Free it operations policy template

Free IT Acceptable Use Policy Template for Employees

An IT acceptable use policy is the set of rules employees sign that explains how they may use company computers, phones, email, internet, software and data, what is prohibited, and what monitoring they should expect. You need one because most breaches still start with everyday actions such as clicking a phishing link, installing unapproved software or sending data to a personal account, and a signed policy gives you one clear standard to train on, enforce and show to customers, insurers and auditors.

An IT acceptable use policy (AUP) is a signed, employee-facing document that sets the rules for using an organization's computers, networks, accounts, software and data, including personal use, prohibited activities and disclosed monitoring.

Template version
v1.0.0
Last reviewed
September 27, 2026
Sections
18
Guided phases
5
Time to complete
About 5 minutes
Price
Free

Why does this policy matter now?

What is inside the IT Acceptable Use Policy template?

18 sections, ending with the document control table and the legal notice every template carries. Select any section to jump to it in the sample below.

  1. 1. PurposeWhy the company sets rules for its technology and what they protect.
  2. 2. ScopeWho the policy covers, what technology it covers, related policies and your rights.
  3. 3. Key TermsPlain-language definitions of the terms used in the policy.
  4. 4. General ResponsibilitiesCompany ownership, business purpose, protecting your login and approved lists.
  5. 5. Company Devices and Personal DevicesScreen locks, physical care, lost devices, personal devices, shared equipment and returning equipment.
  6. 6. Software and Cloud ServicesWho installs software, licensing, unapproved cloud services and browser extensions.
  7. 7. Email, Messaging and PhishingProfessional use of email and chat, forwarding rules, business texting, and spotting phishing and payment fraud.
  8. 8. Internet Use and Personal UseAcceptable internet use, web filtering and the limits on personal use of company technology.
  9. 9. Storing, Sharing and Protecting InformationApproved storage, file sharing, removable media, printing and rules for regulated data.
  10. 10. Social Media and Public CommunicationWho may speak for the company online, and the narrow limits on personal posts.
  11. 11. Prohibited ActivitiesActivities that are never allowed on or with company technology.
  12. 12. Monitoring and PrivacyWhat the company monitors, why, the limits it follows, and your privacy on company systems.
  13. 13. Training and ReportingSecurity training, what to report, how fast, and the no-retaliation promise.
  14. 14. Enforcement, Exceptions and ReviewConsequences of violations, how exceptions are approved, and how the policy stays current.
  15. 15. Related Laws, Standards and PoliciesThe laws and standards this policy is designed to help meet, based on the data you handle.
  16. 16. Employee AcknowledgmentThe statement each employee signs, including the monitoring notice and whistleblower notice.
  17. 17. Document Control and Revision HistoryDocument ID, version, effective date, next review, owner and approver, plus a revision history table.
  18. 18. Template Notice and Legal DisclaimerThe starter-template disclaimer and the reminder to have qualified counsel review the policy.
Template changelog
  • v1.0.0, September 27, 2026

    • Initial release: devices, software, email, internet and personal use, data handling, removable media, social media, disclosed monitoring, protected employee rights, reporting and employee acknowledgment.

Read the full sample IT Acceptable Use Policy

This sample uses the recommended answer to every question and a placeholder company name. Build your own version to put in your organization's name, owners and choices.

Sections in this policy
Sample[Company Name]

IT Acceptable Use Policy

Document ID
PDC-AUP-SAMPLE
Document version
1.0
Template version
v1.0.0
Effective date
September 27, 2026
Next review
September 27, 2027

1. Purpose

This policy sets the rules every [Company Name] employee must follow when using company computers, phones, networks, accounts, software, email, internet access and data (together, "company technology"). It also tells you what the company monitors and why.

Most security incidents start with an ordinary action: clicking a convincing link, installing a free program, plugging in a USB drive, or sending a file to a personal account. These rules exist to protect the company, its customers and you from those mistakes, and to keep company systems available for the work they are meant to do.

Following this policy supports the company in meeting its legal, contract and customer obligations. Where a law, regulation or contract sets a stricter requirement, the stricter requirement applies. If you are not sure whether something is allowed, stop and ask the IT Manager before you act.

2. Scope

Who it covers. This policy applies to all employees of [Company Name], and to temporary workers, interns, contractors and anyone else who uses company technology or handles company or customer information ("users").

