Cowork plans before it touches anything
The defining safety property: Cowork does not modify files until you approve a plan. Send a goal, get back a numbered, file-by-file plan, redirect or approve, then it executes. This is the same idea as Claude Code's Plan Mode but baked into the entire experience instead of an opt-in toggle.
The approval flow is graduated by risk. Reading files inside the working folder — automatic. Creating new files — automatic. Modifying existing files — asks before the first modification. Deleting files — always asks, every time. Network access (WebFetch) — only if you've enabled the relevant connector. Computer Use (driving applications) — only if Computer Use is on.
Iteration is the second loop. After Cowork delivers, you stay in the same session and refine: "trim the executive summary to 100 words," "add a confidence-level column," "rewrite this section in plain language." Cowork reads its own output and revises in place. Multi-round refinement is the normal mode of work.