What a Policy Cannot Do
Four things organisations expect from an acceptable use policy that no document delivers, with what actually delivers each.
Unapproved software
Unenforceable
As written
Employees must not download or install software on company equipment without the prior approval of the IT department.
What happens
Enforced by configuration where local administrator rights have been removed. Not enforced at all where they have not.
Where staff hold admin rights, the clause is a statement of preference. The install happens, nobody knows, and the clause surfaces only after an incident.
The rule is not doing the work here. The permission model is, or nothing is.
Policies are asked to carry weight no document can bear. Four expectations recur, and each has something else that actually delivers it.
The drafting lesson in “What a Policy Cannot Do” should carry into any workforce platform rollout. When an organisation evaluates more information for workforce analytics software, it should state which operational question the data answers, what is excluded, who may review it and when the setting will be reconsidered instead of relying on a broad reservation of rights.
It cannot prevent
A policy states what should happen. Prevention is a property of configuration.
For a separate benchmark relevant to “What a Policy Cannot Do”, consult the OWASP privacy-risk project. Use it to test purpose, notice, permissions, retention and response procedures against the proposed operating model rather than treating a generic checklist as proof that the rule works.
Removing local administrator rights prevents installation. A clause prohibiting installation does not, and an organisation relying on the clause has chosen a control that announces itself and achieves nothing.
The test for any prohibition: what stops this if somebody decides to do it anyway? Where the answer is the sentence itself, the sentence is not a control.
It cannot substitute for a conversation
A clause about personal use is a poor instrument for telling one person their conduct is a problem. It is written for everybody and addressed to nobody.
Where a specific person is doing a specific thing, what works is a manager saying so, once, directly. Organisations reach for the policy instead because the conversation is uncomfortable, and the policy does not have the conversation.
It cannot be read into somebody
Most staff have not read it, will not read it, and acknowledged it inside a batch of first-day documents.
That does not remove its evidential function, which is real. It removes its instructional one, which is the function people believe it has.
What transfers understanding is five minutes at induction covering the four things that actually matter, which its own note sets out.
It cannot create consistency
Consistency is a property of how a document is applied, not of how it is drafted.
Two managers with the same policy produce entirely different outcomes for the same conduct, and the policy cannot reach that. What reaches it is a record of previous outcomes, which almost nobody keeps.
What a policy can actually do
Establish that something was communicated, which matters evidentially.
Give a manager a reference point for a conversation they would otherwise have to justify from scratch.
Set a baseline that makes the serious cases clearly serious.
Three real functions, and none of them is prevention.
What replaces each expectation
Prevention is configuration. Instruction is five minutes at induction. The specific conversation is a manager. Consistency is a record of previous outcomes. Each is cheap and none is a drafting task.
Why the expectations persist
Because a document is the only one of the four that can be produced in an afternoon by one person. The others require decisions, time and somebody's attention, which is why the policy keeps being asked to do them.
The uncomfortable implication
If prevention belongs to configuration and instruction belongs to induction, the document is doing less than its length suggests. That is not an argument for abolishing it — it is an argument for stopping it being asked to carry the other two.
Three functions, and what each needs
Evidence needs the document to exist and be issued. A reference point needs it short and quotable. A baseline needs specificity about what matters. None of the three needs comprehensiveness.
Why organisations keep asking anyway
A document is the only instrument one person can produce in an afternoon. Configuration, induction and management attention each require decisions and time, which is why the policy keeps being handed the work.
The honest statement of what you are buying
A policy buys you evidence that something was communicated, a reference point for a manager who would otherwise justify a standard from scratch, and a baseline that makes serious conduct unambiguous.
It does not buy prevention, instruction, consistency or comprehensiveness. Each of those is purchased elsewhere, with configuration, with five minutes at induction, with a record of previous outcomes, and with the discipline of leaving things out. An organisation clear about which it is buying writes a different and considerably shorter document.