Claude Cowork for insurance brokerages: secure client files and E&O-safe drafting for Canadian brokers

Tags:

Download PDF (533 KB)
PDF version, ready to print or share with your team.

Trusted byToronto law firmsHamilton manufacturersVancouver clinicsGTA accounting firmsOntario non-profitsBritish Columbia professional services

Principal brokers are asking whether Claude Cowork can take the submission and renewal grind off their producers without exposing client files. According to Statistics Canada, finance and insurance firms lead AI use at 40.4%, the highest rate of any industry. These are sector-level figures, not Cowork or firm-level adoption figures. The duty to protect client information stays with the brokerage.

Mike Pearlstein, CISSP, MSc Computer Science (AI), founder of Fusion Computing, which has secured IT for Canadian financial and insurance firms across Toronto, Hamilton, and Metro Vancouver since 2012.

Key takeaways

  • A brokerage can use Claude Cowork on a Team or Enterprise plan with access scoped to one client folder and a written policy.
  • Submission prep, renewal summaries, and claims correspondence drafts are strong fits. A licensed broker reviews anything that states coverage.
  • Unreviewed AI-drafted coverage advice is an errors and omissions exposure. The review step is the control, not a courtesy.
  • Cowork keeps local-session history on the user’s own computer, so the firm builds its own record of AI-assisted work. For RIBO oversight and E&O defence, you build that record yourself.

Plan a Safe Cowork Pilot

Can insurance brokerages use Claude Cowork with client files?

Yes, an insurance brokerage can use Claude Cowork on a Team or Enterprise plan, with access scoped to one client’s working folder and a written usage policy. RIBO holds Ontario brokers to standards of professional conduct and competence, and PIPEDA binds the brokerage on client data, so the duty never moves to the software. On the business plans, your content is not used to train Anthropic’s models by default.

What a brokerage controls is the scope: which client folders the agent opens, which plan governs the data, and who reviews the work before it reaches a client or an insurer. On the business tiers, Anthropic’s privacy commitments keep that data out of model training.

It’s the same secure-adoption logic from the pillar guide on using Claude Cowork securely in your business, applied to a brokerage, and it sits beside the parallel guides for wealth management firms and financial services under their own regulators.

What does Claude Cowork actually do for an insurance brokerage?

Claude Cowork completes multi-step office work rather than answering a single question. Per Anthropic’s Cowork documentation, the agent works across your own files and apps on the desktop, so the practical jobs are submission packages for insurers, renewal comparison summaries, first drafts of claims correspondence, certificate request handling, and cleaning up exported client lists. Each output is a draft for a licensed broker to review.

Here’s how those jobs map to the work, with the guardrail that keeps each one safe. Fusion Computing walks brokerages through this before any pilot, the same way we scope any AI services engagement.

Book a 30-minute call to scope Claude Cowork for your brokerage safely →

Task What to test The guardrail
Submission prep Assembles applications and loss runs into a clean package for markets Scope to one client folder; a broker reviews
Renewal summaries Compares expiring and renewal terms into a plain-English table A licensed broker verifies every coverage statement
Claims correspondence Drafts acknowledgment and status letters from the file Draft only; nothing goes out unreviewed
Certificate requests Drafts certificates and cover notes from policy details Issued through your broker management system, not the agent
Client-list cleanup Deduplicates and categorizes exported contact and policy lists Work on exports in the scoped folder, never the live system

Treat these as pilot hypotheses to validate in your own tenant, not vendor-guaranteed capabilities. Anthropic documents a subset of them directly; the rest are workflows to test before a firm relies on them.

How do the confidentiality and E&O guardrails work?

According to Anthropic’s deployment guidance, the core guardrail is least privilege: scope Cowork to one client’s working folder, never the whole book of business. A renewal summary that misstates a limit or an exclusion is an errors and omissions claim waiting for a loss, so a licensed broker verifies anything that states coverage. Cowork runs in an isolated environment on Anthropic’s servers for remote sessions, or in an isolated virtual machine on the member’s device for local sessions, but prompts still reach Anthropic, so scope limits what can be exposed.

