Unknown unknown #1: First, Build a Fence · Part 1 · Desktop app

One Folder, Every Time: Where You Start Decides What It Can Reach

Unknown unknown #1 — by default, an AI assistant can reach everything on your computer that you can. So the most important thing to do, before you start using it, is to fence it in.

A note on scope: My computer is a Mac, and this version of the post is written for the Claude Code desktop app — the application window you download and run, rather than the command line in the Terminal. (I’ve got a companion version for Terminal, or CLI, users.) Throughout this series, the folder names and the exact wording you will see on screen describe macOS. The ideas apply just as well on Windows; the specifics — where things live, and what the messages say — differ.

Using the Terminal instead? Read the Terminal (CLI) version →

When you sit down to use an AI assistant like Claude Code, the most consequential choice you’ll make is one that is probably an unknown unknown for you. If you’re interested in trying out Claude Code and you’re a non-coder, you’re probably going to use the desktop Claude app (rather than the Terminal app and its user-unfriendly Command Line Interface). And if you want to protect your privacy and security, you need to make a really important decision before you start working with Claude Code in this app.

You’re probably already used to having conversations through the web interface of Claude. That’s the free version of Claude Chat that we’ve all had access to for a while now. But with an Enterprise account, you’ve now got access to the more powerful tools Claude Code and Claude Cowork. If you go to the upper left corner of the Claude app you can choose among Chat, Code, and Cowork. If you click on Code, which lets you do much more in-depth work than you can with Chat, you arrive at a moment when you should make a simple, high-impact choice that can protect your privacy and security.

To see why this choice matters, it helps to know how your computer is arranged — something most of us who are not computing people have never had reason to examine much. Before Claude Code, I used four or five folders on my computer: Documents, where all my real work goes; Applications, when I need an app that’s not in my dock; Downloads, where files land when I pull them from my email or a website; and the Desktop, where I put things I need to do something to RIGHT NOW. I also use my synced Box folder, to access shared folders in the cloud and to back up my work. But I never once thought about the larger architecture of my computer.

Since starting to use Claude Code, though, I’ve learned about the important role played by my home folder. In the Mac Finder window, your home folder has a little house icon, and it’s usually named after you. It’s the top of your computer architecture, the umbrella under which everything else on your computer is nested: Documents, Downloads, Desktop, your photos and music, your cloud-synced Box and Dropbox, the hidden settings and keys your programs rely on, and more. If you’re like me, you probably never go to your home folder. And that is exactly the problem when you dive into using Claude Code: when you launch Claude Code without thinking about where you are launching it from, it defaults into your home folder. In other words, Claude Code enters your computer at the very top of its architecture, able to reach Documents, Downloads, the Desktop, your cloud folders, and everything underneath.

It’s true that the Claude Code desktop app has a very quiet signal (a whisper, really) meant to draw your attention to the importance of making this choice. Look just above the dialog box that’s all set to receive your Claude Code instructions. You’ll see two dropdown boxes: one has a computer icon and the other has a folder icon. The computer icon probably says “Local” next to it, and we can just leave that one aside for now. It’s the folder icon that is the really important one. In fact, it is where the single most important privacy decision in the app is located.

I’m not sure what folder is displayed in your app when you first open it, but whatever is there is telling you: “this is where Claude Code enters your computer.” If the folder icon indicates your home folder, then when you type your first instructions into the Claude Code dialog box, you’ve given the assistant the run of nearly everything on your computer: Documents, Downloads, the Desktop, your cloud folders, your saved settings and keys, and everything underneath. And there’s no red-tinted warning message that will pop up to draw your attention to what you are doing.

So the most important thing you need to do before working with Claude Code is to be deliberate about the folder you point the AI assistant at: to fence it into one folder instead of giving it the run of your whole computer.

Step one: make one folder for your AI-assisted work, and point the desktop app at it every time

Open Finder, click on your home folder, and make a new folder for your AI-assisted work. If you’re using Claude Code, you probably want to avoid naming the folder “Claude,” because other files that are part of Claude Code already use that name in some version. You can pick the name you want, but a good option could be AIWorkspace: it’s one word, no spaces (which keeps it simple to type), and self-explanatory. Once you’ve made the folder, you can even drag it into the “Favorites” section of your Finder sidebar, so it’s easy to locate. The most important thing, though, is what you do each time you start work: when you open the desktop app and you see that folder dropdown box, make sure it’s showing AIWorkspace and not something else.

The desktop app does not lock in a default working folder for you; you choose it at the start of each session (a folder you have used before is easy to pick again). That makes choosing the right folder a small, deliberate step rather than something the app remembers and enforces on your behalf. The first few times, I had to remind myself to check which folder I was pointing the app at. But it soon became an easy habit. And if the only thing you ever do to protect your privacy and security is to confine Claude Code to a single folder, you’ve actually taken a strong protective step.

However. If your computer or cloud folders hold sensitive material, you want to take two additional protective steps. As I’ll discuss in the next post, these steps create a boundary for Claude Code that does not depend on your memory (i.e., choosing the right folder in the dialog each time) or on Claude Code’s good behavior. Read on to the next post to learn about these other two steps. And as a reminder: if you’re using Claude Code from the Terminal instead, the same dangers apply! Read the CLI version of these posts to learn how to protect yourself there, too.

One last caution to carry in the meantime: the desktop app also has powers that reach past any folder —it can connect to your accounts, or act on your screen or in a web browser — and no fence you draw around a folder confines them. Leave those switched off until a later post takes them up.

Next in the series
Part 2 — Two Kinds of Fences You Need: A Sandbox for Commands, Permissions for What Files It Can Touch
Coming soon · desktop app version