# Desktop Commander, Cowork, and Browser Agents for a Small Business Published: October 4, 2026 Canonical: https://jwatte.com/blog/desktop-commander-cowork-browser-agents-small-business/ A bicycle shop owner asks an assistant to organize repair notes, check parts availability, and update a service page. It sounds like one job. It crosses three places: a folder, a supplier website, and the files that become the shop's website. An assistant that can read the supplier page may have no access to the other two. That is the useful way to compare Remote Desktop Commander, Claude Cowork, and browser assistants. Start with where the work lives. Then choose the connection that reaches it without receiving more access than it needs.
Start your own project: Download the workflow starter kit (.md) or save this article as Markdown.
This follows the [Sovereign AI Playbook](https://jwatte.com/blog/sovereign-ai-playbook-remote-desktop-commander/), which covers the persistent server. The [small quantized model article](https://jwatte.com/blog/small-quantized-models-96gb-ai-server/) explains which preparation jobs can stay local. Product details were checked on **October 4, 2026**. The three businesses below are hypothetical, not customer case studies or measured savings. ## Similar outcomes, different access **Remote Desktop Commander is a terminal and filesystem bridge.** Its remote launcher runs on the particular computer you authorize. An assistant can then inspect files, run a build, or check a service there. It is a separate product, not an OpenAI installer or another name for Cowork. Its remote relay is also part of the data path. A command running locally does not make the AI conversation local. [Official remote architecture and setup](https://github.com/wonderwhy-er/DesktopCommanderMCP/blob/main/src/remote-device/README.md). **Cowork is a task experience.** You describe a deliverable, connect the material it needs, and review the work. Its location matters. Anthropic's current rollout is merging chat and Cowork, so some accounts no longer show a mode selector. Its announced October 6 change moves new Pro and Max Cowork tasks to the cloud. That is two days after this article's publication, not an already completed change on every account. Do not turn an old tutorial's promise of local execution into your privacy policy. [Current execution locations and announced change](https://support.claude.com/en/articles/15520349-use-claude-cowork-on-web-desktop-and-mobile). **A browser integration reaches a browser.** It may read tabs, navigate pages, fill fields, or contribute page context to a task. That connection does not automatically authorize SSH or expose your server's files. Likewise, installing a terminal agent does not automatically give it your browser sessions. The practical similarity is that all three can help complete work. The important difference is what each can see and change. A task workspace can coordinate the job, a browser can handle an approved web step, and a terminal can handle a reproducible file step. Each connection needs its own authorization and test. ## Set up the two Chrome extensions deliberately ### Claude in Chrome Use the store link in [Anthropic's installation guide](https://support.claude.com/en/articles/12012173-get-started-with-claude-in-chrome), sign in, pin the extension, and review its permissions. The guide specifies Google Chrome, not every Chromium browser. Installing Chromium in a Linux browser desktop does not prove the extension is supported there. Start with a public page and a request to summarize it without clicking. Add a single approved business site next. Browser tasks involving the computer, local files, or control from another Claude surface may also need the desktop app open and connected. The extension and the desktop connection are not the same installation. Claude also has a built in browser. It maintains a separate browsing context rather than silently inheriting every ordinary Chrome tab. Use that route for work you prefer to keep separate, and your regular Chrome profile when its approved account session is actually needed. [Built in browser guidance](https://support.claude.com/en/articles/16607400-use-the-built-in-browser-in-claude-cowork). ### ChatGPT in Chrome OpenAI's current [browser extension instructions](https://learn.chatgpt.com/docs/chrome-extension) call the extension ChatGPT. Open **Settings > Computer Use** in the updated desktop app, choose the browser, install the prompted integration and extension, and confirm the connection. Start a Work or Codex chat and select the intended browser. Use the profile where the extension was installed. The extension supports page context and browser actions, with permissions for individual sites. Do not confuse it with a search extension that mainly changes where the address bar sends a query. Installing a familiar logo is not proof that you installed the intended product. OpenAI also offers a built in browser with separate browser state. That is another choice, not an automatic copy of your Chrome accounts. [Browser locations](https://help.openai.com/en/articles/20001277-using-the-built-in-browser-in-the-chatgpt-desktop-app). My