Skip to content

The challenges of implementing SAM

The obstacles to a working software asset management programme fall into three groups — inventory, entitlement and the organisation itself. Two of them are now largely solvable with tooling. The third still is not.

Implementing software asset management is not one project. It is three, running at once, and they fail for different reasons.

Most of what goes wrong falls into three groups: getting an accurate hardware and software inventory, understanding what your licence entitlement actually permits, and getting the organisation to back the programme. It is worth separating them, because the first two are now largely a tooling problem and the third never has been.

Hardware inventory

Even a small organisation runs a wide range of devices. Smartphones and tablets, laptops and desktops, servers, the data centre, virtual infrastructure and cloud instances — all of it needs identifying and inventorying, and all of it is running software in different versions and editions, sometimes several of them on the same machine.

The usual failure is not that inventory is hard. It is that inventory is done in parts. One tool covers Windows desktops, another covers the hypervisors, mobile sits in a separate console, and the Unix systems are covered by a script somebody wrote. Each part is reasonable. The join between them is where the licence position leaks.

The fix is to collect everything into one schema. CerteroX ITAM ships ten discovery methods and lands all of them in the same data model: the native agent for Windows, macOS, Linux, AIX, HP-UX and Solaris; command-line inventory for locked-down machines; agentless inventory; standalone inventory for air-gapped systems; Network Discovery over NetBIOS, SNMP and ICMP; Active Directory import; third-party ITAM import; cloud and SaaS connectors; browser monitoring; and file metering. Mobile is not a separate product — iOS and Android device management, including Apple DEP enrolment, is part of the same platform.

Six operating system families get the same agent, the same inventory cycle and the same licence engine. That is the point. Reconciling three inventories is a project. Not having three inventories is not.

Software licence entitlement

Beyond the publishers everybody worries about — Microsoft, IBM, Oracle and SAP — your organisation is almost certainly running software from dozens of mid-sized and small vendors, each with its own licensing model and its own view of what your entitlement permits in which environment.

Virtualisation and thin-client delivery remain the sharpest edge. Organisations adopt them to reduce cost, and a good number do so without checking what the change does to their licence obligations. The saving is real; so is the exposure it creates, and it is entirely possible for the second to be larger than the first. Because the problem is invisible from the infrastructure side, it usually surfaces during a publisher audit, which is the most expensive moment to discover it.

This is answerable with the right engine behind it, and it needs to be publisher-specific — a generic count does not survive contact with any of these rule sets:

  • Microsoft. Device and user CALs, named users and external connectors, alongside SQL Server and Windows Server core and processor licensing with cluster and virtualisation awareness.
  • Oracle. Options and packs with evidence and override, processor types and core factors, licence pools with hosting rights and geographic rules, cover-down logic for Enterprise Edition, and uncapped quantity handling for unlimited agreements.
  • IBM. PVU and Virtual Processor Core metrics, an ILMT connector with compliance gap analysis, and enforcement of the 30-minute inventory cycle that sub-capacity licensing requires.
  • SAP. A non-invasive ABAP connector reading named users de-duplicated across systems, with priority-ordered rules proposing the licence type each user should hold.
  • Citrix, RDS and VDI. Access Control rules licensing streamed and published applications against the people entitled to launch them.

The general point: entitlement is not a field on a purchase record. It is a calculation over how the software is deployed and used, and it has to be performed per publisher because the publishers do not agree with each other.

The organisation

The third group is the one tooling does not solve, and it is usually the one that decides whether the programme survives.

Many organisations recognise they need to manage their technology assets and reach for an ITAM tool to do it. That gets them a device and install inventory, which is necessary and not sufficient. An install count is not a compliance position, and the gap between the two is exactly the detail that determines what an audit costs.

Older SAM tooling made this worse by fragmenting the work. Data arrived in separate feeds, was read through separate interfaces, and represented a point in time rather than a current state. So the position had to be rebuilt each time anybody asked for it, and it was out of date before it was finished. The alternative is a single data model with a compliance position that is computed continuously — where “what is our position on SQL Server” is a question you answer by looking, not by starting a piece of work.

The harder problem is sponsorship. Without a senior owner, SAM becomes a bottom-up initiative run by people who cannot compel anyone to change behaviour. Adoption goes patchy, purchasing carries on outside the process, and the benefits get diluted to the point where the programme looks like it did not work. It did not fail on capability. It failed because nobody above it was accountable for the outcome.

Two things help. Give the programme a named owner senior enough to arbitrate between IT, procurement and finance. And report it in money — recovered spend, avoided purchase, audit exposure closed — because that is the language the sponsor is judged in.

The categories have grown since this was written

These three groups still describe the problem, but they were drawn when software asset management meant installed software. It no longer does.

Three asset classes now sit alongside the original two, and each brings its own version of the same three challenges.

SaaS. Applications reached in a browser, frequently bought outside IT, and invisible to a device inventory however good it is. The average enterprise portfolio runs to 305 applications, and 46% of SaaS licences go unused. The inventory challenge here is discovery without an install to find, which CerteroX SaaS Management answers with three converging signals: identity provider sync from Entra ID and Okta, connector sync across 47 connectors shipping today, and a browser extension with per-user attribution.

Cloud. Resources that appear and disappear faster than any inventory cycle built around physical hardware. Wasted cloud spend runs at 29%, up for the first time in five years. CerteroX Cloud Management runs 26 named, individually tunable cost checks across twelve cloud and data platforms, with tag compliance, resource TTL and expense limits as enforceable policy rather than advice.

AI. The newest class, and the one most likely to be procured without anyone in IT knowing. AI arrives as SaaS seats, as GPU spend, as models and experiments, and as tools people simply start using. CerteroX AI Management governs all four, with Shadow AI detection driven from application feature tags rather than a fixed list, so the detection set grows without maintenance.

The organisational challenge is unchanged and, if anything, sharper. All three of these are easy to buy without IT involvement, which means the sponsorship question — who is accountable for what the organisation spends on software — is now the whole game.

Getting it right

None of this is a reason not to start. The three groups are tractable, and two of them are tractable with tooling that exists.

What decides the outcome is whether you build on one data model or several, whether entitlement is calculated by an engine that knows each publisher’s rules, and whether somebody senior owns the result. Get those three right and the rest is execution.

To see what a continuous licence position looks like once it is fully populated, book a demo.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.