-
-
Notifications
You must be signed in to change notification settings - Fork 27
Checklists and SOPs
Write a procedure once, attach it to any ticket, and see at a glance which steps are done.
Some jobs are done the same way every time, and the cost of getting one step wrong is high. A new starter with no mailbox on day one. A leaver whose VPN token is still live a month later. This module holds those procedures as reusable templates and tracks them per ticket, so nothing is finished from memory.
Contributed by Santhosh Srinivasan. Designed and built from scratch and offered to the project unprompted — the first whole module FreeITSM has received from the community. It arrived in 2.0.0, which is why that release is a 2. Developers: see the Checklists & SOPs — Developer Guide.
| A template | A procedure written once — a title, a description, and an ordered list of steps. Lives in Checklists. |
| An attached checklist | A copy of a template's steps, living on one ticket. Ticking a step records who and when, on that ticket only. |
| A mandatory step | A step marked as one that must actually happen. FreeITSM can warn — or refuse — when a ticket is closed with one outstanding. |
Editing a template never changes work already in progress. An attached checklist is a copy taken at the moment it was attached, so an analyst half way through an onboarding keeps the steps they started with, and every future ticket gets the improved procedure.
Checklists → New template opens the editor on its own screen. It is a writing job rather than a dialogue, and it needs the room.
| Field | What it is for |
|---|---|
| Title | What the procedure is, as somebody searching would say it. New starter onboarding, not Process 4b. |
| Category | Groups templates on the list and colours their pill. Yours to define, in Settings → Categories. |
| Applies to | Whether it is offered on tickets, on tasks, or on both. |
| Description | When and why to use this one. This is what somebody reads when choosing between two similar procedures. |
| Keywords | Comma separated, and the reason a procedure finds its own ticket — see below. |
A step is one thing the analyst does. If it cannot be answered yes or no, it is two steps: a step reading set the account up cannot be ticked off honestly, and a procedure full of those gets ignored.
Each step carries:
- A title — what the analyst does.
- A suggested role — IT, HR, Facilities. Guidance printed beside the step, not a permission: anybody can tick any step. Roles are defined in Settings → Roles.
- Mandatory — this must be done before the ticket is closed. See below.
- Ask for a value — the step prompts the analyst to type something as they tick it: an asset tag, a serial number, a reference. Set the prompt so it is obvious what is wanted; the answer is stored against that ticket's step and shown beside it.
Drag a step by the handle on its left to reorder it. The numbers renumber themselves. Order is the point of a procedure, so it is worth getting right rather than living with "do step 6 before step 4".
Removing a step asks first and names it. Deleting a template removes its steps with it.
Open a ticket and find the Checklist panel.
- Attach a checklist — search by name or keyword and press Attach. More than one can be attached to the same ticket.
- Best match — if a template's keywords match the ticket, FreeITSM offers it at the top without being asked. This is what keywords are for, and it is the difference between a library people use and one they forget exists.
- Tick steps off as you do them. Each tick records who and when; a step set to ask for a value prompts for it.
- The ticket history records it. A note is added each time a step is completed or reopened, so the ticket tells the story on its own — useful months later, and to anybody auditing the work.
- Remove takes a procedure off the ticket. It asks first, because the ticks go with it.
Tip
Spend a minute on keywords, and use the words a requester would use rather than the words you would — "cannot get in", not "authentication failure". A procedure nobody can find is a procedure nobody follows.
A mandatory step is only worth marking if something happens when it is skipped. Since 2.5.0 that is decided per checklist, by whoever wrote it:
| Level | What happens when somebody closes with mandatory steps outstanding |
|---|---|
| Standard (default) | They are warned, may go ahead, and the override is recorded - which steps, who closed it, and whether from the web interface or the API. |
| Critical (padlock) | The close is refused until the steps are done, and the message names them. |
Tickets → Settings → Checklists adds a company-wide floor (block every ticket with outstanding steps) and a rule for closing a ticket with no checklist at all. The full story is on Stopping a ticket closing with a checklist outstanding.
Important
Whichever applies is enforced everywhere a ticket can be closed, not just on the button in front of you: bulk actions, the REST API and workflow automation all obey it. A rule that only lives in one screen is not a rule, and a gate that can be walked around reports control that is not there.
Be sparing with mandatory. Mark everything and people learn to close through the warning without reading it. Mark the three that matter and the warning still means something.
