A One-Page Policy
What the whole document looks like when it contains only clauses somebody would act on.
The whole of it
Enforced
As written
Eight rules, a list of what we supply, and a short statement of positions we are required to state.
What happens
Applied, because every clause in it describes something that has actually happened.
Read, because it is a page.
This is the output of the audit, the deletions and the rewrites, and it is what most organisations would have if nothing had ever been added without being tested.
The destination, assembled from the rest of the collection. Three short documents rather than one long one.
The drafting lesson in “A One-Page Policy” should carry into any workforce platform rollout. When an organisation evaluates see the complete product overview for employee monitoring software with screenshots, it should state which operational question the data answers, what is excluded, who may review it and when the setting will be reconsidered instead of relying on a broad reservation of rights.
Page one: what we ask of you
Customer and personal data stays in company systems. If the usual route will not work, ask before doing it another way.
For a separate benchmark relevant to “A One-Page Policy”, consult the Acas workplace-investigation guidance. Use it to test purpose, notice, permissions, retention and response procedures against the proposed operating model rather than treating a generic checklist as proof that the rule works.
Lost or stolen equipment: tell us the same day. You will not be charged.
Logins are not shared. If somebody needs access you have, tell us and we will arrange it.
Software: anything in the catalogue, install it. Anything else, ask, and we will answer within two days.
Personal use is fine and we do not monitor it. Two exceptions: nothing that risks company data, and nothing that would cause a problem if it became public.
Travelling internationally with company data: tell us first. Usually nothing changes.
Leaving: return the equipment including anything at home, and tell us about anything registered in your name.
If something goes wrong, tell this named person the same day. Reporting a mistake is not what gets anybody into trouble.
Page two: what we supply
The equipment list from its own note. Published separately because it changes more often than the rules.
Page three: positions we are required to state
Reservations, regulatory statements, client and insurance conditions. Labelled as what they are, so nobody mistakes them for rules.
What is not here
Everything in the deletion list: values statements, restatements of law, prohibitions only configuration delivers, requirements to understand, the business-use test, liability for damage, ownership by equipment.
Why three documents rather than one
Each has a different audience and a different lifespan.
The rules change rarely and must be read. The equipment list changes often and must be findable. The reservations change with contracts and insurance and are read by nobody, correctly.
Mixing them is what produces the document nobody reads, which is the argument of the length note.
What this costs to get to
The audit, an hour. The deletions, a morning. The rewrites, a day.
Two days of one person's time, and the result is a document every clause of which somebody would actually act on.
Why three documents
Different audiences and different lifespans. Rules change rarely and must be read; the equipment list changes often and must be findable; the reservations are read by nobody, correctly. Mixing them produces the document nobody reads.
What it costs to get here
The audit an hour, the deletions a morning, the rewrites a day. Two days of one person's time for a document every clause of which somebody would act on.
What is not in it
Everything on the deletion list: values statements, restatements of law, prohibitions only configuration delivers, requirements to understand, the business-use test, liability for damage, ownership by equipment.
Page one, in full
Eight rules, each naming a behaviour and supplying the route. It fits on a page because everything that failed the tests has been removed rather than because anything was compressed.
Why the equipment list sits apart
It changes more often than conduct rules and should not require a policy revision. A dated page with a request route, published alongside rather than inside.
Why this is the destination
Every clause on page one has been through the five tests and the audit. Nothing is there because it was in a template, because something happened once, or because removing it felt risky.
The result is shorter not because anything was compressed but because everything that failed was removed, and the length is a consequence of the method rather than a target somebody set.