,

Plugins and connectors for office work

11 min read
Featured image: Plugins and connectors

You finally have a clean working folder. Receipts rename themselves. The expense workbook opens with real formulas. Then someone says, “Install the finance plugin and connect your mail. Claude can file the report for you.” That sentence jumps three rungs on the risk ladder in one breath. Plugins and connectors are how Cowork leaves the island of a single folder and touches the systems where work actually lives: mail, drive, calendar, tickets, CRM. They are also how a wrong click becomes a message you cannot unsend.

This is Part 4 of Claude Cowork tutorial. Part 3 stayed inside folders, docs, sheets, and decks. Here we map the outer layer for office work: plugins that bundle skills, connectors, and sub-agents; connectors with permissions; and higher-risk surfaces like browser and computer use. The goal is a complexity ladder so you add power only when a folder-only task is not enough. If you still need product orientation, use the Claude product map. Everyday chat habits live in Learn Claude from scratch. The software cousin of this story (MCP, plugins, tools in a repo) is Claude Code tutorial, especially its plugins-and-tools part.

What you’ll learn

  • What a Cowork plugin is in plain English (bundle, not magic)
  • How skills, connectors, and sub-agents fit inside a plugin
  • What connectors change when mail, drive, or calendar enter the task
  • Why permissions and admin policy matter more than marketplace screenshots
  • Where browser and computer use sit on the risk scale
  • A complexity ladder: folders first, then instructions, connectors, plugins, browser/computer
  • A practice plan that does not turn your laptop into a connector zoo

Names, marketplaces, and admin screens move. Treat this as a mental model. Confirm live steps in Anthropic’s Help Center (plugins, connectors, Cowork safety) before you set org policy.

Three boxes: plugins, connectors, higher-risk surfaces

People mash “we integrated Claude” into one phrase. Separate the boxes and the product gets quieter.

Plugins bundle skills agents and connectors; connectors reach mail drive calendar; browser and computer use add extra risk
BoxPlain EnglishTypical office example
PluginA package that ships playbooks and wiring togetherA “finance” or “sales” plugin with skills + suggested connectors
ConnectorA pipe to a system of record outside the folderGoogle Drive, Microsoft 365 mail/calendar, Slack, Jira
Browser / computer useClaude acts in UI when no clean API path existsClick through a web app, drive the desktop

Folder access is still the foundation from Part 3. Plugins do not replace a clear recipe (goal, inputs, constraints, format, done check). They package habits and access so you are not reinventing the same stack every Monday.

Rule of thumb: If the file is already in a working folder, stay on the folder. Reach for a connector when the system of record is mail, drive, calendar, or a ticket tool. Reach for browser or computer use only when the job truly has no safer path.

What a plugin bundles

In Cowork, a plugin customizes how Claude works for a role, team, or company. Anthropic’s docs describe plugins as packages that can combine skills, connectors, and sub-agents (and related wiring) into one install. Think “onboarding kit,” not “new brain.”

PieceWhat it isOffice analogy
SkillsReusable playbooks for a job shapeThe checklist your best ops hire follows for weekly reporting
ConnectorsConfigured access to external systemsKeys to the shared drive and the team inbox, with scopes
Sub-agentsBounded helper roles for slices of workOne person gathers sources while another drafts the brief
Other configCommands, defaults, packaging metadataThe labeled binder so everyone finds the same process

Skills can exist without a plugin. You might keep a personal skill for “status memo voice.” Plugins matter when a team wants the same bundle on many machines, or when Anthropic or your org ships a curated set (for example knowledge-work plugins aimed at functions like finance, sales, or legal). Team and Enterprise admins can manage marketplaces, installation defaults, and group access. That is policy work, not a side quest for one curious analyst.

What to read before you install

  • Which skills ship in the bundle?
  • Which connectors does it expect or enable?
  • Does it want write access or only read?
  • Who maintains it when auth breaks: you, IT, or a vendor?
  • Can you uninstall it, or did admin mark it required?

If you cannot answer those, you are not installing a productivity boost. You are adopting an unknown dependency.

Connectors: mail, drive, calendar, and friends

A connector is how Claude reaches a system outside the working folder. Common office targets: email, cloud drive, calendar, chat, tickets, sometimes CRM or doc suites. On Claude, connectors often show up in Customize or settings areas, with permission prompts during tasks. Exact labels move; the permission idea does not.

