Hi, I'm Adam. In the next few minutes we're going to set up a workspace that Claude can actually use. That means the right local folder, approved access to the APIs you need, and results we can check. Most of the technical work the agent will do for us. The one thing it never touches is the credential. That stays in Outloop, and I'll show you exactly where. I’ll start by creating a workspace for this demo. This gives the work a clear home: a specific local folder, with its own approved access. I choose Claude and Cowork, check the name and location, and let Outloop create the folder. Next, I’ll connect that exact folder in Claude. The folder location is what connects these two apps. I copy it from Outloop and reveal it in Finder. The connection instructions are already inside. Keep this folder: creating another one with the same name would not give Claude the same context. In Claude, I create a project using the folder Outloop just made. I review the permission for that folder and create the project. Then I check that Claude shows the local folder on this computer. That is the connection we need; a matching project name by itself is not enough. Before changing access, I check the workspace again. This demo uses workspace 025. Claude’s connected folder and Outloop’s selected workspace need to refer to the same place, so I know exactly where the next action will run. A shared credential can be reused without showing its value. I assign OpenAI to this demo workspace and keep the test to a read-only model-list request. The audit shows that the real request succeeded through Outloop. This was temporary demo access; I removed the assignment after filming. For a dedicated credential, I confirm the provider and choose only this workspace. I enter the credential privately in Outloop, off-camera. The agent needs the assigned access, not the key. Saving it is one step; we still verify the integration separately. I install the complete Skill package through Claude’s Skills screen, then check that it is enabled. The Skill gives the agent instructions for this workflow. Seeing it installed is the first check; we’ll also test whether the agent actually uses it in a fresh task. The Plugin uses Claude’s Plugin upload route. This package is already present, so I review the replacement before confirming it. Then I check the enabled package and its eight Skills. Installation alone does not prove it works. The fresh-task footage shows the runtime Skill loading, and the provider receipt shows it was usable. We’ll return to that same read after the API setup chapter. You do not have to understand every API field yourself. I download three Skills from the guide. Outloop Custom API Setup helps the agent prepare the integration. API Integration Development supports the technical research. Custom API Operations guides approved work after setup. Keep the complete ZIP packages for installation. These are the catalog versions tested in this recording; their candidate status still matters. I use Claude’s Skills upload route and select the complete ZIP. Keep the package zipped. I review Outloop Custom API Setup and save it. Claude checks the package before installation. This recording replaces an existing copy. I check the intended package, confirm replacement and verify it is enabled. I repeat the upload for API Integration Development and check its enabled state. The catalog package version is different from Claude’s revision number. Finally, I install Custom API Operations. With all three enabled, I start a fresh task in the connected folder to test actual activation and use. Now I tell the agent the outcome I want: set up PandaDoc Sandbox for this Outloop workspace, research the official documentation, and verify a small, approved operation. I ask it to use the installed Skills. If it needs a credential, it must ask me to enter it directly in Outloop. The prompt contains no key. The agent checks PandaDoc’s official documentation before configuring anything. Here it confirms the Sandbox restrictions and that creating a draft is separate from sending it. That distinction keeps this demo’s approval narrow. The agent prepares the integration through Outloop. Here we review the definition it produced: the official destination, authentication template, and limited operations. Outloop holds the credential; the agent works with its assigned reference. This is an edited review of the completed configuration. The secure handoff comes next as an explanation of the human-only step, not a second credential entry. I confirm the provider and workspace. The credential is entered only in Outloop, with recording stopped. After it is saved and assigned, the agent continues without seeing it. Never paste the key into Claude. Validation checks the corrected definition without calling the provider. The agent saves the configuration and preflights the workspace’s allowed operation. Then a real provider request checks whether the integration actually works. Outloop shows the saved configuration, assigned credential and fresh provider verification. Match that evidence to the intended operation and workspace. Now I ask for a small, approved PandaDoc read in the connected folder. Claude checks the workspace and its access before making the request. I match the result to the request and workspace. HTTP 200 confirms the read succeeded; an empty list is a valid result. Outloop’s receipt reports no secret exposure. Here is the same first-task receipt again: workspace 025, the matching request, HTTP 200, and no secret exposure reported. I hold it here so we can inspect the result. Let’s look at what the agent prepared. The connection uses PandaDoc’s HTTPS API origin, and the authentication template refers to a credential kept in Outloop. The read operation defines its path, inputs and response type. Here the query is constrained to our synthetic demo. Validate checks the definition, without calling PandaDoc. I’m reviewing the existing integration, so I close this inspection without saving unnecessary changes. The test panel prepares a request for one declared operation. Here I choose the bounded demo inputs and copy the generated prompt. Copying it does not call PandaDoc. The connected Cowork task provides the real read receipt. I check the workspace, request and HTTP 200 result. This receipt is reused from the first-task demonstration. The agent checks that exact document’s state. It has reached document dot draft. I open the file and inspect the Sandbox watermark and blank sample fields. This is the concrete output of the approved operation. This draft downloaded successfully. Other states can behave differently, so check readiness and the permitted download route. Here I remove the HTTPS prefix in an unsaved diagnostic draft. Validation tells me exactly what is wrong. I restore the official HTTPS origin and validate again. The definition is valid now, but that is not a provider test. I close the unsaved draft, leaving the verified service intact. I create a scheduled task for a small, approved read. This local test requires this computer and uses automatic approval for its bounded operation. Creating the task inside the project did not attach its folder in this Claude version. I edit the task, choose the exact Outloop folder, and review recurring access. The saved overview must show that local folder. Run now is a diagnostic. Its fresh receipt shows the intended workspace and a successful PandaDoc read. The saved schedule is our source of truth for the timer. Here is the genuine 3:12 PM history entry, without a Manual label. The timer started this run. Its separate provider receipt confirms the scheduled run reached Outloop and completed the approved read. I pause the test. Keep this computer awake for future local runs. Here the task belongs to the project, but its session has no connected folder. It stops instead of guessing where to work. I find the exact folder in Outloop, attach it to the scheduled task, and approve the recurring folder access. Then I run a fresh diagnostic. The successful read tells me the repair worked. This demonstrates a missing-folder failure; it is not a test against another client’s workspace. The key is stored, but this workspace is not assigned access. Outloop reports SERVICE_NOT_GRANTED before a provider call is made. I assign the existing shared credential to the intended workspace and repeat the approved read. The new audit result succeeds. There is no reason to paste the key into Claude. I remove the temporary demo assignment when the test is finished. If a schedule fails, start with its saved folder and permissions. A project name alone did not connect the folder in this test. After attaching the correct folder, I run a diagnostic and check its Outloop result. Then I inspect an actual timer-triggered run. Both must reach the intended workspace. The 3:12 PM run has its own successful provider read; the manual test alone could not prove that. These are the same recovery and timer evidence shown earlier. So that's the whole check. The folder, the workspace, the assigned access, and the result. Let the agent do the technical work, keep the credential in Outloop, and always look at what actually happened before you rely on it. Thanks for watching.