What Is an Acceptable Use Policy? (AUP Guide + Free Template)

An acceptable use policy (AUP) sets out how employees may use company technology — devices, networks, email, and accounts. It protects the business from security risks and legal exposure, and gives everyone a clear, shared understanding of what is and isn't allowed.

This guide covers what an AUP should include, why every organization needs one, and how to roll it out so it actually holds up.

💻 IT Acceptable Use Policy & Agreement
Onboarding a new hire — or rolling out the rules for company laptops, email, and AI tools? Get it acknowledged the clean way with a proper IT Acceptable Use Policy (AUP) & Agreement the employee reads and signs. PaperKit drafts a polished one in seconds: pick the focus — GENERAL IT & SYSTEMS, INTERNET & EMAIL, SOCIAL MEDIA & ONLINE CONDUCT, or AI & GENERATIVE AI — and the whole form reshapes (the title, the framing, which rules are emphasised, the ready-made Permitted/Prohibited lists, and the closing). The centerpiece is a clean TWO-COLUMN list — ✓ Permitted uses on the left, ✕ Prohibited uses on the right — seeded with sensible defaults for the focus you chose and fully editable so you can match your own policy. Then choose the acknowledgments the employee attests to from a ready-made checklist — read & understand the policy, use systems for authorized purposes only, protect credentials, no unauthorized software or data exfiltration, consent to monitoring / no expectation of privacy, report incidents, follow data-classification rules, comply with law & licenses, no illegal or offensive use, understand discipline for violations, return or remove company data on exit, and e-signature consent — and each one you turn on shows up as a checked ✓ acknowledgment on the form. Add your own custom statements, a monitoring / no-privacy note, and a default “this doesn’t change at-will employment” line, and record the policy title, version, and effective date. The employee is the one acknowledging it, so THEY e-sign the hosted form online and submit it to IT / HR — there’s no second signature, and the page is set to noindex to keep it private. (This is a convenience template, not legal, HR, or IT-security advice — PaperKit doesn’t draft, review, verify, enforce, or monitor the policy or file anything; your employer owns its IT security program, and what monitoring is permitted and how at-will language applies vary by employer and state.)
Open the free tool →

What an acceptable use policy covers

A practical AUP is specific about permitted and prohibited use:

  • Which devices, systems and accounts the policy applies to.
  • Acceptable personal use (if any) of company equipment.
  • Prohibited activities — illegal content, harassment, unlicensed software.
  • Security expectations — passwords, locking devices, reporting incidents.
  • Email, internet and social media use.
  • Data handling and confidentiality.
  • Monitoring — that the company may monitor use of its systems.
  • Consequences of violating the policy.

Why every organization needs one

Without a written AUP, there is no agreed line between reasonable and reckless use — which makes it hard to act when something goes wrong. A signed policy establishes expectations, supports disciplinary decisions, and is often required for compliance and cyber-insurance.

It also protects employees: it tells them plainly what is expected, so they aren't guessing about whether personal browsing or plugging in a USB drive is okay.

Rolling it out

Keep the language plain — a policy nobody understands is a policy nobody follows. Have every employee read and acknowledge it (a signature or e-sign), and re-acknowledge after any material change.

Pair the AUP with related policies as your program matures: a BYOD policy for personal devices, and a remote-work policy for off-site access.

Frequently asked questions

What is the difference between an AUP and an IT security policy?

An acceptable use policy focuses on how people may use company technology; an IT security policy is the broader set of technical and organizational controls. The AUP is the user-facing piece of that program.

Should employees sign the acceptable use policy?

Yes. A signed acknowledgment shows the employee received and agreed to the policy, which is what makes it enforceable if a violation occurs.

How often should an AUP be updated?

Review it at least annually and whenever technology or regulations change. Have staff re-acknowledge after any material update.

Does a small business need an acceptable use policy?

Yes. Even small teams benefit from clear rules on device, email and data use — it reduces security risk and is often required for insurance or client contracts.

Ready to create one?
Fill a short form and download a clean PDF — no signup.
Use IT Acceptable Use Policy & Agreement