What Is an Acceptable Use Policy?

Compliance
By eMonitor Editorial Team
9 min read

An acceptable use policy sets out how employees may use company devices, networks, and accounts, and what happens when they do not. Done well it prevents incidents and makes enforcement defensible. Here is what to include and how to make it stick.

An acceptable use policy, usually shortened to AUP, is the document that tells everyone in an organization how they may and may not use its technology: company laptops, the network, email and messaging accounts, cloud services, and the data that flows through them. It exists for two reasons. The first is prevention: most security and conduct incidents involve ordinary employees who genuinely did not know a behavior was prohibited. The second is enforceability, because acting on a breach is far harder when nobody can point to a rule that was communicated and acknowledged. This guide covers what an AUP is, what belongs in one, how monitoring and disclosure fit in, and how to write and enforce a policy that actually holds up.

What an acceptable use policy is

An acceptable use policy is a written statement of the rules governing employee use of an organization's IT resources. It defines what those resources are, what constitutes acceptable and unacceptable use, what the organization monitors, and what the consequences of a breach are. It is normally acknowledged in writing by every employee, often at onboarding and again after material changes.

It sits alongside, rather than inside, the wider security and HR policy set. A security policy governs how the organization protects systems; an AUP governs how people may use them. That distinction matters because the AUP is the one that employees actually have to read and follow, which is why clarity beats comprehensiveness in drafting it.

Its practical function is to convert unwritten assumptions into stated expectations. Most people have never been told, precisely, whether they may use a work laptop for personal browsing, install software, forward documents to a personal address, or use an unapproved cloud tool. In the absence of a policy, everyone answers those questions for themselves, and some answers create real risk.

One practical test of a finished policy is whether a new starter could read it once and correctly answer the questions people actually have: may I browse personal sites on my lunch break, may I install this tool, may I email a document to myself to finish at home, is my messaging read. If your policy leaves any of those genuinely ambiguous, it will be resolved by individual guesswork, which is precisely the situation the document exists to prevent.

What to include in an AUP

Start with scope: which people, devices, networks, and accounts the policy covers, explicitly including personal devices used for work if that is permitted. Then define acceptable use in plain terms, generally that resources are provided for business purposes with reasonable personal use permitted, if that is your position, and be specific about what reasonable means.

Next, state prohibited use clearly and with examples: installing unapproved software, sharing credentials, moving company data to personal storage or email, accessing unlawful or harassing content, bypassing security controls, and using unapproved cloud services for company data, which is the shadow IT problem most organizations have without knowing it.

Then cover data handling, security obligations such as password and device rules, and, critically, a monitoring and privacy section stating what the organization records, on which devices, during what periods, who can access it, and how long it is retained. Finish with consequences of breach, a review date, and an acknowledgement the employee signs. A ready-made starting point is available in our acceptable use policy template.

Monitoring, disclosure, and privacy

The monitoring section is the part that most often decides whether an AUP is defensible. In many jurisdictions employers must disclose workplace monitoring, and in several the disclosure must be specific about what is collected and why. An AUP that quietly reserves a broad right to monitor everything is both weaker legally and more damaging to trust than one that states the actual scope plainly.

Write it as a boundary rather than a licence. State that monitoring covers work devices and accounts during working time, name the categories collected such as application and website activity or time and attendance, and say what is not collected, personal devices, personal accounts, and activity outside working hours. Specificity here reassures far more than vague breadth, a principle our guide to monitoring versus surveillance sets out.

Then follow through in the rollout. A policy that appears in an onboarding pack nobody reads is not meaningful disclosure; announcing it, explaining why, and answering questions is. Our guide to announcing monitoring covers doing this well, and the same conversation is the natural moment to introduce the AUP as a whole.

How to write one people will follow

Keep it readable. An AUP written in dense legal language achieves compliance on paper and nothing in practice, because the people whose behavior it is meant to shape will not get past the second page. Aim for plain language, short sections, and concrete examples of the behaviors you care about most.

Be honest about personal use. Policies that ban all personal use of work devices are almost universally ignored, and a rule everyone breaks daily undermines every other rule in the document. Permitting reasonable personal use, while being clear about what is never acceptable, produces a policy that people can actually follow and that you can therefore actually enforce.

Explain the reasoning. People follow rules they understand far more reliably than rules they are simply given, so a sentence explaining why unapproved cloud storage is prohibited, because company data leaves systems you can protect and recover, does more for compliance than a longer list of prohibitions. Then have it reviewed by whoever owns legal risk before it is issued.

Enforcing an AUP fairly

Enforcement has to be consistent to be legitimate. A policy applied to some people and not others, or invoked only when a manager wants a reason, is worse than no policy at all, because it converts a governance document into an instrument of arbitrary treatment and creates exactly the discrimination exposure you were trying to avoid.

Proportionality matters as much as consistency. Most breaches are careless rather than malicious, an unapproved tool adopted to get work done, a document emailed home to finish in the evening, and treating those identically to deliberate data theft is both unjust and counterproductive. Graduated responses, with education for genuine mistakes, keep the policy credible.

Keep the evidence standard high. If you act on a breach, the record should show what the policy said, that the employee acknowledged it, and what specifically occurred, drawn from proportionate monitoring rather than impressions. That combination, clear rule, documented acknowledgement, factual evidence, is what makes enforcement hold up if it is ever challenged.