What it covers. It covers all company technology, wherever and whenever it is used, including at home and while traveling. It also covers any personal device or account used to access company email, files or systems, but only for the company information and company apps on it.

Artificial intelligence. Use of AI tools, including AI features built into software you already use, is governed by the separate AI Acceptable Use Policy where the company has adopted one. Until then, you must not enter confidential, customer or personal information into any AI tool the company has not approved.

Other policies. This policy works alongside the company's information security, password, remote work and device, incident response and HR policies, where adopted. When two rules conflict, follow the stricter rule.

Your rights. Nothing in this policy prohibits or restricts you from discussing or sharing information about your wages, hours or other terms and conditions of employment, including on social media, from acting together with coworkers to improve working conditions, from filing a charge or complaint with, or taking part in an investigation by, any government agency, or from reporting a possible violation of law. This policy will not be interpreted or applied to interfere with those rights.

3. Key Terms

Company technology
Computers, phones, tablets, printers, networks, Wi-Fi, accounts, email, software, cloud services and data that the company owns, leases, licenses or manages.
Company device
Any computer, phone, tablet or other device the company provides to you or manages.
Personal device
A phone, tablet or computer that you own, even if you use it for work.
Company account
Any login the company creates or pays for, such as your email, file storage, business applications and customer or supplier portals used for company work.
Confidential information
Nonpublic business information of the company or its customers and suppliers, such as customer lists, pricing, bids, drawings, financial results, security settings and personal information about customers. It does not include information about your own wages, hours or working conditions.
Removable media
USB drives, external hard drives, memory cards, and phones or cameras connected to a computer as storage.
Phishing
A fake email, text, call or message designed to trick you into clicking a link, opening a file, sharing a password or sending money.
Monitoring
Automated or manual review of how company technology is used, as described in the Monitoring and Privacy section.

4. General Responsibilities

Company property. Company technology, and everything created, sent, received or stored on it, belongs to the company. It is provided so you can do your job.

Your login is yours alone. You are responsible for activity under your accounts. You must:

  • Follow the company's password rules, and never share your password or one-time codes with anyone, including coworkers, managers or someone who says they are from IT
  • Use multi-factor authentication wherever the company provides it, and never approve a sign-in prompt you did not start
  • Never use another person's account, or let anyone use yours
  • Use your company account for company work, and never use a personal email or personal cloud account for company business

Approved technology. The IT Manager maintains the list of approved hardware, software and cloud services and will share it on request. Only technology on that list, set up by or approved in writing by the company, may be used for company work or connected to the company network.

Security tools. Never disable, bypass, uninstall or interfere with antivirus, device management, encryption, web filtering, backup or other security tools, and never try to get around access restrictions, even to get your work done faster. Ask IT for help instead.

5. Company Devices and Personal Devices

Caring for company devices. You must:

  • Lock your screen whenever you step away. Screens also lock automatically after 15 minutes of inactivity, and you must not change that setting.
  • Restart when prompted so security updates install, and never postpone updates for more than a day without IT approval
  • Keep devices with you or locked away when traveling, never leave them visible in a vehicle, and never check them as luggage
  • Use only company Wi-Fi, a trusted home network or a mobile hotspot for company work, and avoid public Wi-Fi for sensitive tasks
  • Not let family members, friends or anyone else use a company device
  • Not take company devices out of the country without approval from IT

Lost or stolen devices. Report a lost or stolen company device, or a personal device with company apps on it, to the IT Manager right away, and no later than 1 hour after you notice. Early reports let the company lock or wipe the device before anyone can use it.

Personal devices. You may use a personal phone or tablet for company email, chat and files only through the company-managed apps IT sets up, and only if the device:

  • Has a screen lock with a PIN, password or biometric
  • Runs an operating system version that still receives security updates
  • Is not jailbroken or rooted

Company management applies only to the company apps and data on your device. The company can remove company data from those apps, for example when a device is lost or you leave, but it does not see or remove your personal photos, messages or apps.

Shared computers. Sign out of shared computers, such as front desk, conference room or break room computers, after every use, and never save company files on them.

Leaving the company. On or before your last day, you must return all company devices, drives, badges and equipment, and must not keep, copy or forward company information. Company accounts are disabled when you leave.

6. Software and Cloud Services

Installing software. Only IT may install software on company devices, and employees do not have administrator rights. This includes free programs, trial versions, browser extensions, plug-ins and utilities. Request anything you need through IT.

