BYOD policy: personal devices, company data, one page of rules
Friday, 5:40. A designer photographs a whiteboard full of client material with her personal phone, edits the render on her own laptop over the café wi-fi, and emails the draft from her personal Gmail because the company one is signed out on her phone. Nobody did anything malicious. But the client files now live on two machines nobody can wipe, inside a cloud drive the company has never seen, behind an inbox that will still work after she resigns. That is what happens without a BYOD policy — and the fix is not buying everyone a second phone. It is one page that says which personal devices may touch company data, what the company sees and wipes in exchange, and the five things any such device must have before the first sync. The remote work baseline covers working from home; BYOD is the narrower and leakier problem: your hardware, their data.
1. Decide the device list before anyone asks
- Phones: yes, for mail, calendar, chat, and the MFA app. The phone is where work already lives and where the second factor must be. Personal phones with a proper work profile (below) are the sensible default for a small team; refusing them means someone re-adding work mail into a browser and calling it a day — shadow IT with worse hygiene.
- Laptops: usually no, for client data. A personal laptop is a full desktop with a personal browser, personal cloud sync, family logins, and unknown disk state. The house rule that survives contact with reality: company work happens on a company machine built to the provisioning build sheet, and personal laptops get read-only exceptions (the shared dashboard, the docs link) rather than sync clients and credentials. Every exception is written down, or it is not an exception — it is a leak with an excuse.
- Tablets, old phones, the spare Samsung in the drawer: the yes needs a date. A BYOD policy that says "approved devices" without naming them decays into "anything that opens the inbox." Name the models, review the list annually with the security review, and retire devices whose OS stopped getting updates.
2. The trade: enrollment for privacy — made explicit
- A work profile, not supervision of the whole phone. On iOS, the work space is the managed apps and accounts; on Android, the work profile. Company policy reaches into that container and nowhere else. Say so in the policy in one honest sentence, because the rumor version ("IT can see my photos") is what kills enrollment at the dinner-table conversation.
- What the company can see, and can wipe. The managed apps, the work account, the compliance state (OS version, encryption, screen lock), and the ability to remove the work container or the work apps remotely — which is how the lost device runbook ends on a phone, too. What the company cannot see: photos, personal messages, browsing history, location, or anything outside the container.
- The wipe has a boundary, and everyone should know it. Removing the work profile deletes work mail, work files, and the MFA enrollment from the device — it does not touch the camera roll or the personal apps. When a person leaves, this is the difference between offboarding and confiscation. The same distinction the offboarding checklist makes for accounts applies to the pocket they live in.
3. The five non-negotiables, checked before first sync
- Screen lock with a biometric or six-digit passcode, auto-lock at two minutes. The phone that unlocks to a swipe is a door with no latch — mail, chat, and the MFA app are one glance away from whoever borrows it at the bar.
- OS updates installed within thirty days of release. A personal device from 2021 on its final iOS is not eligible; the check is the same console or enrollment report the patch program already runs for company machines, pointed at the personal fleet. Eligibility ends when updates end, not when the policy gets annoyed.
- Disk encryption on, verified. Modern phones are encrypted by default; personal laptops — the exception class — are not, and FileVault or BitLocker on and verified is the difference between a stolen laptop and a breach with a timeline.
- The MFA app lives on the device, enrolled to the company's MFA rollout. If the authenticator dies with the phone, the lost MFA runbook is the recovery path — and it starts the same hour, not when the person gets around to it.
- No jailbroken or rooted devices, ever. A device whose security model has been deliberately removed is not "personally customized"; it is a compromised terminal asking politely to hold your session tokens.
4. Where company data may and may not live
- Company apps only, inside the container. Work mail in the managed mail app, work files in the managed sync client, work chat in the managed chat app. The corporate password manager — see the password manager rollout — gets an exception list: some personal apps need the work login, and the policy names which.
- The personal cloud drive is the shadow perimeter. The slide deck exported to personal iCloud "to finish tonight" is the actual data exfiltration of most small teams, and it is almost always innocent. The policy sentence is short: company files sync through company accounts. The habit that makes it true: the managed sync client is signed in and reachable, because a tool that is annoying gets routed around — the same physics behind the permissions audit.
- Printing and screenshots: decide, don't assume. A home printer spooling client invoices is a retention problem wearing a paper tray. One line in the policy — no client data on personal printers; screenshot only what the email and comms policy would already allow — converts a silent habit into a stated rule.
5. Accounts: separation is the whole trick
- Work sign-in stays in work apps, personal sign-in stays personal. The browser profile split (work profile / personal profile) on exception laptops, separate container accounts on phones. The account boundary is what the wipe counts: wipe the work container and the company is gone; the person's life is untouched.
- No password reuse across the boundary. The work password reused on a personal forum is the pivot attack: breach the forum, replay into the company. The password manager's breach report is the quarterly check; the wi-fi baseline and the shared-household router are the network half of the same story — company sessions ride whatever network the personal device trusts.
- The separation survives enthusiasm, not discipline. Nobody keeps two inboxes straight by willpower in week twelve. The container does it by architecture: the work apps visibly different, the notifications labeled, the badge counts separate. Choose tooling that separates by default, then the policy is a description of reality instead of a New Year's resolution.
6. The exit: offboarding a device the company never owned
- Revoke first, wipe second, in that order. Sessions and app tokens die in the admin console the hour notice is given — the same access-revocation sweep the offboarding checklist runs, extended to the phone in the person's pocket. Then the container wipe removes the work space. A wipe without revocation leaves tokens that still open the door; revocation without a wipe leaves the person's photos intact and the company's files gone from the device.
- The MFA re-home happens the same day. The authenticator enrollment moves off the departing device and onto whatever comes next — the MFA lost-device runbook is the procedure, whether the phone was lost, replaced, or resigned.
- Personal data returns to the person, fully. The boundary working in reverse: contacts the person imported, photos on the camera roll, personal apps — all untouched. Offboarding that feels like confiscation gets named in the group chat; offboarding that respects the container gets forgotten by the following Tuesday. One of those is cheaper.
7. Lost or stolen personal device: the same runbook, one twist
- Report it in hours, not when the upgrade cycle feels right. The personal phone with the MFA app and work mail inside is, from the company's side, a company endpoint. The report path is the same one the lost laptop runbook uses: revoke sessions, wipe the container, re-enroll the person on whatever device comes next, and rotate any credentials the device held.
- The twist: the device can often be located by its owner, not by the company. Find My and Google's device tools are the owner's personal superpower — the policy should say clearly that the company never tracks personal devices, and the recovery attempt belongs to the person. The company's job is containment: assume it is gone from minute one.
8. One page, signed at onboarding, alive in the reviews
- The policy is one page, attached to the onboarding checklist. Device list, the trade (container vs privacy), the five non-negotiables, the data boundaries, the exit. Signed at week one, when the new hire still reads things, and re-signed when the device list changes — the same living-document discipline as every other note in this collection.
- Two review hooks keep it from rotting. The annual security review re-walks the device list and the eligibility rule; the access review asks the device question per person: what personal devices hold sessions right now? When the answer changes, the enrollment console is where the truth lives — not in anyone's memory of who brought what.
- The done-signals: every personal device holding company data is enrolled or explicitly exception-listed; a new phone is productive in twenty minutes without IT touching it; a leaver's phone is work-clean the same day with the camera roll intact; and nobody can name a client file living in a personal cloud drive. When those are true, the one page is doing its job — and the nine devices in the company fleet are no longer the only ones worth auditing.