Workspace Migration Services

Template

Acceptable use policy template

An acceptable use policy tells staff what they may do with company accounts and data. This template covers 7 areas including generative AI prompts, personal device access and external file sharing, which are the 3 topics most policies written before 2024 do not mention at all.

Last checked · template reviewed against the current admin console · See what changed

Acceptable use policy scope
Areas covered7: accounts, mail, files, AI, devices, personal use, monitoring
Reading levelWritten for staff, not for auditors
LengthRoughly two pages when filled in
Signature blockIncluded, with a dated acknowledgement line
AI clauseExplicit, covering prompts and outputs
FormatPlain text, adopt or adapt freely

Copy the template

Free to use and adapt, including commercially. Every bracketed placeholder is meant to be replaced before the document is adopted.

Acceptable use policy — plain text

ACCEPTABLE USE POLICY
[ORGANISATION] | Effective [DATE] | Owner [NAME, ROLE]

This policy explains how you may use [ORGANISATION] accounts, devices
and data. It applies to everyone with an [ORGANISATION] account.

1. YOUR ACCOUNT
Your account is yours alone. Do not share your password, and do not
let anyone else use your logged-in session.
2-step verification is required. If you lose your phone or security
key, contact [IT CONTACT] the same day.
Do not forward company mail to a personal address.

2. EMAIL
Treat anything you send as potentially permanent and disclosable.
Check the recipient before sending anything confidential; Gmail will
warn you when a recipient is outside [ORGANISATION].
If a message asks you to change bank details, pay an unexpected
invoice, or buy gift cards, verify by phone using a number you already
hold. Report it to [IT CONTACT] even if you spotted it.

3. FILES AND SHARING
Store work files in [SHARED DRIVE NAME], not in My Drive, so they
survive your departure.
Share with named people or groups. Do not use "anyone with the link"
for anything confidential.
Before sharing outside [ORGANISATION], check whether the recipient
needs edit access or only view access.

4. GENERATIVE AI
You may use [APPROVED AI TOOLS] for [PERMITTED PURPOSES].
Do not paste client data, personal data, credentials, unpublished
financials or source code into any AI tool that is not on the approved
list. Anything you paste leaves our systems.
You remain responsible for anything an AI tool produces in your name:
check facts, figures and quotations before sending or publishing.

5. DEVICES
Access company data only from devices that are [enrolled / managed].
Lock your screen when you step away. Encrypt laptops.
Report a lost or stolen device to [IT CONTACT] immediately, at any hour.
Do not install applications that request access to your [ORGANISATION]
Google account without checking with [IT CONTACT] first.

6. PERSONAL USE
Reasonable personal use of your account is permitted. Do not use it
for another business, for anything illegal, or for anything you would
not want associated with [ORGANISATION].

7. MONITORING
[ORGANISATION] retains and may review account logs, mail and files for
security, legal and operational reasons, in line with [PRIVACY NOTICE]
and applicable law. We do not monitor casually or without cause.

8. IF SOMETHING GOES WRONG
Tell [IT CONTACT] straight away. Reporting a mistake quickly is always
better than hiding it, and nobody has ever been disciplined here for
reporting their own error promptly.

9. BREACHES
Serious or repeated breaches are handled under the [DISCIPLINARY
PROCEDURE].

ACKNOWLEDGEMENT
I have read and understood this policy.
Name: ______________  Signature: ______________  Date: __________

Write it for staff, not for the auditor

An acceptable use policy has one job: to change what people do at their desks. That makes it a different document from the information security policy, which exists to prove to a third party that controls are in place. Mixing the two produces something staff skim and assessors find vague.

So this template uses second person, short sentences and concrete instructions. It tells someone what to do when a message asks them to change bank details, rather than asserting that staff shall exercise appropriate vigilance regarding financial requests. Vigilance is not an instruction anybody can follow.

The generative AI clause, and why it belongs here

Section 4 is the clause most existing policies lack. The risk is not that staff use AI tools; it is that a single paste of client information into an unapproved tool moves that data outside your control silently. No sharing alert fires, no data loss prevention rule triggers on a browser paste, and no audit log records it.

The workable version of this clause names the tools that are approved and the categories of data that never leave, rather than banning AI outright. Blanket bans move usage onto personal accounts and personal devices, where you have neither visibility nor recourse.

