/
/

How to Document Workarounds That Don’t Belong in SOPs

by Lauren Ballejos, IT Editorial Expert
How to Document Workarounds That Don’t Belong in SOPs blog banner image
How to Document Workarounds That Don’t Belong in SOPs blog banner image

Key Points

  • Define clear criteria that separate temporary workarounds from standard SOPs.
  • Maintain a centralized, structured register to document all workarounds.
  • Link workaround entries to relevant assets and service records for visibility.
  • Review and retire outdated workarounds through regular governance cycles.
  • Train technicians to document and manage workarounds consistently.

Standard operating procedures (SOPs) are a key tool for managed service providers (MSPs), enabling them to deliver consistent, thorough service by defining repeatable steps for recurring tasks.

However, there are scenarios where you’ll need troubleshooting workarounds and “once-off” solutions to meet a client or user’s specific needs. The problem is that these quick fixes can easily clog up your SOP register if they’re not documented properly.

This guide explains how to document IT workarounds that don’t belong in your SOPs.

Why you need to document workarounds in IT

IT workarounds are temporary solutions to unexpected system or software issues. They allow users to continue working while IT investigates and looks for a long-term solution.

One of the biggest issues with workarounds is that they often become “tribal knowledge” that lives in people’s heads. It’s very common for technicians to forget to document the workarounds they’ve built, and when a new employee encounters the same issue, the original technician has either forgotten it completely or has left the company.

This is the reality for many support organizations. According to Atlassian’s 2024 State of Teams report, 55% of knowledge workers struggle to find information even though they know it exists within their organization, while 50% have unknowingly duplicated work due to poor knowledge sharing. This highlights how undocumented processes and tribal knowledge can create operational bottlenecks.

While documenting these workarounds in SOPs preserves them, it can also lead to confusion or cause them to be misconstrued as part of standard configurations, resulting in their broad deployment. This could lead to inconsistent configurations and potential security or compliance gaps.

How to document IT workarounds without cluttering SOPs

The good news is that there’s a way to document IT workarounds without accidentally bloating your organization’s SOPs. But to do this, you’ll need:

  • An existing SOP documentation platform (e.g., IT Glue, Confluence, NinjaOne Docs, or SharePoint)
  • Defined SOP review cadence (quarterly or biannual)
  • Agreement on what qualifies as a workaround vs. a standard SOP item
  • Technician training on how to log new workarounds consistently
  • A clearly defined policy on how AI assistants and copilots are allowed to access, surface, or act on workaround documentation
StepActionOutput
1Define workarounds vs. SOP candidates.Defined criteria or decision tree
2Create a workarounds register.Centralized, searchable log
3Tag workarounds to service records.Asset and ticket linkage
4Review and retire workarounds.Governance cadence
5Communicate the workaround scope to technicians.Trained, aligned team

Step 1: Define workarounds vs. SOP candidates

Clearly separate which procedures and what information belong in your SOPs, and what is considered a “workaround”. For example, a workaround may be considered any fix that addresses an issue temporarily, or has a single once-off purpose, like a setting or permission for a specific user due to an edge-case requirement (like legacy software that needs local administrative privileges to run). Deciding whether information belongs in an SOP or workaround document can be tabulated or presented as a decision tree and included in your documentation platform for future reference.

Step 2: Create a workarounds register

Documented workarounds should be centrally stored in a structured way, and made searchable. This provides oversight and makes sure workarounds can be found (if they can’t be, efforts will be duplicated, defeating their purpose). Fields should include:

  • Unique workaround ID
  • Date added
  • Issue or system context
  • Steps taken
  • Risks or limitations
  • Source (e.g., ticket number, technician, or client site)
  • Status (e.g., active, replaced, or retired)
  • Compliance/risk flag
  • Review or expiration date

A consistent structure will ensure technicians always know how to record workaround details and prevent information from being missed. Some documentation platforms automatically send notifications or reminders when a workaround or document is due for review or is nearing its expiration date, reducing the need for manual checks.

Step 3: Tag workarounds to service records

Your ITSM toolchain should include asset management, allowing you to account for and track the status of the components in your IT infrastructure. Adding references to your workaround register to an asset (such as recording the unique workaround ID or attaching a link) ensures that they are discoverable in context. Devices can also be tagged if they have an active workaround for visibility.

