Skip to content

SaaS or on-prem – which option is best for ITAM / SAM solutions?

Not every ITAM or SAM platform survives the move to the cloud intact. The questions worth asking a vendor before you accept a hosted option — on functionality, tenancy, upgrade control, integration and security.

Moving workloads to the cloud has clear benefits, but it cuts both ways. Some things you depend on do not perform as expected once they are hosted off-premises, and some are fundamentally unsuited to it.

ITAM and SAM platforms have historically fallen into that awkward category, and the early attempts at cloud-hosted versions by the major vendors were not good.

Most were little more than a cloud-hosted reporting portal sitting in front of what was still a conventional on-premises product, because there was no way to make network discovery and inventory work from the cloud. Others were presented as a hosted version of the on-premises product but behaved very differently in practice. Gaps in data were common. So were unexpected losses of service when background maintenance ran. In the worst cases, customers could not apply a fix they urgently needed because they unknowingly shared a tenant with another customer who did not want to upgrade.

The lesson is that you cannot select on face value. Vendors have addressed these problems in very different ways, and some have not really addressed them at all. Here are the questions worth asking before you take the leap.

Will moving ITAM and SAM to the cloud help control costs?

Yes, in the sense that matters most: predictability. A SaaS model removes the infrastructure overhead and, more usefully, removes the far less predictable cost of maintaining and managing the platform yourself — the server capacity, the database administration, the upgrade weekends, the internal time nobody accounts for.

What you get instead is a transparent annual total cost for hosting, which makes budget planning and cost-benefit analysis considerably easier to do honestly.

Does a hosted ITAM / SAM platform reach value faster?

It does, and the reason is procedural rather than technical. Most of the elapsed time in a traditional ITAM implementation is not spent configuring software. It is spent waiting — for infrastructure to be provisioned, for change approval, for three departments to align their schedules, for a maintenance window.

Removing that removes the bulk of the delay. With SaaS provisioning you switch on the products you need and start discovery, rather than starting a project to prepare to start discovery.

Does a cloud-hosted platform give better accessibility?

This is a genuine advantage and it is worth being specific about what it changes.

An on-premises ITAM platform tends to be reachable from the corporate network, which quietly shapes who uses it. It becomes a tool for the team that administers it, and everyone else consumes exported reports at second hand.

Hosting removes that constraint. Asset intelligence becomes reachable by the people who need it — procurement heading into a renewal, security triaging a vulnerability against affected versions, finance testing a chargeback assumption — without any of them needing to be on a particular network or hold a licence to a thick client. Role-based access control and reporting levels are what make that safe: visibility can be restricted by organisational unit or location, so wider access does not mean everyone sees everything.

It also matters for discovery itself. Remote and hybrid workers are the population an on-premises inventory tool struggles most with, because devices that rarely touch the corporate network rarely report in. Cloud-hosted collection removes that dependency.

Would we lose data or functionality by choosing SaaS?

This is the one to investigate hardest, because it is where the real differences sit and where some vendors cannot honestly answer without significant redevelopment. The market wants SaaS, so what gets offered is often a materially compromised version of the product.

With CerteroX you get the same functionality, depth and detail from a SaaS-provisioned deployment as you would on-premises. That is possible because the platform was designed to run in the cloud rather than adapted to it, and because it is entirely in-house development — no acquired products stitched together, no third-party engines, no legacy code inherited through acquisition. One data model, built rather than bought. That has a large effect on how stable the platform is and how cleanly it extends.

Our recommendation is to test this properly rather than take it on assurance. Do not accept pre-canned vendor reports, which are chosen to flatter. An ITAM and SAM platform should tell you what you want to know, not restrict which questions you are allowed to ask. Bring real scenarios from your own environment and see how easily you can get to the answer.

Does SaaS provisioning restrict how we access, upgrade and use the platform?

You would hope not. This is precisely where several major ITAM and SAM vendors fall down.

Some products are severely constrained by their provisioning architecture, particularly in shared tenants. That produces an inability to update your own instance on your own timetable, and it undermines access governance where you need clear control over user permissions and upgrade timing. A dedicated single tenant may work better, but it is often positioned as a premium that puts it out of reach.

Ask these three questions directly:

  • Can I have a dedicated tenant if I need one?
  • If I want to upgrade, can I do that independently, without it depending on other customers in a shared tenant?
  • If I want to add products, can I do that independently too?

With CerteroX the answer to all three is yes. Standard multi-tenant and dedicated single-tenant options are both available, and both give you the freedom to upgrade, add or remove products when it suits you. Provisioning is looked after for you, but control stays with you. No lock-outs, and no dependency on another customer’s decisions.

