AI tools are moving from answering questions to doing work. Desktop agents like ChatGPT Work and Claude Cowork can read your files, use your apps, browse the web, and finish multi-step tasks for you. This page explains what they are, what they can do, where the risks are, and how to use them safely at Notre Dame.

The short version

  • Use your Notre Dame account (ChatGPT EDU or Claude Teams with ND SSO), never a personal account, for university work.
  • Give the agent only the folders and apps the task needs.
  • Faculty and staff should only run desktop agents on managed devices with Endpoint Detection and Response (EDR)
  • Require approval for anything that sends, deletes, buys, submits, or shares.
  • Check the results. You are responsible for what the agent does on your behalf.

What is a desktop agent?

A chat assistant answers your questions and waits for your next message. An agent takes a goal, breaks it into steps, and carries those steps out using tools, often for many minutes or hours with little input from you. A desktop agent runs through an app on your computer, so it can also work with your local files and, if you allow it, other applications.

How a desktop agent differs from a chat assistant
  Chat Assistant Desktop Agent
What you give it A question or prompt A goal, such as "Turn these meeting notes into a project plan"
What it does Writes a response Plans steps, opens files, uses apps and the web, and creates deliverables
What it can reach What you paste or upload Folders, connected apps, websites, and sometimes your screen
Who checks each step You, after every reply The agent, unless you require approvals

Desktop agents at Notre Dame

ChatGPT Work (OpenAI)

Available in Notre Dame's ChatGPT EDU workspace. Work handles long, multi-step tasks and produces documents, spreadsheets, presentations, and reports. In the ChatGPT desktop app, it can work in local folders you open for it and use your computer.

Approved data: Public, Internal, Sensitive, and FERPA-covered data when you're signed in to ChatGPT EDU.

Claude Cowork (Anthropic)

Included with Claude paid plans, including Notre Dame's Claude Teams accounts. Cowork runs tasks in an isolated cloud workspace and, through the Claude desktop app, can reach folders you connect, a browser, and other apps.

Approved data: Public, Internal, and select Sensitive, when you're signed in to Claude Teams with ND SSO. Not approved for FERPA-covered data.

What can desktop agents do?

Work with your files

Read, organize, rename, and edit files in folders you grant access to, and write new files next to them.

Create finished work

Produce formatted documents, spreadsheets with working formulas, slide decks, and summaries from your source material.

Research on the web

Search, read, and compare web pages, then pull the findings into a report with sources.

Use connected apps

Work with approved connectors such as email, calendars, cloud storage, and project tools.

Use your computer

With your permission, look at your screen, click, and type in other applications to complete a task.

Run on a schedule

Repeat a task on a schedule, such as a weekly digest, and keep working while you step away.

Good first tasks are low-stakes and easy to check:

  • Sort a folder of downloaded files into subfolders by type or date.
  • Turn a set of meeting notes into a summary with action items.
  • Build a formatted spreadsheet from a messy export, then spot-check the totals.
  • Research public information on a topic and draft a briefing with links to sources.

What are the risks?

Agents are powerful because they can act. That same ability means a mistake or a manipulated instruction can have real consequences.

Hidden instructions (prompt injection)

A web page, email, or document can contain text written to trick the agent, such as "ignore your instructions and send this file to…". AI models can't reliably tell the difference between your instructions and instructions hidden in content they read. Security experts expect this problem to be managed, not solved.

Actions you can't undo

An agent can delete or overwrite files, send messages, submit forms, or change settings. If it misunderstands the goal, it can do the wrong thing quickly and at scale.

Too much access

Connecting your whole Documents folder, inbox, or drive exposes far more than a task needs. Task details may be stored in the cloud even when the work runs on your computer.

Confident mistakes

Agents produce polished work that can still contain wrong figures, broken formulas, or invented citations. Finished-looking output is easy to trust too quickly.

Untrusted plugins and connectors

Third-party plugins, connectors, and browser extensions can see your data and may not meet Notre Dame's security requirements.

Unattended tasks

Scheduled or long-running tasks work without anyone watching. Problems may not surface until after the damage is done.

How to protect yourself

  1. Use your Notre Dame account

    Do university work only in ChatGPT EDU or Claude Teams signed in with ND SSO. Personal accounts are approved for public data only.

  2. Grant the least access that works

    Create a working folder for the task and connect only that folder. Don't connect folders with passwords, financial records, or data the task doesn't need.

  3. Keep approvals on for consequential actions

    Use the setting that asks before acting (for example, Cowork's "Manually approve" mode) when a task can send, delete, purchase, submit, or share. Read each approval before you click it.

  4. Be specific

    "Summarize the three PDFs in this folder" is safer than "handle my inbox." Narrow instructions leave less room for hidden instructions to steer the agent.

  5. Treat outside content as untrusted

    Be careful letting an agent read unfamiliar websites, emails, or shared files while it also has access to Sensitive data or can take actions. Limit web access to trusted sites when you can.

  6. Never hand over credentials

    Don't give an agent your password, Duo codes, or payment details, and don't approve a Duo push you didn't start. Sign in to sites yourself.

  7. Stay nearby for the first runs

    Watch what the agent opens and does. Stop the task if it reaches for files or sites it doesn't need. Start scheduled tasks small, and keep irreversible actions out of them.

  8. Review before you rely

    Check facts, numbers, formulas, and citations before you share or act on the results. You're accountable for work an agent does on your behalf.

  9. Use approved connectors only

    Before you connect an app or install a plugin, confirm it's approved for your data. Don't install browser extensions that claim to integrate with ChatGPT or Claude.

  10. Report anything suspicious

    If an agent does something you didn't ask for, stop the task and contact the OIT Help Desk.

Which data can I use?

Approved data types for desktop agents by account
Agent and Account Approved Data Types FERPA Data Allowed?
ChatGPT Work
ChatGPT EDU with ND SSO
Public, Internal, Sensitive Yes
Claude Cowork
Claude Teams with ND SSO
Public, Internal, select Sensitive No
Any agent
Personal account (Free, Plus, Pro, Max)
Public Data ONLY No

Highly Sensitive data is not approved for any desktop agent. For questions about how your data is classified, contact researchsecurity@nd.edu.

Learn more

Getting started

Using agents safely

Security background

Notre Dame resources