Deal · $59 once

IT Admin AI Acceptable-Use Kit

The organizational AUP, a redaction guide, a local-model standard, runbook and user-notice templates, and the vendor questionnaire. The policy you keep being asked to write, drafted.

Ship the AI acceptable-use policy this month, with the redaction rules, the approved-tool list, and the user notices that make it real.

Beer Bond holder? Sign in and it is already yours.

The situation you are in

Somebody forwarded you an article. Or your director came back from a conference. Or a customer asked, in a security review, what your AI policy is. Now you own AI, on top of the device refresh, the identity migration, the audit remediation, and a help desk queue that does not care what year it is.

Meanwhile it is already happening. Your developers are pasting configs into chatbots. A meeting-notes bot is joining calls with a mailbox grant somebody clicked through eight months ago. Finance is uploading spreadsheets. Someone on your own team asked an assistant to write a cleanup script and ran it, and it worked, and nobody wrote that down anywhere. Two of your existing vendors shipped AI features into products you already license, without a new contract and without asking you.

You are not behind. Everyone is here. But the longer there is no written rule, the more the vendor's terms of service are your policy — and the worse the first incident goes, because the person who pasted the key knew it was wrong and had no reason to tell you.

What this kit is

A starter set. An eleven-chapter guide, a draft acceptable-use policy, a redaction standard, a local-model standard, a vendor questionnaire, and the operational templates that make a policy real instead of filed — written so one person can go from an inventory to a published policy in about thirty days of part-time work.

It is opinionated where opinions help. It says do not open with a ban, because a ban produces measurable non-compliance in a month and costs you the visibility you need. It says write the policy about information, not about tools, because tools change every quarter and information classes do not. It says stand up a local model, because a model that does not leave your network turns most of your hard policy questions into easy ones. It says publish a turnaround commitment for tool requests and hold it, because the request path is only real if waiting is cheaper than routing around you. And it says make self-reporting a mistake carry no consequence, in writing, because you would rather hear about the pasted credential from the person who pasted it than from a vendor's abuse report.

Where your organization reasonably differs, the templates leave room and the guide says which decisions are genuinely yours.

What is inside

  • The guide. Eleven chapters, about 18,000 words: what your org is already doing and how to find it in a week; the data-and-destination matrix; redaction with worked examples; tiers and the request path; scripts and configs; runbooks from ticket threads; user communication; the local model as a policy answer; vendor vetting; incidents; and the 30-day rollout with a quarterly review.
  • Fifteen templates. Four policy documents: the AI acceptable-use policy, the data classification and AI destination matrix, the local-model standard, and the AI incident response procedure. Three process documents: the tool request form, the approved-tool register, and the vendor security questionnaire in long and short form. Two redaction documents: the five-rule standard and a separate worked-examples file. Five documentation and communication templates: the runbook template, the ticket-to-runbook prompt set, the outage notice, the change announcement, and the user how-to. And the plan: a 30-day rollout, week by week, with a quarterly review on a standing six-item agenda.
  • The free piece. The Redaction Guide — the five rules and three worked examples on one page, given away for an email address and useful on its own.
  • START-HERE. What to do with one hour, one day, or one week, and a table telling you which file to bring to which meeting or moment.

Every template uses [BRACKETED PLACEHOLDERS] for organization-specific items and carries a short "how to adapt" note. They are plain markdown, so they paste into a word processor, a wiki, a ticketing system, or a policy platform without fighting formatting.

Who wrote it and why he can

Wayne Bridges, a public-sector solutions engineer who builds and runs AI agent systems daily.

Which matters here for a specific reason: the guidance on what these tools do with your data comes from operating them, not from reading about them. The redaction rules exist because of logs actually pasted and keys actually rotated. The local-model chapter exists because on-machine models run every day, and the honest list of what they are good enough for is a list of observed results rather than a vendor claim. The policy structure exists because a register that separates durable rules from volatile tool assignments is the only version of this that is still accurate a year later.

He is not a lawyer. That is stated at the top of every chapter that touches law, policy, HR, or procurement, and it is the reason the kit is built to be reviewed rather than adopted as-is.