The second half of the clause matters as much: whoever sends the output owns it. Attribution of responsibility is what stops an unverified figure from an AI summary appearing in a client document with your logo at the top.

  • Name the approved tools rather than banning the category
  • List the data classes that must never be pasted anywhere
  • State that the sender owns the accuracy of any AI output
  • Point at the shared drive as the default storage location
  • Give one clear instruction for suspected invoice fraud

Getting it acknowledged and keeping it current

A policy nobody signed is difficult to rely on later, so the template ends with a dated acknowledgement line. Collecting those at induction and after each material revision costs very little and is routinely requested during due diligence.

Review it when the environment changes rather than on a fixed annual timer alone. New approved AI tools, a move to managed devices or a change of shared drive structure all invalidate specific lines here, and a policy describing an environment that no longer exists teaches staff to ignore all of it.

What we see that others don't say

The clause most organisations are missing entirely is the one governing what staff may paste into a generative AI tool, and it matters more than any other new clause because a prompt containing client data leaves the tenant without triggering a single Drive sharing alert or data loss prevention rule.

What this doesn't cover

  • This is a template, not employment law advice. The monitoring and disciplinary clauses must be checked against local law and your existing contracts.
  • Monitoring rights differ substantially between jurisdictions; the clause as written assumes a lawful basis already set out in your privacy notice.
  • It does not replace a separate information security policy, which serves auditors rather than staff.
  • The approved AI tool list is yours to define; we do not recommend specific consumer tools here.

Want this done for you?

Three fields. We come back with whether this is a 20-minute fix or a project, and what it costs.

Prefer to talk? Call +44 20 7183 3436 (Mon–Fri 08:00–18:00 GMT), or message WhatsApp +44 7403 423563.

Questions we get asked

What should an acceptable use policy cover in 2026?
Accounts and authentication, email and invoice fraud, file sharing defaults, generative AI prompts and outputs, device requirements, permitted personal use, monitoring, and how to report a mistake.
Should an acceptable use policy ban AI tools?
Banning the category tends to push usage onto personal accounts where you have no visibility. Naming approved tools and prohibited data classes produces better compliance than a blanket prohibition.
Do staff need to sign an acceptable use policy?
A dated acknowledgement is worth collecting at induction and after material revisions. It costs little and is routinely requested during client due diligence.

How this page is verified

Reviewed by Workspace Migration Services security desk, Workspace security and compliance reviewers. Last checked .

  • Clause set reflects acceptable use policies Workspace Migration Services has reviewed for Workspace tenants to 2026-08-07.
  • Gmail external recipient warning behaviour verified in Google Workspace on 2026-08-07.

Sources you can check

Cite this page

Free to reuse with attribution. Copy whichever form your publication needs.

Plain citation

Workspace Migration Services, "Acceptable use policy template", https://workspacemigration.services/templates/acceptable-use-policy-template (last checked 2026-08-07).

HTML with source link

<p>Pasting client data into a consumer generative AI tool moves it outside the tenant without triggering any Drive sharing alert, which is why acceptable use policies now need an explicit AI clause. Source: <a href="https://workspacemigration.services/templates/acceptable-use-policy-template">Acceptable use policy template</a> — Workspace Migration Services.</p>

Embed this table

<table>
  <caption>Acceptable use policy template — Workspace Migration Services, 2026-08-07</caption>
  <tr><th>Areas covered</th><td>7: accounts, mail, files, AI, devices, personal use, monitoring</td></tr>
  <tr><th>Reading level</th><td>Written for staff, not for auditors</td></tr>
  <tr><th>Length</th><td>Roughly two pages when filled in</td></tr>
  <tr><th>Signature block</th><td>Included, with a dated acknowledgement line</td></tr>
  <tr><th>AI clause</th><td>Explicit, covering prompts and outputs</td></tr>
  <tr><th>Format</th><td>Plain text, adopt or adapt freely</td></tr>
</table>
<p><a href="https://workspacemigration.services/templates/acceptable-use-policy-template">Acceptable use policy template</a> — data maintained by Workspace Migration Services.</p>

Related pages

Want the policy enforced rather than published?

We set the sharing defaults, application allowlists and warning banners in your console so the behaviour the policy describes is the behaviour the tenant actually permits.