FREE TEMPLATE
Acceptable Use Policy
Where the line is on company equipment, accounts and networks — written so you can point at it when somebody crosses it, with a signature block at the end.
Where should we send it?
[COMPANY NAME]
Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change
Purpose
This policy sets out how [COMPANY NAME] equipment, accounts, networks and data may be used. It exists so that everyone knows where the line is before someone crosses it, and so the company can act consistently when that happens.
Scope
This policy applies to every employee, contractor, temporary worker, intern and vendor who uses a [COMPANY NAME] account, device or network — including personal devices used for company work.
It covers company-owned computers, phones and tablets; email, file storage and collaboration accounts; the company network and remote access to it; and any third-party service used to conduct company business.
General use
Company systems are provided for company work. Limited personal use is permitted where it does not interfere with your job, consume meaningful company resources, or create risk or liability for the company.
You should have no expectation of privacy in anything created, stored, sent or received on company systems. The company may access, monitor and retain this information as needed to run the business, meet legal obligations, or investigate a suspected violation of this policy.
What is not allowed
The following are prohibited on company systems and accounts:
- Sharing your password with anyone, including coworkers and managers, or using another person’s credentials
- Disabling, bypassing or interfering with security controls — antivirus, endpoint protection, encryption, screen locks, multi-factor authentication or software updates
- Installing software, browser extensions or applications that have not been approved by [POLICY OWNER OR IT PROVIDER]
- Storing company data in a personal account or unapproved service (personal email, personal cloud storage, personal messaging apps, unsanctioned AI tools)
- Connecting unapproved devices to the company network, including personal routers, wireless access points and USB storage
- Using company systems to harass, threaten, defame or discriminate against anyone
- Accessing, storing or distributing material that is illegal, sexually explicit, or that would reasonably be considered offensive in a workplace
- Attempting to access accounts, files or systems you have not been granted access to
- Using company systems for a personal business, political campaign or outside commercial venture
- Sending company data to a personal address or device on your way out the door
Email, messaging and the internet
Treat every message as a permanent record that could be read aloud by someone who is not on your side.
Do not open attachments or click links you were not expecting, even when the sender looks familiar. If a message asks you to move money, change payment details, buy gift cards or provide credentials — verify it by phone, using a number you already have, before acting. Report anything suspicious to [POLICY OWNER OR IT PROVIDER] rather than deleting it quietly.
Company email addresses may not be used to register for personal accounts or services.
Company data
Company data stays in company systems. Do not copy files to personal storage, forward work to a personal address, or paste confidential information — customer records, financial data, credentials, source code, anything covered by a contract or NDA — into a public AI tool, translation site, file converter or other external service.
If your role requires moving data somewhere new, ask first. There is almost always an approved way to do it.
Devices
Lock your screen when you step away. Keep devices updated. Do not leave a laptop visible in a vehicle or unattended in a public place.
Report a lost or stolen device to [POLICY OWNER OR IT PROVIDER] immediately — not the next business day. Speed is the entire difference between a wiped device and a reportable breach.
Personal devices
Where personal devices are permitted for company work, they must have a passcode or biometric lock, current operating-system updates, and the company’s required security software or mobile management profile.
You agree that company data on a personal device may be removed remotely when you leave, or if the device is lost. Removal is limited to company accounts, company applications and company data. [COMPANY NAME] does not perform a full-device wipe of a personal device, and does not access personal photos, messages, contacts or accounts.
Where a device cannot be selectively wiped, company data will not be placed on it.
When you leave
All company equipment, data, credentials and access must be returned or surrendered on or before your last day. Company data on personal devices and personal accounts must be deleted. Company accounts remain company property.
Responsibilities
Everyone is responsible for reading this policy, following it, and reporting anything that looks wrong.
Managers are responsible for making sure their people have read it, and for requesting access changes when someone joins, changes role or leaves.
[POLICY OWNER OR IT PROVIDER] is responsible for maintaining the controls this policy relies on and for investigating reported issues.
Exceptions
Exceptions must be requested in writing from [POLICY OWNER] and, if granted, documented with a business reason, a scope and an expiration date. An undocumented exception is a violation.
Enforcement
Violations may result in loss of access and disciplinary action up to and including termination. Violations that involve illegal activity may be referred to law enforcement.
Review
This policy is reviewed at least annually by [POLICY OWNER], and after any material change to the business, its systems or its regulatory obligations.
Acknowledgment
I have read and understood the [COMPANY NAME] Acceptable Use Policy, and I agree to follow it.
Name: ______________________________
Signature: __________________________
Date: ______________________________
Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your state’s employment law. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.
EDITABLE VERSION
Want the Word version you can edit?
The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the signature block ready for your team to sign. Tell us where to send it.
Free. About 20 seconds.
THE REST OF THE SET
Nine more, and someone to run them.
This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.
A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.
