A one-page IT policy: which tools and AI may your employees use?
Personal Dropbox, ChatGPT with customer data, WhatsApp for work: in a small team shadow IT appears on its own. Nobody reads a thirty-page policy. This is what belongs on one page, and how to write it.

Ian
Co-Founder & CEO

In a team of fifteen it happens by itself. Someone puts customer files in a personal Dropbox because it is quicker. Someone pastes a customer email into ChatGPT to draft a reply. Planning runs through a WhatsApp group, and for invoices a colleague uses a free tool nobody else knows about. No bad intentions, but shadow IT all the same: tools and habits nobody has an overview of. The answer is not a thirty-page policy. Nobody reads that, let alone follows it. What does work: one page, in plain language, that says what is allowed, what is not, and who to turn to.
Why shadow IT appears so quickly, and why thirty pages do not help
Small teams are pragmatic. When something does not work or is too slow, someone finds their own solution. That is a strength, until it goes wrong.
- Customer data sits in places that are not in the back-up and that nobody can revoke when that employee leaves.
- Personal data ends up in public AI tools or free apps, and then you as a company are responsible under the GDPR.
- Accounts without MFA, created with a reused password, sit outside everything you did secure.
- During an incident nobody knows which tools are in use, so you do not know what has leaked either.
A hefty policy does not solve that. Nobody reads thirty pages, and those who do will not remember them. What employees need is a page that fits on a noticeboard and where you find the answer to 'is this allowed?' in thirty seconds.
What goes on that one page
Seven points, each in two or three sentences. Nothing more is needed.
- Approved tools. A list of what we use for email, files, chat, accounting and planning. Want something new? Ask one designated colleague, and you get an answer within the week.
- AI tools. No personal data, customer data, contracts or passwords in public AI tools. The approved business variant, such as Copilot within your Microsoft 365 environment or a paid business version with a data processing agreement, is fine. Not sure whether something is sensitive? Then it is sensitive.
- Passwords and MFA. Everything in the password manager, MFA enabled on every account that offers it, and never share a password via email or chat.
- Devices and working from home. Work happens on a company device that installs updates automatically. A personal PC is used only through the browser and with MFA, and no company files stay on it.
- Sharing data with external parties. Via a shared link with an expiry date or a guest account, never as an attachment containing a whole customer list. External parties get access to one folder, not to everything.
- Incident or doubt. Clicked on something, received a strange message or lost a device? Report it immediately to the agreed colleague. Reporting quickly is always good, even if it turns out to be a false alarm. No blame follows.
- Who decides. One person, usually the owner, decides on new tools and exceptions. When in doubt you ask, you do not guess.
How to write it, and how to keep it alive
The trap is leaving it to a lawyer or a generic template. Then you get language nobody on your team uses. Write it yourself, or have your IT partner draft a first version that you then put into your own words.
- Plain language: 'turn on MFA for your email', not 'employees shall activate multi-factor authentication in accordance with the directive'.
- Discuss it with the team in a twenty-minute meeting. Ask what is missing and which tool they are already quietly using. That conversation yields more than the document.
- Review it once a year, for example in October during cybersecurity month. Tools change, AI changes even faster.
- Having it signed is fine, but understanding matters more. A signature under something nobody has read does not protect you.
The link with the EU AI Act and AI literacy
The EU AI Act expects companies that use AI to make sure their employees are sufficiently AI-literate: they need to understand what the tools do, what the risks are and where the limits lie. The AI point on your one page is a concrete part of that, but not a replacement for it. What that obligation exactly involves is explained in our post on AI literacy and the AI Act. How we approach it practically for a small team is on our AI literacy page.
What an IT partner does here
You can write a page yourself. Where an IT partner makes the difference is enforcing the agreements where that is technically possible, so the policy does not rest on goodwill alone.
- A template that fits a team of fifteen and that you can tailor in an hour.
- Technically locking down approved apps in Microsoft 365, so unknown apps get no access to company data.
- Adjusting sharing settings: external links with an expiry date, no anonymous links, guest accounts that expire automatically.
- Making MFA mandatory instead of asking for it, and rolling out the password manager to the whole team.
- Scheduling a yearly review, together with the question of which tools have been added in the meantime.
Would you rather not do this alone? Our advisory modules guide you in a short engagement towards an IT policy your team actually uses. This may fall under the SME portfolio subsidy, as we explain in our post on the four advisory modules.