Skip to content

Improve software deployment and ensure compliance

Getting software to people quickly, keeping it secure and staying licensed are usually treated as three problems. Self-service deployment turns them into one process, with the approval, the entitlement check and the audit record all captured at the moment of request.

Managing an application across its whole life — getting it out, keeping it safe, keeping it licensed — is usually handled by three teams using three tools that disagree with each other. It does not have to be three problems. It is one process with three checks in it.

Those checks are:

  • Deployment. Getting software onto diverse devices quickly and predictably.
  • Security. Controlling which applications run and what they can reach.
  • Licences. Metering, reporting and reclaiming the expensive ones.

The interesting thing about that list is that all three are decided at the same moment: when somebody asks for software. Handle the request properly and you have handled all three. Handle it as a ticket and you have handled none of them.

Self-service is the mechanism

Your users already know how this works. They find, request and install software on their own devices without help, and they have done for years. Everywhere except at work, where the same request becomes a queue.

Bringing that interaction inside the organisation is not a concession to user impatience. It is the control point. A request that arrives through a self-service portal can be checked against policy, against a manager’s approval and against your actual entitlement position before anything installs. A request that arrives as an email cannot be checked against anything, because by the time it reaches you the person has usually already found a workaround.

So the case for self-service deployment is:

  • Access in minutes rather than days, which is the reason people will use it instead of going around it.
  • Control over what is installed and what is retired, because every grant is recorded and every reclamation is deliberate.
  • A licence check before the install, rather than an audit finding afterwards.
  • Automation of the request, delivery and approval steps that currently consume service desk time without needing service desk skill.

What sits behind the portal

In CerteroX ITAM this is the App-Centre self-service portal, with manager approval chains built in — a request that needs sign-off gets routed for one, and a request that does not is fulfilled without anyone touching it.

The portal is the front of it. The delivery underneath is the part that decides whether this works across a real environment rather than a pilot:

  • Software distribution for MSI, EXE and Click-to-Run packages.
  • Windows 11 upgrade orchestration, so the largest deployment most organisations are running is driven from the same place as everything else.
  • An SCCM interface that imports and drives existing SCCM applications, packages and jobs, so you are not asked to abandon what already works.
  • WSUS-integrated patch management, including downstream servers.
  • Mobile device management for iOS and Android, including Apple DEP — because the request will not always be for a Windows machine.
  • Passworks self-service password reset for Windows and macOS, which removes the other high-volume, low-skill ticket type.

That breadth matters more than it sounds. The standard endpoint disappeared some years ago. A deployment mechanism that only reaches managed Windows desktops leaves the rest of the organisation to solve the problem privately, which is exactly the behaviour you were trying to stop.

The security check

Unknown software is unmanaged software. You cannot patch it, you cannot vouch for where its data goes, and you cannot say whether it was in scope after an incident.

Self-service reduces how much of it arrives, because the approved route is now the fast route. What it adds is evidence: who asked, who approved, what was installed, on which device, when. That record is the thing you actually need when somebody asks a hard question three months later.

Prevention sits alongside it. Governance Policies express compliance rules as code with a reusable filter builder — BitLocker enabled, Defender running, Azure VM tag hygiene — and CerteroX SAM adds application blacklisting and prohibition rules. Together that is detection and prevention rather than one without the other.

The licence check

This is where a deployment portal earns its cost.

Granting a licence you do not hold is the most avoidable form of non-compliance there is, and in most organisations it happens invisibly for years until a vendor audit converts it into a bill. The fix is to make the availability check part of the grant.

That requires a genuine entitlement position rather than a purchase spreadsheet. CerteroX SAM computes the Effective Licence Position continuously — purchased, used, available, required, variance and exposure — so the question “is there a spare one?” has a real answer at the moment somebody asks it, not at the end of a reconciliation project.

Reclamation is the other direction and it is worth as much. Every organisation carries licences issued to people who stopped using the software long ago. AppsMonitor meters file-based usage with first-used and last-used tracking and reports a % Used figure over a rolling 90-day window, which turns “nobody seems to need this” into a defensible harvesting decision. Reclaimed licences go back into the pool and satisfy the next request instead of triggering a purchase.

Downgrade rights, second-use entitlements and the Exclude From Licensing workflow for MSDN, development, training and second-use devices all feed the same position, so the availability check reflects what you are genuinely entitled to rather than a raw install count.

What an app store can no longer reach

This article was written when deploying software meant installing it. That assumption has expired.

Most of the applications people now use are never deployed at all. They are signed up for in a browser, with a work email address, and no distribution mechanism ever sees them. An app store cannot intercept something that is not downloaded.

That half of the problem needs discovery rather than delivery, and it is what CerteroX SaaS Management does:

  • Three converging discovery signals — identity provider sync from Entra ID and Okta, connector sync pulling authoritative user and licence lists directly from the vendor across 47 connectors shipping today, and a browser extension detecting SaaS domains with per-user attribution.
  • Provisioning and deprovisioning across Entra, Okta, Google Workspace, Microsoft 365 and more, driven by a workflow engine with 8 triggers, 11 conditions and 13 actions on one canvas — so the self-service grant and the eventual revocation are both automated, not just the grant.
  • An offboarding checklist per user, showing every licence held, the connector status behind each revocation and whether it is pending, in progress or complete, with the monthly cost of anything still open.
  • Unused licence detection at 30 or more days of zero usage, with reclaim, reassign, downgrade tier, archive, remind and dismiss as actions rather than a report you then have to act on.
  • Shadow AI detection, classified from application feature tags across a catalogue of 35,000+ applications rather than a hardcoded list, so the detection set keeps up with a category that changes monthly.

The point

Deployment, security and licence compliance are the same decision viewed from three angles. Make that decision once, at the point of request, with the entitlement position and the policy already in the room, and the three stop competing for the same evidence.

Then extend it past the device, because that is where most of the software went.

To see a request, an approval, a deployment and the licence position that moves with them, book a demo.

Related reading

Other posts covering the same ground.

  • Certero Insider Newsletter – July 2025

    The licensing changes that mattered in June and July 2025 — Microsoft Product Terms, the return of the SAMOSA Act, the end of the Microsoft 365 nonprofit grant, Adobe's AI credit cuts, a Dutch ruling against Broadcom, and rising Oracle Java audit activity.

    • ITAM
    • SAM
    • SaaS
    • Governance
    10 min
  • Software Asset Management Plan

    A six-step plan for building a SAM programme that covers on-premises, SaaS and cloud as one problem rather than two — scope, maturity, people and technology, accountability, and what to do first.

    • ITAM
    • SAM
    • SaaS
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.