Article

What can Claude do on its own for a small business?

Claude can send email and schedule tasks on its own at a business, but each door has a different rule on approval.

By Piet Baudoin · September 2026

Claude can send email, update calendars and click around in your browser on its own, at a business. It does that through three doors with three different rules. At one of those three, the owner of the subscription can turn approval off.

“Can Claude do it” is the wrong question, because Claude can do a lot. The question is which door is open and who has the key. That fits the bigger picture of what the agentic economy means for a small business.

Every point below is backed by Anthropic’s own documentation, with a date.

Can Claude send email on its own at our business?

That depends on the door. Anthropic has three for the same action.

The Gmail connector sends, replies and forwards, and by default asks for your approval. On Team and Enterprise, the owner decides whether members can waive that request, according to the documentation from 17 August 2026.

The security guide for the Microsoft 365 connector, from 18 September 2026, forbids exactly that: for sending email, calendar items and Teams messages, “always allow” does not exist. The Outlook add-in never sends on its own, because the draft waits for your click.

The door Approval needed Can it be turned off Who decides
Gmail connector Yes, per email Yes The owner
Microsoft 365 connector Yes, per email No No one
Outlook add-in You send it Not needed You

So approval does not live in Claude, it lives in the door someone at your business opened. More on that in the article on an AI assistant that sends email on its own.

What does Claude do when you are not there?

It keeps working without asking every time, because the default has shifted. Claude in Chrome has been available on every paid plan since 26 August 2026, and according to Anthropic it acts independently there, instead of asking for approval per action.

Scheduled tasks run on Anthropic’s servers, even with your laptop closed. For routines in Claude Code on the web, the documentation states there is no permission choice: connectors you give it run without asking, including the ones that write. The same page still calls them a preview.

For its assistant for small businesses, the same maker says the opposite. The announcement of 15 September 2026 states: “By default, Claude does the work and waits for your approval before anything sends, posts, or pays.” So Claude waits for approval before anything is sent, posted or paid.

So the same maker runs three speeds. Which rule applies at your business depends on which product someone opens that morning.

What does this cost for ten people?

The math is short. Team costs $20 per seat per month billed annually, $25 billed monthly. Ten people: $200 a month, $2,400 a year. Replace two of those ten seats with Premium, eight times $20 plus two times $100, and it becomes $4,320 a year. A worked example using Anthropic’s own prices, read on 20 September 2026, in dollars.

You are buying capacity, not unlimited use. At every step, Claude reads back through everything said before, and that is charged per piece of text. Such a piece is called a token. A Standard seat has 1.25 times the capacity of a Pro account per session, Premium 6.25 times.

That limit is real. A business owner who sells freight software wrote on 23 August 2026 that Claude Desktop handled invoices from Gmail fine, but that token use cut him off before he finished a single real workload. Compare that to a meter that counts per document: what an AI agent costs per month for ten people.

What can Claude not do for your business today?

Four things you might actually have wanted.

Operating your desktop is not part of Team. Computer use is in beta, and only for Pro and Max.

The technical documentation on where your data is processed lists only two options for Claude itself, “us” and “global,” with storage in the United States. Another Anthropic page does mention “regional processing within EU/EEA,” meaning processing within the EU. Ask in writing which of the two applies to your plan before you put customer data in it.

Among the connectors Anthropic names, there is no Dutch accounting software: the list has Shopify, Salesforce, TikTok, Atlassian, Zoom, Xero, Gusto, Square, Stripe and Zapier. That is ten names out of 27 in total, and I have not seen the other seventeen. So ask whether your own software is on it. For what is still possible inside such software, see the article on ChatGPT and your accounting software.

And according to its own help page, Claude can report that it sent an email when it did not even have access to do so. So you cannot take its word that the quote went out. Anthropic places the responsibility for everything Claude does on your behalf on you, payments included: see who is liable when an AI agent makes a mistake.

What happens if this pace continues?

The brakes keep coming off, and you can track that through a single measurement.

Look at Anthropic’s own injection test, where a hidden instruction on a web page tries to take Claude over. In November 2025, that still worked against Opus 4.5 in 16.7 percent of attempts. In August 2026, not a single attempt succeeded against three of the new models, and 0.3 percent against the fourth. In that same month, on 26 August 2026, acting independently in the browser became the default on every paid plan. On 15 September 2026, the small business package counted 43 workflows, and 27 connectors were added. Anthropic does add: “the chances of an attack are still non-zero.” Still not zero, then.

My hypothesis: by the end of 2027, “asks for approval” will be the exception you have to switch on yourself at the big makers, not the state a product ships in.

The reasoning goes like this. A maker who watches its own risk figure drop from 16.7 percent to almost zero in nine months removes the brake from the default setting first, because that costs the least explaining. On 26 August 2026, exactly that happened. Users are heading the same way: a co-founder of an accounting firm wrote on 1 September 2026 that he first had his emails made as drafts and sent them himself, then flipped the switch so Claude now does it on its own.

What would break my hypothesis: an incident that gets wide coverage, or European rules that make approval mandatory.

For a business, that means you need to decide now who at your business can flip a default setting, and which actions must never happen on their own. Comparing products can wait, because these settings change faster than you can track them.

Which three settings do you check today?

Three, and it takes you fifteen minutes.

In the admin settings of your Team plan, “always allow” for connectors that write is off by default, and auto-approve is on by default. Check who at your business can flip those two.

In the browser, acting independently has been on since 26 August 2026. For a business of twenty people, I would set that back to approval per action, at least for tabs where you do your banking.

In the list of scheduled tasks, check who can create them, and whether any of them send on their own.

Then take this one question to your vendor. Which actions at our business can be set to “always allow,” who can flip that, and can I see afterward who approved it?

How do you start small?

Pick one task that comes back every day and whose outcome you can check yourself, such as sorting a shared inbox. Let it run alongside your own work as a proposal for two weeks and compare.

Bombos reads what comes in: email, messages, receipts and invoices. It finds the matching details in the software you already use, and gets the work ready with the reason behind it. No message and no payment goes out without someone at your business clicking Approve, and that is technically enforced.

If the default settings at the big makers keep shifting toward independence, Bombos grows along with that without approval shifting too. That approval is technically enforced and stays on, even as the models improve. What does shift is how often Bombos needs to put something in front of you: as a type of work keeps going well, that happens less, and you set that pace per type of work. The model itself is a part we can swap out, so a better model goes in underneath without you having to set anything up again. We can put the strongest and most cost-efficient model underneath right away, and switch per client to what that client wants. What Bombos learns from you does not sit in that model, it sits in your approvals and corrections, and that stays in place.

The promise: after three months, the work we start with is ready every day, without anyone having to think about it.

Check first where approval sits, and only then what the assistant can do. If you would rather sort it out on the phone, leave your number and we will call you back.

Sources

Every source was opened on 20 September 2026 and every quote appears in it word for word.

Anthropic on sending and approval:

Anthropic on acting independently and safety:

Anthropic on price, plans and data:

From the field: