Skip to content

Writing an acceptable use policy

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · Compliance

The AUP is the one policy every employee should actually read. Write it for them, not for the auditor.

What it is

The acceptable use policy (AUP) defines how people may use company systems, data, devices, and accounts — and what is off-limits. It is the behavioural backbone that other policies reference, and one of the documents auditors expect every employee to have acknowledged.

What to cover

Acceptable use of company systems and internet; handling of company and customer data per your classification scheme; device and account rules (no credential sharing, MFA, locking screens); prohibited activities; expectations for personal use; and the consequences of violations. Reference the specific policies (data classification, password, BYOD) rather than duplicating them.

Keep it readable

The AUP only works if people read it, so write it in plain language and keep it short. A ten-page legal document gets clicked through unread, which defeats the purpose and looks hollow when an auditor asks an employee what it says.

The evidence

The proof is acknowledgement: every employee has read and accepted the AUP, captured at onboarding and re-acknowledged when it materially changes. SentinelPanda distributes the policy and tracks acknowledgements as evidence tied to your roster.

Security policies auditors accept Security awareness training that counts

Run your compliance program in one workspace.