rule for either extension is one operator per task tab. Finish or pause one assistant before handing the tab to another. It is much easier to review a form when two agents have not been changing it at once. ## Where Gemini, Kimi, and other products fit This is a map of documented capabilities, not a performance ranking. A nearby equivalent may exist for one part of the job and not another. | Family | Useful task or browser surfaces | Terminal or server route | Boundary to check | |---|---|---|---| | Claude | Claude tasks and Cowork; Claude in Chrome | Claude Code | Cloud tasks, your browser, and the terminal have different access. | | OpenAI | ChatGPT Work and browser integration | Codex CLI; an authorized terminal connector | Browser access does not itself grant remote administration. | | Google | Gemini Spark; Gemini in Chrome and eligible auto browse | Gemini CLI | Account, region, language, plan, and administrator controls affect availability. | | Kimi | Kimi Claw; Kimi Browser Extension; Kimi Code Desktop | Kimi Code CLI | Desktop, extension, and Linux CLI support must be checked separately. | | Microsoft | Copilot Cowork; Copilot browsing in Edge | Use a separately approved development or remote access tool | Edge is not a Chrome extension, and tenant licensing matters. | | Perplexity | Computer; Personal Computer; Comet | Use the documented host setup | The documented Personal Computer setup uses a Mac. | | Manus | Manus tasks and Browser Operator | Do not infer general server access from browser control | Authorize the intended browser session and retain a way to stop it. | | Local models | Open WebUI with configured local models | Aider or another deliberately connected tool | Weights alone provide neither a browser controller nor a task workspace. | ### Google Gemini in Chrome is a supported Chrome experience, not a reason to install an arbitrary extension. Where available, use **Ask Gemini**, complete consent, and test a page question. Auto browse adds actions; review its plan and use the takeover control when needed. [Google's Chrome setup](https://support.google.com/chrome/a/answer/17030585). Gemini Spark is the closer comparison for delegated tasks. Google documents a Chrome browsing connection and an expanded rollout. Eligibility still matters. Custom MCP apps, for example, have requirements that do not automatically match every Workspace account. [Spark and Chrome](https://blog.google/innovation-and-ai/products/gemini-app/gemini-spark-updates-july-2026/) and [custom app requirements](https://support.google.com/gemini/answer/17209137). For command work, choose the official [Gemini CLI](https://github.com/google-gemini/gemini-cli) and its supported authentication route. It is not the same installation as Spark or Gemini in Chrome. [CLI authentication](https://geminicli.com/docs/get-started/authentication/). ### Kimi Kimi's documentation now calls WebBridge **Kimi Browser Extension**. It describes a sidebar and connections to local agents, including Kimi Code, Claude Code, and Codex. Set it up separately on each computer. Its FAQ also describes creating a local Kimi Claw from Kimi Desktop by choosing **My Computer**. [Official extension FAQ](https://www.kimi.com/en/help/kimi-webbridge/kimi-webbridge-faq). Kimi Code Desktop is another surface, with a graphical project workspace and a built in browser. The documented desktop release supports macOS and Windows. A Linux Kimi CLI installation does not establish that the desktop application is available there. [Desktop release notes](https://www.kimi.com/code/docs/en/kimi-code-desktop/changelog.html) and [browser documentation](https://www.kimi.com/code/docs/en/kimi-code-desktop/built-in-browser.html). ### Microsoft, Perplexity, and Manus **Copilot Cowork** is a real Microsoft offering, not a nickname for Claude Cowork. Check the account, tenant setup, and current billing before connecting Microsoft 365 work. Edge browsing is a related but separate feature. [Copilot Cowork](https://www.microsoft.com/en-us/microsoft-365-copilot/cowork) and [Edge at work](https://support.microsoft.com/en-us/microsoft-copilot/using-microsoft-copilot-in-edge-at-work). Perplexity separates **Computer**, **Personal Computer**, and the **Comet** browser. Its Personal Computer setup documents a Mac with approved folders and applications. That is not evidence of a native Ubuntu equivalent. [Personal Computer setup](https://www.perplexity.ai/personal-computer-setup) and [Comet](https://www.perplexity.ai/comet). **Manus Browser Operator** is another documented browser choice. Follow its extension setup, authorize the session, and use its dedicated task tab rather than exposing every business account. [Official setup](https://manus.im/blog/manus-browser-operator). For a product not covered by the documentation, write **no direct equivalent verified** rather than filling the gap with an unofficial extension. None of this establishes that every listed browser integration has been tested inside our Linux desktop. A missing feature may be an eligibility or platform limit, not an installation