Claude Training NZ, home

11 min read. Updated 6 October 2026

Agents and automation with Claude: what is realistic in 2026

Claude can now take a task, work through it across files, apps and websites, and come back with a finished result, sometimes on a schedule while nobody is watching. That is genuinely useful for a New Zealand business. It is also a new kind of risk, because an agent that can act can also act wrongly.

Illustration generated with AI.

What an agent means in Claude today

In a normal chat you ask, Claude answers, and you do the work. An agent closes that loop. Anthropic describes Claude Cowork as using the same agentic architecture as Claude Code, with no terminal required, and it lets you hand off complete tasks1. Cowork is available on the Pro, Max, Team and Enterprise plans in the desktop app for macOS and Windows, with web, mobile and Chrome side-panel access depending on plan and admin settings1. Anthropic is also folding Cowork into the main Claude app, and its help centre now says Claude Cowork is just Claude, so the Cowork name may disappear1.

Where tasks run has just changed. From 6 October 2026, new Cowork tasks run in the cloud and the option to keep them only on your computer is being removed1. Cloud tasks keep going when you close the laptop, but if a task needs local files or your browser, the desktop app has to stay open so Claude can reach them1.

Several other pieces turn Claude from a writer into a worker. Connectors link it to business systems; the Microsoft 365 connector, for example, can search SharePoint, OneDrive, Outlook and Teams, and optional write tools let it send email, edit files and post Teams messages on a person's behalf6. Skills are folders of instructions, scripts and resources that Claude loads only when a task needs them, and Team and Enterprise admins can provision them across the organisation7. For developers, Claude Code reads a codebase, edits files, runs commands, and can run recurring jobs as routines in the cloud, while the Agent SDK lets a team build its own agents on the same tools5.

Scheduled tasks: automation without a developer

Scheduled tasks are the feature most small businesses will actually use. They are available on every paid plan, and they run hourly, daily, weekly, on weekdays or on demand2. You can type /schedule inside any Cowork task, or open Scheduled in the left sidebar to create and manage them1. Because they run remotely, they keep their cadence even when your computer is asleep, and they can use the same connectors, skills and plugins as a normal task2.

There is one catch worth knowing before you design anything. A scheduled task cannot be tied to a folder on your computer, so a job that depends on local files only runs locally2. If you want a reliable Monday report, keep its inputs in a connected system such as SharePoint or Google Drive, not on someone's desktop.

  • A Monday summary of last week's jobs, complaints and open quotes, drafted from shared files for a manager to read.
  • A daily scan of public tender notices or industry news, filtered against your own criteria.
  • A month-end pack that collects figures from named spreadsheets into one draft report with every source listed.
  • A weekly check of a shared policy library for documents that are past their review date.

What is realistic, and what is not

The work agents do well in 2026 has three features in common: the inputs are digital and reachable, the output is a draft someone reviews, and a mistake is cheap to catch. Research digests, document assembly, data tidying across spreadsheets and first-pass inbox triage fit that pattern. So does software work, where Claude Code can plan a change, edit several files, run tests and open a pull request for a developer to review5.

Unattended actions with money, people or legal effect do not fit, and Anthropic's own rules show it. Claude in Chrome is barred from stock trading, bypassing captchas, entering sensitive data and similar actions3. Anthropic advises against using it on banking, healthcare, legal documents, work accounts holding sensitive data and other people's personal information3. Cowork asks for explicit permission before it permanently deletes files, and sessions cannot be shared with colleagues1.

So the honest picture is a capable assistant that finishes multi-step chores and hands you the result, not a digital employee that runs your accounts payable overnight. Plan for the first, and you will get real value. Plan for the second, and you will spend your time cleaning up.

The security model you need before you switch it on

The defining risk of agents is prompt injection: instructions hidden in a web page, document or email that try to redirect the agent3. The National Cyber Security Centre lists it, alongside hallucinations, as a way AI output can be manipulated or unreliable9. An agent that reads your inbox and can also send email is the obvious target.

In May 2026 the NCSC and partner agencies published joint guidance on careful adoption of agentic AI services8. Its recommendations include enforcing least privilege, limiting the data an AI system can see, validating outputs before use and keeping AI-assisted actions auditable8. Translated for a small firm: give the agent the fewest systems it needs, read-only where possible, and make sure a person approves anything that changes a record or leaves the business.

Claude gives admins real levers for this. On Team and Enterprise, admins can control whether auto-approval is available in Cowork and can require per-task approval for connector tools that write1. Claude in Chrome can be switched off for the organisation or limited with site allowlists and blocklists, and users can choose Manually approve so every action waits for a click3. Cloud Cowork sessions run in a temporary sandbox with no access to your internal network by default, outbound traffic limited to an allowlist, and short-lived credentials4. Team and Enterprise admins can monitor cloud session activity through the Compliance API and OpenTelemetry4.

  • Start every connector read-only and enable write tools one at a time, for named people6.
  • Keep auto-approval off until a workflow has run cleanly under manual approval for several weeks.
  • Block Claude in Chrome from banking, payroll, health and government portal sites3.
  • Write down who owns each scheduled task and review the list every quarter.