Licensing. Use software only as its license allows. Do not copy company software to personal devices, share license keys, or install pirated, cracked or unlicensed software on any device used for company work.

Cloud services and apps. Do not sign up for, or use, any online service, app or website account for company work unless the company has approved it, even if it is free. This includes file sharing, note-taking, scheduling, e-signature, design, project management and messaging services. Request new services through the IT Manager, and include what you need it for and what information it would hold.

Downloads. Download files and apps only from trusted sources. Never run a program, script or macro that arrived unexpectedly by email, text or chat, or that a website or pop-up tells you to run. If a pop-up says your computer is infected or tells you to call a phone number, close it and call IT.

7. Email, Messaging and Phishing

Professional use. Write every email and message as if it could be read by a customer, a court or a news reporter, because it might be. Company email and messaging must not be used to send harassing, threatening, discriminatory, obscene or illegal content, chain letters or mass personal messages.

Forwarding and personal email. Do not forward company email to a personal email account, set up automatic forwarding outside the company, or send company files to yourself at a personal address. Do not use a personal email account for company business.

Business texting. You may use text messages for quick coordination, such as arrival times, meeting places or a reminder to check email. Decisions, orders, change requests, approvals, pricing and customer commitments must be made or confirmed in company email or company systems, so there is a company record of them. Never send confidential or personal information by text message.

Phishing. Be suspicious of any message that is unexpected, urgent, or asks you to click a link, open an attachment, sign in, share information or send money, even if it appears to come from a coworker, customer or supplier you know. Use the report phishing button where one is provided, or forward the message to IT, then delete it. If you clicked a link, opened a file or entered your password, report it immediately.

Payment and banking changes. Before you change anyone's bank or payment details, send a wire or payment because of an email, or buy gift cards because someone asked, confirm the request by calling the person at a phone number from company records, not one given in the message. Do this every time, even when the request looks like it comes from an executive. Business email compromise is one of the costliest crimes reported to the FBI.

8. Internet Use and Personal Use

Internet use. Internet access on company devices and networks is provided for company business. You must not visit, download or stream content that is sexually explicit, hateful, violent, related to illegal activity or gambling, or that could create a hostile work environment. Do not use file-sharing, torrent, proxy or VPN services the company has not approved.

Web filtering. The company filters web access and blocks websites that are known to be malicious or that fall into risky categories. If a site you need for work is blocked, ask IT to review it. Do not try to get around the filter.

Limited personal use. Brief, occasional personal use of company devices and internet access is allowed, such as checking the news, a personal appointment or a family message on a break, as long as it:

  • Does not interfere with your work, your coworkers or company systems
  • Happens on your own time, such as breaks and lunch, except for brief necessary messages
  • Does not involve a personal business, outside job, political campaign or fundraising
  • Does not involve downloading or installing software, streaming large amounts of video, or storing personal files on company systems
  • Follows every other rule in this policy

Personal use is never allowed on production, shop floor, payment or other systems the company designates as business-only.

Personal devices on company networks. Connect personal phones and devices only to the guest Wi-Fi network, never to the company network or to company computers, unless IT has approved it.

9. Storing, Sharing and Protecting Information

Where information lives. Store and share company information only in company systems, such as company email, file storage and business applications. You may also use a portal or file-sharing service that a customer or supplier provides and requires for their own work, using the company account they set up for you, and only for that work.

Personal accounts and storage. Never store or send company information using personal cloud storage, personal email, personal messaging apps or personal devices, other than through the company-managed apps described in this policy.

Share only what is needed. Share information only with people who need it for their work, use the most limited sharing setting that works, and remove access when a project ends. Do not create "anyone with the link" shares for confidential information.

Removable media. Use only encrypted, company-issued USB drives and external drives for company information, and only when company file sharing will not work. Never plug in a drive you found, received at an event or were sent unexpectedly. Hand it to IT instead. Report a lost drive right away.

Paper and printing. Collect printouts right away, lock up confidential papers, and shred them when they are no longer needed.

Personal information. Personal information, such as Social Security numbers, driver's license numbers, bank account numbers, dates of birth and medical details about employees or customers, must be stored only in approved company systems and sent only by approved secure methods, such as encrypted email or company file sharing. It must never be kept in personal accounts, on personal devices or on unencrypted removable media. State laws, including those of North Carolina, can require the company to notify people when their personal information is exposed, so report any possible exposure right away.

