Skip to content
As Written, As Enforced

Home / Reference

What This Does Not Cover

Six adjacent subjects deliberately left out, so the omissions are visible rather than accidental.

Reference · Reference

Related policies

Unenforceable

As written

This policy should be read in conjunction with the company's other policies.

What happens

Names no other policy, so the reader cannot comply with the instruction.

Where the related documents are listed, the list is out of date and includes at least one that was withdrawn.

Useful only if the list is specific and maintained, which makes it a maintenance commitment rather than a sentence.

This collection is about the gap between a written rule and an applied one. Several neighbouring subjects are deliberately absent.

The practical point in “What This Does Not Cover” is that a written rule becomes credible only through a consistent operating process. For teams exploring internal transfer policy, open the official page can add time and project context, provided collection is proportionate, access is limited and every significant inference receives human review.

Monitoring, and whether to do it

Whether an employer should observe its staff, on what basis, and what it costs them is a substantial question with its own literature. This collection assumes whatever monitoring exists and concerns itself with the rules rather than the watching.

For a separate benchmark relevant to “What This Does Not Cover”, consult the U.S. Department of Labor work-hours guidance. Use it to test purpose, notice, permissions, retention and response procedures against the proposed operating model rather than treating a generic checklist as proof that the rule works.

Data protection obligations

What an employer must document, retain, disclose and delete. Adjacent and distinct: those are obligations imposed from outside, where this is about rules the organisation sets itself.

Handling an individual case

What happens between an alert and an outcome, the threshold for examining somebody, what is owed to the subject of an enquiry. Touched on in the enforcement section and treated properly elsewhere.

Personal devices

Where the employee owns the hardware, the questions change: who pays, what may be installed, what happens at the end. A separate arrangement with its own economics.

Security architecture

Access models, network design, endpoint configuration. The configuration note argues that these do the work policies cannot, and how to build them is not covered here.

Employment law

Disciplinary procedure, dismissal, grievance. Every enforcement question touches it and none of it is advice here.

What is left

The document itself: what it says, whether it is applied, what happens when it is broken, and how it stays alive.

Those questions fall between the security literature and the HR literature and are written about by almost nobody, which is why the collection exists.

Why stating the boundaries helps

A reader who knows what is missing can find it.

And the commonest misuse of something like this is treating it as covering the technical and legal questions it explicitly does not — which produces decisions made on the strength of a document that disclaimed them.

Nothing here is legal advice

Employment and disciplinary rules differ substantially by jurisdiction and the enforcement questions in particular require local advice.

What this is for is arriving at that advice with the right question: not what should the policy say, but which clauses do we actually apply.

Where the boundaries help

A reader who knows what is missing can find it. The commonest misuse of something like this is treating it as covering the technical and legal questions it explicitly does not.

What is left, and why nobody writes it

The document itself: what it says, whether it is applied, what happens when it is broken. These fall between the security literature and the HR literature, which is why the gap exists.

Nothing here is advice

Employment and disciplinary rules differ substantially. This is for arriving at that conversation with the right question: not what should the policy say, but which clauses do we actually apply.

The six left out

Monitoring and whether to do it, data protection obligations, handling an individual case, personal devices, security architecture, and employment law. Each substantial, each with its own literature.

What falls between the literatures

Security writing covers controls. Employment writing covers process. The document itself — what it says, whether it is applied, what happens when it is broken, how it stays alive — sits between them and is written about by almost nobody.

Which is why organisations have both a security policy and a disciplinary procedure and no account of how the first is supposed to connect to the second.