The first thing I check is scope. When a brokerage points the agent at a full book export, a single task can read every insured’s file. Scope it to the active client and the file-exposure risk drops sharply, though prompt-injection, connector and web-access risk remain.

Field note. The first thing I change is access. I’ve seen a CSR hand an agent a full book-of-business export to answer one renewal question. We scoped it to the single client folder, and the workflow that felt reckless became routine. The work’s identical; the exposure isn’t.

The policy is the other half. A short rule set, the kind we cover in our guide on what belongs in an AI acceptable use policy, names the approved tool, the data that may go in, and who may run it. I pair the policy with a technical review so the scope survives renewal season.

Fusion Computing pairs that policy work with a cybersecurity review so the brokerage has a defensible position.

The oversight gap for RIBO oversight and E&O defence

According to Anthropic, Claude Cowork stores local-session conversation history on each user’s computer, where it is not subject to Anthropic’s standard data retention policies and cannot be centrally managed or exported by admins. Cowork activity is captured in the Compliance API, and Enterprise admins can retrieve local-session content through it in beta. For a brokerage it matters twice: RIBO’s conduct oversight assumes the office can show how client work was done, and an E&O defence turns on documentation of the advice. Team and Enterprise owners can stream Cowork events to a SIEM through OpenTelemetry, which Anthropic notes does not replace audit logging for compliance. Cowork exports the full text of user prompts by default, along with tool parameters, file paths and user email addresses, so configure filtering or redaction at the collector and set SIEM access and retention before enabling export.

According to Anthropic’s guidance on using Cowork on Team and Enterprise plans, the local history “is not subject to Anthropic’s standard data retention policies and cannot be centrally managed or exported by admins.”

The wider governance frame for AI in a RIBO-licensed shop, including the Code of Conduct duties in section 14 and the FSRA IT risk expectations, is in our AI compliance roadmap for Ontario insurance brokerages.

Field note. When I walk a principal broker through the oversight gap, I open the local Cowork history on the demo machine and ask who else can see it. Nobody can. If a client disputes what was recommended at renewal, the file the defence lawyer wants is the one that shows how the summary was produced, and that transcript lives on one CSR’s laptop.

“Principal brokers ask me whether Cowork can run renewals. It can draft them. The coverage advice still belongs to the licensed broker who gives it, and the offices that hold that line get the speed without the E&O problem.”

Mike Pearlstein, CISSP, CEO, Fusion Computing

That doesn’t rule Cowork out. It means the brokerage designs its own record of AI-assisted work.

If the pilot needs centralized monitoring, define the destination, filtering, access and retention before enabling OpenTelemetry. If a draft could support a coverage decision or an E&O defence, the office keeps that record on purpose.

Plan tier and a setup checklist for an insurance brokerage

The plan tier is the first decision: per Anthropic’s plan lineup, only Team ($25 USD monthly, $20 USD annual, 2-seat minimum) and Enterprise carry the “not trained on by default” commitment a brokerage needs. A safe rollout: scope to one client folder, keep “Manually approve” on for client files, write a usage policy, turn on OpenTelemetry monitoring, and keep a licensed broker reviewing anything that states coverage.

Need the policy first? Use our AI acceptable use policy template.

Cowork runs on Pro, Max, Team, and Enterprise plans per Anthropic’s release notes, but only the two business tiers fit client work. Here’s the checklist Fusion Computing runs with a brokerage before the first client file goes near the tool. The steps come from our 2026 professional-firm pilots; in our practice the plan-tier fix is the first change we make.

Why Canadian firms bring this work to Fusion Computing

CISSP-led, a Microsoft Solutions Partner and a CompTIA Managed Services Trustmark holder, securing IT for Canadian SMBs across Toronto, Hamilton, and Metro Vancouver since 2012.

  1. Choose Team or Enterprise. A producer running client files on a personal account is the first risk to fix.
  2. Scope to one client folder. Never the book of business or the shared drive. Widen only with a reason.
  3. Default to “Manually approve.” Cowork always asks before deleting files; keep approvals on for client data.
  4. Write an acceptable use policy. Name the approved tool, the data that may go in, and who may run it.
  5. Turn on OpenTelemetry monitoring only after deciding what may be logged. It gives the firm a structured visibility stream into what the agent did.
  6. Keep a licensed broker signing off. Nothing that states coverage, from summaries to certificates, ships without review.
  7. Map the terms to your duties. Check Anthropic’s data handling against RIBO conduct standards and PIPEDA before go-live.

None of it’s exotic. The technical setup can be quick; the privacy, logging and approval work is what decides how long the pilot takes.

Fusion Computing sets it up as part of the managed IT work we already do for financial firms, and the same pattern carries to accounting firms and law firms under their own regulators. The review work is CISSP-led at a Microsoft Solutions Partner, the same team that has secured Canadian practices since 2012.

Claude Cowork is worth adopting for the submission and renewal work that fills a brokerage.Start with one low-risk workflow. If the controls hold and the numbers are right, expand from there.

Fusion Computing helps Canadian businesses across Toronto and the GTA, Hamilton, and Metro Vancouver with managed IT, cybersecurity, and Microsoft 365.

Frequently Asked Questions

Is Claude Cowork safe for insurance client files?

Claude Cowork can be safe for client files on a Team or Enterprise plan, with access scoped to one client folder and a licensed broker reviewing the output. Team and Enterprise do not train on organization content by default, but that alone is not a confidentiality determination: verify the execution mode, Anthropic’s current terms and DPA, retention, the applicable privacy law and your professional obligations before client data is used. Cowork sessions run remotely by default on Anthropic’s servers. Existing desktop deployments may still run locally, with code in an isolated virtual machine on the member’s device. On Team and Enterprise plans, your content is not used to train Anthropic’s models by default. The duty to protect client information stays with the brokerage, so the controls around the tool are what make it safe.

Can Claude Cowork read my broker management system?

Treat the answer as no by design. Cowork works across local files, so the safe pattern is exporting what a task needs into a scoped folder rather than connecting the agent to the live broker management system. The BMS stays the system of record, certificates and policy changes issue from it, and the agent only ever sees the export.

Does using Claude Cowork create an E&O exposure?

The exposure comes from unreviewed output, not from the tool. A renewal summary that misstates a limit or an exclusion can ground an errors and omissions claim, so the control is simple: a licensed broker verifies every coverage statement before a client sees it. Documented review closes most of the gap, and a written policy makes the practice provable.

What plan does an insurance brokerage need for Claude Cowork?

A brokerage should use the Team or Enterprise plan, not a personal Pro or Max account. Only the business tiers carry Anthropic’s commitment not to train on your content by default, plus the owner and admin controls an office needs. A CSR running client files on a personal account is the first risk to remediate.

Is client policy data used to train the model?

On Team and Enterprise plans, your content is not used to train Anthropic’s models by default, so client and policy data processed under a business plan stays out of training. Personal Pro and Max plans follow individual privacy settings, which differ from the business default. For a brokerage, that difference is the reason to standardise on a business plan.

How is Claude Cowork different from AI built into my BMS?

AI features inside a broker management system work only on the data that platform holds. Claude Cowork is a general agent that works across your own files and apps on the desktop, so it can draft a submission from a folder of applications, loss runs, and emails the BMS never sees. Most offices use both, with the BMS as the system of record.

Does Claude Cowork work on Windows or only Mac?

Claude Cowork works on both macOS and Windows through the Claude desktop app, and it reached general availability on both on April 9, 2026. Cowork is available on paid plans across desktop, web and mobile. Web and mobile remote sessions are in beta and are rolling out gradually across plans, so confirm availability for your plan before launch. Some capabilities, such as computer use, arrived first as research previews, so confirm the current feature list for your platform inside the app.

Who at the brokerage should run Claude Cowork?

Start with a small group who understand the client files and the conduct duty, not the whole office at once. Cowork has an organization-wide enablement switch, and on Enterprise, groups and custom roles can restrict it to selected users or teams while Team remains organization-wide, so a deliberate pilot with named users beats a broad rollout. Pair it with training and a written policy before wider use.

Talk to Fusion

Tell us your biggest headache across IT, security, or AI. We’ll let you know if we’re a fit.Get in Touch

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611