What this is not

  • Not legal advice. Your counsel and compliance owner review anything with contractual or regulatory weight. The chapters are written so you can brief them efficiently, not replace them.
  • Not a product recommendation. No AI products are named except the open local-model runtimes you would install to follow chapter 8. The register you maintain is where products live; the rubric for judging them is what does not expire.
  • Not a security program. It covers one domain. It assumes you already have acceptable use, change management, incident response, and third-party risk, and it tells you to hang the AI rules off those rather than build parallel ones.
  • Not a finished policy. It is a draft about 80 percent of the way there. The last 20 percent is local: your classification scheme, your approval authority, your regulated data, your leadership's appetite.
  • Not a training curriculum. There is a fifteen-minute staff session and a thirty-minute session for your own team in the rollout plan. That is the training, and it is deliberately that small.

Who should not buy this

  • Organizations whose security team has already published an AI acceptable-use policy that legal reviewed and leadership adopted. You may still want the redaction guide, the local-model standard, and the questionnaire for embedded AI features, but you do not need the policy templates.
  • Anyone looking for a list of approved AI tools. That list is yours to build, it is different for every organization, and it is stale in a quarter. The questionnaire and the register show you how to build and keep one.
  • Anyone who needs the policy to be specific to a named regulatory regime out of the box. The kit treats regulated data as a class, tells you where your obligations plug in, and marks every place counsel needs to answer a question. If your environment is governed by one regime end to end, you want a specialist, not a starter kit.
  • Anyone hoping a document will settle the argument for them. The kit makes the decisions explicit and gives you the draft; the ninety-minute classification meeting is still yours to run.

If you are the person who was handed AI on top of everything else and has been putting off the blank document, this is for you. Start with the inventory in chapter 1, bring one page to your manager, and you have a real conversation instead of another deferred one.

Who it is for
  • IT administrators and systems people at organizations of 50 to 5,000 who have been asked to 'own AI' on top of everything else, with no budget line and no committee behind them.
  • IT managers and security leads who need a policy that survives an audit question — one that says which data may go where, who approved it, and when it was last reviewed.
  • MSPs and consultants who write the same AI policy for every client and would rather adapt one good draft than start from a blank document each time.
What you walk away with
  • An acceptable-use policy with three tiers — approved, approved with conditions, prohibited — and a request path with a turnaround you can actually hold.
  • A redaction guide with worked before-and-after examples for logs, configs, ticket threads, and scripts, using invented hosts, keys, and addresses.
  • A local-model standard: when on-machine processing is required, how it gets stood up, what it may see, and what it must never see.
  • Ticket-to-runbook prompt sets and user-communication templates for outages, changes, and how-tos, with the approval rule that keeps a generated outage notice from making things worse.
  • A vendor security questionnaire built for AI features — including the ones added to products you already own — plus an approved-tool register and the annual re-check that keeps it honest.
Inside
  • 11-chapter guide, about 18,000 words, from the inventory of what your org is already doing through the 30-day rollout and the quarterly review
  • 15 editable templates in plain markdown, in five groups, each one a finished document you fill in rather than an outline
  • Policy (4): AI acceptable-use policy, written to sit beside your existing acceptable-use and security policy; the data classification and AI destination matrix, four classes of information by five classes of destination with a decision in every cell; the local-model standard; the AI incident response procedure
  • Process (3): the five-field tool request form with a published turnaround; the seven-column approved-tool register with an exception log and a changelog an auditor can read; the AI vendor security questionnaire, fifteen questions plus a six-question short form for AI features in products you already license
  • Redaction (2): the redaction standard, five rules applicable in under a minute, and a separate worked-examples file with before-and-after pairs for a log excerpt, a reverse-proxy config, a ticket thread, and a PowerShell script
  • Documentation and communication (5): runbook template, ticket-to-runbook prompt set, outage notice, change announcement, and user how-to
  • The plan (1): a 30-day rollout, week by week, and a quarterly review with a standing six-item agenda
  • The Redaction Guide, the free one-page piece: five rules and three worked examples, given away for an email address
  • A START-HERE map: what to do with one hour, one day, or one week, and which file to bring to which meeting or moment

11 chapters · 15 template files · read on the site or download the zip.

Free

The Redaction Guide

Five rules and three worked examples for making a log, a config, or a ticket safe to paste. One page, free, no login.

