While there is nothing to be gained from adding to the noise, when organisations
around the world start preparing contingency plans for how to keep operating
through a widening emergency, it is worth walking through what that means for IT
and software asset management specifically.
Colleagues in HR and IT are refreshing their business continuity plans. ITAM and
SAM leaders should be doing the same, because most of the decisions taken in a
hurry during a disruption land in your ledger afterwards.
Employees self-isolating or working from home
BYOD, secondary use rights and licensing
Organisations with a highly mobile workforce are usually well prepared for empty
offices and staff taking laptops home. Organisations that do not routinely issue
laptops are not. Expect a jump in people using personally owned devices to reach
corporate applications — email, productivity suites, collaboration platforms —
over the public internet.
If those applications are modern and cloud-delivered, such as Microsoft 365,
Google Workspace or Salesforce, this is rarely a licensing problem, provided
entitlement is tied to the user rather than the device. Where it is tied to the
device, you need secondary use rights in place. Older applications licensed under
schemes that never anticipated home working are where the difficulty sits: you
may not be able to give people enough access to stay productive without buying
something.
Free trials are still commitments
A great many productivity and collaboration vendors push free trials hard the
moment remote working spikes. That can be genuinely useful. But a free trial is
exactly that. Continued use after it lapses can convert automatically into a
charge, or leave you carrying a cost nobody budgeted for. Take the offer if it
helps — just decide in advance what happens on the day it expires, and record the
expiry date somewhere that is not one person’s calendar.
Security follows the device
When personal devices reach corporate systems, they arrive without the
protections you normally assume: managed anti-malware, patch levels you control,
a corporate firewall between the machine and the internet. Access to sensitive
systems needs re-scrutinising and risk assessments need revising to reflect a
higher likelihood of unsanctioned devices and insecure connections.
The same applies to phones. Most modern applications accommodate a licensed user
working across several devices, but confirm that is true of yours, and assess
what the increase means for data integrity and privacy.
Whatever you change in a hurry, record it. Every short-term relaxation made to
enable home working needs to be reviewable, and reversible, once the emergency
passes. In CerteroX ITAM this is what Governance Policies are for: compliance
rules expressed as reusable filters — BitLocker enabled, Defender running, tag
hygiene on cloud VMs — with the policy definitions exportable and importable as
JSON, so a temporary exception is a tracked change rather than an oral tradition.
Changing user rights
Contingency plans often assume that technical and administrative staff will
backfill for sick colleagues, or temporarily pick up additional responsibilities,
so that business operations keep running.
With enterprise systems from Oracle, IBM and SAP, that is a licensing event.
Users may need additional rights, or a change of licence type, to hold the
privileges required to support a mission-critical system.
If this applies to you, track it. The expensive failure mode is not granting the
rights — it is granting them for an emergency and never reversing them, so that a
temporary elevation quietly becomes a permanent entitlement class that you are
still paying for, and still liable for, at the next audit. Hoping for a
compassionate reading of your licence terms is not a control.
CerteroX SAM’s SAP analysis exists for precisely this shape of problem:
priority-ordered analysis rules propose the licence type each named user should
hold, so current, suggested and optimal positions sit side by side and an
elevation that outlived its reason is visible rather than buried. For SaaS
applications, CerteroX SaaS Management’s workflow engine can drive the reversal
itself — eight triggers, eleven conditions and thirteen actions on one canvas,
with every provisioning and deprovisioning step written to an audit log.
New software and hardware requests
Disruption changes how teams work together and which tools they reach for.
Organisations with existing investments in collaboration platforms are
well-equipped to absorb it. In some cases the emergency is the event that finally
drives adoption of a platform that has been paid for and under-used for years —
which is worth measuring, because it changes the renewal conversation.
Organisations without an established platform get a harder version. Teams either
suddenly demand access to software they previously ignored, or they go their own
way and adopt whatever works, outside IT’s visibility and control.
Head that off if you can, by making sure department leads know what is already
available to them before everyone is working from a kitchen table. But assume
some of it will happen anyway — and that is now a discovery problem rather than
an unknown. CerteroX SaaS Management converges three signals to surface
applications nobody registered: identity provider sync from Entra ID and Okta,
authoritative user and licence lists pulled through 47 vendor connectors, and a
browser extension that attributes SaaS domain use per user. Applications resolve
against a catalogue of more than 35,000, and AI tools are classified from
catalogue feature tags rather than a hardcoded list, so the Shadow AI dashboard
keeps finding things after you stop maintaining it. OAuth grants that people
consented to along the way are discovered too, scored from 0 to 100 on
sensitivity, scope, consent and dormancy, and revocable in one click.
On hardware, expect a squeeze from both directions. A sudden move to remote
working competes for laptop stock at exactly the moment everyone else wants the
same units, and procurement lead times do not compress to match. Knowing what you
already own — including what is sitting in a drawer, out of warranty, or assigned
to someone who left — is worth more in that week than a purchase order.
Maintaining visibility of devices off the network
Governance responsibilities do not lessen because the office is empty. They
increase. Visibility of the assets actually in use is the whole basis of the
function.
If your ITAM tool depends on machines being reachable on the corporate network at
the time of audit, an extended period of home working degrades your inventory
faster than most people expect — weeks, not years. The licensing consequence is
slow. The service desk consequence is immediate: a remote user calls with a
problem and nobody can see the current configuration of the device or what is
installed on it.
This is the practical difference between agent-based and network-scan inventory.
CerteroX ITAM ships a native inventory agent for Windows, macOS, Linux, IBM AIX,
HP-UX and Oracle Solaris, so the record follows the device rather than the
subnet. Where an agent cannot be deployed there is agentless and command-line
collection (csinvcli) for locked-down machines, and standalone inventory for
air-gapped and offline systems. Ten discovery methods in total land in one
schema, which is what stops “we have partial visibility” turning into a
reconciliation project later.
Impacts on the ITAM and SAM functions directly
Suppose your own team is affected and people have to work away from the office.
Do they stay productive, or does the function stall?
Ask the practical questions. Can your team reach both the reporting and the
administrative side of the toolset remotely? Can cover be delegated without
handing someone the keys to everything? CerteroX uses role-based access control
with granular permissions, Reporting Levels that restrict visibility by
organisational unit or location, and personal as well as role-shared dashboards —
so a stand-in gets exactly the scope they need. There is also a read-only API
with a documented Power BI data source, which means routine reporting can carry
on without anyone logging into the tool at all.
Then plan for the worse case. What if one or more of the ITAM and SAM team are
ill for an extended period? Can the function afford the lost output, and what
does that do to the wider projects you are supporting? If it cannot, do you have
people trained well enough to backfill? And if not, do you have a services
agreement in place with a provider who can supply skills at short notice?
None of us wants the disruption. But ITAM and SAM professionals are the
custodians of technology governance, and planning for the worst is the job.