Skip to content

HR policies for startups: the first eight policies to write (with templates)

A policy is a decision written down once, so managers stop deciding case by case. These are the eight to write first, with the template each one should follow.

Francisco Campos7 min read

An HR policy is a decision the company takes once and writes down, so that managers stop taking it again — differently — every time the question comes up. Starting from nothing, eight policies cover almost every recurring question a company of twenty to three hundred people gets asked: remote and hybrid working; time off and leave; expenses and equipment; performance and feedback cadence; promotions and pay review timing; onboarding and probation; conduct and communication tools; and parental leave and flexibility. Write those eight, keep each to a page, and most of the case-by-case negotiation disappears.

Everything else — the full employee handbook, the benefits catalogue, the code of ethics — can wait until the eight are in use and someone has found the gaps in them.

What HR policies for startups are actually for

A policy is not a legal text and it is not a statement of culture. It is the answer to a question that has already been asked more than twice: can I work from the Algarve in August, who pays for the laptop, when do salaries get reviewed. Until it is written, each of those questions costs a conversation, and the answer depends on who was asked and what kind of week that person was having.

The inconsistency is the real cost. Two people in different teams get different answers to the same question, both answers are defensible, and the company has quietly created a precedent it never decided on. A written policy replaces a hundred small negotiations with one decision the leadership team took deliberately.

The test of a policy worth having is simple: a manager can answer from the document, without escalating, and would give the same answer any other manager would give.

The first eight policies to write

Order them by how often the question comes up, not by how important the topic sounds. Each entry below names the decision the policy settles, who owns it, and the single exception rule — because a policy with no stated route for exceptions gets worked around quietly instead of amended openly.

  1. Remote and hybrid working. Settles where work happens and what presence the company expects. Owner: the leadership team, drafted by whoever holds People. Exception: a manager can approve a temporary change of up to one month; anything permanent goes back to the leadership team.
  2. Time off and leave. Settles how annual leave is requested and approved, the notice expected for longer absences, how much carries over, and what happens on a sick day. Owner: the People lead. Exception: the direct manager approves the request; only the People lead approves anything beyond the stated carry-over.
  3. Expenses and equipment. Settles what the company pays for, what someone can buy without asking, what needs approval first, and who keeps the laptop when a person leaves. Owner: finance, written with People. Exception: the budget holder approves above the stated limit, in writing, before the money is spent.
  4. Performance and feedback cadence. Settles how often a manager and a team member sit down, what a performance conversation covers, and when the formal cycle happens. Owner: the People lead. Exception: none for the cadence itself; a function lead can adapt the format as long as the frequency holds.
  5. Promotions and pay review timing. Settles when pay is looked at, who proposes a change, who approves it, and what a promotion requires beyond good work. Owner: the CEO with the People lead. Exception: an off-cycle change needs the CEO's written approval and a recorded reason.
  6. Onboarding and probation. Settles what the first day, the first week and the first ninety days include, who is accountable for each part, and how the probation conversation is held. Owner: the hiring manager, working from a company template. Exception: the People lead can extend a probation once, with the reason written down.
  7. Conduct and communication tools. Settles which tool is used for what, what response time is expected on each, what is never handled in a private channel, and how a concern about behaviour is raised. Owner: the leadership team. Exception: none for the route to raise a concern — having no exception is the point of it.
  8. Parental leave and flexibility. Settles what the company adds to the statutory minimum, how the return to work is planned, and what flexibility is available in the months after. Owner: the People lead with finance. Exception: the CEO approves anything beyond the written arrangement, and it is added to the policy at the next review.

Eight documents, one page each, is a realistic first pass over a few weeks rather than a quarter-long project. The writing is quick once the decision is made; the decision is the slow part, and it belongs to the leadership team rather than to whoever drafts.

Most policies fail not because the rule is wrong, but because nobody named the person who can say yes to an exception.

The policy template

Every one of the eight should carry the same six sections, in the same order. Sameness matters more than elegance here: a manager who has read one policy should be able to find the answer in any other without hunting for it.

SectionWhat it has to sayWhat happens when it is missing
PurposeThe question this policy answers, in one sentenceThe document drifts into a statement of values and stops being usable
Who it applies toEvery group covered, and any group deliberately left outContractors, part-timers and new joiners each generate their own argument
The ruleThe default answer, stated plainly enough to act onManagers fall back on personal judgement and the answers diverge
Exceptions and who approves themWhat can be varied, by whom, and how it gets recordedExceptions are granted informally and become the real policy
OwnerOne named role accountable for keeping the document trueNobody updates it and it quietly stops matching practice
Review dateThe month it will be looked at againIt ages until someone discovers it is wrong at the worst possible moment

A hybrid working policy skeleton

This is the policy most companies write first and the one most often written badly, because it gets written as an aspiration instead of a rule. A usable remote work policy answers six things:

  • Eligibility. Which roles can work remotely and which cannot, stated by role rather than by person.
  • Days and presence. How many days in the office, who decides which days, and what a team can require of everyone — a fixed anchor day is far easier to run than a floating count.
  • Equipment. What the company provides for working from home, what it does not, and what happens to it when someone leaves.
  • Expenses. What is reimbursed for home working, what limit applies, and how a claim is made and approved.
  • Security. Where company data may be accessed from, what device and network rules apply, and who to tell when a device is lost.
  • Review. When the arrangement is reassessed, and what would cause it to be revisited sooner.

Check the draft against the employment rules that apply where your people actually work before you publish it. A policy is an internal commitment; where the law sets a minimum, the law wins, and that check belongs with a lawyer rather than with the drafter.

Three questions worth answering before you start

Do we need an employee handbook?

Not at first. A handbook is a binder for policies that already exist and are already used; producing one before the underlying decisions are made is how a company ends up with forty pages nobody opens. Write the eight as separate one-pagers, put them where everybody can find them, and assemble a handbook when the collection is large enough that finding things has itself become the problem.

How many policies are too many?

The count is the wrong measure. The test is whether each policy is still being used: one that has not been consulted or applied in a year is either covering a situation that never arises or has been quietly replaced by custom. At this size, somewhere between eight and fifteen is normal. Past that, the risk is not bureaucracy in the abstract — it is that managers stop reading, and they stop reading all of them at once.

Who should approve exceptions?

One named role per policy, and never the person asking. A workable default: the direct manager for anything with a local, reversible cost; the policy owner for anything that sets a precedent; the CEO for anything that touches pay. Record every exception in the same place, and at the review date the pattern of exceptions will tell you whether the rule itself is wrong. A policy that needs constant exceptions is not being broken — it is out of date.

Where this fits

Policies are the cheapest part of a people system to build and the easiest to leave half-done, because nothing visibly breaks when they are missing. The cost shows up instead as a founder's week spent on decisions that should have been taken once. Deciding what the eight should say for a specific company, and getting them written in a form managers will actually use, is the work in Policies and Benefits.

Related reading: the management systems a 50 to 300 person company needs, which places policies next to the other systems they depend on, and role clarity in growing teams, because a surprising share of policy exceptions turn out to be unclear ownership wearing a different hat.

Francisco Campos

Co-founder — Organisation & Operations

Francisco Campos

Built growing companies from the inside: first employee to COO at Onport through its acquisition by Farfetch.

More from Francisco

Related reading

Leadership & Management5 min read

One-to-one meetings: how to run a 1:1 worth the hour

Most one-to-ones are status meetings with two people in them. The fix is not a better template — it is deciding what the meeting is for, then protecting thirty minutes for it.

Ana Reis

Your company has changed. Has your organisation caught up?

The People Diagnostic establishes where the organisation is constrained, and what to fix first.