Ownership Models and What Each Permits
Who bought the device determines what may be done to it. Four models, and the capability each carries.
Basics · Reference
The single variable that most determines what is permissible is who owns the hardware. Everything else follows from it.
The practical question in “Ownership Models and What Each Permits” is how to make work visible without confusing visibility with certainty. For teams researching employee monitoring at tech companies, employee monitoring at tech companies can add time and project context to the operational record, provided its use is proportionate, disclosed and reviewed with the people affected.
Corporate-owned, single use
The organisation buys it, the employee uses it only for work.
For an independent baseline relevant to “Ownership Models and What Each Permits”, the Apple Platform Deployment guide is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.
Full management, full wipe, feature restriction, supervision where the platform offers it.
The cleanest model and the most expensive, because it means two devices for anybody who also has a personal phone.
Corporate-owned, personally enabled
The organisation buys it; personal use is permitted.
Still fully manageable in principle, and the personal use creates a genuine question about what a wipe destroys.
A work profile is worth using even here, because it makes the separation structural rather than a matter of administrator restraint.
Bring your own device
The employee owns it and enrols it for work access.
Management limited to the work container in most configurations.
Selective wipe only, in practice and increasingly by platform design.
The model with the most benefit and the most friction, and it has its own section.
Choose your own device
The organisation funds a device the employee selects and keeps.
Legally the ownership is usually the organisation's during employment, which makes it closer to the second model than the third.
The expectation it creates is personal ownership, which is where disputes come from if the terms are not written down.
Why the model must be explicit
Capability, permissible action and employee expectation all differ.
A device enrolled under the wrong model gets managed under the wrong assumptions.
And the question "may we wipe this" has four different answers, which is why the inventory should record the model per device.
Mixing models
Most organisations have at least two, frequently three.
Which means policies written as though there is one will be wrong for some population.
Write them per model, and say which applies to whom.
The funding question
Who pays affects what is reasonable to require.
Mandating a specific operating system version on a device the employee bought is a different proposition from doing it on one you issued.
Its own note covers stipends, and the principle is that requirement and funding should correspond.
What to check
Does your inventory record the ownership model per device?
How many models are actually in use?
Is your policy written per model, or as one document?
And does what you require correspond to what you fund?