Skip to content

Building a SAM function within your organisation

Six steps to standing up software asset management: maturity, business case, tooling, process, audit readiness and team. One of them has changed fundamentally since the framework was written.

Standing up a software asset management function is a different problem from doing software asset management. The work is not licensing; it is organisational. You are creating a capability that has to survive people leaving, budgets tightening and priorities changing.

The six steps below follow a framework set out by The ITAM Review. They still hold up. One of them, though, rests on an assumption that is no longer true, and it is worth reading that section carefully.

1. Assess your SAM maturity

Anyone starting out feels the same thing: the task looks impossible. Thousands of software titles, thousands of devices, constant change, and a volume of data nobody has ever assembled in one place. Where do you even begin?

You begin by finding out where you are. A maturity assessment is not a formality — it is what stops you designing a function for an organisation you do not have. There is no point drafting a licence optimisation process for a business that cannot yet produce a reliable list of installed software, and equally no point starting from first principles in an organisation that already has good procurement records and simply never joined them to deployment data.

Be honest in the assessment. An optimistic maturity score produces a plan that fails in month four.

2. Develop a business case that survives

SAM delivers real value, but a business case that says so in general terms will not hold attention past its first budget cycle. Build one tailored to your organisation specifically: your publishers, your renewal calendar, your known exposure, your actual spend.

The strongest business cases usually rest on three things. The recurring cost of software nobody uses. The exposure sitting in the publishers you have never measured properly. And the cost of the disruption an audit causes, which is real even when the finding is small — the finance and legal time, the projects that stop, the engineers pulled off delivery.

Frame it as a permanent function rather than a project with an end date. A project delivers a baseline and then decays. You are asking for something that keeps the position current.

3. Select relevant tooling

A SAM function is process, people and technology together. Technology’s job is the heavy lifting: maintaining the register of assets, users, devices and systems, automating what can be automated, and helping the people interpret what they are looking at.

Be specific about what you need it to do, because this is where the difference between tools actually shows:

  • Discovery that reaches everything. Not just the Windows machines. CerteroX ITAM collects through ten discovery methods and covers six operating system families — Windows, macOS, Linux, AIX, HP-UX and Solaris — with a native agent, plus agentless and command-line collection for locked-down systems, standalone inventory for air-gapped machines, network discovery, Active Directory import and cloud connectors, all landing in one schema.
  • Recognition, not just inventory. A list of executables is not a list of licensable products. Raw inventory is resolved against the Software Recognition Database — more than 3.5 million normalised publisher, product and version titles — which is what makes the data usable for licensing rather than merely accurate.
  • Usage, not just installation. Installed and used are different questions, and the gap between them is where reclamation lives. Software usage is metered at file level with first-used and last-used tracking, reported as a percentage-used figure over a rolling ninety-day window.
  • Real depth on the publishers that matter. Generic tooling tells you that you have 400 installs of Oracle Database. It does not tell you which options are enabled, which cores are licensable under which core factor, or which hosts are covered down by an Enterprise Edition pool — and that gap is where the audit finding lives. Dedicated engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce are what close it.

Choose tooling that produces a position rather than a report. The distinction matters more than any feature comparison.

4. Build efficiency and automation into your processes

Processes are the checks and balances that keep the view of your assets accurate. They are also what moves an organisation on from periodic true-ups to maintaining an up-to-date record at all times.

The processes worth building first are the ones at the boundaries, where assets enter and leave: request and approval, procurement, deployment, and — most neglected — retirement and reclamation. Software that is never harvested when someone changes role or leaves accumulates quietly and expensively.

Automate the repetitive parts. Governance Policies express compliance as code with a reusable filter builder, so the rules are enforced and evidenced rather than remembered. Self-service request and approval through an application portal with manager approval chains takes the routine transactions off the team entirely. Every hour the SAM function spends on administration is an hour it is not spending on the renewal that is worth six figures.

5. Stay audit ready — and understand what that now means

This is the step that has changed most.

The original argument ran like this: audits are a fact of life and a serious distraction, but monitoring compliance continuously may not be worthwhile or realistic. It was compared to providing 100% availability for a service that is only seldom required. Better, the argument went, to aim for a state of readiness — so that when the request arrives, the team can respond.

That trade-off was real, and it was correct at the time, because compliance was reconciled by hand. Continuous monitoring meant continuous human effort, and the comparison to always-on availability was apt.

It no longer applies. CerteroX SAM computes the effective licence position continuously — purchased, used, available, required, variance and exposure — rather than producing a point-in-time reconciliation. Continuous monitoring costs no more effort than periodic monitoring, because the effort is not the constraint any more.

That changes what “audit ready” should mean when you design the function. It is not a state you can enter on request; it is a property the data either has or does not. Design for the position to be readable on an ordinary day. Then an audit request is a formatting exercise and a negotiation about interpretation, rather than a three-week reconstruction of your own organisation carried out under a deadline someone else set.

The rest of readiness is still organisational, and still worth planning: who leads the response, who talks to the publisher, where the entitlement evidence lives, and how you prove the chain from purchase to install.

6. Build a virtual SAM team

The last consideration is the team, and it is rarely a team in the org-chart sense. Very few organisations can justify a large dedicated SAM headcount, and they do not need to. What they need is a defined set of people, mostly sitting elsewhere, who each own a piece: procurement, IT operations, service desk, security, finance, legal, and a nominated owner per major publisher.

Resourcing that group belongs in the business case at step two, not as an afterthought. A plan with objectives and no named owners is a document, not a function.

It is also entirely legitimate to buy in capability while you build it. NHS South West London ICB did exactly that:

Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.

— Reece Emson, ITAM Asset/PSL Manager, NHS South West London ICB

Alongside that, £100k of Microsoft compliance risk was mitigated. The point is not that external help is necessary; it is that the maturity curve is the constraint, and it can be shortened.

Where to start

If you take one thing from the six steps, take this: build the function around a position that stays current, rather than around an exercise you repeat.

Everything else — the business case, the processes, the team — is easier to justify and easier to sustain when the underlying data does not decay between reviews. The organisations that struggle with SAM are usually not the ones that lack a plan. They are the ones whose plan assumed the numbers would still be true in six months.

To see a continuous licence position instead of a periodic one, book a demo.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.