fault. ## Try one ordinary job before connecting everything Create a work browser profile and a project folder containing copies of approved material. Keep personal tabs, banking, employee records, payment information, and saved customer credentials out of the pilot. Use an application's dedicated connector when it offers a narrower, clearer action than browser clicking. For Desktop Commander, launch the remote process on the computer you intend to use, authorize the device, and connect the assistant side. Ask for the hostname and a listing of your test folder. A connected browser extension is not a substitute for that check. The [server guide](https://jwatte.com/downloads/sovereign-ai-setup-guide.md) gives the separate terminal setup. Test one read, one draft saved into a new output directory, and one reversible edit to a copy. Require a review before sending messages, buying anything, changing a live website, deleting records, or making a commitment to a customer. Treat instructions found inside webpages and documents as source material, not permission to expand the job. ## Example one: a bicycle repair shop Imagine a shop with six staff and repair notes scattered across a booking export, short documents, and a parts list. The owner wants tomorrow's work packet before opening. Start with a redacted export using job references instead of customer names. A document workspace can prepare a repair queue and a list of missing details. A small local model could extract categories first. Let a script perform the arithmetic and preserve the original job references. One browser assistant can check approved public supplier pages and record the part, displayed availability, URL, and check time. An unavailable page means unknown, not out of stock. The assistant should not place orders or promise collection times. For a supplier portal that is unsuitable for the browser tool's privacy rules, staff can export the necessary information instead. > Use only the redacted repair notes in this project folder. Draft tomorrow's queue by job reference. Separate confirmed parts from missing parts. Preserve every stated deadline and flag contradictions. Check only the three public supplier links I provide. Save a draft packet and source list. Do not order anything, contact customers, or change the booking system. The owner approves priorities and commitments. A terminal agent can maintain the script that produces the packet. Desktop Commander becomes useful when that script lives on the shared server rather than the owner's laptop. Measure omitted jobs, corrected fields, and the minutes staff spend reviewing the packet. If correction takes longer than the original task, improve the inputs or stop the experiment. A plausible looking queue is not a successful queue. ## Example two: an event catering business A small caterer has menu files, ingredient prices, and redacted inquiry notes. The owner wants a draft proposal packet, not an assistant making dietary promises or taking deposits. Use a document workspace to compare each inquiry with approved menu options. Keep guest counts, dates, venue requirements, and unresolved questions separate. A script can calculate quantities from the business's own portion rules. The assistant should not invent a conversion or substitute an ingredient because a supplier webpage suggested it. A browser assistant can check an approved supplier's public price sheet. Ideogram may help produce a conceptual cover illustration, but a generated dish must not be presented as a photograph of the caterer's actual food. Figma is useful if someone maintains branded proposal templates there; it is unnecessary if the existing document template works. > Prepare draft proposal packets from these five redacted inquiries and the approved menu file. Mark missing guest counts and dates. Use our supplied pricing sheet and portion rules. Keep dietary questions unresolved for a staff member. Cite the source of each quoted price. Save the drafts without emailing them, collecting payment, or changing an order. The owner checks ingredients, dates, quantities, margins, and any dietary issue. The pilot succeeds when staff can approve the packet with fewer corrections, not when the assistant produces the longest proposal. ## Example three: a commercial cleaning company A cleaning business has an approved service checklist, completed job exports, supply purchases, and a weekly operations report. The aim is to find missing information and draft a supervisor handoff. Keep alarm codes, access instructions, personal contact details, and anything about an employee's health outside the AI inputs. Replace customer names with site references. A local model can classify notes into supplies, scheduling questions, and work that needs inspection. A script compares job IDs against the schedule so a missing completion record cannot disappear in a summary. > Compare the redacted completed job export with the approved schedule. List missing job IDs, supply exceptions, and notes that require a supervisor's review. Quote the relevant source text for each exception. Produce a draft handoff grouped by