Employee offboarding checklist for IT and operations
An employee offboarding checklist covering the full sequence, with the equipment half in depth: assignments, r...
Quick answer
An acceptable use policy (AUP) sets the rules for using company technology: permitted and prohibited use, security duties, personal use, monitoring, reporting loss or theft, and returning devices. It works best when each employee acknowledges it at the moment a device is issued.
An acceptable use policy (AUP) is the set of rules employees agree to when they use company technology. It explains what is allowed, what is prohibited, what the employee must do to keep devices and data secure, and what happens when the rules are broken.
Many AUPs focus on networks, email, and internet use. This guide focuses on the part that is easiest to neglect: the physical devices a company issues, such as laptops, phones, tablets, and accessories. Those are the items that go missing, get lent to family members, or never come back when someone leaves.
This is a practical starting point, not legal advice. Employment, privacy, and monitoring rules vary by country and state, so have HR and legal counsel review the policy before you adopt it.
A device-focused AUP usually includes:
For remote work and personally owned devices, NIST's SP 800-46 Rev. 2, Guide to Enterprise Telework, Remote Access, and BYOD Security covers securing both organization-issued and personal client devices and gives advice on creating related security policies. For a broader IT acceptable use policy that covers email, internet, and system use in depth, the SANS Institute publishes a free acceptable use standard template in PDF and Word formats.
Copy the template below and replace the bracketed text. Remove any clause that does not match how your organization actually works; a policy nobody follows is worse than a short one people do.
[COMPANY NAME] COMPANY DEVICE ACCEPTABLE USE POLICY
1. Purpose and scope
This policy applies to all laptops, desktops, phones, tablets, and accessories
issued by [Company Name] ("company devices"), and to everyone who receives one,
including employees and contractors.
2. Ownership
Company devices and all data stored on them remain the property of
[Company Name]. Devices are issued for business use and may be reassigned
or recalled at any time.
3. Acceptable use
Company devices are provided for [Company Name] business. Limited personal use
is permitted if it does not interfere with work, break the law, or breach
this policy.
4. Prohibited use
You must not:
- use a company device for illegal activity or to harass others;
- install software that has not been approved by [IT contact];
- disable, bypass, or remove security software, encryption, or device management;
- allow family members or other people to use the device;
- store company data on personal devices or accounts unless approved.
5. Security
You must keep the device locked when unattended, install updates when
prompted, use only approved networks or the company VPN, and keep the device
physically secure, including in vehicles and when traveling.
6. Monitoring
[Company Name] may monitor company devices and accounts for security,
compliance, and support purposes, as permitted by law. [Describe what is
monitored.]
7. Loss, theft, and damage
Report a lost, stolen, or damaged device to [IT contact] within [24 hours].
Report theft to the police where appropriate and provide the report number.
8. Return of equipment
Return all company devices and accessories [on your last day / within X days
of a request]. Devices must be returned with passwords removed and in the
condition issued, allowing for normal wear.
9. Consequences
Breaking this policy may lead to loss of access, disciplinary action, or
recovery of costs where permitted by law.
10. Acknowledgment
I have read and agree to this policy.
Name: ____________________ Signature: ____________________ Date: ________
Devices issued (asset tag / serial): _____________________________________
Personal use. "Occasional personal use, such as checking personal email during a break, is acceptable. Streaming, gaming, and personal business activity are not."
Travel. "Do not leave company devices unattended in vehicles, checked luggage, or public places. Carry them as hand luggage when flying."
Remote work. "When working outside the office, connect through [the company VPN] and do not use public computers to access company systems."
Departing employees. "Before your last day, return every company device listed on your acknowledgment, together with chargers and accessories. Unreturned equipment will be handled under [the return procedure]."
A policy signed once during onboarding and then filed away rarely changes behavior. The most reliable moment to collect an acknowledgment is when a device physically changes hands:
The acknowledgment is only useful if you can match it to specific devices. "Received a laptop" is weak evidence; "received laptop tag AC-000184, serial 9K2X71F, on March 3" is strong.
AssetCenter records which person holds each device, keeps every earlier assignment in the device's history, and lets you attach files such as a signed acknowledgment to the record. When someone leaves, their person record lists everything currently assigned to them, which turns the return clause into a checklist rather than an investigation.
The AssetCenter IT inventory page covers the wider device record. AssetCenter does not enforce the policy on the device itself; security controls, encryption, and device management stay with your MDM and security tools. For how those systems relate, see what IT asset management covers.
To set clear rules for using company technology, protect company data and devices, and give the organization a documented basis for enforcing those rules.
Not generally, although some regulations and contracts expect documented security policies. Monitoring and disciplinary clauses must follow local employment and privacy law, which is why legal review matters.
If employees use personal phones or computers for work, yes, either in the AUP or in a separate BYOD policy. NIST SP 800-46 covers the security considerations for personally owned devices used for remote access.
At least once a year, and whenever devices, systems, or working patterns change, such as a move to remote work.
Adapt the template with HR and legal review, then start collecting acknowledgments whenever a device is issued or replaced, recording the asset tag or serial number on each one. Within a single refresh cycle, every employee's acknowledgment will match the devices they actually hold.
Founder & CEO, AssetCenter
An employee offboarding checklist covering the full sequence, with the equipment half in depth: assignments, r...
Identity offboarding is automated; equipment recovery usually is not. What offboarding automation covers, wher...
What IT asset management means for a small IT team: which assets and records to track first, the lifecycle, th...