What changes when a connector is on

  • Blast radius leaves the folder. A bad summary in a local doc is annoying. A bad send from your mailbox is an incident.
  • Identity is yours. Actions happen as the connected account, with whatever that account can already do.
  • Read and write are different planets. “Search my drive for the Q2 brief” is not the same as “update the shared sheet and email finance.”
  • Org policy may override your clicks. Team and Enterprise admins can restrict connectors, require approvals, or gate write tools.

Microsoft 365 is a useful concrete case. Anthropic has expanded the Microsoft 365 connector beyond search so Claude can draft and send mail, manage calendar events, and create or update files in OneDrive and SharePoint when write tools are enabled and admins consent. That is powerful for real office loops. It is also why “just connect M365” is a governance decision, not a personal gadget toggle.

Permission habits that travel well

HabitWhy
Start read-only when the product allows itLearn the data shape before write tools exist
Prefer draft over sendHuman eyes on outbound messages
Name the mailbox or drive scope in the taskAvoid “search everything I can see”
Keep a deny list of systemsPayroll, production admin, customer production DBs
Log what you connected for the teamFuture you will not remember last quarter’s experiment

Cowork permission modes (Manual, Auto, Skip, with product naming that can shift) change how often Claude pauses before connector actions. Part 5 of this series goes deeper on autonomy. For now: new connectors plus Skip is how people earn exciting stories and uncomfortable Slack threads.

Browser and computer use: higher rung, higher care

Some tools never offer a clean connector. The work lives in a clunky web UI, a vendor portal, or a desktop app that only understands clicks. That is why browser control (for example Claude in Chrome) and computer use features exist: Claude can navigate interfaces, not only call APIs.

Higher capability, higher risk:

  • UI flows change; agents mis-click
  • Prompt injection and hostile pages are real concerns on the open web
  • You may grant vision into whatever is on screen
  • Parallel tabs and long workflows are harder to audit than a single spreadsheet diff

Use browser or computer use when the alternative is you doing 40 brittle clicks, and when the stakes of a wrong click are acceptable or heavily supervised. Do not start there on day one because a demo video looked smooth. Anthropic’s own Cowork safety materials exist for a reason; read them before you unattended-run anything that can move money or messages.

The complexity ladder

Add one rung when you are stuck, not when you are bored. This is the same philosophy as the Claude Code ladder (plain task → instructions → skills → MCP → plugins), translated for office work.

Complexity ladder: folder task, then global instructions, connector, plugin, then browser or computer use
RungYou add…When it is enoughWhen to climb
1. Folder taskWorking folder + clear recipeOrganize, rename, local expense sheet, local deckSource of truth is not on disk
2. Global / folder instructionsStanding tone, no-delete defaults, project lawsSame mistakes keep recurring in pure session textYou need live data from mail/drive/calendar
3. ConnectorOne system, least privilege“Find the latest brief in Drive and draft locally”You reinvent the same skill+connector stack weekly
4. PluginBundled skills + connectors + sub-agentsTeam-standard workflow, org marketplace packageNo API/connector path; UI is the only door
5. Browser / computer useUI actuationSupervised portal work, brittle internal toolsRarely: only with eyes on and a rollback plan

Rung 1 example

Connected folder only. “Build expense.xlsx from these PDFs with formulas. No deletes.” Done. No plugin required.

Rung 2 example

Global instructions: “Default currency USD. Never email. Prefer tables. Flag low-confidence OCR.” Folder instructions for Client-Acme: “Client name is Acme Health; never use internal codename Raven.”

Rung 3 example

Drive connector, read-heavy: “Find the latest QBR folder for Acme, copy the metrics CSV into my working folder, then build a local summary sheet. Do not modify the Drive originals.”

Rung 4 example

Your company installs a curated “customer ops” plugin: skills for ticket tone, a connector profile for the helpdesk, a sub-agent pattern for “gather then draft.” New hires install one package instead of five tribal screenshots.

Rung 5 example

A vendor portal has no API and no connector. You watch Claude fill a form in the browser for a non-production account, with Manual approvals, while you sit on the session. You do not start here for payroll.

Worked example: climb only as far as you must

Goal: weekly internal status for Project Harbor.

Attempt at rung 1: Notes and CSVs already live in Harbor/weekly. You run a folder task: summary doc + five-slide PPTX. It works. Stop.