Make your monitoring disclosure specific

eMonitor's work-hours-only tracking, role-based access, and employee self-access give you a monitoring scope you can state plainly in your AUP and actually stand behind.

Keeping the policy current

An AUP decays quickly because the technology it governs changes constantly. A policy written before generative AI tools entered daily work, for example, says nothing about pasting company data into a chatbot, which is now one of the most common ways sensitive information leaves an organization.

Set a fixed review cycle, annually is typical, and additionally review after any material change: new tooling, a shift to remote or hybrid work, a merger, or a new regulatory obligation. Each review should ask what employees are actually doing that the policy does not address, which is a question the monitoring data can answer directly.

Re-acknowledge after substantive changes. A policy people signed three years ago covering systems you no longer run is not meaningful consent, and re-issuing it periodically is both a compliance safeguard and a useful prompt to re-explain the reasoning. Treated as a living document rather than an onboarding formality, an AUP quietly prevents most of the incidents it describes.

Best practices

What makes an acceptable use policy work:

  • Define scope precisely: people, devices, networks, accounts, personal devices.
  • Give concrete examples: abstract prohibitions do not change behavior.
  • State monitoring specifically: what is collected, when, by whom, for how long.
  • Say what you do not monitor: specificity reassures more than broad rights.
  • Permit reasonable personal use: rules everyone breaks undermine every rule.
  • Explain the reasoning: understood rules are followed far more reliably.
  • Enforce consistently and proportionately: careless is not malicious.
  • Review annually and re-acknowledge: the technology changes constantly.

An acceptable use policy earns its keep twice: it prevents the ordinary mistakes that cause most incidents, and it makes acting on the serious ones defensible. Both depend on the same qualities, clarity, honesty about monitoring, and consistent application.

Written that way, an AUP stops being a formality in an onboarding pack and becomes the document that quietly keeps an organization out of trouble.

Monitoring you can disclose plainly

The monitoring section is where most acceptable use policies become either defensible or fragile, and that depends on whether the scope you state matches what your tools actually do. eMonitor is built to be described precisely: tracking on work devices during working hours, categories rather than content, role-based access, and employee self-access to their own data.

That specificity is what lets you write a monitoring clause that reassures rather than alarms, and stand behind it if it is ever challenged. It runs across Windows, Mac, Linux, and Chromebook. Trusted by 1,000+ companies worldwide and rated 4.8/5 on Capterra, eMonitor starts at $3.90 per user with a 7-day free trial.

If your AUP reserves broad monitoring rights you cannot describe in detail, tighten both the policy and the tooling together. Start a free trial and see exactly what a proportionate monitoring scope looks like in practice.

Frequently Asked Questions

What is an acceptable use policy?

An acceptable use policy (AUP) is a written statement of how employees may use an organization's IT resources, devices, networks, email, and cloud services, what is prohibited, what the organization monitors, and what happens if the policy is breached. It is normally acknowledged in writing by every employee.

What should an acceptable use policy include?

Scope of people and devices covered, acceptable and prohibited use with concrete examples, data handling and security obligations, a specific monitoring and privacy section, consequences of breach, a review date, and an employee acknowledgement.

Why do you need an acceptable use policy?

For prevention and enforceability. Most security and conduct incidents involve employees who did not know a behavior was prohibited, and acting on a serious breach is far harder when no communicated, acknowledged rule exists to point to.

What is the difference between an AUP and a security policy?

A security policy governs how the organization protects its systems and is aimed largely at IT. An acceptable use policy governs how people may use those systems and is aimed at every employee, which is why readability matters far more in an AUP.

Should an acceptable use policy mention monitoring?

Yes, and specifically. Many jurisdictions require disclosure of workplace monitoring, and a policy that states exactly what is collected, on which devices, during what hours, and who can access it is both more defensible and less damaging to trust than one reserving broad, vague rights.

Can an AUP ban all personal use of work devices?

It can, but such policies are almost universally ignored, and a rule everyone breaks daily undermines every other rule in the document. Permitting reasonable personal use while being clear about what is never acceptable produces a policy people can follow and you can enforce.

How do you enforce an acceptable use policy?

Consistently and proportionately. Apply it to everyone equally, distinguish careless mistakes from deliberate misuse with graduated responses, and base any action on a clear rule, a documented acknowledgement, and factual evidence from proportionate monitoring rather than impressions.

How often should an AUP be reviewed?

At least annually, plus after any material change such as new tooling, a shift to remote work, a merger, or a new regulatory obligation. Technology changes fast, and policies written before tools like generative AI entered daily work often say nothing about them.

Do employees have to sign an acceptable use policy?

Signed acknowledgement is standard practice and strongly advisable, because it evidences that the rules were communicated. Re-acknowledgement after substantive changes matters too, since a policy signed years ago covering systems you no longer run is not meaningful consent.

Is an acceptable use policy legally required?

An AUP itself is not usually mandated, but the disclosure it contains often is: many jurisdictions require employers to inform employees about workplace monitoring, and various regulations require documented controls over data handling, which an AUP is the natural place to record.

Write an AUP that holds up

eMonitor gives you a monitoring scope specific enough to state plainly and defend. Start a 7-day free trial.