The chapters
  1. What your org is already doing with AI, and why the policy is lateAn honest inventory of the AI use already happening in your environment, how to find it in a week with tools you own, and why the absence of a policy is not neutral — it is a decision that has already been made for you.
  2. The boundary first: classes of data and where each may goBefore you write a single rule about tools, define four or five classes of information and decide, for each class, which destinations are allowed. The matrix is the policy; everything else is commentary.
  3. Redaction that actually works, with before and after examplesA five-rule redaction standard your staff can apply in under a minute, with worked before-and-after examples for a log excerpt, a configuration file, a ticket thread, and a script. Every host, key, and address in the examples is invented.
  4. Tiers of tools and the request pathThree tiers — approved, approved with conditions, prohibited — plus a request path with a stated turnaround. How to set the tiers, who owns them, and how to keep the process fast enough that nobody routes around it.
  5. Scripts and configs: draft, explain, review, and the test-environment ruleThe four ways your own team should use AI on code and configuration, the one rule that prevents the worst outcome, and how to write the standard so it raises quality instead of speed alone.
  6. Documentation and runbooks from ticket threadsThe highest-return AI use in an IT shop: turning solved tickets into runbooks nobody had time to write. The redaction pass, the prompt set, the review gate, and how to keep the output from becoming a second pile of stale documentation.
  7. User communication: outage, change, and the how-toThree kinds of message every IT shop sends badly under pressure, the structure each one needs, how AI helps with the draft and where it hurts, and the approval rule that keeps a generated outage notice from making things worse.
  8. The local model as a policy answerA model running on hardware you control turns most of your hard policy questions into easy ones. What it is genuinely good enough for, what it costs, how to stand one up, and the standard that says what it may see.
  9. Vendor vetting: the questionnaire, the register, the annual re-checkFifteen questions that separate a vendor who has thought about AI data handling from one who has not, how to score the answers, what the register tracks, and why the annual re-check is the control that actually matters.
  10. Incidents: a secret in a prompt, a bad change from an AI draft, a shadow toolThree incidents you will actually have, each with a runbook: the first hour, the decisions, who to tell, what to write down, and the follow-up that prevents the repeat. Plus the reporting culture that determines whether you hear about any of them.
  11. Rollout in 30 days and the quarterly reviewA week-by-week plan that ends with a published policy, a register, a local model, and a communication that landed. Then the quarterly review that keeps all four current instead of letting them go stale in a folder.
Questions
Is this legal advice?

No. The author is a public-sector solutions engineer, not an attorney. Every chapter that touches law, policy, HR, or procurement opens with that statement, and every template carries a disclaimer. Where regulated data is in scope, the AUP and the vendor questionnaire should go through counsel or compliance before adoption. The kit gets you to a reviewable draft fast. Counsel makes it yours.

Will it fit the policies we already have?

That is what it is built for. The AUP is written to sit beside your existing acceptable-use, security, and change-management policies, with [BRACKETED PLACEHOLDERS] for owners, systems, and your own data classification. If you already classify data, the kit tells you to use your scheme rather than its four classes — a parallel AI-only classification is a guaranteed audit finding. The guide is explicit about which decisions belong in policy and which belong in the register that changes without a policy revision.

How big does an organization have to be for this to make sense?

It is written for 50 to 5,000 people, where one person or a small team owns AI on top of a full job. Below 50 the tiers still work but the request path is overkill — read chapters 2, 3, and 8 and skip the process chapters. Above 5,000 you likely have a third-party risk program already, and the parts that will earn their keep are the redaction standard, the local-model standard, and the questionnaire for AI features in products you already own.

Does it name specific AI tools?

Deliberately not, except for the open local-model runtimes you would actually install to follow chapter 8. Products change every quarter; a policy that names them is out of date on publication. The tier assignments live in the register, which you maintain. The guide tells you how to judge a tool, which does not expire.

How current is it, and what happens when things change?

Written September 2026 against the tools, terms, and obligations in force then. Capability and vendor defaults move fast, which is exactly why the kit separates the durable policy from the volatile register and builds in a quarterly review. One payment. When the kit is revised, the current version is what you see and download from your account, and chapter 11 tells you what to re-check each quarter.

What is the refund policy?

30 days, no questions. If it does not save you a week, email and you get your money back.

Can I share it with my team and my leadership?

Yes. The license covers use inside your organization: your IT and security teams, your leadership, your counsel, and your staff. It does not cover reselling it, posting it publicly, or distributing it to other organizations. If a peer at another company wants it, send them the link.

IT Admin AI Acceptable-Use Kit. $59, once.

Card through Stripe. Yours the moment it lands: read it here, download the zip, keep it. Or a Beer Bond: every deal and every product, for life.