Your obligations to staff and customers

Automation changes jobs, and New Zealand employment law has a process for that. Under section 4 of the Employment Relations Act 2000, an employer proposing a decision likely to have an adverse effect on the continuation of someone's employment must give the affected staff access to relevant information and a chance to comment before deciding10. Most Claude rollouts reshape tasks rather than remove roles, but if your plan does point toward fewer positions, run the good faith process first.

Health and safety law also has a say. WorkSafe's guidance on the Health and Safety at Work Act 2015 says a business must engage with workers when it proposes changes that may affect their health or safety, give them timely information, and take their views into account11. Talk to the people whose work the agent will touch, and ask what could go wrong on the ground.

Customers count too. The Privacy Commissioner expects senior leadership approval, a privacy impact assessment, transparency with customers about how and why a generative AI tool is used, and human review before acting on its output13. The public service guidance makes the same point about accountability: a responsible human, with the authority and skills to do so, makes the decision about how the output is used14.

Worked example: a freight business in Tauranga

Picture a Tauranga freight forwarder with about forty staff, running on Microsoft 365 and Claude Team. The operations manager spends Monday morning building a status report from a shared tracking spreadsheet, a customer complaints folder and the week's delay emails.

The first version is deliberately modest. An admin adds the Microsoft 365 connector with read access only, which mirrors each person's existing permissions6. The operations manager writes a scheduled task that runs every weekday morning, reads the three sources, and saves a draft report with a link beside every figure2. Nothing is sent anywhere. For a month the manager compares the draft against the old manual report and notes each discrepancy.

Only after that month does the firm consider a second step: letting Claude draft, but not send, replies to routine delay enquiries. Write tools stay limited to the two customer service leads, and every reply waits for a human to press send.

Worked example: a consultancy in Dunedin

Picture a six-person Dunedin engineering consultancy that wins most of its work through public tenders. A scheduled Cowork task gathers new notices that match the firm's disciplines and regions, and drafts a shortlist with a one-paragraph reason for each.

The partner keeps Claude in Chrome on Manually approve for this work and never lets it sign in to anything3. A skill holds the firm's bid criteria, so every run applies the same rules7. The partner reads the shortlist and decides; Claude never submits a bid or registers an interest.

A sensible first three months

Use the first 90 days to prove one or two workflows, not to automate the business. There is no official New Zealand baseline to compare against yet: Stats NZ paused its Business Operations Survey for 2024 and 2025, and a new survey run with MBIE in 2026 adds questions on the use and impact of AI12. Measure your own results instead.

  • Weeks one and two: list ten repetitive tasks and pick the two with digital inputs, a reviewable output and low cost of error.
  • Weeks three and four: set admin controls first, including connector permissions, approval settings and Chrome site rules1,3.
  • Weeks five to eight: run each workflow under manual approval and log every correction.
  • Weeks nine to twelve: talk to affected staff, update the privacy impact assessment, and decide whether to keep, widen or stop each workflow11,13.

Related

  1. 1Organisation

    Claude team rollout

    Move from a few keen users to a whole team using Claude well: plan and seats, Projects structure, usage rules, connectors, Skills and champions.

  2. 2Advanced

    Claude Code and MCP for developers

    For developers and technical leads: agentic coding with Claude Code, team settings and permissions, building an MCP server, and the Claude API.

  3. 3Role-based

    Claude for HR and people teams

    For HR and people leaders: policies, job descriptions, inductions and clear letters, with firm rules on employee information and fair decisions.

Industries

Regions

See all guides.

Questions

Do we need a developer to use Claude agents?

Not for Cowork or scheduled tasks. Anthropic built Cowork on the Claude Code architecture specifically so no terminal is needed1. You need a developer for Claude Code work, custom connectors or anything built with the Agent SDK5.

Can Claude send emails for us automatically?

It can, if an admin enables write tools on a connector such as Microsoft 3656. We suggest starting with drafts only. Let Claude prepare the message and have a person send it until the workflow has a clean track record.

Is it safe to let Claude in Chrome use our business accounts?

Anthropic itself advises against using it for banking, healthcare, legal documents or work accounts holding sensitive data3. Use it on public websites, keep manual approval on, and have an admin block sensitive sites.

What happens to a scheduled task when the person who set it up leaves?

Treat it like any other system access. Keep a register of scheduled tasks and their owners, reassign or turn them off during offboarding, and make sure inputs live in shared systems rather than personal folders, since scheduled tasks cannot be tied to a local folder anyway2.

Train your team

  1. You tell us about the teamSize, where you are, the documents people work with, and what you would like to change.
  2. We suggest a course and formatBy email, with a few questions about the tasks and documents you want to train on.
  3. People practise on real workOn-site or remote. Everyone leaves with Claude set up for tasks they do every week.
  • In person
  • Remote
  • Half-day workshop
  • Full-day workshop
  • Team rollout

Independent training by TheColab. Not affiliated with Anthropic.

Enquire

Tell us about your team. We reply by email with a suggested course and format.

We use these details only to reply to you, and store them securely with TheColab. Privacy

Sources