
Using AI to Create Useful SOPs
Originally published May 27, 2026 — Updated July 22, 2026 —
Most businesses know they should have better documentation.
The problem is that documentation always seems to get pushed to the bottom of the list.
The network needs attention. A user can’t log in. A vendor needs to be called. A new employee is starting tomorrow. The phone system needs a change. By the time everything else is handled, nobody wants to spend the next three hours writing a Standard Operating Procedure.
This is one area where I have found AI can be extremely useful.
AI doesn’t need to replace the person who understands the business or the technology. Instead, it can help that person take what they already know and turn it into organized, consistent, usable documentation.
Why SOPs Matter
Every business depends on processes and technology.
That might include:
- Internet connectivity
- Wi-Fi
- Firewalls
- VPNs
- Servers
- Cloud services
- Telephone systems
- Workstations
- Microsoft 365 or Google Workspace
- Cybersecurity systems
- Backups
Unfortunately, important information about these systems is often scattered everywhere.
Some of it may be in an employee’s notebook. Some may be buried in an old email. Other information may be sitting in a spreadsheet that nobody knows exists.
And sometimes the only person who knows how something works is the person who installed it five years ago.
That’s a problem.
What happens if that person retires, resigns, becomes ill, changes jobs, or simply isn’t available during an emergency?
Good documentation helps reduce that dependency.
It can make a business easier to support, troubleshoot, secure, recover, and eventually hand over to someone else.
Where AI Can Help
Creating a professional SOP traditionally involves much more than writing.
You have to decide what information belongs in the document, organize it into logical sections, create tables, standardize terminology, maintain consistent formatting, and make sure the finished document is understandable to someone other than the person who wrote it.
AI can help accelerate much of that process.
For example, I might provide the technical information about a customer’s environment and ask AI to help organize it into a standardized SOP.
The AI can help me:
- Organize information into logical sections
- Create a consistent document structure
- Build tables and checklists
- Standardize formatting
- Identify information that may be missing
- Turn technical notes into understandable instructions
- Create a repeatable template for additional locations
- Update existing documentation as systems change
That can save a tremendous amount of time.
But there is an important distinction.
AI helps me document the solution. It doesn’t replace the experience required to design the solution.
The IT professional is still responsible for the network design, security decisions, architecture, operational standards, and technical accuracy.
AI is the assistant.
The professional remains responsible for the work.
A Simple Example: Documenting a Company’s IT Environment
Let’s use a fictional company called ABC LLC.
Suppose ABC LLC has several offices and wants to improve its IT documentation.
We might start by creating a standard naming convention:
| Device Type | Example |
|---|---|
| Firewall | ABC-HQ-FW01 |
| Core Switch | ABC-HQ-SW01 |
| Access Point | ABC-HQ-AP01 |
| Phone System | ABC-HQ-PBX01 |
| Server | ABC-HQ-SRV01 |
| Workstation | ABC-HQ-PC001 |
Then we document the company’s locations:
| Site | Code |
|---|---|
| Headquarters | HQ |
| Tampa Office | TMP |
| Orlando Office | ORL |
| Daytona Office | DAY |
| Warehouse | WH |
This may seem simple, but establishing standards early makes future documentation much easier.
Now every new device can follow the same naming structure.
Building the SOP Step by Step
Once the basic standards are established, we can begin documenting the actual environment.
Step 1: Company Information
Document information such as:
- Legal company name
- Main office
- Additional locations
- Primary contacts
- Emergency contacts
- Office hours
- After-hours support procedures
Step 2: Internal Network
Document:
- Network subnets
- VLANs
- DHCP scopes
- DNS servers
- Active Directory or identity systems
- Server addresses
- Firewall management
- Switch management
Step 3: Internet and External Services
Document:
- Internet providers
- Circuit information
- Static IP assignments
- Backup internet connections
- DNS providers
- SIP or telephone carriers
Account numbers and other sensitive information should only be included when appropriate and when the document itself is properly secured.
Step 4: Wi-Fi
Document:
- SSID names
- VLAN assignments
- Access point locations
- Authentication methods
- Guest access policies
Actual Wi-Fi passwords should not be stored in an unsecured SOP.
