Runbook

Definition
A runbook is a step-by-step guide for handling one urgent, defined situation, so anyone can follow it under pressure.

Why it matters

The first time something breaks, one person works it out under stress. If nothing is written down, the next occurrence needs the same investigation, and only that person can do it. A runbook turns a one-off discovery into a repeatable fix. It also lets someone else take over: a colleague, a contractor or an AI agent with the right access can follow the steps without calling the original expert.

How to apply it

  • Write it straight after the first incident, while the details are fresh.
  • Name the trigger in the title so the right runbook is easy to find when it counts.
  • Lay out checks and decisions as a sequence: if A, do this, otherwise do that.
  • Include where to look, such as which dashboard, which log and who holds the login.
  • Keep it short enough to follow while something is actively broken.
  • After each use, fix any step that was unclear or missing.

What it is

A runbook answers one question: when this particular thing goes wrong, what is the right next step? It starts with a named trigger, for example "the payment webhook has stopped arriving" or "a customer cannot log in". It then lists what to check, in order, and what to do depending on what is found. The best ones read like a short branching checklist, not an essay.

A runbook differs from a Standard Operating Procedure (SOP). An SOP describes a routine task done regularly, such as onboarding a client. A runbook describes an interruption, which may happen twice a year.

Common mistakes

  • Writing it as a reference manual that nobody can scan in a crisis.
  • Storing it somewhere that is unreachable when the failing system is the one that holds the documents.
  • Never testing it. A runbook that has not been followed once may have gaps nobody has seen.
Worked example

Suppose an online training business gets an alert that its payment webhook has stopped arriving. The operations lead handled this once before, from memory, and it took three hours. This time she opens a runbook titled "Payment webhook has stopped arriving" in Process Street, a checklist with conditional steps. Step one: check the webhook log for the last successful event. Step two: if the log shows events, the fault is in the app, so restart the service. If not, check the payment provider's dashboard for a disabled endpoint. Each step is a yes or no with one next action. The next incident took forty minutes, and a colleague followed the steps without calling her.

Tools in the example

Some links are affiliate links: we may earn a commission at no cost to you. It never decides a ranking. How we work with partners

  1. Article

    Standard Operating Procedure (SOP)

    The routine counterpart.

  2. Article

    Human-in-the-loop

    Where a person approves a step an agent could otherwise run.

  3. Article

    Handoff

    The moment a runbook protects when work passes between people.