Acceptable Use Policy for Small Business | Checklist

Acceptable Use Policy for Small Business: IT Checklist
An acceptable use policy (AUP) is the short set of rules that tell employees how they may use company internet, email, devices, SaaS apps, and AI tools — and what happens when they do not. For roughly 20–100 person companies, a useful AUP is not a 40-page legal wall; it is a one-to-three page document people will actually read, signed or acknowledged on day one, that covers personal use bounds, prohibited activities, data handling, and how IT enforces it alongside MFA, passwords, MDM, and shadow-IT controls. This playbook is a practical acceptable-use-policy checklist for IT managers: what to include, how to roll it out in 30 days, and how it fits next to device and identity posts — without fake compliance statistics or a hosted-PBX pitch.
What is an acceptable use policy (and how is it different from an employee handbook clause)?
An acceptable use policy is a short, system-focused document that defines how people may use company internet, email, chat, devices, SaaS apps, file shares, remote access, calling apps, and generative AI — and what happens when they break those rules.
A handbook clause often says “follow IT policies” in one paragraph and stops there. An AUP (acceptable use policy) is the operational playbook behind that sentence: personal-use bounds, a plain-English prohibited list, credential and data rules, monitoring expectations, and an acknowledgment path. You can keep a thin handbook pointer and still need a readable AUP people sign on day one.
This post is operational guidance for IT managers — not legal advice, not a free lawyer-reviewed PDF, and not a jurisdiction-specific employment-law template. Align wording with HR/legal for your region; keep the document short enough that staff will finish it.
Why does a small business need an AUP if “we already have MFA, a password vault, and MDM”?
MFA proves who is signing in. A password manager stores secrets cleanly. MDM enrolls and can wipe devices. None of those alone tell people whether lunchtime browsing is fine, whether personal cloud sync on a work laptop is allowed, or whether an unapproved AI tool may touch customer data.
Without a written acceptable use policy, you typically get:
- Shared passwords “just for this week”
- Personal Dropbox/Drive sync on company machines
- Shadow SaaS and browser extensions nobody approved (shadow IT)
- Softphone or calling apps installed outside the approved path
- Generative AI pasting customer or HR data into consumer accounts
Technical controls enforce identity and device posture. The AUP is the behavioural contract that states what is allowed before those controls kick in — and how coaching, tickets, and incident response escalate when they do not.

What should a 20–100 person company put in an acceptable use policy?
Aim for one to three pages. Use a clear section outline (template-shaped, not legal advice):
- Purpose & scope — who is covered; which systems (internet/Wi-Fi, email/chat, company and BYOD devices, SaaS, file shares, VPN/remote access, softphones/calling apps, generative AI).
- Acceptable personal use — one paragraph: lunchtime browsing vs never; personal email on work devices; personal cloud sync.
- Prohibited use — illegal content, harassment, credential sharing, unapproved software installs, customer-data exfiltration, cryptomining, toll fraud / abuse of calling systems — plain English.
- Credentials, MFA, and account sharing — no shared logins; MFA required where IT sets it; vault over sticky notes.
- Devices and remote access — company-owned vs BYOD expectations; enroll where MDM requires it; VPN only on approved paths.
- SaaS, cloud storage, and generative AI — approved catalogue vs request-an-exception path; no customer/HR data in consumer AI by default.
- Monitoring & privacy expectations — plain language about what IT can see on company systems.
- Enforcement & exceptions — warning → ticket → manager → IR for data/credential incidents; who approves exceptions (helpdesk ticketing).
- Acknowledgment / signature — e-sign, LMS checkbox, or paper on day one — and where the record lives.
Optional softphone note: if company calling apps are in scope, say that only approved softphones may place work calls, and point joiners at your enrollment path. Company softphone trials stay on sessiontalk.io — not a hosted-PBX SKU pitch. For personal-device calling detail, keep the AUP as the umbrella and use the BYOD softphone policy for the softphone-specific cut.
AUP vs related IT work
- Artifact: Acceptable use policy — Job: Written rules for how people use IT systems — Not the same as: Shadow IT discovery (finding unmanaged apps)
- Artifact: MFA / password vault — Job: Prove identity / store secrets — Not the same as: Defining allowed behaviour
- Artifact: Mobile device management — Job: Enroll devices, apply technical policies, wipe/lock — Not the same as: The behavioural contract employees sign
- Artifact: BYOD softphone policy — Job: Softphone-specific personal-device calling rules — Not the same as: Company-wide AUP covering all systems
- Artifact: Incident response — Job: Contain and investigate breaches — Not the same as: Day-to-day AUP coaching and acknowledgment
How do you roll out an AUP without freezing hiring or starting a culture war?
- Draft short, enforce what you can detect. Cut jargon and rules you cannot coach or spot-check.
- Pilot with 3–5 managers + IT before all-hands. Fix language that sounds like a gotcha.
- Align with HR on acknowledgment for joiners — criteria only; do not invent employment-law claims in the blog or the AUP draft itself.
- Publish on the intranet / shared drive and link from the device onboarding and offboarding checklist.
- Require acknowledgment before mail/VPN/softphone access for new joiners where your stack allows.
- Run a 15-minute all-hands or async Loom: what changed, why, how to ask for an exception (shadow SaaS → approved path).
- Coach first on low-risk misses; escalate data and credential incidents into IR promptly.
Hiring should not wait on a 40-page rewrite. Ship a readable acceptable usage policy people finish in one sitting, then improve every six months.

