Skip to content

A Consultant's Story: No Tool Can Do It All

Certero’s vendor licensing specialists on where the line sits between what a SAM platform computes and what only a human can decide — contract clauses, restricted-use rights, divestments and audit tactics.

First published in March 2021. The consultants quoted are described by the roles they held at the time.

Certero is best known as a developer of IT asset management and software asset management technology. It has also always kept a global network of in-house SAM and licensing specialists, who deliver Certero’s independent SAM and ITAM services.

That team works in a way we call technology-led services. The vendor specialists have the full Certero platform at their disposal, which lets them reach a defensible answer faster, and with better evidence, than the traditional consultancy-heavy, “tool agnostic” or manual approaches to the same engagement.

It works because the direction of travel runs both ways. The licensing knowledge inside Certero is what shapes the technology and how the consultancy team uses it in practice — each part doing what it does best.

This piece is a round-table with Certero’s SAM team, including specialists in Microsoft, Oracle, IBM, SAP, and SaaS and cloud. The question put to them was where the line sits between the expert knowledge and the insight the platform produces on its own — and what they know that will never be captured inside any SAM tool.

Compliance and controlling risk — it is not just numbers

Establishing a compliance position for a publisher means telling the customer exactly where they carry financial risk from under-licensing, and exactly where they are overspending on software nobody evidently needs. That is not the same as adding up numbers and producing a tidy effective licence position screen. The screen is the starting point.

The consultant’s job is to understand the publisher, and to know what to do with the information. Noel Donovan, Certero’s Oracle and IBM licensing consultant for APAC, puts it this way:

Knowing what’s deployed and what licences you own is only the first step to licence compliance. How you reconcile the two data sources comes next. Ensuring you understand all the publishers’ licensing and policy nuances and how they apply to all of the operating systems, processor types and partitioning/virtualisation technologies you’re using is paramount to making sure you don’t end up in an awkward, costly situation with said publisher come audit time — and expecting the, often under-resourced, SAM team within the organisation to possess these skills, across all publishers, is a tall order.

That last point is the one IT leaders tend to under-weight. A SAM platform gives you visibility, and it can identify the technical complexity in your environment and show how that complexity lands on licensing for a specific publisher. It cannot supply someone who knows a given publisher in detail and can hold the interpretation of the rules in line with what that publisher will actually accept.

With several publishers’ software in use, it is rarely realistic for one person to be expert in all of them. Recognising where you need additional help is itself part of staying in control.

The vendor smorgasbord of rules

SAM platforms carry a great deal of automation now — software recognition, and built-in intelligence about how publishers define their licensing. That removes a lot of otherwise cumbersome manual work. CerteroX SAM resolves recognition against the Software Recognition Database, a normalised publisher, product and version library of more than 3.5 million titles, and carries dedicated licence engines for six publishers: Microsoft, Oracle, IBM, SAP, Adobe and Salesforce.

The important design constraint is that the platform must always show the evidence and the underlying data, so a consultant can verify every optimal position it proposes rather than take it on trust.

Every publisher still has its peculiarities, and some of those only licensing expertise will spot. Hazel Hopes, Certero’s Oracle and Salesforce licensing consultant for the UK and EMEA:

Like all of Certero’s publisher-specific engines, the Oracle engine applies many of the licensing rules and uses its built-in functionality to build compliance data — however there are always elements in any engagement which sit outside the solution and require human analysis.

Areas such as contractual clauses, third-party or restricted-use licensing, disaster recovery environments, hosting rights, oddities around usage profiles and sometimes even usage bugs produced by the Oracle products themselves; these all need to be traced, addressed and, if needed, mitigated.

Some of that boundary has since moved. CerteroX SAM now models Oracle licence pools with hosting rights and geographic rules, cover-down logic for Enterprise Edition, options and packs with per-instance evidence and an override, processor types and core factors, uncapped quantity for unlimited agreements, and E-Business Suite responsibilities. There is also an explicit Exclude From Licensing workflow for MSDN, development, training and second-use devices, so a consultant’s judgement lands in the model rather than in a spreadsheet beside it.

What has not moved, and will not, is reading the contract. Restricted-use grants, disaster recovery terms and the intent behind a clause signed nine years ago are not data problems.

Change and contractual conundrums

Reviewing contractual data matters more than it looks, because these documents carry complexity that organisations sign up to and then forget. That becomes a compliance issue years later.

In our experience it is most common where a publisher’s products have been in use for a long time and the stakeholders who agreed the original terms have moved on, leaving confusion for the people who inherited the arrangement.

Then there are acquisitions and, more dangerous, divestments. Businesses lose track of who may use what and where. We have seen divested companies happily running a publisher’s products without realising they lost the right to do so during the divestment, which is a substantial and entirely avoidable financial risk.