10. Social Media and Public Communication

Speaking for the company. Only employees the company has authorized may post on company social media accounts, respond to reviews or comments as the company, or speak to the media for the company. Company accounts must use company-owned logins with multi-factor authentication, and the IT Manager keeps the list of who has access.

Your personal accounts. What you post on your personal accounts is your own business, subject to these limits:

  • Do not suggest that you speak for the company. If you post about the company or its products, make clear the views are your own.
  • Do not post confidential information, such as customer names and project details the customer has not made public, pricing, bids, drawings, security information, or personal information about customers.
  • Do not harass, threaten or discriminate against coworkers, customers or anyone else.
  • Do not post photos from inside customer sites or restricted work areas without permission.

These limits do not restrict the rights described under Your Rights in the Scope section, including discussing wages, hours and working conditions with coworkers or the public.

11. Prohibited Activities

You must never use company technology, or any technology used for company work, to:

  • Break the law, or help anyone else break it
  • Harass, threaten, bully or discriminate against anyone, or view, send or store sexually explicit, hateful or violent material
  • Access, copy, change or delete information or systems you are not authorized to use, or try to learn other people's passwords
  • Scan, test or probe networks or systems, or install hacking, password-cracking, packet capture or remote access tools, unless it is part of your approved job
  • Connect unapproved routers, wireless access points, switches, cameras or other devices to the company network
  • Mine cryptocurrency, run personal servers or share company internet access
  • Send spam, chain letters or unauthorized mass email
  • Download, copy or share pirated software, music, movies or other material you do not have the right to use
  • Impersonate another person, or send messages that hide or fake who sent them
  • Take, copy or send company or customer information for any purpose outside your job, including before leaving the company

12. Monitoring and Privacy

Notice of monitoring. [Company Name] monitors the use of company technology to protect its systems and information, to meet legal and customer requirements, to investigate problems, and to support its operations. This policy is your written notice of that monitoring. Depending on the system, the company monitors:

  • Email, chat and messages sent or received through company accounts, including attachments
  • Websites visited and internet activity on company devices and networks, including web filtering logs
  • Security, software and activity logs on company devices, including the software installed and security alerts
  • Sign-ins, file activity and sharing in company cloud services such as email, file storage and business applications

No expectation of privacy on company systems. Company technology belongs to the company. You should not expect privacy in anything you create, send, receive, browse or store on company devices, accounts or networks, including personal messages and files. Deleting something does not mean it is gone, because systems keep logs and backups. The company may access, review, copy, preserve and disclose that information when it has a legitimate business reason, as the law allows.

Limits the company follows. Monitoring information is restricted to the people who need it for security, IT support, legal or HR purposes. The company will not:

  • Ask for the password to your personal email, social media or other personal accounts
  • Monitor your personal device beyond the company apps and data on it
  • Use monitoring to watch, record or interfere with employees discussing wages or working conditions, or with lawful activity protected by law

Reviewing an individual. A targeted review of a specific person's email, files or activity, other than automated security alerts, requires approval from the Chief Executive Officer or a person the Chief Executive Officer designates, and a record of why it was done.

State notice requirements. Some states, including New York, Connecticut and Delaware, require a specific written notice, acknowledgment or posting before an employer monitors email, phone or internet use. Where those laws apply, the company provides that notice, and your signed acknowledgment of this policy is part of it.

13. Training and Reporting

Security awareness training. You must complete security awareness training when you join the company and at least once a year after that. The company may also send simulated phishing messages to help you practice. Clicking one is a chance to learn, not a disciplinary matter by itself.

What to report. Report right away, and no later than 1 hour after you notice, if:

  • A company device, or a personal device with company apps, is lost or stolen
  • You clicked a suspicious link, opened a suspicious file, or entered your password on a site you now doubt
  • You see a sign-in or multi-factor prompt you did not start, or think someone else knows your password
  • Company or customer information was sent to the wrong person, posted, lost or shared in a way this policy does not allow
  • A device behaves strangely, such as unexpected pop-ups, files you cannot open, or security warnings
  • You see someone using company technology in a way that breaks this policy

How to report. Contact the IT Manager. If you think a device is infected, disconnect it from the network but leave it powered on, and do not try to fix it yourself. Do not delete emails, files or messages involved unless you are told to.

