Start here
Useful tool, one setting to check first
Anthropic has released a Claude for Small Business plugin, and parts of it are genuinely useful. Thirty-one pre-built skills covering payroll planning, cash flow snapshots, invoice chasing, month-end prep, and quarterly reviews — all running inside the Cowork desktop app and connecting to tools like QuickBooks, HubSpot, Stripe, and PayPal.
But before you connect your accounting software, there is something in the privacy documentation you should read first. Half of small business owners cite data security as their biggest hesitation about AI adoption — Anthropic’s own survey says so in their launch article. It is worth knowing exactly what you are agreeing to.
The product is solid. The gap, as with most AI tool launches, is in the defaults.
What it is
A plugin, not a standalone product
This is not a standalone product. It is a plugin you install inside the Claude Cowork desktop app. Once installed, it gives Claude access to your business tools through 12 connectors and surfaces 31 workflow skills you can run on demand.
The skills cover the tasks that eat partner and senior-staff time: plan payroll, close month, cash flow snapshot, invoice chase, Monday and Friday briefings, contract reviews, lead triage, margin analysis, tax prep. Connect the tools you use, leave the rest disconnected.
To run a skill, you open a new task in Cowork, click the plus icon, select the Small Business plugin, and pick the skill you want — say, quarterly review — and a slash command drops into your chat. Claude follows the skill, does the work, shows you the output, and waits for your approval before anything is sent, posted, or actioned. Nothing happens without your sign-off.
See it run
A quarterly business review against live data
To show what this looks like in practice: select the quarterly review skill from the plugin menu. Claude asks a few clarifying questions, then connects to your data sources. In this case that meant pulling financial data from BigQuery alongside Xero and HubSpot pipeline data — revenue month-on-month, quarter-on-quarter changes, and deal flow. From there it builds a formatted report with graphs, styled in your brand colours and fonts if you have set that up.
That is the Workflow layer of the KWA framework — Knowledge, Workflow, Agents — working as intended. The knowledge (your financial and CRM data) feeds a documented workflow (the quarterly review skill), producing a repeatable output without a senior person manually assembling it.
The detail that matters
The privacy small print, plan by plan
Here is what the documentation actually says, and why it matters for professional-services firms handling client data.
- Teams or Enterprise (Claude for Work). Your data is not used for model training. That is covered by the commercial terms. Your data stays yours.
- Pro or Max. The rules are different — and this covers a significant number of solo consultants and small-firm owners. Anthropic’s privacy documentation states they may use your chats and coding sessions to improve their models, including the full conversation and any content shared within it.
Raw connector data is not pulled into training automatically. Your QuickBooks ledger does not go directly into a training dataset. But if Claude surfaces something from your accounts and you discuss it in chat, that conversation is eligible for training. With the training setting on, Anthropic can retain that data for up to five years. With it off, the standard retention window is 30 days.
The setting is called “Help improve Claude”. If you are using this for business, turn it off before you connect anything: Settings → Privacy → Help improve Claude → toggle off.
The setup
Three steps to make this operational, not risky
The AI hype around productivity tools rarely gets into plan types and data-handling defaults. That is the vendor noise that wastes firms’ time and exposes them to risks they did not anticipate. Here is the practical approach instead.
- Sort your plan first. If you are connecting business financial data and want no conversation going near model training, move to a Teams plan — the commercial terms cover you, with no toggle to manage. If you are staying on Pro or Max, turn off the training toggle before connecting anything. Do this first, not after you have run ten workflows.
- Start with read-only workflows. Cash flow snapshots, margin analysis, performance summaries — tasks where Claude reads your data and returns analysis rather than taking external actions. Get comfortable with how it pulls data and what it returns before moving to outbound workflows like invoice chasing or email sending.
- Customise before you scale. The pre-built skills are a starting point, not a ceiling. Go into the plugin settings and tell Claude what to adjust — tone, business context, how it handles specific tasks. You can also edit individual skills: if the invoice chase skill works but does not match how your firm follows up, open it, click edit, and adjust it. And if you need something more specific than the pre-built skills offer, you can build your own inside Cowork.
Starting with read-only work maps directly to the Govern step of the 5 Steps for AI Leadership framework: know your approved tools, understand your data-handling rules, and document what AI is and is not permitted to touch before you expand what it can do.
The honest assessment
Know your plan, then build from there
The product is solid. The skills are well-structured, the connector list covers the tools most small professional-services firms actually use, and the approval-before-action model means Claude does not go off and send client emails without your sign-off. The gap, as with most AI tool launches, is in the defaults: half of business owners worry about data security, yet the default behaviour on the most common plan types is to have training opt-in switched on. That is the mismatch worth fixing before you start.
Know which plan you are on. Check your privacy settings. Start with read-only workflows. Then build from there. That is how AI becomes operational rather than experimental — the difference between tools that stick and tools that get quietly abandoned after the first awkward client-data conversation.