Personal-device use often begins as a convenience and quietly becomes an operating rule. A useful decision starts earlier: define the exact workflow, test whether a safer approved alternative exists, and make security, privacy, support, continuity, and exit conditions visible before anyone treats the device as authorized.
This guide records that decision without inspecting a personal device or collecting personal information. Its outcome applies to one bounded device category and workflow—not to a named person, a specific device, every business system, or future use.
Keep eight decision concepts separate
- Business need and safer alternative: why access is requested and whether a company-managed or other approved path can meet the need.
- Device ownership and control: user-controlled status without treating the device as company-managed.
- Workflow and data boundary: the bounded capability and information category, not copied content.
- Minimum device-state dependency: applicable DN-16 categories recorded as requirements or unknowns, not inspected settings.
- Identity and access dependency: AA-07 and AA-08 decisions without choosing methods or privileges here.
- Work/personal separation, privacy, and monitoring boundary: required separation, proposed visibility, and unresolved authority.
- Support, continuity, and exit/removal boundary: support ownership, absence or loss continuity, and a safe end-of-use path.
- Evidence, exception, escalation, and review: reported versus inspected evidence, residual risk, authority, expiry, and reopening triggers.
Do not collapse these concepts into one BYOD approved, managed, compliant, private, or secure checkbox. A good state in one area cannot silently compensate for an Unknown, Blocked, Deferred, or Exception state elsewhere.
What the NIST sources establish—and what they do not
NIST SP 800-114 Rev. 1 distinguishes organization-controlled, third-party-controlled, and user-controlled telework devices; it identifies user-controlled devices as BYOD. NIST SP 1800-22 describes BYOD as creating cybersecurity and privacy challenges for organizations and device owners.
Those sources support separate treatment of ownership, security, and privacy. They do not prescribe the four outcomes, eight stages, 18 fields, evidence threshold, exception model, completion rule, review cadence, consent, or a universal BYOD architecture below. Those are PlainFort editorial judgment, not NIST requirements, certification, compliance, legal or HR advice, or a security guarantee.
Decide in eight stages
1. Bound the workflow and accountable owner
Describe the requested business capability and device category using inert labels. Record the internal owner, responsible operator, genuine backup, decision authority, and approved evidence location. A device owner, contractor, or provider does not silently acquire organizational accountability.
2. Test the business need and safer alternative
Record why the personal-device path is requested. Compare it with a company-managed device, an approved browser-only or limited-access path, a scheduling or equipment alternative, or deferral. These are categories, not product recommendations.
Convenience, speed, or current informal use does not by itself establish necessity. If a safer approved path meets the bounded need, record that result before designing personal-device conditions.
3. Classify ownership, data, and exposure
Record the user-controlled category, bounded workflow, data category, and whether family or shared use, personal backups, personal applications, or unknown storage paths could affect attribution or separation. Do not copy identifiers, applications, content, locations, telemetry, or configuration.
4. Map minimum-state and access dependencies
Use DN-16 categories as references: support and updates, stored-data protection, local access, privilege handoff, endpoint-protection applicability, backup/recovery dependency, evidence, and exceptions. Do not inspect the device or treat it as company-managed.
AA-07 owns MFA-method choice, fallback, and recovery trade-offs. AA-08 owns everyday/admin separation, elevation, privilege boundaries, and exceptions. DN-17 records whether those decisions exist; it does not configure them.
5. Define separation, privacy, and monitoring boundaries
State the required work/personal separation and the category of organizational visibility proposed. Make clear what the organization would be able to see, what it must not collect, who is authorized, how notice or consent questions are handled, and which uncertainty blocks progression.
Do not let business need override privacy, employment, accessibility, family/shared-use, contractual, records, or legal constraints. Stop if the workflow would require undisclosed surveillance, personal-content inspection, location collection, broad application inventory, or authority that has not been established.
6. Plan support, continuity, and exit on paper
Record who supports the business workflow, what happens when the device or person is unavailable, and which safe exit/removal authority would be required. DN-18 owns loss/theft preparation; AA-09 owns departure-triggered revocation; DN-20 owns general remote-work practices.
Do not enroll, track, lock, wipe, remove data, revoke access, inspect backups, or perform a loss response. If safe separation or removal cannot be described without risky live action, use a blocked or excluded outcome.
7. Record outcome, conditions, and exceptions
Choose one bounded outcome:
Allow — bounded workflow and conditions documentedConditionally allow — conditions, owner, evidence, expiry, and review requiredDefer — unresolved dependency, owner, and review date requiredExclude — reason, approved alternative or escalation path, and review trigger required
An exception needs a scope, reason, owner, expiry or exit condition, residual risk, and review trigger. These outcomes are not risk scores, security ratings, consent records, or compliance states. Allow does not prove technical separation, secure configuration, user understanding, or legal sufficiency.
8. Close only with evidence and review
Every field must contain a truthful value or a visible unknown, blocked, deferred, exception, dedicated-guide, or not-applicable state. The outcome must not hide a blocking privacy, support, continuity, access, or exit issue.
Completion means the decision record can coordinate later authorized work. It does not prove consent, security, privacy, technical separation, monitoring proportionality, supportability, recoverability, or enforceability.
Supporting non-scoring states
Documented — evidence referencedReported — evidence not inspectedUnknown — follow upBlocked — qualified help requiredException — bounded scope and expiry requiredDedicated-guide decision requiredNot applicable — rationale and reviewer required
These are workflow states, not a score or verdict.
The 18-field admission-decision record
- Bounded workflow and decision scope: The capability and device category covered.
- Internally accountable owner: The internal role answerable for the outcome.
- Responsible operator, backup, and decision authority: Execution, continuity, and approval roles.
- Personal-device category and ownership/control boundary: User-controlled category without a specific identifier.
- Business need: The reason the workflow is requested.
- Safer or company-managed alternative: The alternative considered and its result.
- Business-data and workflow boundary: Category only; no content copied.
- DN-16 minimum-state dependencies and evidence state: Required categories and reported or referenced evidence.
- AA identity/access dependency: AA-07/AA-08 handoff without methods, accounts, or secrets.
- Work/personal separation requirement: The required conceptual boundary.
- Privacy notice and consent/authority boundary: The unresolved or documented authority category.
- Monitoring/visibility boundary: Permitted category, prohibition, and evidence reference.
- Support and continuity boundary: Support owner and alternate business path.
- Exit/removal and loss handoff: AA-09/DN-18 dependency without live action.
- Decision outcome and conditions: One of the four bounded outcomes.
- Exception, residual risk, and expiry or exit condition: The visible gap and its bounded treatment.
- Non-sensitive evidence reference and escalation/stop result: Where authorized evidence exists and what prevents progression.
- Completion evidence and next review trigger: What supports closure and what reopens the decision.
Keep the record vertical. It is not a device inventory, monitoring record, legal form, consent template, dashboard, heat map, maturity model, compliance checklist, product comparison, or scorecard.
Worked example
Fictional example — do not copy as a completed device or network record
The Example Co. record below contains no real or plausible person, device, application, location, account, content, consent fact, monitoring configuration, employment situation, or removal event.
- Bounded workflow and decision scope: Limited access to a low-sensitivity scheduling workflow from a personal-device category.
- Internally accountable owner: Operations owner.
- Responsible operator, backup, and decision authority: Approved support role; backup authority is documented separately.
- Personal-device category and ownership/control boundary:
Personal-device category record — details held in approved system. - Business need: Temporary access-gap coverage; convenience alone is not the reason.
- Safer or company-managed alternative: Approved managed-device alternative assessed but not yet available.
- Business-data and workflow boundary: Scheduling capability only; content is not copied here.
- DN-16 minimum-state dependencies and evidence state:
Reported — evidence not inspected; personal and managed devices are not treated as equivalent. - AA identity/access dependency:
Dedicated-guide decision requiredfor AA-07 and AA-08. - Work/personal separation requirement: Business access must remain within the approved workflow boundary.
- Privacy notice and consent/authority boundary:
Blocked — qualified help required; notice and authority have not been confirmed. - Monitoring/visibility boundary: No location, personal-content, browsing-history, or broad application collection is authorized.
- Support and continuity boundary: Operations owns the alternate path; device-owner support is not assumed.
- Exit/removal and loss handoff: AA-09 and DN-18 handoffs required; no revocation, tracking, lock, wipe, or removal is performed.
- Decision outcome and conditions:
Defer — unresolved dependency, owner, and review date required. - Exception, residual risk, and expiry or exit condition: Temporary access gap remains; privacy authority and access decisions block admission.
- Non-sensitive evidence reference and escalation/stop result:
Approved evidence location — personal and sensitive content not copied; stop before enrollment or access change. - Completion evidence and next review trigger: Decision record complete as a deferral; reopen when managed equipment, privacy authority, or AA decisions change.
All 18 fields are populated, but the personal-device category is not admitted. The blocked privacy boundary and dedicated-guide dependencies prevent false completion.
Dedicated-guide boundaries
- DN-16 owns the company-managed laptop baseline and supplies categories without pre-approving personal devices.
- DN-20 owns the cross-location remote-work baseline.
- DN-18 owns pre-incident preparation for device loss or theft.
- AA-06 owns password-manager rollout and attributable credential migration.
- AA-07 owns MFA-method choice, fallback, device dependency, and recovery trade-offs.
- AA-08 owns everyday/admin separation, elevation, privilege boundaries, and exceptions.
- AA-09 owns departure-triggered access revocation.
- SF-05 owns operational vendor-access fields and lifecycle.
DN-17 records admission and handoffs only. It does not perform enrollment, monitoring, account or privilege change, credential migration, offboarding, loss response, remote-work surveillance, backup/restore work, remote lock/wipe, data removal, incident response, or legal, HR, or privacy determination.
Review triggers
Reopen the decision when the workflow, data category, business need, alternative, device ownership, support state, access decision, separation capability, proposed visibility, privacy authority, continuity, exit path, exception, or official guidance changes—or when loss, compromise, or an operational failure exposes a gap.
Where this guide stops
This guide records a decision; it does not touch a personal device. Do not use it to inspect, enroll, configure, monitor, collect telemetry or location, inventory applications, access personal content, change an account, track, lock, wipe, remove data, test recovery, or respond to loss or compromise.
Seek qualified IT, security, privacy, legal, HR, accessibility, contractual, records, or incident-response help when authority is unclear, sensitive data or shared use is involved, monitoring or removal is proposed, safe separation or continuity is absent, or a live action could cause privacy intrusion, lockout, evidence loss, or data loss.