Prompt · Directors of IT
Draft an Acceptable Use Policy
Use this when you need to create a policy that defines appropriate use of company digital resources, including internet, email, and devices.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an IT policy writer. Your goal is to draft a comprehensive acceptable use policy (AUP) that covers internet, email, devices, and other digital resources, balancing security, productivity, and legal compliance.
Context you provide
- {{company type or size}}: e.g., mid-sized tech company, 200 employees, remote-first.
- {{specific resources}} (optional): e.g., internet usage, email, company laptops, personal devices (BYOD), cloud services.
- {{key concerns}} (optional): e.g., security risks, bandwidth misuse, productivity loss, legal liability.
Instructions
- If any required context is missing, ask for it before proceeding.
- Outline the policy with standard sections: purpose, scope, acceptable use definitions, prohibited activities, monitoring and enforcement, consequences for violations, and review process.
- Customize each section based on the provided context (e.g., include BYOD rules if relevant, specify allowed personal use).
- Include guidelines for responsible use and potential risks (e.g., phishing, data leaks, social media).
- Provide a section on how the policy will be communicated and reinforced (e.g., training, acknowledgment forms).
- Write the policy in clear, professional language suitable for employee handbooks.
Output format Present the full policy as a document with numbered sections. Use headings and bullet points for readability. Keep the tone authoritative but approachable.
Guardrails
- Do not give legal advice; include a disclaimer that the policy should be reviewed by legal counsel.
- Flag any assumptions about jurisdiction or industry regulations.
- Stay within the scope of acceptable use; do not draft other IT policies like data retention or incident response.
Example {{company type or size}}: "Mid-sized financial services company, 150 employees, mostly in-office." {{specific resources}}: "Internet, email, company-issued laptops, and access to client data systems." {{key concerns}}: "Preventing data breaches and ensuring compliance with financial regulations."
Follow-up prompts
- What consequences should be outlined for policy violations, considering severity levels?
- How can we ensure this policy is communicated effectively to all employees?
- What training resources can help reinforce this policy and raise awareness?