The dedicated single tenant exists for organisations with heightened security or data sensitivity requirements. It is not a prerequisite for the platform to work properly.

Can we integrate a SaaS-provisioned ITAM and SAM platform with our service desk?

Yes, and we would strongly recommend it. Hosting does not prevent this integration, which is worth stating plainly because it is a common assumption.

The case for doing it is the data quality. Discovery and inventory across ten methods and six operating system families produces a consolidated, cleansed and reconciled source that is a far better foundation for a CMDB than the service desk can assemble on its own. East of England Ambulance Service put it this way:

The tool has truly transformed how we work, making life a lot easier with complete visibility of assets and automation removing the need for manual intervention.

— Andy Marrs, IM&T Security & Resilience Manager

Their deployment brought 130 sites into view. Any service desk can be the consumer of that data — ServiceNow is a supported integration, and there are 28 named system connectors alongside a read-only API for everything else.

What is the impact of hosting on software recognition?

The information the platform holds feeds operational, financial, security and governance processes, so the health of the processes that populate it matters as much as the interface on top.

Automated software recognition is the clearest example. It resolves discovered software against the Software Recognition Database — over 3.5 million normalised publisher, product and version titles — and the Software Recognition Service adds release date, end-of-support and extended-support dates. That is what turns an inventory into something security can act on, because “which versions are we running and which are unsupported” is answerable continuously rather than on request.

Hosting improves this rather than compromising it, because recognition content is maintained centrally and applied without you scheduling anything.

Does hosting improve maintenance and availability?

Yes. Maintenance and upgrades stop being your problem — provisioning keeps the platform current and available.

The drawbacks that have plagued weaker SaaS platforms do not apply here: no being locked out while an upgrade runs, no dependency on other tenants. It works the way SaaS is supposed to.

Is SaaS provisioning secure?

This varies considerably by vendor, and SaaS can genuinely raise your security position rather than lower it — but only if the vendor has done the work. Formal testing and certification is the evidence that they have submitted to external scrutiny rather than describing themselves as secure.

Certero maintains independent certification for:

  • ISO 27001:2022 — information security management
  • Cyber Essentials Plus — the highest level of the UK NCSC scheme
  • SOC 2 Type 1 attestation

Alongside those, dedicated single-tenant hosting is available, and off-site backup and recovery is provided by default.

The point that gets missed is that assessing the cloud service provider’s credentials is not sufficient. The platform vendor has to be vetted too, because they are the ones handling your data.

SaaS provisioning also strengthens disaster recovery and business continuity. Off-site backup and recovery come as standard, and partnerships with the major cloud platforms mean you have control over how and where your data is held.

What is available as SaaS on the CerteroX platform?

The platform simplifies how you see, report on and manage technology assets everywhere, through a single interface. Delivered as SaaS, it gives you one detailed, accessible and reliable source of asset intelligence.

Five products sit on that one data model, and you switch on the ones you need:

  • CerteroX ITAM — discovery and inventory across Windows, macOS, Linux, AIX, HP-UX and Solaris, plus mobile, virtual and cloud.
  • CerteroX SAM — Effective Licence Position with dedicated engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce. Formally verified by Oracle License Management Services, which means Oracle’s audit team can accept data from Certero during an official audit as an alternative to installing Oracle’s own measurement tools.
  • CerteroX SaaS Management — 47 connectors, a catalogue of over 35,000 applications, shadow IT and Shadow AI discovery, licence reclamation and offboarding you can evidence.
  • CerteroX Cloud Management — twelve cloud and data platforms, twenty-six named optimisation checks, native FOCUS support. A FinOps Certified Platform.
  • CerteroX AI Management — models, experiments, GPU spend and AI seats governed as an asset class rather than an exception.

The architecture is what makes that switch-on model real: because it is one platform rather than several acquired products behind a shared login, adding a product adds capability to the data you already have instead of starting another integration.

Time for change

Provisioning ITAM, SAM and cloud asset management as SaaS is an extension of the same aim: deliver value, sooner, with less of your time consumed by the mechanics.

You are not left to it either. We schedule periodic health checks to make sure you are actually using what you have and that the platform is configured to your environment as it changes. Given how much intelligence sits in the platform, there are few limits on how you can use it to inform decisions and speed up processes elsewhere.

Bring those scenarios and book a demo — the session gets built around the questions you actually need answered.

Can existing customers migrate from on-premises to Certero provisioning?

Yes, and we will help you do it. You will not lose data, and the two can run side by side until you are satisfied. Speak to your account manager or raise a request through the Certero Customer Centre.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.