First published in March 2021. The consultants quoted are described by the roles
they held at the time.
Certero is best known as a developer of IT asset management and software asset
management technology. It has also always kept a global network of in-house SAM
and licensing specialists, who deliver Certero’s independent SAM and ITAM
services.
That team works in a way we call technology-led services. The vendor
specialists have the full Certero platform at their disposal, which lets them
reach a defensible answer faster, and with better evidence, than the traditional
consultancy-heavy, “tool agnostic” or manual approaches to the same engagement.
It works because the direction of travel runs both ways. The licensing knowledge
inside Certero is what shapes the technology and how the consultancy team uses it
in practice — each part doing what it does best.
This piece is a round-table with Certero’s SAM team, including specialists in
Microsoft, Oracle, IBM, SAP, and SaaS and cloud. The question put to them was
where the line sits between the expert knowledge and the insight the platform
produces on its own — and what they know that will never be captured inside any
SAM tool.
Compliance and controlling risk — it is not just numbers
Establishing a compliance position for a publisher means telling the customer
exactly where they carry financial risk from under-licensing, and exactly where
they are overspending on software nobody evidently needs. That is not the same as
adding up numbers and producing a tidy effective licence position screen. The
screen is the starting point.
The consultant’s job is to understand the publisher, and to know what to do
with the information. Noel Donovan, Certero’s Oracle and IBM licensing consultant
for APAC, puts it this way:
Knowing what’s deployed and what licences you own is only the first step to
licence compliance. How you reconcile the two data sources comes next. Ensuring
you understand all the publishers’ licensing and policy nuances and how they
apply to all of the operating systems, processor types and
partitioning/virtualisation technologies you’re using is paramount to making
sure you don’t end up in an awkward, costly situation with said publisher come
audit time — and expecting the, often under-resourced, SAM team within the
organisation to possess these skills, across all publishers, is a tall order.
That last point is the one IT leaders tend to under-weight. A SAM platform gives
you visibility, and it can identify the technical complexity in your environment
and show how that complexity lands on licensing for a specific publisher. It
cannot supply someone who knows a given publisher in detail and can hold the
interpretation of the rules in line with what that publisher will actually
accept.
With several publishers’ software in use, it is rarely realistic for one person
to be expert in all of them. Recognising where you need additional help is itself
part of staying in control.
The vendor smorgasbord of rules
SAM platforms carry a great deal of automation now — software recognition, and
built-in intelligence about how publishers define their licensing. That removes a
lot of otherwise cumbersome manual work. CerteroX SAM resolves recognition
against the Software Recognition Database, a normalised publisher, product and
version library of more than 3.5 million titles, and carries dedicated licence
engines for six publishers: Microsoft, Oracle, IBM, SAP, Adobe and Salesforce.
The important design constraint is that the platform must always show the
evidence and the underlying data, so a consultant can verify every optimal
position it proposes rather than take it on trust.
Every publisher still has its peculiarities, and some of those only licensing
expertise will spot. Hazel Hopes, Certero’s Oracle and Salesforce licensing
consultant for the UK and EMEA:
Like all of Certero’s publisher-specific engines, the Oracle engine applies
many of the licensing rules and uses its built-in functionality to build
compliance data — however there are always elements in any engagement which sit
outside the solution and require human analysis.
Areas such as contractual clauses, third-party or restricted-use licensing,
disaster recovery environments, hosting rights, oddities around usage profiles
and sometimes even usage bugs produced by the Oracle products themselves; these
all need to be traced, addressed and, if needed, mitigated.
Some of that boundary has since moved. CerteroX SAM now models Oracle licence
pools with hosting rights and geographic rules, cover-down logic for Enterprise
Edition, options and packs with per-instance evidence and an override, processor
types and core factors, uncapped quantity for unlimited agreements, and
E-Business Suite responsibilities. There is also an explicit Exclude From
Licensing workflow for MSDN, development, training and second-use devices, so a
consultant’s judgement lands in the model rather than in a spreadsheet beside it.
What has not moved, and will not, is reading the contract. Restricted-use grants,
disaster recovery terms and the intent behind a clause signed nine years ago are
not data problems.
Change and contractual conundrums
Reviewing contractual data matters more than it looks, because these documents
carry complexity that organisations sign up to and then forget. That becomes a
compliance issue years later.
In our experience it is most common where a publisher’s products have been in use
for a long time and the stakeholders who agreed the original terms have moved on,
leaving confusion for the people who inherited the arrangement.
Then there are acquisitions and, more dangerous, divestments. Businesses lose
track of who may use what and where. We have seen divested companies happily
running a publisher’s products without realising they lost the right to do so
during the divestment, which is a substantial and entirely avoidable financial
risk.