What does a 30-day acceptable use policy checklist look like?
Week 1 — Scope & draft
- List systems the AUP must cover: internet/Wi-Fi, email/chat, company and BYOD devices, SaaS apps, file shares, VPN/remote access, softphones/calling apps, and generative AI tools.
- Decide “personal use” bounds in one paragraph (allowed lunchtime browsing vs never; personal email on work devices; personal cloud sync).
- Draft prohibited list: illegal content, credential sharing, installing unapproved software, exfiltrating customer data, cryptomining, toll fraud / abuse of calling systems — keep it plain English.
- Name owners: who writes the AUP, who approves exceptions, who investigates breaches (an AUP breach can become an incident-response ticket).
Week 2 — Align controls & stakeholders
- Map each AUP rule to a real control you already run or plan: MFA, password vault, MDM enrollment, patch cadence, helpdesk ticket path.
- Align with HR/legal for employment acknowledgment — criteria only; this checklist is not legal advice.
- Pilot language with 3–5 managers + IT; cut jargon and anything you cannot actually detect or enforce.
- Decide acknowledgment method: e-sign, LMS checkbox, or paper on day one — and where the record lives.
Week 3 — Publish & onboard
- Publish the AUP on the intranet / shared drive; link it from the joiner pack (device onboarding/offboarding).
- Require acknowledgment before mail/VPN/softphone access for new joiners where your stack allows.
- Run a 15-minute all-hands or async Loom: what changed, why, and how to ask for an exception (shadow SaaS → approved path — shadow IT).
- Update BYOD / softphone expectations so personal-device calling matches the AUP (BYOD softphone policy — AUP is the umbrella; that post is the softphone-specific cut).
Week 4 — Enforce & review
- Define escalation: first warning → ticket → manager → IR for data/credential incidents.
- Spot-check: unapproved browser extensions, personal file sync, shared passwords — fix with coaching first where risk is low.
- Capture metrics you can see: % acknowledged, open AUP-related tickets, repeat offenders — no fake industry benchmarks.
- Schedule a semi-annual review: AI tools, new SaaS, remote-work patterns (IT manager remote-work checklist).
How do AUP, shadow IT, MDM, and remote-work tooling fit together?
Think of layers, not duplicates:
- Acceptable use policy — written behavioural rules and acknowledgment.
- Shadow IT — finding and routing unmanaged apps into the approved path.
- MDM — technical enrollment, policies, wipe/lock on devices that touch mail/VPN/calling.
- MFA + password vault — identity and secrets hygiene the AUP references.
- Remote-work checklist — hybrid tooling context for remote-use clauses.
- BYOD softphone policy — softphone-specific personal-device calling under the AUP umbrella.
- Incident response — when an AUP breach becomes a data or credential incident.
If approved calling apps are in your AUP scope, keep the softphone note optional and point trials at sessiontalk.io. Do not turn this playbook into a PBX product comparison.
FAQ
What is an acceptable use policy?
A short document that defines how employees may use company internet, email, devices, apps, and data — and the consequences of misuse.
Do we need an AUP if we already have MFA and MDM?
Yes. MFA and MDM are technical controls; an AUP is the behavioural contract that tells people what is allowed before those controls kick in.
How long should a small-business AUP be?
Aim for one to three pages people will read. Long legal PDFs that nobody acknowledges fail in practice.
Is an acceptable use policy template enough?
Use a clear outline (sections above) and adapt it with HR/legal for your jurisdiction — this post is operational guidance, not legal advice.
How often should we update the AUP?
At least every six months, or when you add major tools (new AI, new VPN, new softphone/MDM path).