site reference. Do not change shifts, message staff, update access instructions, or mark work complete. A browser assistant can inspect the approved scheduling interface during a supervised test. A terminal workflow can perform the repeatable comparison. n8n may eventually run that comparison on a schedule, but only after duplicate handling, failure reporting, and a manual review path have been tested. Measure missing jobs caught and false alarms raised. Do not turn an AI classification into an automatic employee performance judgment. ## Which optional server tools are actually useful? The original playbook lists optional components because businesses have different workloads. Here is the full set, including when I would leave each one out. | Optional component | A reason to add it | A reason to wait | |---|---|---| | Cloudflare Tunnel and Access | Reach a private application over HTTPS with an explicit identity policy. | Local SSH forwarding already covers the only operator's needs, or Access and DNS are not ready. | | Tailscale | Connect your own approved devices through a private access path. | You only need a browser link, or cannot install a client on the device you will use. | | Persistent browser desktop | Keep an approved work browser and terminal on the server. | An ordinary laptop browser is sufficient, or the required extension is unsupported there. | | Deno | Run a project that actually uses Deno. | No current project requires it. | | Vercel CLI | Maintain a site hosted on Vercel. | All deployments remain on other platforms. | | PM2 | Supervise an existing Node application designed around it. | Docker or systemd already supervises the same process. | | Gitleaks | Review source changes for possible credentials before pushing. | Never treat a clean scan as proof that no secret exists. | | Trivy | Review package and container vulnerability findings. | Installing the scanner without reviewing results achieves little. | | Figma integration | Supply approved design context or templates. | The business has no maintained Figma design source. | | Ideogram | Produce conceptual artwork from a nonconfidential brief. | A genuine product or service photograph is needed. | | Qdrant | Retrieve relevant passages from a growing document collection. | A few files and ordinary search solve the problem. | | n8n | Connect a repeatable, tested sequence of operations. | The process changes every week or lacks a failure owner. | These are proposed uses, not a claim that every component has been connected to every business account. [Cloudflare access setup](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/self-hosted-public-app/), [Tailscale documentation](https://tailscale.com/kb), [browser desktop documentation](https://docs.linuxserver.io/images/docker-webtop/), [Qdrant](https://qdrant.tech/documentation/), and [n8n](https://docs.n8n.io/) explain their individual requirements. Restic and rclone also deserve a clear distinction. Restic is for encrypted recovery snapshots. Rclone is a transport and synchronization tool. A mirror that faithfully copies a deletion is not a substitute for a recoverable backup. Test restoration and keep the credentials somewhere that survives losing the workstation. [Restic](https://restic.readthedocs.io/en/stable/) and [rclone](https://rclone.org/docs/). ## The remote URL should not become an unattended root prompt For travel, a browser editor or terminal can sit behind Cloudflare's email OTP check and a separate application password. A named tunnel with an appropriate Access policy is the durable setup to evaluate. Confirm the hostname's actual DNS provider before changing records. The [Cloudflare application guide](https://developers.cloudflare.com/cloudflare-one/access-controls/applications/http-apps/self-hosted-public-app/) requires an active supported zone and describes origin token validation. A text box in Open WebUI is not automatically a shell. For command work, open the protected terminal, select the intended project, and use a native coding assistant with its normal approval controls. Keep administrative access separate. Two login checks protect entry; they do not make an agent's proposed command correct. ## Start with one packet, not a new department The first useful result might be a repair queue, a proposal draft, or a list of missing cleaning records. Pick one output, give the assistant only the inputs it needs, and compare the result with the way staff already do the job. Add a server when persistence helps. Add a browser connection when a web interface is genuinely part of the task. Add another model when a measured limitation calls for it. The business does not benefit from collecting integrations that nobody maintains.Download the starter kit with all three project briefs. It includes folder structure, permission boundaries, review questions, and a pilot scorecard. Download the article text.
*The three examples are hypothetical. Product names identify the documented tools, not endorsements or vendor affiliation. Availability and prices can change. The hero is a conceptual illustration generated with Ideogram for this article.*