Steve Wood, Certero’s IBM and SAP licensing expert for the UK and EMEA, on SAP
contractual data and how it relates to usage and optimisation:
Customers using the SAP ERP solution will have purchased their SAP licences over
many years and under many contracts, and in many cases these licences have no
direct relationship to the user’s ability to access the ERP system, and
therefore many customers may not be taking full advantage of their licences. The
addition of SAP services for any SAP ERP system will provide an additional level
of understanding which often has not been encouraged by SAP. Through the use of
the services alongside the in-house SAP team we can provide the additional
understanding of the SAP contracts and licence entitlements and how these can be
applied to the current users, to assist with the optimisation of their licensing
and to also ensure that a user is correctly licensed, so that the SAP ERP
licences are right-sized for what the organisation actually runs.
With mergers and acquisitions this is even more important — get the current
position right before going out and buying additional licences. Using our
services team will provide a view of the current system and provide options for
alternative licensing as appropriate.
CerteroX SAM supports that work with a non-invasive ABAP connector that reads
named users de-duplicated across systems, along with roles, role groups, engines
and authorisation definitions, and priority-ordered analysis rules that propose
the licence type each user should hold. You can see the current, suggested and
optimal positions side by side. What the connector cannot do is tell you which
contract those entitlements arrived under.
Audit anxiety, mitigation and control
A licensing consultant does more than help you understand what you already own.
They help you judge whether your publisher’s suggestion — or your reseller’s — is
the right one for you, or whether a different strategy would serve you better.
Kevin Barnes, Certero’s IBM consultant for the UK and EMEA:
Our IBM licensing specialists can help you reduce exposures, optimise your
software usage, provide audit defence services during an audit, as well as other
more general help, such as: is a new proposal by IBM for a piece of software
actually going to work in your favour?
When it comes to reducing exposures, it is not always just a case of removing
software — for example, the timing of a decommission and ILMT deployment can be
critical to not putting yourself in an adverse position. Optimising software can
involve understanding how to use IBM’s complex licensing to your advantage, and
during an audit, do you know if you are inadvertently sharing information which
is contradictory, thus putting yourself in a bad position?
That last question is the one no platform answers for you. Understanding how a
major publisher approaches an audit, and how to use that knowledge, sits outside
any tool.
Forrest Silverman, Certero’s IBM and Oracle expert in the US, warns that a lack
of clarity here has financial consequences that arrive late:
ELP services for Oracle and IBM are paramount to fully understanding your
licensing requirements. The complexities involved with Oracle and IBM licensing
can easily lead a customer into using the wrong version, edition or type of
product, which can lead to mis-licensing and eventually a serious unexpected
financial outlay.
With our expertise comes the understanding of the whys and hows, which can
provide the mechanism for correction of misunderstood requirements. Additionally,
our expertise allows us to facilitate change, advise where duplicative products
are in use and identify where overspending might occur — all of which are endemic
problems with using IBM and Oracle software.
We have seen too many businesses agree to additional expenditure simply to make
an audit go away, when other options existed. Steve Wood again, on IBM:
IBM covers a wide spectrum of products and has a very active audit programme.
Customers struggle with understanding the requirements of IBM licensing and the
complexity of the IBM product bundles. The addition of IBM services to any ITAM
project where IBM software licences have been purchased provides a complementary
technical resource with specialised knowledge of IBM licensing and the IBM audit
process.
If a customer doesn’t have any IBM expertise in house, but has IBM products
installed, having our services team provide the IBM licensing function for the
ITAM team is critical and would help to avoid the risk of unplanned expenditure
from audits, through providing the ITAM team with full visibility of the IBM
licensing and thus reducing the overall risk.
On the technology side, CerteroX SAM handles PVU and Virtual Processor Core
metrics, carries an ILMT connector with compliance gap analysis, and enforces the
thirty-minute inventory cycle that IBM sub-capacity licensing actually requires.
Component Resolution matches deployed components to products with a scored
suggestion you can apply in bulk. The timing decisions Kevin describes remain
yours to make.
In summary
ITAM and SAM technology has moved a long way, and many of the old data problems
simply do not need to be problems any more. Bringing the asset management
disciplines onto one platform has changed where SAM professionals spend their
time — from collating information to acting on it.
That consolidation is now broader than it was in 2021. CerteroX covers five
disciplines on one data model: ITAM, SAM, SaaS Management, Cloud Management and
AI Management. Software recognition resolves against more than 3.5 million
titles. SaaS discovery runs on 47 shipping connectors against a catalogue of more
than 35,000 applications, with Shadow AI classified from application feature tags
rather than a static list. Cloud carries twenty-six named, individually tunable
optimisation checks across twelve platforms.
None of which changes the conclusion the team reached. The role of the SAM
consultant is more valuable than it was, not less, because they are the ones who
turn information into a business decision — and they now have better information
and more time to act on it.
Specialist expertise makes the platform worth more. Certero’s consultancy team
brings clarity to the rules and, working directly for the customer, adjusts the
findings for environments and business structures no product could infer on its
own. The tool computes the position. Somebody still has to decide what to do
about it.