First published in July 2019. Updated on migration so that what it says about
CerteroX is true of the product today.
Cloud-based IT asset management software is among the most widely bought
categories in enterprise IT, and among the most disappointing. The reason is
usually the same: the tool covers one asset class and quietly assumes you have
the others covered somewhere else.
What “cloud based asset management software” actually means
The phrase normally gets used to mean the tools you deploy to improve governance
and security of hardware assets. In practice it has to mean more than that. It
has to cover software and cloud applications as well, because asset lifecycle
management only works when hardware, software and cloud are the same record.
Take something simple: tracking your Windows and Mac assets. You need the
hardware data and the software data and, increasingly, the SaaS data about what
those users are signed into. Any one of them on its own is close to useless.
Knowing a laptop exists tells you nothing about the licensing risk sitting on
it. Knowing an application is installed tells you nothing about whether the
machine it is installed on was decommissioned last quarter.
Most of the tools in this category were built decades ago for on-premises
deployment, and many were never genuinely modernised — they were re-hosted.
A SaaS delivery model wrapped around an architecture that assumes an
on-premises data collection tier is not the same thing as a SaaS product, and
the difference surfaces the first time you ask it for data it was never designed
to hold.
As organisations move more of what they run to the cloud, those tools drift
further from the strategy they are supposed to support. Several vendors have
responded with cut-down SaaS versions, but the scope is usually narrow: Microsoft
applications on PCs and laptops, and nothing else. They do not cover assets
already migrated to cloud, they do not cover other device types, and critically
they contain no hardware data at all.
Where the gap costs you
Licence compliance
While anything remains on-premises, managing licences properly requires data
from both sides — the hardware and the software installed on it. Without the
hardware data you will have applications running in parts of your environment
you cannot see, and you cannot manage what you cannot see.
Most cloud-delivered asset management tools do not give you that data. They
cover software, and they discard or never collect the hardware data underneath
it. The limitation goes further than that, though. Many cannot even discover all
your software, because recognition is only as good as the recognition database
behind it. If an application is not in the vendor’s library, the tool has
nothing to say about it — and you have no way of knowing it was there. The
resulting data set is hard to trust and close to impossible to validate, which
is exactly the position you do not want to be in when a publisher asks you to
prove something.
This is worth asking about directly in an evaluation. The relevant question is
not “do you have a recognition database” but “how large is it, how is it
maintained, and what happens to a title that is not in it”. CerteroX SAM
resolves against a Software Recognition Database of more than 3.5 million
titles, with centrally maintained categorisation, release date, end-of-support
and extended-support dates, and SWID tag support with UNSPSC classification.
Licence optimisation
For organisations migrating to cloud, the pressure shifts from compliance to
optimisation. There are real cost benefits to running in cloud, and real new
risks: an expanding environment nobody has a full picture of, applications
bought outside procurement, and bills that arrive larger than anyone forecast.
The 2019 version of this argument was that most cloud-based asset management
tools could not discover or inventory cloud and SaaS applications at all, so you
would have to buy a second tool, and then a third, and stitch the outputs
together by hand — assuming the SaaS tool would let you export at all, which
many would not.
That is no longer a gap you have to live with, so here is what covering it
properly looks like.
CerteroX SaaS Management discovers applications through three converging
signals rather than one: identity provider sync from Entra ID and Okta, 47
vendor connectors pulling authoritative user and licence lists from the source,
and a browser extension that detects SaaS domains with time-on-app and per-user
attribution. Those signals resolve against a catalogue of more than 35,000
applications. Unused licences surface at 30-plus days of zero usage, app
rationalisation ranks overlapping applications by recoverable saving, and
renewals appear with days-to-renewal against actual utilisation rather than
seat count.
CerteroX Cloud Management covers twelve cloud and data platforms with a cost
model built on FOCUS, the FinOps open cost and usage specification, so the data
stays portable rather than locked in a vendor schema. Optimisation runs as
twenty-six named, individually tunable checks — abandoned instances, obsolete
snapshot chains, instances stopped but not deallocated, rightsizing, reserved
instance and savings plan opportunities — rather than an unexplained “potential
savings” figure. Certero’s average cloud cost saving across environments under
management is 38%.
The point is not the feature list. It is that both of those run on the same data
model as the hardware and software records, so a holistic analysis across
on-premises and cloud does not require an export.
Governance and security
For governance, SaaS-only tools give you limited visibility of software and no
hardware or cloud data. As above, you procure a second tool for hardware — and
the vendors who supply that data often cannot deliver it as SaaS, so it is
deployed on-premises.
That works against a cloud-first strategy and creates a compounding problem.
Instead of two systems with two data sources and two formats, you now have
three, and more again if you want data centre coverage. And because the SaaS
tool for software frequently will not let you export, you cannot manually bridge
the gap even if you are willing to.
Without visibility you cannot govern. That includes identifying and resolving
security exposure across hardware and the software running on it. If you cannot
see all your hardware and everything installed on it, you are exposed to threats
you do not know exist and therefore cannot resolve.
There is a modern version of this problem that the original article predates.
The exposure is no longer only unpatched software on unmanaged hardware; it is
also the OAuth grant a departed employee gave a third-party application that
still has read access to a company drive. CerteroX SaaS Management discovers
consented third-party grants, scores them from 0 to 100 on data sensitivity,
scope, consent and dormancy, and revokes them in one click or as a workflow
action. Offboarding is tracked per user, per licence, with the revocation status
behind each one — so you can prove it finished, rather than assume it did.
Change programmes involve retiring older hardware and software and replacing it
with something newer. That cannot be done quickly without visibility of both the
current and the intended future state. With it, you can see what needs retiring,
whether it needs replacing, and what the replacement looks like in the new
environment.
With a SaaS tool for software, a second tool for hardware and a third for cloud,
you cannot assemble that view fast enough to matter. Falling back to a fully
on-premises tool set does not help either — the manual work is still there. The
best case is that the programme slows down. The worst case is that it stalls.
The criteria, summarised
Judged against the categories above, the recurring limitations of the older
generation of tools are:
- No end-to-end SaaS option covering hardware, software and cloud together
- Separate logins per tool, with conflicting interfaces
- Fragmented data sources in inconsistent formats
- Incomplete data across vendors and device types
- Manual processes and data entry between every step
Those are architectural symptoms rather than feature gaps, which is why they do
not get fixed by the next release. There are vendors making large claims about
having solved them. Do not take the claim — make the vendor show you the
architecture doing the work.
What one data model actually buys you
CerteroX is five products on one platform and one data model: CerteroX ITAM,
CerteroX SAM, CerteroX SaaS Management, CerteroX Cloud Management and CerteroX
AI Management. One login, one interface, one normalised data source.
Coverage runs across six operating system families — Windows, macOS, Linux, IBM
AIX, HP-UX and Oracle Solaris — with mobile device management for iOS and
Android, virtualisation from VMware, Hyper-V, Citrix, IBM HMC, Oracle VM, oVirt
and Nutanix, dedicated licence engines for Microsoft, Oracle, IBM, SAP, Adobe
and Salesforce, and the SaaS and cloud coverage described above. It deploys as
SaaS, on-premises or any hybrid combination, with the same functionality in
each.
The reason that matters is not that it is a longer list. It is that a compliance
position, an optimisation decision and a security question all resolve against
the same record, so nobody has to argue about which system is right first.
One record, one position, one place the action happens. Talk to us or
book a demo.