FREE TEMPLATE

Acceptable Use Policy

Where the line is on company equipment, accounts and networks — written so you can point at it when somebody crosses it, with a signature block at the end.

[COMPANY NAME]

Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change

Purpose

This policy sets out how [COMPANY NAME] equipment, accounts, networks and data may be used. It exists so that everyone knows where the line is before someone crosses it, and so the company can act consistently when that happens.

Scope

This policy applies to every employee, contractor, temporary worker, intern and vendor who uses a [COMPANY NAME] account, device or network — including personal devices used for company work.

It covers company-owned computers, phones and tablets; email, file storage and collaboration accounts; the company network and remote access to it; and any third-party service used to conduct company business.

General use

Company systems are provided for company work. Limited personal use is permitted where it does not interfere with your job, consume meaningful company resources, or create risk or liability for the company.

You should have no expectation of privacy in anything created, stored, sent or received on company systems. The company may access, monitor and retain this information as needed to run the business, meet legal obligations, or investigate a suspected violation of this policy.

What is not allowed

The following are prohibited on company systems and accounts:

  • Sharing your password with anyone, including coworkers and managers, or using another person’s credentials
  • Disabling, bypassing or interfering with security controls — antivirus, endpoint protection, encryption, screen locks, multi-factor authentication or software updates
  • Installing software, browser extensions or applications that have not been approved by [POLICY OWNER OR IT PROVIDER]
  • Storing company data in a personal account or unapproved service (personal email, personal cloud storage, personal messaging apps, unsanctioned AI tools)
  • Connecting unapproved devices to the company network, including personal routers, wireless access points and USB storage
  • Using company systems to harass, threaten, defame or discriminate against anyone
  • Accessing, storing or distributing material that is illegal, sexually explicit, or that would reasonably be considered offensive in a workplace
  • Attempting to access accounts, files or systems you have not been granted access to
  • Using company systems for a personal business, political campaign or outside commercial venture
  • Sending company data to a personal address or device on your way out the door

Email, messaging and the internet

Treat every message as a permanent record that could be read aloud by someone who is not on your side.

Do not open attachments or click links you were not expecting, even when the sender looks familiar. If a message asks you to move money, change payment details, buy gift cards or provide credentials — verify it by phone, using a number you already have, before acting. Report anything suspicious to [POLICY OWNER OR IT PROVIDER] rather than deleting it quietly.

Company email addresses may not be used to register for personal accounts or services.

Company data

Company data stays in company systems. Do not copy files to personal storage, forward work to a personal address, or paste confidential information — customer records, financial data, credentials, source code, anything covered by a contract or NDA — into a public AI tool, translation site, file converter or other external service.

If your role requires moving data somewhere new, ask first. There is almost always an approved way to do it.

Devices

Lock your screen when you step away. Keep devices updated. Do not leave a laptop visible in a vehicle or unattended in a public place.

Report a lost or stolen device to [POLICY OWNER OR IT PROVIDER] immediately — not the next business day. Speed is the entire difference between a wiped device and a reportable breach.

Personal devices

Where personal devices are permitted for company work, they must have a passcode or biometric lock, current operating-system updates, and the company’s required security software or mobile management profile.

You agree that company data on a personal device may be removed remotely when you leave, or if the device is lost. Removal is limited to company accounts, company applications and company data. [COMPANY NAME] does not perform a full-device wipe of a personal device, and does not access personal photos, messages, contacts or accounts.

Where a device cannot be selectively wiped, company data will not be placed on it.

When you leave

All company equipment, data, credentials and access must be returned or surrendered on or before your last day. Company data on personal devices and personal accounts must be deleted. Company accounts remain company property.

Responsibilities

Everyone is responsible for reading this policy, following it, and reporting anything that looks wrong.

Managers are responsible for making sure their people have read it, and for requesting access changes when someone joins, changes role or leaves.

[POLICY OWNER OR IT PROVIDER] is responsible for maintaining the controls this policy relies on and for investigating reported issues.

Exceptions

Exceptions must be requested in writing from [POLICY OWNER] and, if granted, documented with a business reason, a scope and an expiration date. An undocumented exception is a violation.

Enforcement

Violations may result in loss of access and disciplinary action up to and including termination. Violations that involve illegal activity may be referred to law enforcement.

Review

This policy is reviewed at least annually by [POLICY OWNER], and after any material change to the business, its systems or its regulatory obligations.

Acknowledgment

I have read and understood the [COMPANY NAME] Acceptable Use Policy, and I agree to follow it.

Name: ______________________________

Signature: __________________________

Date: ______________________________

Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your state’s employment law. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.

EDITABLE VERSION

Want the Word version you can edit?

The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the signature block ready for your team to sign. Tell us where to send it.

Free. About 20 seconds.

THE REST OF THE SET

Nine more, and someone to run them.

This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.

A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.

Book 20 Minutes