In short
- Yes—Claude Code can access files outside the current project directory under certain conditions, such as when directories are explicitly added, user-level configuration is involved, or approved terminal commands run with the user's permissions. It does not automatically have unrestricted access to every file on the computer.
- Use –add-dir or /add-dir only for directories Claude Code should access.
- Review permission rules, hooks, settings, and user-level ~/.claude configuration.
- Run Claude Code in a dedicated unprivileged account, container, or tightly scoped environment for stronger isolation.
- Keep sensitive files outside the accessible environment and approve terminal commands carefully.
Yes—Claude Code can access files outside your current project under certain conditions, including added directories, configured paths, and approved terminal commands using your permissions.
It does not automatically have unrestricted access to every file on your computer. The effective boundary depends on your operating-system account, available tools, configuration, sandboxing, and the commands or directory grants you approve.
When can Claude Code access files outside the project?
The launch directory or repository root is the normal working area, but it is not necessarily an absolute filesystem security boundary. Outside-project access can occur when you:
- explicitly add another directory;
- use a configured or user-level path, such as
~/.claude; or - approve a terminal or Bash command that runs with your operating-system permissions.
In practice, treat the project directory as a working scope, not complete operating-system isolation. Behavior can vary by product version, platform, terminal environment, permission mode, and sandbox configuration.
Can Claude Code see every file on your computer?
No—not automatically. Claude Code should not be described as having unrestricted, computer-wide visibility. Its effective reach depends on:
- the account running the terminal;
- the paths that account can access;
- the commands and tools available to the session;
- directories explicitly added or configured;
- permission prompts, allow-rules, and sandboxing; and
- the actions you approve.
The accurate answer is conditional: Claude Code can potentially reach files outside the project, but it does not automatically see everything on the computer.
What can it do outside the project?
With suitable permissions, tools, and approval, Claude Code may be able to read, create, modify, move, or delete files outside the project. Reading and changing files are separate risks: a search or display command can expose information, while another command can overwrite, move, or remove data.
Approved terminal or Bash commands can operate with the permissions available to the user who launched Claude Code. Review commands that use absolute or broad paths, recursive searches, environment variables, file copies, permission changes, or deletion operations.
Permission prompts and allow-rules can limit operations, but they are not an absolute filesystem boundary. Approval confirms that an operation is requested; it does not make a broad or destructive command safe by itself.
How additional directories and configuration affect access
| Access route | Possible effect | What to verify |
|---|---|---|
| Launch directory or repository root | Normal work in the intended project area | Whether the active mode applies additional restrictions |
| Explicitly added directory | Work with files outside the primary project | Whether --add-dir or /add-dir is supported and how it works in the current version |
| Configured external path | Access to a deliberately included location | The setting’s scope, exact path, and session behavior |
| Terminal or Bash command | Potentially reading, creating, modifying, moving, or deleting accessible files | The command, user permissions, approval requirement, and sandbox behavior |
User-level configuration such as ~/.claude | Potentially relevant configuration or supporting files | Which settings are read and whether they apply to the current session |
Use --add-dir or /add-dir only for directories Claude Code genuinely needs. Do not assume that the same mechanism behaves identically across versions or platforms.
How to restrict Claude Code
Keep the working scope narrow
- Start Claude Code in the intended project folder.
- Add only the directories required for the task.
- Avoid exposing an entire drive or broad user folder.
- Review proposed terminal commands before approving them.
- Check permission prompts, hooks, settings, and allow-rules.
- Use a small or disposable test directory for unfamiliar work.
Keep sensitive files outside the accessible environment whenever possible. Narrow scope reduces the risk of accidental disclosure and modification.
Use stronger isolation when necessary
For a stronger boundary, run Claude Code in a dedicated unprivileged account, container, or other tightly scoped environment. A restricted directory helps, but an operating-system boundary is more robust than relying on the project folder alone.
Before relying on the setup, check which directories are available or mounted, which account runs the terminal, which tools are enabled, and which permission mode is active.
Protect secrets and personal files
Keep high-risk information outside Claude Code’s accessible environment unless it is essential to the task. This includes:
- credentials and API keys;
- passwords and password stores;
- SSH keys;
.envfiles;- personal or confidential information; and
- sensitive environment variables.
Be especially cautious with commands that print environment variables, search broadly, copy files, or send file contents through tools. Review the paths and data involved before approving them.
Claude Code, Desktop, Cowork, and MCP
Claude Code uses a terminal-based access model. Claude Desktop, Cowork, and MCP filesystem integrations may instead rely on explicitly mounted, selected, or configured paths.
For an MCP filesystem server, verify which paths are configured and which operations its permissions allow. Those boundaries should not be treated as interchangeable with Claude Code’s terminal permissions.
Does outside-project access create cross-project memory?
No. Filesystem reach during one terminal session does not establish that Claude Code automatically retains files or context, or makes them available in another project or later session. Filesystem access and cross-project or later-session availability are separate behaviors; check the current version and configuration for the latter.
How to verify access
During a session, review the commands Claude Code proposes, the paths they use, the directories you grant, and any resulting file changes. Available command history, logs, or monitoring features may provide additional visibility, but their coverage depends on the environment.
Before relying on a boundary, verify:
- the current Claude Code version;
- your operating system and terminal environment;
- the active permission mode;
- the behavior of
--add-dirand/add-dir, if available; - which configuration paths are read and at what scope;
- the active prompts, hooks, and allow-rules;
- whether sandboxing is enabled and what it restricts; and
- what command history or auditing is available.
Post-session retention and access are not universal. Verify what access, configuration, or context remains after the session instead of assuming that access either persists or disappears.
Bottom line
Claude Code can access files outside your project when additional directories, configured paths, or approved terminal commands make them reachable through your user permissions. It cannot accurately be described as automatically seeing every file on the computer.
For routine use, keep scopes narrow and approve commands carefully. When strong isolation matters, use an unprivileged account, container, or tightly scoped environment, and verify its behavior on your platform.