Steve Wood, Certero’s IBM and SAP licensing expert for the UK and EMEA, on SAP contractual data and how it relates to usage and optimisation:

Customers using the SAP ERP solution will have purchased their SAP licences over many years and under many contracts, and in many cases these licences have no direct relationship to the user’s ability to access the ERP system, and therefore many customers may not be taking full advantage of their licences. The addition of SAP services for any SAP ERP system will provide an additional level of understanding which often has not been encouraged by SAP. Through the use of the services alongside the in-house SAP team we can provide the additional understanding of the SAP contracts and licence entitlements and how these can be applied to the current users, to assist with the optimisation of their licensing and to also ensure that a user is correctly licensed, so that the SAP ERP licences are right-sized for what the organisation actually runs.

With mergers and acquisitions this is even more important — get the current position right before going out and buying additional licences. Using our services team will provide a view of the current system and provide options for alternative licensing as appropriate.

CerteroX SAM supports that work with a non-invasive ABAP connector that reads named users de-duplicated across systems, along with roles, role groups, engines and authorisation definitions, and priority-ordered analysis rules that propose the licence type each user should hold. You can see the current, suggested and optimal positions side by side. What the connector cannot do is tell you which contract those entitlements arrived under.

Audit anxiety, mitigation and control

A licensing consultant does more than help you understand what you already own. They help you judge whether your publisher’s suggestion — or your reseller’s — is the right one for you, or whether a different strategy would serve you better. Kevin Barnes, Certero’s IBM consultant for the UK and EMEA:

Our IBM licensing specialists can help you reduce exposures, optimise your software usage, provide audit defence services during an audit, as well as other more general help, such as: is a new proposal by IBM for a piece of software actually going to work in your favour?

When it comes to reducing exposures, it is not always just a case of removing software — for example, the timing of a decommission and ILMT deployment can be critical to not putting yourself in an adverse position. Optimising software can involve understanding how to use IBM’s complex licensing to your advantage, and during an audit, do you know if you are inadvertently sharing information which is contradictory, thus putting yourself in a bad position?

That last question is the one no platform answers for you. Understanding how a major publisher approaches an audit, and how to use that knowledge, sits outside any tool.

Forrest Silverman, Certero’s IBM and Oracle expert in the US, warns that a lack of clarity here has financial consequences that arrive late:

ELP services for Oracle and IBM are paramount to fully understanding your licensing requirements. The complexities involved with Oracle and IBM licensing can easily lead a customer into using the wrong version, edition or type of product, which can lead to mis-licensing and eventually a serious unexpected financial outlay.

With our expertise comes the understanding of the whys and hows, which can provide the mechanism for correction of misunderstood requirements. Additionally, our expertise allows us to facilitate change, advise where duplicative products are in use and identify where overspending might occur — all of which are endemic problems with using IBM and Oracle software.

We have seen too many businesses agree to additional expenditure simply to make an audit go away, when other options existed. Steve Wood again, on IBM:

IBM covers a wide spectrum of products and has a very active audit programme. Customers struggle with understanding the requirements of IBM licensing and the complexity of the IBM product bundles. The addition of IBM services to any ITAM project where IBM software licences have been purchased provides a complementary technical resource with specialised knowledge of IBM licensing and the IBM audit process.

If a customer doesn’t have any IBM expertise in house, but has IBM products installed, having our services team provide the IBM licensing function for the ITAM team is critical and would help to avoid the risk of unplanned expenditure from audits, through providing the ITAM team with full visibility of the IBM licensing and thus reducing the overall risk.

On the technology side, CerteroX SAM handles PVU and Virtual Processor Core metrics, carries an ILMT connector with compliance gap analysis, and enforces the thirty-minute inventory cycle that IBM sub-capacity licensing actually requires. Component Resolution matches deployed components to products with a scored suggestion you can apply in bulk. The timing decisions Kevin describes remain yours to make.

In summary

ITAM and SAM technology has moved a long way, and many of the old data problems simply do not need to be problems any more. Bringing the asset management disciplines onto one platform has changed where SAM professionals spend their time — from collating information to acting on it.

That consolidation is now broader than it was in 2021. CerteroX covers five disciplines on one data model: ITAM, SAM, SaaS Management, Cloud Management and AI Management. Software recognition resolves against more than 3.5 million titles. SaaS discovery runs on 47 shipping connectors against a catalogue of more than 35,000 applications, with Shadow AI classified from application feature tags rather than a static list. Cloud carries twenty-six named, individually tunable optimisation checks across twelve platforms.

None of which changes the conclusion the team reached. The role of the SAM consultant is more valuable than it was, not less, because they are the ones who turn information into a business decision — and they now have better information and more time to act on it.

Specialist expertise makes the platform worth more. Certero’s consultancy team brings clarity to the rules and, working directly for the customer, adjusts the findings for environments and business structures no product could infer on its own. The tool computes the position. Somebody still has to decide what to do about it.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.