No retaliation. You will not be disciplined for reporting a mistake or concern in good faith, and a prompt, honest report counts in your favor. Hiding a problem, or delaying a report on purpose, is a violation of this policy. The company does not allow retaliation against anyone who reports in good faith.

14. Enforcement, Exceptions and Review

Consequences. Violating this policy may lead to loss of access to company technology and to discipline, up to and including termination of employment or of a contract, consistent with company policy and applicable law. The company may report illegal activity to law enforcement and may seek to recover losses caused by intentional misconduct.

Exceptions. Any exception to this policy must be requested in writing from the IT Manager, explaining the business need and how the risk will be limited. Exceptions are approved by the IT Manager, recorded, limited in time, and reviewed at least once a year. No exception can allow something that breaks the law or a contract.

Review. The IT Manager is responsible for this policy and will review it no later than September 27, 2027, and sooner after a significant security incident, a new law or contract requirement, or a major change in company technology. The company will tell you when the rules change.

16. Employee Acknowledgment

Whistleblower immunity notice. Under the Defend Trade Secrets Act, 18 U.S.C. 1833(b), you will not be held criminally or civilly liable under any federal or state trade secret law for disclosing a trade secret in confidence to a federal, state or local government official, directly or indirectly, or to an attorney, solely for the purpose of reporting or investigating a suspected violation of law, or in a complaint or other document filed under seal in a lawsuit or other proceeding.

I have received and read the [Company Name] IT Acceptable Use Policy, effective September 27, 2026. I understand it, I have had the chance to ask questions, and I agree to follow it. I understand that the company monitors company technology as described in the Monitoring and Privacy section, and that I should not expect privacy in anything I create, send, receive or store on company systems. I understand that violations may lead to discipline, up to and including termination, that the company may update this policy, and that this acknowledgment is not a contract of employment.

Employee name (printed)

Job title

Employee signature

Date

17. Document Control and Revision History

FieldValue
DocumentIT Acceptable Use Policy
Organization[Company Name]
Document IDPDC-AUP-SAMPLE
Document version1.0
Effective dateSeptember 27, 2026
Next scheduled reviewSeptember 27, 2027
Policy ownerIT Manager
Approved byChief Executive Officer
Source templatePreferred Data Corporation IT Acceptable Use Policy template v1.0.0

Revision history. Record every change to this policy below. Increase the document version and obtain approval again each time the policy is revised.

VersionDateDescription of changeApproved by
1.0September 27, 2026Initial adoption, generated from template v1.0.0.Chief Executive Officer
BlankBlankBlankBlank
BlankBlankBlankBlank

18. Template Notice and Legal Disclaimer

This document was generated from a starter template provided by Preferred Data Corporation. It is general information only. It is not legal advice and it is not a substitute for advice from a licensed attorney.

Preferred Data Corporation is not a law firm. It makes no representation that this document is complete, current, or suitable for any particular organization, industry, jurisdiction, or regulatory requirement, and it is not responsible or liable for any use of this template or of any policy created from it. You are solely responsible for how you adapt, adopt, and enforce it.

Laws, regulations, insurance requirements, and contracts that apply to your organization may require different or additional terms. Before you adopt, publish, or rely on this policy, and in every case where you have a legal, regulatory, or contractual obligation, have it reviewed by qualified legal counsel.

How does the IT Acceptable Use Policy generator work?

5 short phases, about 5 minutes in total. Every question is pre-filled with a best-practice answer and the reason we recommend it.

  1. Your organization

    The basics that shape who the policy covers and which obligations it has to respect.

  2. Devices and software

    Personal use, personal devices, software installation and removable media.

  3. Email, internet and social media

    Web filtering, where files may be shared, business texting and who speaks for the company online.

  4. Monitoring and enforcement

    What the company monitors, how fast problems must be reported, and how often staff sign and train.

  5. Ownership and review

    Who owns the policy, who approves it, and how it stays current.

  6. Review and download

    Preview your policy, unlock the full document and download it as a PDF with a document ID and review date.

Start the generator

Who should adopt this policy?

  • Owners and managers of small and mid-sized businesses that have never written down their computer, email and internet rules
  • Manufacturers, contractors and distributors with shared, shop floor and jobsite devices
  • Companies answering cyber insurance applications or customer security questionnaires that ask for a signed acceptable use policy
  • HR and IT leaders who need a monitoring notice and employee acknowledgment for onboarding
  • Businesses that handle payment card, health, defense or customer financial data and must document end-user rules

Which frameworks does this template align with?

