Controlling the purchase and installation of software is the obvious first step
in a Software Asset Management programme. It is not the last one, and stopping
there is where most of the available value gets left behind.
Purchase records tell you what you are entitled to. Inventory tells you what is
installed. Neither tells you what anybody is actually using — and usage is the
data that turns a compliance report into a decision. Understanding software usage
across the organisation pays back in four distinct ways:
- Improved security — unauthorised software that nobody sanctioned and
nobody is patching shows up as something in use, not just something present
- Reduced costs — software that is installed and untouched can be reclaimed
and reissued instead of bought again
- Optimised licences — users can be moved to the licence type that matches
what they actually do, rather than the one they were given on day one
- Increased productivity — software being used during work hours that has no
business justification becomes visible
Taken together, this is what lets you say what the business genuinely needs going
forward, rather than renewing last year’s shape of the problem because nobody
could prove otherwise.
The two things that made usage hard to measure
Two technologies have historically broken usage measurement: virtualisation and
cloud applications. Both are now solved, but it is worth understanding why they
were difficult, because the reasoning explains what to check when you evaluate
any tool.
Virtualisation
The first problem is non-persistent desktops. A new desktop is created when
someone logs on and destroyed when they log off. Most monitoring tools consolidate
usage into a single file and send it to the server at the end of the day — so
when the desktop disappears mid-afternoon, so does the record of everything that
ran on it. You end up with a systematic blind spot in exactly the part of the
environment where licensing is most contested.
CerteroX ITAM supports non-persistent VDI inventory directly, so the session’s
data survives the session. This is a specific capability, not a side effect of
general discovery, and it is worth asking any vendor about explicitly.
The second problem is application virtualisation and streaming. When an
application is delivered to the desktop rather than installed on it, working out
who is entitled to use it — and who actually did — is genuinely harder, and
getting it wrong has compliance consequences in both directions. You can be
under-licensed because more people can reach the application than you licensed
for, or over-licensed because you counted everyone who could reach it rather
than everyone who used it.
CerteroX SAM handles this with Access Control rules for RDS, Citrix and VDI
streamed-application licensing, alongside Terminal Server and RDS remote-usage
tracking per device. The point is that entitlement is calculated from who can
actually access the application under the controls you have in place, rather than
from a worst-case reading of the environment.
Cloud and SaaS applications
Cloud applications changed the shape of the question rather than the question
itself. High availability, scale and managed operations are appealing, and the
commercial consequences of not governing usage are easy to overlook precisely
because nothing breaks when you get it wrong.
The mechanics are inverted compared with on-premises software. A user cannot log
in without an assigned licence, so under-licensing is largely designed out. The
exposure is the opposite one: paying, every month, for seats nobody opens. Nobody
is ever forced to notice, because nothing fails.
When this post was first written, that left an open question — how do you measure
usage in an application you do not host and cannot inventory? That question now
has a product answer.
CerteroX SaaS Management measures SaaS usage through three converging signals: a
browser extension that records SaaS domains, time on application and per-user
attribution; identity provider sync from Entra ID and Okta; and connector sync
that pulls authoritative user and licence lists from 47 vendor APIs. Applications
are resolved against a catalogue of more than 35,000, so what comes back is a
named application with an owner, not an unrecognised domain.
From that, the optimisation work is direct. Unused licences are flagged at 30 or
more days of zero usage. App Rationalization detects overlapping applications and
ranks them by recoverable saving. Upcoming renewals are shown with days remaining
and the utilisation rate beside them, which is the one moment when the data is
worth the most. Cost per licensed user sits next to cost per active user, and the
gap between those two numbers is the whole argument. And because the same system
handles offboarding, the seats belonging to people who left four months ago stop
being an annual discovery.
Detailed usage across everything you own
For installed software, the measurement comes from AppsMonitor in CerteroX SAM.
It meters usage from file activity continuously, without per-application
configuration, and tracks first-used and last-used dates for every title. The
headline metric is % Used over a rolling 90-day window.
That framing is deliberate. It gives a clear view of what has and has not been
used, and avoids the two failure modes of usage reporting. One is vagueness —
tools that classify software as “rarely used” or “frequently used”, which is
subjective and impossible to act on when a user disputes the reclamation. The
other is false precision — average time in use, or number of launches per day,
which is data-intensive to collect, often limited to a subset of applications,
and no more decisive when it comes to actually removing software from someone.
A percentage over a defined window is defensible in the conversation that
follows, which is the test that matters.
Support for virtualised environments is out of the box, covering VMware,
Microsoft Hyper-V, Citrix XenServer, IBM HMC, Oracle VM, Red Hat oVirt and
Nutanix. Inventory extends across six operating system families — Windows, macOS,
Linux, AIX, HP-UX and Solaris — through the same native agent, so usage data from
a Solaris frame arrives in the same schema as usage data from a laptop.
Where this ends up
Usage data is what makes every other part of SAM actionable. An effective licence
position built on installations tells you whether you are compliant. The same
position with usage underneath it tells you what to do next — which titles to
harvest, which users to downgrade, which renewals to cut and which contracts to
renegotiate before they roll.
One is a report. The other is a budget line.
If you have a question about monitoring software usage, get in
touch.