Making the tagging and recording of, as well as checking for workarounds in your asset management platform, part of your SOPs is one way of ensuring the process is accounted for there, without having to include each workaround in SOP documents.

Step 4: Review and retire workarounds

Regularly review your workarounds register in its entirety to prevent outdated or no-longer-required workarounds from persisting in your infrastructure. This can be done as part of periodic IT governance cycles. Optionally set expiry dates or automate ticket creation for workarounds that present a security or compliance risk so that they are reviewed and retired, or so that mitigation measures can be maintained.

Having a review cadence is not only considered a best practice for data housekeeping, but it can also help demonstrate compliance.

Some cyber insurers are requesting proof of ongoing controls and continuous monitoring before issuing or renewing a policy. An outdated workaround register can easily become an audit finding if not reviewed regularly.

Commonly deployed workarounds may be considered for inclusion in SOPs after further testing to ensure they meet best practices.

Step 5: Communicate workaround scope to technicians

Your tech team members should understand the difference between approved SOPs and workarounds. Workarounds should be treated as temporary, with the technical details thoroughly documented alongside the risks they may present. High-risk workarounds should require escalation approval before being applied.

Technicians should be made aware of these policies during onboarding and during regular reviews.

It’s also crucial that you have a policy around AI agents accessing, surfacing, or acting on workarounds. AI agents can read and act on this information through the Model Context Protocol.

Workaround documentation and maintaining effective SOPs with NinjaOne

NinjaOne provides a comprehensive set of tools for MSPs that includes remote monitoring and management (including remote access), mobile device management (MDM), and backup, with IT asset management (ITAM), ticket desk, and documentation. This allows you to document workarounds outside of SOPs, link them to tickets and assets, and tag endpoints where workarounds are active.

Automation and patch management help ensure workarounds do not cause conflicts and can be rolled back using scheduled scripts. Dashboards and summary reports can also be created for full oversight.

Workarounds are inevitable in IT, and while active, can present an ongoing compliance or security risk. Systematic documentation and ensuring that each workaround is fully documented and accounted for prevent them from becoming tribal knowledge.

Quick-Start Guide

Documenting Workarounds in NinjaOne

NinjaOne offers several documentation options for capturing workarounds that don’t fit into standard SOPs:

Recommended Approaches
1. Knowledge Base Tool: Use NinjaOne’s Documentation feature to create internal knowledge base articles. This allows you to:
– Document workarounds in a controlled, accessible format
– Create articles with specific permissions
– Organize workarounds by product or functional area

2. Internal Troubleshooting Documentation Guidelines:
– Include a clear disclaimer that the document is for internal use only
– Structure the document with:
– Top section: Disclaimer and sections covered
– Middle section: Detailed workaround explanation
– End section: Potential escalation process if applicable

Key Considerations
– Mark documents as “Internal” to prevent customer-facing sharing
– Link to corresponding customer documentation when possible
– Verify and vet workarounds with management
– Update documentation regularly as product functionality changes

Best Practices
– Use clear, concise language
– Include context for why the workaround exists
– Specify any limitations or potential risks
– Consider creating a dedicated section for known workarounds in your internal documentation

FAQs

A workaround becomes a candidate for a permanent fix when it is used repeatedly across multiple clients or scenarios. If testing shows it aligns with best practices and doesn’t introduce risk, it can be standardized into your SOPs.

Clear escalation rules and technician training help ensure workarounds stay temporary. Reinforcing SOPs as the “source of truth” and regularly reviewing workarounds discourages ad-hoc fixes from becoming long-term habits.

Establish a review schedule and assign ownership for updating or retiring workaround entries. Automation, such as reminders or governance tickets, can help keep the register from becoming outdated.

Outdated workarounds can create security gaps, performance issues, and inconsistencies across managed environments. They may also mask underlying problems that should be addressed and resolved permanently.

Make documentation part of the troubleshooting workflow and provide a simple, standardized template. Reinforce expectations during onboarding and hold teams accountable through periodic audits or spot checks.

Clients should be notified when a workaround introduces risk, affects performance, or requires future remediation. Transparent communication builds trust and ensures clients understand the temporary nature of the fix.

You might also like

Ready to simplify the hardest parts of IT?