Writing an acceptable use policy
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · Compliance
The AUP is the one policy every employee should actually read. Write it for them, not for the auditor.
What it is
The acceptable use policy (AUP) defines how people may use company systems, data, devices, and accounts — and what is off-limits. It is the behavioural backbone that other policies reference, and one of the documents auditors expect every employee to have acknowledged.
What to cover
Acceptable use of company systems and internet; handling of company and customer data per your classification scheme; device and account rules (no credential sharing, MFA, locking screens); prohibited activities; expectations for personal use; and the consequences of violations. Reference the specific policies (data classification, password, BYOD) rather than duplicating them.
Keep it readable
The AUP only works if people read it, so write it in plain language and keep it short. A ten-page legal document gets clicked through unread, which defeats the purpose and looks hollow when an auditor asks an employee what it says.
The evidence
The proof is acknowledgement: every employee has read and accepted the AUP, captured at onboarding and re-acknowledged when it materially changes. SentinelPanda distributes the policy and tracks acknowledgements as evidence tied to your roster.