skills/legal/byod-policy/SKILL.md
Drafts a Bring Your Own Device (BYOD) policy for U.S. employers governing personal device access to company systems. Covers MDM enrollment, encryption, remote wipe authority, privacy expectations, data classification, and regulatory overlays (HIPAA, GLBA, SOX, GDPR). Use when creating or updating BYOD policies, mobile device security policies, or personal device programs.
npx skillsauth add casemark/skills byod-policyInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Generates an employer-facing BYOD policy balancing operational flexibility with data security, regulatory compliance, and enforceable employee obligations.
Gather before drafting:
| # | Section | Key Contents | |---|---------|-------------| | 1 | Purpose & Scope | Why BYOD is permitted; covered employees, devices, systems | | 2 | Eligibility & Enrollment | Approval process; IT registration; MDM installation | | 3 | Security Requirements | Minimum device standards (see checklist below) | | 4 | Company Rights | Remote access, monitoring, wipe authority and triggers | | 5 | Privacy Expectations | What company may/may not access; commingled data | | 6 | Employee Responsibilities | Reporting obligations; financial responsibility | | 7 | Data Handling | Permitted classifications; backup, retention, deletion | | 8 | Regulatory Compliance | Industry-specific overlays | | 9 | Support & Liability | IT support scope; negligence liability | | 10 | Acknowledgment | Signature block; disciplinary consequences |
Include minimum standards:
Enumerate trigger conditions: termination/resignation, lost/stolen device, confirmed/suspected breach, sustained non-compliance (after notice), employee opt-out.
Distinguish selective wipe (corporate data only) from full device wipe and specify which MDM capability applies to each.
| Company MAY access | Company will NOT access | |---|---| | Business email, calendar, contacts synced to company systems | Personal photos, texts, personal email | | Company app activity and data | Personal app data outside company systems | | Traffic routed through company VPN | Personal browsing not on company infrastructure | | Documents in company cloud storage | Personal files never synced to company systems |
Include: employee printed name, signature, date, department/manager, optional witness/HR signature. Statement must confirm employee has read, understands, and agrees to comply, with notice that violations may result in discipline up to termination, BYOD revocation, and/or legal action.
tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.