New in 2.10.0, from discussion #138. Off by default: an administrator switches it on in Tasks → Settings → Checklists. Santhosh, who built the module, thought checklists might sit awkwardly beside subtasks for some teams - so it is offered rather than imposed, the same way time recording is.
Once it is on, every task and subtask has a Checklist section:
- Attach any checklist set to apply to Tasks or Both (its Applies to field). The task gets its own copy of the steps, so editing the template later never changes work already in progress.
- Tick steps off as you go. Each tick records who and when; a step that asks for a value cannot be ticked without one.
- Completing the task follows the same two levels as a ticket. A Standard checklist asks before you complete it with mandatory steps outstanding, and the task's history records who did it and what was skipped. A Critical one refuses until those steps are done - whether you use the status box, drag the card into a closed column, tick a subtask, or use the API. The company block every ticket floor applies to tasks too.
- Repeating tasks give each new occurrence a fresh, unticked copy of the checklists - from the current version of the template where it still exists.
- More than one, in your order. A task can carry several checklists. Drag a checklist by the ⋮⋮ handle in its heading to move it up or down, or drag a step by its own handle to change the order inside that checklist. A step stays in its own checklist - it cannot be dragged into another one. (2.10.0)
The no checklist at all rule is tickets-only: on tasks it would gate every to-do on the board. Switching the feature off hides the section and stops enforcing it; it never deletes a checklist. How it works underneath: Checklists on tasks - Developer Guide.
Two screens, doing different jobs.
Checklists → Settings
- Categories — group templates and colour their pills.
- Roles — fill the suggested role list on a step.
- Left panel — a per-account preference: keep the template sidebar always visible, or let it appear on hover.
Categories and Roles both tell you how many templates or steps use an entry before you delete it.
Tickets → Settings → Checklists — the company floor and the no-checklist rule, as above. It sits with the ticket settings rather than with the module because it is a rule about closing tickets, and that is where somebody will look for it.
Tasks → Settings → Checklists — switches checklists on tasks on or off.
System → Demo data seeds five realistic procedures — onboarding, offboarding, server decommissioning, VPN troubleshooting and a firewall change — with 29 steps between them, 22 mandatory and 7 not. Removing the demo data removes exactly those and nothing you wrote.
- In-app help: the Help button in the Checklists header.
- Developers: Checklists & SOPs — Developer Guide and Checklists module — house style.
- Tickets: the Tickets module.
FreeITSM — an open-source IT Service Management platform · github.com/edmozley/freeitsm · MIT licence
- Installation
- ⏰ Scheduled tasks (cron jobs)
- Architecture
- 🧪 Developer tests
- AI Providers
- Internationalisation (i18n)
- Timezones & Time Handling
- 📅 Date & Time Formats
- Theming & Dark Mode
- 🗂️ Recent — getting back to what you were doing
- ⌨️ Command palette (⌘K)
- 🔍 Searching inside tickets
- 📄 Attached documents
-
Mobile‑Friendly
- ↳ 🎫 Mobile: Tickets
- ↳ 💻 Mobile: Assets
- ↳ 📅 Mobile: Calendar
- ↳ 📚 Mobile: Knowledge
- ↳ 🚦 Mobile: Service Status
