It does not make untrusted websites safe.
A Weekly Dashboard Workflow
A useful recurring dashboard workflow gathers named metrics, records their source and date range, and returns a draft report without changing the account. It is a good second workflow after a public research task because the owner can verify every number against the dashboard.
Try this process:
- Give Claude the approved dashboard URL and report name.
- Define the exact date range and metrics.
- Require the page or section where each metric appeared.
- Ask for a draft summary that separates facts from interpretation.
- Keep exports, emails, and account changes behind approval.
A local service business might ask for leads, booked appointments, cost per lead, and conversion rate from the prior week. A retailer might ask for orders, average order value, returns, and top products. The browser task should collect what the owner already uses, not invent a new scorecard.
Measure the workflow before keeping it. Record the manual time for one report, then record the full Claude-assisted time including login setup, corrections, and review. Keep it only if the verified result saves time.
When the Built-In Browser Is the Wrong Tool
Do not use browser control when a connector, export, or direct file gives Claude a narrower and more reliable source. Browser automation is flexible, but that flexibility also creates more failure points.
Use a connector when Claude needs structured access to a supported inbox, calendar, or document system. The Claude Connectors guide explains how to choose read, prepare, and live-action permissions. Use an uploaded file when the work is contained to one document. Use a Project when the same instructions and approved references should carry across several conversations.
Use the browser when the information lives in a web interface with no better supported path, or when the task requires several page steps that would otherwise be manual. Do not use it merely because watching an agent click is impressive.
If you need a broader map of Chat, Projects, Connectors, Skills, Cowork, and browser control, start with the complete Claude guide for small businesses.
Troubleshooting Claude's Built-In Browser
Most failures come from rollout, desktop availability, login state, site compatibility, or a task that is too broad. Check those conditions before rewriting the prompt repeatedly.
- The built-in browser option is missing. Update Claude Desktop, confirm the paid plan and organization policy, then wait for the gradual rollout if the account is still ineligible.
- The browser works on desktop but not from mobile. Keep Claude Desktop open and online. The browser runs through the desktop app even when you steer the task elsewhere.
- Claude cannot reach an account page. Confirm the login in the built-in browser and check whether the site blocks automated access.
- Claude opens too many sites. Provide exact domains and state that any other source requires approval.
- The result has numbers without evidence. Require the page label, date range, source URL, and a screenshot or cited row when the site allows it.
- Claude tries to submit a form. Put the stop condition in the initial task and switch to manual approval for the run.
- The site contains sensitive data. Stop. Choose a narrower account, export the minimum data, or use a supported connector instead.
Website terms still apply. A site may restrict automated access even when Claude can technically open it. Check the service's rules before turning a manual process into a repeated browser task.
Frequently Asked Questions
Is Claude's built-in browser available on the free plan?
No. Anthropic says the built-in browser is rolling out in Cowork for paid Pro, Max, and Team plans, plus Enterprise plans where an owner enables it. Availability can differ by account, organization policy, operating system, and rollout timing.
Does Claude's built-in browser use my Chrome history and tabs?
No. It runs as a separate browser inside Claude Desktop. It does not use your normal tabs or history by default. Claude in Chrome is the option that works in your existing Chrome session.
Can Claude log in to business websites?
Yes, after you sign in or import a supported login, but that grants the browser access to the account. Start with one approved site and the narrowest available role. Do not import broad administrator or financial access for a first workflow.
Can Claude submit forms for me?
The browser can click, type, and fill forms. Keep the final submit behind manual approval until the exact form, source data, and failure behavior have passed repeated tests. For customer, legal, financial, or public submissions, human review should remain the default.
Does the built-in browser work when my computer is off?
No. Anthropic says the desktop app must be open and online for Cowork to use the built-in browser, including when you steer the task from web or mobile.
Is the built-in browser safer than Claude in Chrome?
It separates the task from your normal browser session, which reduces accidental exposure to unrelated tabs and history. Both browser options use the same safeguards and both face prompt-injection and live-action risks. Safety still depends on the sites, logins, data, permissions, and approval rules you provide.
Start with One Site and One Finished Result
The built-in browser can remove the work between a request and a usable result: opening the portal, finding the right page, copying the numbers, and organizing the evidence. That only saves time when the task is bounded enough to verify.
Choose one trusted site. Ask for one finished output. Require the source and date. Keep live action behind your approval. Then measure whether the whole workflow, including review, beat the manual process.
If you want help selecting a first browser task, setting the permission boundary, and testing it against your real business tools, book a 1:1 coaching consultation. I will help you build one useful workflow and verify where Claude must stop.
One free AI workflow, every Tuesday
Each week I break down what changed in AI and walk you through setting up one workflow, step by step. Subscribers also get first notice when my academy opens.
Built for non-technical business owners. Free to join, unsubscribe anytime.

About the Author
Thomas Echezabal helps small business owners automate their busywork with AI and get real hours back each week. He has worked with small businesses his entire career, including 200+ clients on Fiverr.



