Mobility & UEM

BYOD, COPE or corporate-owned: choosing an ownership model

The ownership model decides your privacy position, your cost base and how much control you actually have. Most organisations pick it by accident.

CDTS Australia 4 min read

Ask an organisation what its mobile ownership model is and you will usually get an answer that describes two or three models running at once, none of which was chosen deliberately.

That is not unusual and it is not fatal. But the ownership model determines what you are legally allowed to do to a device, what you can enforce, and what the fleet costs — so it is worth deciding rather than inheriting.

The three models, stated plainly

Corporate-owned, corporate-only. The organisation buys the device, owns it, and it is used for work. Full supervision, full control, full visibility, and the organisation pays for everything.

COPE — corporate-owned, personally enabled. The organisation buys and owns the device, and the user is permitted to use it personally within a policy. Control is nearly as complete as the model above, with a privacy boundary around the personal side.

BYOD. The user owns the device. The organisation manages only its own data and applications on it, and has no claim on the rest.

The distinction that matters is not who paid. It is who owns the device at the moment you need to wipe it, because that determines what you can do without consent and what you cannot do at all.

What the platforms actually give you

The technical implementations have converged usefully.

Android Enterprise work profile creates a cryptographically separated container. Work apps and data sit inside it; the organisation manages the profile and can remove it completely, and has no visibility into or control over anything outside it. Personal apps, photos, messages and location are genuinely not accessible.

iOS User Enrolment does the equivalent on Apple’s side: a separate managed identity, managed apps and accounts logically separated from personal ones, and an organisational wipe that removes only the managed data. Notably it will not give you the device serial number or let you erase the device — deliberately.

Both models let you make a truthful and specific promise: we can remove our data, and we cannot see yours. That promise is the whole basis of a workable BYOD programme, and it should be written into the policy in those terms rather than left to trust.

Choosing between them

Cost is not the deciding factor people assume. BYOD moves the hardware cost to the user but adds a stipend in most arrangements, plus a support burden across every device model and OS version anyone owns. The saving is real but smaller than the business case usually claims, and it comes with a support cost that is hard to forecast. We have written about where the money in a fleet actually goes separately.

Control has a hard ceiling on BYOD. You cannot require a minimum OS version on a device you do not own without effectively excluding the user. You cannot enforce full-disk configuration, you cannot supervise, and you cannot mandate a security agent outside the work container. If your risk position requires those things, BYOD is not available to you regardless of how the business case reads.

Records and discovery favour corporate ownership. If work communications on the device are official records, or could be subject to discovery or an FOI request, the organisation needs a defensible way to access them. On a personally owned device that is a legal question with an expensive answer.

COPE is the default answer for government work, and usually the right one. The organisation owns the asset, can supervise it, can enforce OS versions and security agents, and can retire it cleanly — while the privacy boundary makes it acceptable as the only phone somebody carries. Most of the fleets we run are COPE, for that combination of reasons.

The mistakes that cost the most

Running BYOD without a written policy. What is managed, what is not, what happens on departure, and who pays for what. Without it, the first difficult departure is negotiated from scratch under pressure.

Full-device management on a personally owned phone. Some organisations still enrol BYOD devices in full management, either because the platform allowed it or because nobody chose otherwise. It creates a privacy exposure the organisation does not want, and a wipe capability that will eventually be used by accident on somebody’s personal photos.

Not deciding what happens at departure. Removing a work profile is straightforward. Deciding whether a phone number that customers know belongs to the person or the organisation is not, and it should be settled in the policy rather than in the exit interview.

A mixed fleet with one policy set. BYOD and corporate devices need different compliance rules, different app catalogues and different support expectations. One set applied to both is either too loose for the corporate devices or unenforceable on the personal ones.

The short version

Decide the model per cohort, not per organisation. Field and executive users usually need corporate ownership; a broad staff base is often better served by BYOD with a work profile; and COPE sits between them and covers most government requirements.

Then write down what you can see and what you cannot, and make sure it is true.

More on how we run mobile fleets.

Next step

Let’s talk about your environment

Tell us what you are running today and where it hurts. We will give you a straight answer on whether we are the right fit, and what we would look at first.