Skip to content

Project Where's My Stuff?

Before optimisation, rationalisation or audit defence, most organisations need something less glamorous: a trustworthy answer to what they actually own. Why the foundational phase deserves its own name — and what counts as "stuff" now that most of it never touches your network.

From “Project Where’s My Stuff” to “Project Optimise My Stuff”

Perhaps it is a symptom of having been in this industry a long time, or of spending too much energy aligning with business buyers and budget holders, but I occasionally forget how differently placed organisations are on their IT asset and software asset management journeys.

In the enthusiasm to explain how ITAM and SAM underpin a digital transformation programme, it is easy to skip past the foundational work — and the foundational work is where most people actually are.

A customer of ours has a nickname for phase one of their programme. There is an official project name, and it is a good one, but his version is better: “Project Where’s My Stuff?”

I like it because it is honest. As a provider of software asset management tools and services, we spend a lot of time on the sharp end of the problem — optimising large SaaS portfolios, getting control of a substantial Oracle position, proving to a publisher why a client does not owe them what the audit letter claims. It is easy to lose sight of the fact that for a great many organisations the pressing question is simpler and more fundamental: what have we got?

Of course, discovering and inventorying everything is only simple to describe. It is the doing that is hard. But it is only once you have that visibility — and genuine confidence in it — that anything downstream is worth attempting. An effective licence position built on an incomplete inventory is not a licence position. It is a guess with a total at the bottom.

What “stuff” means now

When this phase was first named, “stuff” meant machines. Servers, laptops, the desktops nobody had logged since a reorganisation, the printers, the AIX frames that the last discovery tool politely ignored.

That work has not gone away. It is still where a programme starts, and the mechanics matter:

  • Find the machines before you own them. Network Discovery sweeps a class-C subnet in under five seconds across NetBIOS, SNMP and ICMP, then probes to work out where an agent can actually be deployed. Agentless and command-line collection covers locked-down devices; standalone inventory covers air-gapped and offline systems.
  • One schema, not a reconciliation project. Agent, command-line, agentless, standalone, Active Directory, network scan, third-party import, cloud connector, browser monitoring and file metering — ten methods, all landing in the same data model. Duplicate system detection and stale device archiving keep it honest.
  • Every platform, not the convenient ones. Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris get the same native agent and the same inventory cycle.

The temptation at this point — and it is a strong one, because custom dashboards are quick to build — is to dive straight into the detail. Resist it for a while. Get the big picture of what exists before you start pulling threads.

The threads are there when you want them, though, and they are more granular than people expect. Warranty retrieval and expiry tracking tells you which hardware is out of cover. The Software Recognition Service carries release, end-of-support and extended-support dates, so “which machines are running something we should have replaced” is a filter rather than a research project. SNMP collection returns printer consumables and page counts, which is a small thing that pays for itself surprisingly often.

The black holes moved

Here is what has changed since the phase was named, and it is the reason the foundational work is harder now, not easier: most of what an organisation owns no longer sits on its network.

The average enterprise portfolio now runs 305 SaaS applications, and 46% of SaaS licences go unused — the average organisation uses 54% of what it pays for. None of that is discoverable by scanning a subnet. Neither is the AI tooling people have signed up to with a corporate email address.

So “Where’s My Stuff” now has a second half. CerteroX SaaS Management converges three signals: identity provider sync from Entra ID and Okta, authoritative user and licence lists pulled through 47 vendor connectors, and a browser extension that attributes SaaS domain use and time-on-app per user. Applications resolve against a catalogue of more than 35,000, and because AI tools are classified from catalogue feature tags rather than a maintained list, the Shadow AI view keeps finding new tools without anyone updating it. OAuth grants that staff consented to on the way past are discovered as well, scored on sensitivity, scope, consent and dormancy.

Then, and only then, optimise

What made the original phase name work is the implied sequence. You cannot rationalise an application portfolio you cannot see. You cannot harvest licences nobody uses if usage is a matter of opinion. You cannot defend an audit with an inventory you do not trust.

Once you can see it, everything downstream becomes tractable: unused licence detection at thirty days of zero usage, overlap analysis ranked by recoverable saving, renewals sequenced by utilisation rather than by date, entitlement reconciled against what is genuinely installed and genuinely running.

That is the next phase, and it deserves a name too. Project Optimise My Stuff.

Related reading

Other posts covering the same ground.

  • Choosing the Right IT Asset Discovery and Inventory Tools

    Discovery and inventory are not the same thing, and most tools that claim the first are only good at the second. Six criteria for choosing between them, and why "good enough" coverage stops being good enough the moment anyone outside SAM uses your data.

    • ITAM
    • SAM
    • SaaS
    8 min
  • Licence Reharvesting: Reclaiming Your IT Assets

    Reclaiming hardware and licences that nobody is using is the cheapest saving available to an IT team. What it takes is metering you can trust, a policy people will accept, and an inventory that actually finds everything.

    • ITAM
    • SAM
    • SaaS
    7 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.