- ↳ 🗼 Mobile: Watchtower
- ↳ 🧩 Mobile: Problem Management
- ↳ 🔁 Mobile: Change Management
- ↳ 💿 Mobile: Software
- ↳ ✅ Mobile: Tasks
- ↳ 📝 Mobile: Forms
- ↳ 📄 Mobile: Contracts
- ↳ 📄 Mobile: Domains
- ↳ 📄 Mobile: People
- ↳ 🎓 Mobile: LMS
- ↳ 🗺️ Mobile: CMDB
- ↳ 🗺️ Mobile: Network Mapper
- ↳ 🧭 Mobile: Process Mapper
- ↳ ⚙️ Mobile: Workflow
- ↳ 🖥️ Mobile: System
- ↳ 📊 Mobile: Reporting
- ↳ 📖 Mobile: System Wiki
- ↳ 🙋 Mobile: Self-Service Portal
- ↳ 🧰 Mobile: Techniques & Tricks
-
Security
- Layer 1 — which modules you can enter
- ↳ 🧩 Module Access Control
- ↳ 🛠️ Module Access — Developer Guide
- Layer 2 — what you can administer
- ↳ 🎭 Roles & Permissions
- ↳ 🛠️ Roles — Developer Guide
- ↳ 🔤 Why capabilities are constants
- Layer 3 — the System module
- ↳ 🔑 Admin Access Control
- Hardening
- ↳ 📄 Security review response 2026-08
- ↳ 🛡️ Security hardening 2026-08
- ↳ 🛠️ Security hardening 2026-08 — Developer Guide
- ↳ 🛡️ Round three — plain English
- ↳ 🛠️ Round three — Developer Guide
- ↳ 🛡️ CSRF protection (S4) — Developer Guide
- Single Sign-On (SSO)
- 🗂️ LDAP & Active Directory
- 📇 CardDAV contact sync
- Browser Extension
- API Reference
-
🔌 REST API — how it works
- ↳ 🎫 REST API: Tickets
- ↳ 💻 REST API: Assets
- ↳ 🔴 REST API: Problems
- ↳ 🟠 REST API: Changes
- ↳ 📚 REST API: Knowledge
- ↳ ✅ REST API: Tasks
- ↳ 🗄️ REST API: CMDB
- ↳ 📜 REST API: Contracts
- ↳ 🗓️ REST API: Calendar
- ↳ 💿 REST API: Software
- ↳ 🌐 REST API: Domains
- ↳ 🚦 REST API: Service Status
- ↳ ☀️ REST API: Morning Checks
- ↳ 📝 REST API: Forms
- ↳ ⚙️ REST API: Workflow
- ↳ 🏷️ REST API: Cost centres
- ↳ 🗺️ REST API: Network Mapper
- ↳ 🧭 Using the API docs page
- ↳ 📐 OpenAPI specification
- ↳ ✅ OpenAPI: kept correct
- ↳ 🛠️ Maintaining the catalogue
- Watchtower
-
Tickets
- ↳ 📋 Rota copy and paste — Developer Deep Dive
- ↳ ✅ Checklists & SOPs
- ↳ ☑️ Mandatory fields
- ↳ 🏷️ Ticket categories
- ↳ 👥 Assigning tickets to a team, and escalation
- ↳ 🏢 One board across every company
- ↳ Mailbox Authentication
- ↳ 📤 Email send log
- ↳ Basic IMAP mailboxes
- ↳ Email rendering & images
- ↳ SLA Management
- ↳ WhatsApp channel
-
↳
✈️ Telegram channel - ↳ ⭐ CSAT company scope and filters — Developer Guide
- ↳ 👥 Microsoft Teams channel
- ↳ 🗨️ Mattermost channel
- ↳ 💬 Web chat channel
- ↳ 🟣 Slack channel
- ↳ 🔗 Linking tickets
- ↳ ⓘ Record previews
- ↳ 📝 Ticket notes: internal or shared
- ↳ 🗒️ Canned responses
- ↳ ✉️ Limiting replies to particular senders
- ↳ 📨 Telling the analyst a ticket is theirs
- ↳ ✍️ Email signatures
- ↳ 🌐 The public web address
- ↳ 🔢 Ticket numbering
- ↳ 🙋 Raising a ticket for someone else
- ↳ 🔀 Merging tickets
- ↳ 🔒 Confidential tickets
- ↳ 👥 Portal managers
- ↳ 👁 Who has seen a ticket
- ↳ 📜 Reading long tickets
- ↳ ⑂ Splitting tickets
- ↳ ✅ Selecting several tickets
- ↳ 🗂️ The folder pane
- ↳ 🔽 Just my tickets, or no closed ones
- ↳ 🛠️ Snoozing tickets — Developer Guide
- ↳ 👥 Collision detection
- ↳ ⏱️ Time tracking
- ↳ 📅 Scheduled work in your own calendar
- Problem Management
- Tasks
-
Assets
- ↳ 🏢 Moving an asset between companies
- ↳ 📍 Shared asset locations
- ↳ 🧑💼 Assigning assets to analysts
- ↳ 📆 Warranty and lease alerts
- ↳ 🔭 Saved table views
- ↳ 🖨️ Recording anything, and importing it
- ↳ 🏷️ QR asset labels
- ↳ 📋 Who holds what, and handover documents
- ↳ 🖥️ The inventory agent (PowerShell)
- ↳ 🗄️ Proxmox VE servers
- ↳ ☁️ VMware Cloud Director servers
- ↳ 🔗 Linking equipment to tickets
- ↳ ☑️ Follow-up tasks on a ticket
- Knowledge
- Change Management