Blocker: The metrics CSV is always outdated because the source of truth is a Drive file marketing updates daily.

Climb to rung 3: Connect Drive read access. Task becomes: “Download the latest harbor-metrics.csv from the Harbor shared folder into Harbor/weekly/inbox, then rebuild the summary and deck locally. Do not edit the Drive file. Do not send email.”

Blocker later: Three teammates each invent different summary skills and different connector settings.

Climb to rung 4: Ops ships a small internal plugin: Harbor status skill, Drive connector defaults, sub-agent split for “metrics vs narrative.” Everyone installs the same bundle. Still no auto-send.

What you never did: Browser-control into the production billing console to “just grab the number.” That number belongs in a proper export or a governed dashboard.

Team and admin reality (short version)

On Team and Enterprise plans, owners can manage plugin marketplaces, set install defaults (including required plugins), and control who sees what. Skills and Cowork itself may need to be enabled before marketplaces matter. Connector write tools can require admin consent (the Microsoft 365 write expansion is a clear example). Compliance and monitoring features also differ by plan and product surface; Cowork has had important caveats around what appears in which audit pipelines. If you are not an admin, assume your personal laptop habits are not the company architecture.

Part 7 of this series returns to team and enterprise notes in more depth. Here, one sentence is enough: install less than you can; document what you did; prefer org-approved sources.

How this maps to Claude Code (without mixing jobs)

If you already studied plugins in the Claude Code tutorial, the rhyme is intentional:

IdeaClaude Code worldCowork office world
Local work firstRepo + built-in toolsWorking folder + file outputs
Standing lawsCLAUDE.md / AGENTS.mdGlobal + folder instructions
External systemsMCP serversConnectors (mail, drive, calendar…)
DistributionPlugins packaging skills/hooks/MCPPlugins packaging skills/connectors/sub-agents
UI fallbackBrowser tools in some setupsBrowser / computer use

Same family of ideas. Different artifacts. Do not open Cowork to refactor a monorepo, and do not open Claude Code to rename 200 receipt PDFs unless you enjoy theatrical overkill.

Common mistakes

Installing the zoo on day one

Four plugins, six connectors, browser control “just in case.” Every task gets noisier and harder to debug. Start at rung 1. Add one capability when a real task blocks.

Confusing “connected” with “governed”

OAuth success is not a data classification review. A connector that can read your whole drive includes the folder you forgot was sensitive.

Write scopes for convenience

“Send the email too” saves three minutes until the draft is wrong. Prefer: draft in a local doc or as a draft message you send yourself.

Treating plugins as unreviewed code

A plugin can bring skills and connector expectations you did not audit. Prefer official or org marketplace sources. Read the bundle contents. Pin or note versions when your process allows it.

Skipping the folder recipe after connectors exist

Connectors do not excuse vague goals. “Handle my inbox” is not a task. “Label newsletters from the last 7 days into a local triage.md; do not reply or delete” is a task.

How to practice this week

  1. Run one pure folder task from Part 3 with zero connectors. Confirm you still can.
  2. Write three global instruction lines you actually want on every Cowork run (include “no send” if that is your default).
  3. Enable one read-oriented connector you already use at work (or a personal sandbox account). Complete one task that copies or summarizes into a local folder.
  4. Inspect permissions: what can it read? Can it write? Who approved it?
  5. Browse available plugins without installing a pile. Pick at most one official or org-approved plugin that matches a weekly job. Read what it bundles first.
  6. Do not enable browser or computer use until you have a supervised, low-stakes exercise planned.
  7. Write a five-line “team note” for yourself: connected systems, plugin list, and what is forbidden.

Need the chat foundation again? Learn Claude. Choosing surfaces? Claude product map. Building software agents instead? Claude Code tutorial.

What’s next

Part 5 covers autonomy: when to watch versus walk away, what permission modes are for, and how scheduled tasks change the supervision story. Plugins and connectors make that part more important, not less.

Quick recap

  • Plugins bundle skills, connectors, and sub-agents into one package.
  • Connectors reach mail, drive, calendar, and other systems of record; permissions define blast radius.
  • Browser and computer use are higher-risk UI paths; start without them.
  • Climb the ladder only when stuck: folder → instructions → connector → plugin → browser/computer.
  • Prefer read and draft over send and delete; prefer org-approved sources.
  • A clear task recipe still beats a pile of integrations.

Sources

Research and further reading used for this article: