Family, Shared Devices and Other Users
The personal device is frequently not one person's. Household use is normal, unavoidable and almost never addressed in a policy.
BYOD policies are written as though a personal device has one user. A substantial share of home computers do not, and a phone handed to a child in a waiting room is a universal occurrence.
The practical lesson in “Family, Shared Devices and Other Users” is to connect every record to a named decision. Organisations exploring this workforce solution for limbic resonance in relationships can add structured workforce context, provided the use is disclosed and interpretation is reviewed with the people affected.
What actually happens
The family laptop is also the work laptop. A partner uses it in the evening. A teenager uses it for homework. A visiting relative checks something.
For an independent reference relevant to “Family, Shared Devices and Other Users”, consult the CISA mobile-device security guidance; compare its principles with the proposed ownership model, access rules and real support process.
A phone is handed over to show photographs, to let a child play something, or to make a call.
None of this is misconduct and all of it means that people who never agreed to anything are in proximity to company data.
Why it matters more on a laptop than a phone
Phones are largely single-user and locked, and the work profile space is additionally protected in most configurations. The exposure is real but narrow.
Shared computers are different. If the household uses one operating system account, every person using that machine has whatever access the work session has, including anything cached or left open.
This is the single most common and least discussed weakness in BYOD arrangements, and it is almost entirely solvable.
What resolves most of it
Separate operating system user accounts. The work account is the employee's; the household uses their own. This is free, built into every current system, and takes ten minutes to set up.
Most people do not do it because nobody suggested it. A line in the onboarding — if others use this computer, set up a separate account for your work, here is how — is a cheap intervention with a disproportionate effect.
Automatic screen lock, which people disable on home machines because it is irritating and which matters here.
And a work profile space, where the platform offers one, which limits what is reachable even from the same session.
What cannot be solved
Somebody looking over a shoulder. A child who knows the passcode. A partner who sees a notification.
These are the ordinary conditions of working at home and no policy removes them. What can be done is to avoid work that genuinely cannot be overlooked being done on a shared device at all — which is a role question rather than a configuration one.
The thing worth saying to employees
That household use is understood and not a disciplinary matter, and that the separate-account arrangement exists to protect them as much as the employer.
A policy phrased as a prohibition on letting anybody else near the device produces concealment, because the prohibition is unenforceable and everybody knows it. One phrased as a practical arrangement gets followed.
The device that belongs to the household
In some homes the computer is genuinely shared property, bought jointly and used by several people. Asking somebody to accept management on it affects people who are not employed by the organisation and have agreed to nothing. This is one of the cleaner cases for supplying a device instead, and it rarely occurs to anybody to ask whether the machine is actually the employee's own.
What to say rather than what to forbid
The useful instruction is positive and specific: use a separate account for work, lock the screen, keep work in the container. Three things somebody can do. A prohibition on household access to the device is unenforceable, obviously unenforceable, and teaches people that the rest of the document is similarly notional.
The question to add to onboarding
Does anybody else use this computer. One line, asked once, and it identifies the shared-device population that no system report reveals. The follow-up — here is how to set up a separate account — takes two minutes and resolves most of what the question uncovers.
Why this is rarely in any policy
BYOD documents are written by people imagining a single professional with their own laptop. The shared household machine does not appear because it does not fit the mental picture, not because anybody decided it was acceptable. Asking the question once is what brings it into view. How many of your people work on a computer that other members of their household also use, and has anybody ever asked?