The document should instead identify the approved password or credential vault where authorized personnel can retrieve them.
Step 5: Telephone Systems
Document:
- PBX platform
- SIP carrier
- Main telephone numbers
- Extension ranges
- Voicemail procedures
- Paging systems
- After-hours routing
- Emergency calling configuration and testing procedures
Step 6: Vendors and Support Contacts
Keep a central list of critical vendors.
This might include:
- Internet provider
- Telephone carrier
- Firewall vendor
- Copier company
- Alarm company
- Low-voltage contractor
- Software vendors
- IT support provider
Knowing who to call during an outage can be just as important as knowing how the technology works.
Step 7: Credentials
Credentials deserve special attention.
Passwords, recovery codes, service accounts, VPN credentials, API keys, and other secrets should not be scattered throughout SOP documents.
Use an approved credential-management system with appropriate access controls and multifactor authentication.
The SOP should tell authorized personnel where the credential is securely stored, rather than unnecessarily exposing the credential itself.
Don’t Forget Backups
A good IT documentation library should explain the backup environment as well.
Document:
- Backup platform
- Backup schedule
- Retention period
- Off-site or cloud replication
- Recovery procedures
- Last recovery test
Having a backup is important.
Knowing how to recover from it is just as important.
HIPAA and Other Compliance Considerations
For organizations that handle protected health information or other sensitive information, documentation becomes even more important.
In a healthcare environment, well-maintained SOPs can support an organization’s broader efforts around security, access control, incident response, contingency planning, workforce responsibilities, and risk management.
Documentation can help answer practical questions such as:
- Who is authorized to access a system?
- What happens when an employee leaves?
- How are accounts disabled?
- Where are backups stored?
- When was recovery last tested?
- Who should be contacted during an outage?
- How is a security incident reported?
- Who has administrative access?
- How are system changes documented?
However, simply having an SOP does not make an organization HIPAA compliant.
The procedures must accurately reflect the organization’s environment and applicable requirements, appropriate safeguards must actually be implemented, employees must follow the procedures, and the documentation itself must be appropriately protected.
AI-generated documentation should also be reviewed carefully before use.
Organizations should not enter protected health information, patient data, passwords, credentials, or other restricted information into an AI service unless that specific use of the service has been appropriately evaluated and approved by the organization.
AI can help create the document.
It does not remove the organization’s responsibility to protect sensitive information or verify the accuracy of what the AI produces.
Review the Documentation
An SOP shouldn’t be written once and forgotten.
Operational documentation should be reviewed periodically and whenever significant changes occur.
For example:
- Major network changes
- New locations
- New vendors
- Firewall replacements
- Telephone system changes
- Cybersecurity incidents
- Backup changes
- Changes in key personnel
An outdated SOP can sometimes be worse than having no SOP at all because someone may rely on information that is no longer correct.
From One SOP to an Entire Documentation Library
This is where AI-assisted documentation becomes especially interesting.
Once you establish a good structure and standard, you don’t have to start from scratch every time.
The first SOP can become the foundation for additional documentation covering:
- Network infrastructure
- Wi-Fi
- Firewall management
- Telephone systems
- Cloud services
- Endpoint security
- Backup and recovery
- Employee onboarding and offboarding
- Disaster recovery
- Cybersecurity incident response
- Vendor management
- Change management
Over time, a business can build an organized operational knowledge library instead of relying on information scattered across people’s memories, notebooks, emails, and spreadsheets.
Final Thought
An undocumented network is a liability. A documented network is a recoverable network.
AI makes creating good documentation faster and easier, but the real value still comes from the knowledge and experience of the people using it.
My approach is to use AI as an assistant: I provide the technical knowledge, real-world experience, decisions, and standards. AI helps me organize that knowledge and turn it into documentation that other people can actually use.
For small and medium-sized businesses that have put off creating SOPs because the process seemed too time-consuming, that can be a very practical use of AI.
And sometimes, the easiest way to get started is simply to tell your AI assistant:
“I need to document this process. Ask me questions, one at a time, about how we do it. Then help me organize my answers into an SOP.”
You might be surprised how much of the documentation already exists.
It’s just sitting in your head.
