Your IT to-do list is long and most of it is aspiration. One item on it earns its place, because it addresses several problems at once.
Your users already know how an app store works. iTunes, Google Play, the Microsoft Store — finding, requesting and installing software is a solved interaction for them everywhere except at work. Bringing that experience inside the organisation pays off in five places:
- It reduces shadow IT
- It improves software licence compliance
- It strengthens IT security
- It increases user productivity
- It reduces cost
That is a broad enough set of benefits that the case for the project is straightforward to make. Let us take each in turn.
Reducing shadow IT
What shadow IT is. Hardware or software used inside the business without the approval of the organisation, and unsupported by central IT.
The volume of it keeps rising, and the reason is simply how easy software has become to acquire. From IT’s side this is a persistent irritation. From the user’s side it is entirely rational, and understanding that is the key to fixing it.
If someone is working on a touchscreen device, they want software built for touch, not a desktop build shoehorned onto it. If IT offers only the desktop version, they will find another way to get what they need. They are not being subversive. They are trying to do their job with a tool that fits.
The consequences are real regardless of the intent: unsupportable software, unknown data flows, and a genuine malware exposure through installers nobody vetted.
So how do you reduce it? There are two approaches.
The first is to stop it — restrictions, policies, sanctions. You will get somewhere with this, but it is like herding cats. Every time you think you have it contained, someone finds a route around the controls and you are back where you started.
The second is better: make it easier to get approved software than unapproved software. That is precisely what a corporate app store does. Users get a fast, self-service route to what they need; IT keeps the control it needs to manage resources properly. You are competing with the unauthorised path on convenience, and winning, rather than trying to police it.
In CerteroX ITAM this is the App-Centre self-service portal, with manager approval chains built in — so a request that needs a sign-off gets one automatically, and a request that does not is fulfilled without a ticket.
Strengthening IT security
Protecting the network and the data on it is a permanently growing job. Unknown, unauthorised software is an open back door. You can only be confident that door is closed if you know what is installed.
An app store reduces the incidence of unauthorised software arriving in the first place, which reduces the exposure. It also produces a clean record of what was requested, by whom, approved by whom, and installed where — which is the part that matters when you have to answer a question about scope after an incident.
Pair it with Governance Policies, which express compliance rules as code with a reusable filter builder, and prohibition and blacklisting rules in CerteroX SAM, and you have prevention and detection rather than one or the other.
Improving software licence compliance
An app store changes the shape of licence management, because it moves the control point to the moment of request.
Having more people using software than you hold licences for is a common and expensive problem. In many organisations it only surfaces during a vendor audit, and by then it is a true-up bill you did not budget for rather than a decision you could have made differently.
It is much better to control both issue and reclamation from the outset. An app store can only grant a licence if one is available — which means under-licensing does not happen by accident. That check requires a real entitlement position behind it, not a spreadsheet: CerteroX SAM computes the Effective Licence Position continuously, covering purchased, used, available, required, variance and exposure, so “is there a spare one?” has an answer at the moment somebody asks.
The reverse direction matters just as much. You will have a significant number of licences issued to people who no longer use the software. Reclaiming those automatically lets them be recycled instead of triggering a purchase. AppsMonitor meters actual file-based usage with first-used and last-used tracking, and reports a % Used figure over a rolling 90-day window — which is what turns “probably nobody needs this” into a defensible harvesting decision.
Increasing user productivity
The diversity of the device landscape is good news for end users. Corporate mobile devices, bring-your-own-device arrangements and a wider range of form factors all mean people can work in the way that suits the work. Being able to find, request and receive the software they need on those devices, quickly, saves a genuinely useful amount of time.
The flip side is that managing this is harder. The standard endpoint disappeared some years ago and is not coming back. Rather than forcing everyone into one configuration, the better move is to accept the diversity and manage towards unified endpoint management — one place that covers Windows, macOS, Linux, iOS and Android, so software deployment is controlled and the user experience is still good.
That is only practical when the device inventory, the software recognition and the licence position sit in one data model rather than three products that have to agree with each other.
Reducing cost
Support and service desk teams spend a lot of time on low-level work that could be automated, and software requests and installations are a large share of it. Automating them frees skilled people for work that needs them.
Centralising software distribution through an app store also gives you something more valuable than the time saved: complete usage and licensing information in one place, ahead of a renewal rather than after it. Going into a vendor negotiation able to show exactly what is deployed, what is actually used and what you are prepared to drop is a materially different conversation to going in with an install count.
The same information improves what you get from what you already own — reclaiming licences from leavers, pooling licence types, moving people to the right edition rather than the most expensive one. That is the core of licence optimisation, and it depends entirely on having the usage data.
What has changed since this was written
This article was published in 2017, and one of its assumptions no longer holds.
Back then, shadow IT overwhelmingly meant software installed on a device. An app store addresses that directly, which is why the original version of this piece claimed it removed the root cause. Today most shadow IT is not installed anywhere. It is SaaS, signed up for in a browser with a work email address and a corporate card, and no app store can intercept it because nothing is ever downloaded.
The average enterprise portfolio now runs 305 SaaS applications, and 46% of SaaS licences go unused — the average organisation uses 54% of what it pays for. Both numbers describe a problem that sits outside the app store’s reach entirely.
So the app store is still worth building. It just handles one half of the problem now, and the other half needs discovery rather than provisioning. CerteroX SaaS Management covers it with:
- Three converging discovery signals — identity provider sync from Entra ID and Okta, connector sync pulling authoritative user and licence lists from the vendor across 47 connectors shipping today, and a browser extension detecting SaaS domains with per-user attribution.
- OAuth grant discovery and risk scoring, on a 0 to 100 scale weighing data sensitivity, scope, consent and dormancy — because the third-party application somebody consented into your tenancy two years ago still has the access it was granted, and one-click revocation is available directly or as a workflow action.
- Unused licence detection at 30 or more days of zero usage, with reclaim, reassign, downgrade, archive, remind and dismiss as first-class actions rather than a report you then act on manually.
- Shadow AI detection, classified from application feature tags in a catalogue of 35,000-plus applications rather than a hardcoded list — so the detection set grows on its own as new tools appear, which for AI it does constantly.
- Offboarding you can prove finished, showing every licence a departing user held, the connector status behind each revocation, and the monthly cost of anything still open.
Self-service is still the way forward
Give people the ability to choose and deploy what they need to do their jobs, with the approvals and checks that belong in the process, and you remove most of the incentive to go around you. You also raise the standing of IT across the organisation, which is not a small thing.
Just do not stop at the device. The app store closes the door people used to walk through. Discovery is how you find the ones they are walking through now.
To see App-Centre, the licence position behind it and SaaS discovery in a fully populated environment, book a demo.