- Calendar
- Morning Checks
- Reporting
- Software
-
Forms
- ↳ 🎨 The form designer — Developer Guide
- ↳ 📐 Layout & the grid — Developer Guide
- ↳ 🗂️ Collections — grouping submissions
- ↳ 📄 Submissions as PDFs
- ↳ ⚡ What happens next — a form's own actions
- ↳ 🛠️ Sections & conditional logic — Developer Guide
- ↳ 🛠️ Lookup fields — Developer Guide
- ↳ 🛡️ Catalogue request approvals
- People
- Domains
- Contracts
- Service Status
- 🔔 Notifications
- 🚨 War Room
- Self-Service Portal
- LMS
- Process Mapper
- CMDB
- Network Mapper
- Workflows
- Issue trackers (Jira, Azure DevOps)
- System
-
Overview
- ↳ 📊 Progress tracker
- ↳ Concepts & vocabulary
- ↳ Email routing & mailboxes
- ↳ Settings: global vs per-company
- ↳ Users & self-service
- ↳ Staff cross-company access
- ↳ 🏢 One board across every company
- ↳ Worked examples
- ↳ Pitfalls & gotchas
- ↳ Scope: what it's for
- ↳ 🛠️ Developer Guide (make a module multi-company)
- ↳ 🗄️ Case study: CMDB (a linked graph)
- ↳ 🧪 Test harness (prove it's isolated)
-
🐞 Bugs resolved
- ↳ 🔢 Chat tickets ignored your ticket numbering
- ↳ 📅 Dates shown as a dash, or in server time
- ↳ 🔒 Assets → Users showed people from other companies
- ↳ 🔒 Restricted analysts could read other modules' data
- ↳ 🖼️ Replies with a picture in the thread failed to send
- ↳ 📎 Reply attachments never reached the customer
- ↳ 🛠️ Outbound email attachments — Developer Guide
- ↳ 🔑 A global SSO provider was missing from the portal
- ↳ 🔀 Behind a proxy, the SSO redirect said http
- ↳ ✏️ The portal tagline moved when you saved it
- ↳ 🎨 The portal settings screen forgot what you saved
- ↳ 🛡️ The approvals inbox said "Error" and nothing else
- ↳ 📄 A table's answers were missing from the PDF
- ↳ ◉ A single-select column let you tick every option
- ↳ 📐 The portal ignored a form's field widths
- ↳ 📋 The tasks board stopped taking clicks
- ↳ 🗂️ #121 The index list is out of date after upgrading
- ↳ 📅 #133 The calendar subscription was empty
- ↳ 📋 #131 Tasks always reopened on the board
- ↳ 💥 #129 Every page returned HTTP 500 after upgrading
- ↳ 🐳 #127 A PHP warning above the System page
- ↳ 🕐 #126 Notes stamped with the server's clock
- ↳ 🌍 Storing every date in UTC
- ↳ 🚪 The portal was down for everyone signed in
- ↳ ⚙️ #120 Workflow notes could never be written
- ↳ ⚙️ #123 Three errors when running Database Verification
- ↳ 📝 #122 The description box was a stub in the corner
- ↳ 💣 Demo data deleted real accounts
- ↳ 🔐 #117 Sign-in redirected to the wrong address
- ↳ 🎨 #108 The priority dot was invisible
- ↳ ⏱️ #116 Time logged from the right-click menu
- ↳ 🔑 #114 API keys refused by our own guard
- ↳ 🗂️ #110 Assigning a task told nobody
- ↳ 🚪 #107 Signed out while still working
- ↳ 📎 #103 "Share with Requester" reached nobody
- ↳ 🔍 #102 Search found nothing for hyphens
- ↳ 🪟 #101 Source code editor opened behind
- ↳ ☑️ #88 Subtasks could not be ticked off
- ↳ 💻 #84 Asset deep link selected nothing
- ↳ 🎫 #79 A new ticket arrived with no status
- ↳ 📧 #79 A ticket from email did not say so
- ↳ 🔔 #78 Bell opened to nothing
- ↳ 📬 #77 Mail only collected from Inbox
- ↳ 🔐 #74 The default password could not be changed
- ↳ 🚦 #70 Renaming an impact level
- ↳ 📤 #67 App-only mailboxes could not send
- ↳ 📭 #45 Verify only ever worked for Microsoft
- ↳ 📭 #45 IMAP reported as not authenticated
- ↳ ✉️ An email template stopped escaping itself
- ↳ 🕐 The portal dashboard showed the wrong time
- ↳ 🔢 The folder said 99 and the list showed 96