The template was written against these public frameworks, laws and standards. Alignment is not certification, and your obligations depend on your industry and location.

Framework or lawWhy it matters for this policy
PCI Security Standards Council, PCI DSS v4.0.1(opens in a new tab)Requirement 12.2.1 requires acceptable use policies for end-user technologies, including explicit approval and a list of approved hardware and software.
HIPAA Security Rule, 45 CFR 164.310 Physical safeguards(opens in a new tab)Requires policies on workstation use, workstation security and the movement of devices and media that hold health information.
NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems(opens in a new tab)The CUI security requirements behind CMMC, including rules of behavior, media protection and awareness training.
FTC Safeguards Rule: What Your Business Needs to Know(opens in a new tab)Expects security awareness training, access limited to business need, and monitoring of user access to customer information.
National Labor Relations Board, Interfering with employee rights (Section 7 and 8(a)(1))(opens in a new tab)Explains that work rules must not reasonably tend to inhibit employees from exercising their Section 7 rights, which shapes the social media and monitoring sections.
New York Civil Rights Law Section 52-c, electronic monitoring notice(opens in a new tab)Requires written notice of electronic monitoring upon hiring, an employee acknowledgment and a posted notice, which the acknowledgment block is designed to support.
Defend Trade Secrets Act, 18 U.S.C. 1833(opens in a new tab)Requires employers to give employees notice of whistleblower immunity in documents that govern confidential information.

IT Acceptable Use Policy questions, answered

What should an IT acceptable use policy include?

At minimum: who and what it covers, rules for company devices and personal devices, software installation, email and internet use, personal use, data storage and sharing, removable media, social media on behalf of the company, prohibited activities, a clear monitoring notice, how to report problems, consequences, and a signed employee acknowledgment. It should also state that nothing in it limits employees from discussing working conditions or reporting possible violations of law to a government agency.

Can employers monitor employee computers and email?

Generally yes, on company-owned devices, accounts and networks, when the monitoring has a legitimate business purpose and employees are told about it. Some states require a specific notice: New York Civil Rights Law Section 52-c requires written notice upon hiring, an employee acknowledgment and a posted notice, and Connecticut and Delaware have similar notice laws. Monitoring must not target employees for discussing wages or working conditions, which the National Labor Relations Act protects.

Is an acceptable use policy legally required?

No single U.S. law requires every business to have one, but several rules effectively do. PCI DSS v4.0.1 Requirement 12.2.1 requires documented acceptable use policies for end-user technologies, including a list of approved hardware and software, and the HIPAA Security Rule requires policies on workstation use. Cyber insurers, CMMC assessors and customer security questionnaires also routinely ask for a signed acceptable use policy.

Do employees need to sign an acceptable use policy?

Yes, a signature is best practice and sometimes required. The signed acknowledgment proves each employee received the rules and the monitoring notice, which matters in discipline decisions and in states such as New York that require employees to acknowledge monitoring notices. Collect it at hire, again whenever the policy changes significantly, and ideally every year with security awareness training.

Can an acceptable use policy restrict what employees post on social media?

Only narrowly. A policy can limit who speaks officially for the company, prohibit harassment and illegal conduct, and protect genuine trade secrets and customer data. Section 7 of the National Labor Relations Act protects employees, union or not, who discuss wages and working conditions, including online, so broad bans on criticizing the company or discussing pay can be unlawful.

Should employees be allowed to use work computers for personal tasks?

Most small and mid-sized businesses allow limited personal use, such as checking the news or a personal appointment on a break, because total bans are rarely enforced and invite selective discipline. The policy should say that personal use must be brief, must not interfere with work or security, and has no expectation of privacy on company systems. Production, shop floor and payment systems should be excluded entirely.

What is the difference between an IT acceptable use policy and an AI acceptable use policy?

An IT acceptable use policy covers all company technology: devices, accounts, email, internet, software, data and monitoring. An AI acceptable use policy adds the specific rules for ChatGPT, Copilot and other AI tools, such as which AI tools are approved and what information may never be entered into them. Most businesses adopt both and have employees sign them together.

Related policy templates

Services that put this policy into practice

Want help rolling out your IT Acceptable Use Policy?

A policy works when the tools, training and controls behind it do. Preferred Data Corporation helps North Carolina businesses put policies like this one into practice, from High Point since 1987.