Skip to content
As Written, As Enforced

Acceptable use and company devices

A rule nobody has applied is not a rule

Eighteen clauses in a typical policy. Filled: applied to somebody at least once. Dashed: never applied to anybody. Grey: not something a document can deliver at all.

Acknowledgement

Enforced

As written

I confirm that I have read and understood the Acceptable Use Policy.

What happens

Signed in a batch of onboarding documents on the first morning, usually unread.

Enforced in the sense that the signature is chased until it exists. Not enforced in the sense that anybody checks understanding.

It is the one clause that reliably does its job, and the job is evidence rather than instruction.

Acceptable use policies are written as though compliance follows from drafting. Most of their clauses have never been applied to anybody, the staff know exactly which ones, and the gap between the written rule and the operative one is the actual policy.

Nothing here is legal advice. Disciplinary and employment rules differ substantially by jurisdiction. Named product comparisons are kept in separate guides; the core notes remain focused on rules, evidence and accountable process.

Three more, read against what actually happens

Password sharing

Never enforced

As written

Credentials must not be shared with any other person, including colleagues.

What happens

Shared constantly: for a mailbox nobody budgeted a licence for, for a system where one person has access and they are on leave.

Never enforced, because enforcing it would stop the work and everybody knows it.

The fix is not the clause. It is the licence and the delegation nobody arranged.

Reporting loss

Enforced

As written

Loss or theft of company equipment must be reported immediately.

What happens

Genuinely enforced and genuinely followed, in organisations where reporting is blameless.

Where people fear being charged for the device, reported late or not at all, and the delay costs more than the laptop.

Monitoring notice

Unenforceable

As written

The company reserves the right to monitor use of its systems at any time.

What happens

Not a rule for employees to follow. A reservation of rights, placed among things people are asked to agree to.

It does not create the right it asserts, and where the monitoring is disproportionate the clause does not rescue it.

The gap is the subject

Everything about what an acceptable use policy should say has been written somewhere. What has not been written is what happens when a clause is broken, which is the only question that establishes whether the clause exists at all.

The practical point in “A rule nobody has applied is not a rule” is that a written rule becomes credible only through a consistent operating process. For teams exploring employee monitoring software with screenshots, the official product page can add time and project context, provided collection is proportionate, access is limited and every significant inference receives human review.

Open any policy and read it against the organisation. A large share of the clauses have never been applied to anybody, and everybody who works there has already worked out which. They calibrate against enforcement rather than against text, and they calibrate accurately.

For a separate benchmark relevant to “A rule nobody has applied is not a rule”, consult the NIST Cybersecurity Framework. Use it to test purpose, notice, permissions, retention and response procedures against the proposed operating model rather than treating a generic checklist as proof that the rule works.

What a dormant clause costs

It is treated as free: it sits there, costs nothing to keep, and might be useful one day. Each of those is wrong in a specific way.

It discounts the clauses that are live. A document half composed of theatre is read as theatre throughout, including the parts the organisation most needs followed.

It produces the inconsistency argument. Somebody disciplined under a clause never applied to anybody else has the defence that wins employment cases, and it wins on the strength of the dormancy rather than the conduct.

And it gets quoted selectively, which turns the document into a resource for managers in conflict rather than a standard applying to everybody.

What a document cannot do

It cannot prevent. Prevention is a property of configuration. Removing local administrator rights prevents installation; a clause prohibiting it does not. The test for any prohibition is what stops somebody who decides to do it anyway — and where the answer is the sentence itself, the sentence is not a control.

It cannot substitute for a conversation. A clause is written for everybody and addressed to nobody. Where one person is doing one thing, what works is a manager saying so.

It cannot be read into somebody. Most staff acknowledged it in a batch of first-day documents. That preserves its evidential function and removes the instructional one.

And it cannot create consistency, which is a property of how a document is applied rather than how it is drafted. Two managers with the same policy produce different outcomes for the same conduct, and nothing in the text reaches that.

What it can do

Establish that an expectation was communicated, which matters when something becomes a disciplinary matter. Give a manager a reference point they did not have to invent. And set a baseline that makes the serious cases unambiguously serious.

Three functions, all real, and prevention is not among them.

Finding the rule that is actually in force

Every written clause has an operative counterpart. Ask somebody who has worked there three years what would actually happen if they did the thing, and the answer arrives immediately and accurately.

The operative rules are usually narrower and more sensible than the written ones. Written: no personal use. Operative: not conspicuously. Written: no software without approval. Operative: nothing that costs money or touches customer data.

In each case the operative rule is roughly what a thoughtful person would have drafted, arrived at by the organisation without anybody drafting it. Where it is sensible, make it the written one — the clause becomes enforceable the day it is issued, because people already follow it.

Most breaches are workarounds

A file sent to a personal address because the transfer limit is smaller than the file. A login shared because one person has the access and they are on leave. A tool installed because the approved one cannot open the format a client sent.

Each produces a clear policy breach and each is somebody solving a problem the organisation created. One question establishes which: what were you trying to achieve? The answer comes immediately, specifically, and is checkable within the hour.

Treating it as misconduct does not stop the behaviour, because the underlying problem is unchanged. What stops is the mentioning, which trades a known problem for an unknown one.

The exercise

Two people, one spreadsheet, an hour. The policy owner and somebody who has been there three years and did not write it.

For each clause: enforced, dormant, or unenforceable by a document. Enforced means somebody can recall an actual instance — not that it could be applied in principle, that it was.

The verdicts come out as a handful kept, several rewritten to match the operative rule, a group relabelled as reservations, and a substantial number deleted. The resulting document is typically half the length and composed entirely of clauses somebody would act on.

04 / 07

The unclear parts

Where the written rule and the operative one are furthest apart, and where the honest version is easier to write than it looks.

The whole method

An hour with a spreadsheet, a morning of deletions, one decision

Two people go through the document and mark each clause enforced, dormant or unenforceable. The deletions follow in a morning. Then one decision per surviving dormant clause: who enforces it, and what happens the first time.