From “Project Where’s My Stuff” to “Project Optimise My Stuff”
Perhaps it is a symptom of having been in this industry a long time, or of
spending too much energy aligning with business buyers and budget holders, but I
occasionally forget how differently placed organisations are on their IT asset
and software asset management journeys.
In the enthusiasm to explain how ITAM and SAM underpin a digital transformation
programme, it is easy to skip past the foundational work — and the foundational
work is where most people actually are.
A customer of ours has a nickname for phase one of their programme. There is an
official project name, and it is a good one, but his version is better: “Project
Where’s My Stuff?”
I like it because it is honest. As a provider of software asset management tools
and services, we spend a lot of time on the sharp end of the problem — optimising
large SaaS portfolios, getting control of a substantial Oracle position, proving
to a publisher why a client does not owe them what the audit letter claims. It is
easy to lose sight of the fact that for a great many organisations the pressing
question is simpler and more fundamental: what have we got?
Of course, discovering and inventorying everything is only simple to describe. It
is the doing that is hard. But it is only once you have that visibility — and
genuine confidence in it — that anything downstream is worth attempting. An
effective licence position built on an incomplete inventory is not a licence
position. It is a guess with a total at the bottom.
What “stuff” means now
When this phase was first named, “stuff” meant machines. Servers, laptops,
the desktops nobody had logged since a reorganisation, the printers, the AIX
frames that the last discovery tool politely ignored.
That work has not gone away. It is still where a programme starts, and the
mechanics matter:
- Find the machines before you own them. Network Discovery sweeps a class-C
subnet in under five seconds across NetBIOS, SNMP and ICMP, then probes to work
out where an agent can actually be deployed. Agentless and command-line
collection covers locked-down devices; standalone inventory covers air-gapped
and offline systems.
- One schema, not a reconciliation project. Agent, command-line, agentless,
standalone, Active Directory, network scan, third-party import, cloud
connector, browser monitoring and file metering — ten methods, all landing in
the same data model. Duplicate system detection and stale device archiving keep
it honest.
- Every platform, not the convenient ones. Windows, macOS, Linux, IBM AIX,
HP-UX and Oracle Solaris get the same native agent and the same inventory
cycle.
The temptation at this point — and it is a strong one, because custom dashboards
are quick to build — is to dive straight into the detail. Resist it for a while.
Get the big picture of what exists before you start pulling threads.
The threads are there when you want them, though, and they are more granular than
people expect. Warranty retrieval and expiry tracking tells you which hardware is
out of cover. The Software Recognition Service carries release, end-of-support
and extended-support dates, so “which machines are running something we should
have replaced” is a filter rather than a research project. SNMP collection
returns printer consumables and page counts, which is a small thing that pays for
itself surprisingly often.
The black holes moved
Here is what has changed since the phase was named, and it is the reason the
foundational work is harder now, not easier: most of what an organisation owns no
longer sits on its network.
The average enterprise portfolio now runs 305 SaaS applications, and 46% of SaaS
licences go unused — the average organisation uses 54% of what it pays for. None
of that is discoverable by scanning a subnet. Neither is the AI tooling people
have signed up to with a corporate email address.
So “Where’s My Stuff” now has a second half. CerteroX SaaS Management converges
three signals: identity provider sync from Entra ID and Okta, authoritative user
and licence lists pulled through 47 vendor connectors, and a browser extension
that attributes SaaS domain use and time-on-app per user. Applications resolve
against a catalogue of more than 35,000, and because AI tools are classified from
catalogue feature tags rather than a maintained list, the Shadow AI view keeps
finding new tools without anyone updating it. OAuth grants that staff consented
to on the way past are discovered as well, scored on sensitivity, scope, consent
and dormancy.
Then, and only then, optimise
What made the original phase name work is the implied sequence. You cannot
rationalise an application portfolio you cannot see. You cannot harvest licences
nobody uses if usage is a matter of opinion. You cannot defend an audit with an
inventory you do not trust.
Once you can see it, everything downstream becomes tractable: unused licence
detection at thirty days of zero usage, overlap analysis ranked by recoverable
saving, renewals sequenced by utilisation rather than by date, entitlement
reconciled against what is genuinely installed and genuinely running.
That is the next phase, and it deserves a name too. Project Optimise My Stuff.