Certero is usually described as a developer of IT asset management and SAM
technology, but it has always kept a global network of in-house SAM and licensing
specialists alongside it, delivering independent SAM and ITAM services.
That combination is deliberate. The consultancy team works with the full platform
at their disposal, which lets them reach an accurate position far faster than a
tool-agnostic or manual engagement can. It also runs the other way: what the
specialists learn in the field is what shapes the product. Each part does what it
is best at.
This piece looks at the first honest step in any SAM programme — assessing where
you actually are — and at the options for closing the gaps that assessment
exposes.
SAM maturity
Based on the ISO framework and the SAM process standard, ISO/IEC 19770-1, the SAM
maturity assessment and the SAM optimisation model have been widely adopted in
various forms across the industry.
The idea began in a fairly basic form and has since become a much more thorough
examination of how sound an organisation’s policies, procedures and capabilities
really are — not just whether a tool is installed. Performing it properly needs
the right skills, the right experience and senior sponsorship. A Certero SAM
maturity assessment covers five areas:
Overall management — responsibility, risk management, policies and
procedures, competence, awareness and training, performance and continuous
improvement, service continuity and availability management.
Core software asset management — asset identification, asset control and
financial management.
Logistics processes — requirements definition, design, evaluation,
procurement, build, deployment, operation, optimisation and retirement.
Verification and compliance — verification and audit, licence compliance.
Relationship processes — contract management, supplier management, internal
business relations and outsourcing.
There is a separate advantage to having a third party validate internal licensing
decisions. Technical teams are not licensing specialists, and they should not
have to be. Left to make purchasing requests without that expertise, they
reasonably choose the option that solves the technical problem — and sometimes
that option costs more than it needs to, or quietly creates audit exposure. An
independent review catches the pattern rather than the individual mistake.
Switching on capability on demand
Once you can see the weaknesses, you can decide how to fill them: with
technology, with in-house skills, or with a partner.
Retaining specialist knowledge for the major publishers is the classic example.
Very few organisations keep dedicated licensing experts for Microsoft, Oracle,
IBM and SAP simultaneously, on top of managing the desktop environment. Until
recently there was no single technology that covered all of them either, so
holistic governance and reporting across every publisher was extremely difficult
to achieve in practice.
That part is now solved. CerteroX SAM ships dedicated licence engines for six
publishers — Microsoft, Oracle, IBM, SAP, Adobe and Salesforce — on one data
model, so the scope can simply be switched on rather than procured as another
tool. The depth is where it needs to be: Oracle options and packs with evidence
and override, processor types, core factors and cover-down logic for Enterprise
Edition; IBM PVU and virtual processor core metrics with an ILMT connector and
enforcement of the thirty-minute inventory cycle that sub-capacity licensing
requires; a non-invasive ABAP connector for SAP that reads named users
de-duplicated across systems and proposes the licence type each user should hold;
and Microsoft server licensing that understands CALs, cores, clusters and
virtualisation rather than just desktop installs. The effective licence position
— purchased, used, available, required, variance, exposure — is computed
continuously, not reconciled the week the audit letter arrives.
Acquiring the human expertise is not as easy as switching on scope. Publisher
rules are not intuitive and misunderstanding how a vendor operates causes real
problems. Having expertise you can call on when a specific question arises is
what makes the difference between holding data and being able to act on it, and
it takes pressure off a SAM team that is almost always smaller than the remit.
Building an in-house SAM team for all the major publishers
If the preference is to build an internal team around a single platform, knowing
where to start is itself a challenge — particularly with no established programme
in place.
Skills transfer is the usual answer, and it is sometimes built into a SAM managed
service. Certero does the initial heavy lifting of establishing an effective
licence position — which is the valuable position of control — and then hands it
over to an in-house team it has trained to run from there.
For many organisations this is the missing link. It removes the risk of the
programme stalling before it produces anything, and it bridges the gap between an
often chaotic starting position and a functioning capability that delivers
measurable benefit.
New environments: cloud, on-premises and hybrid
The widening scope of environments demands new knowledge as well as new
visibility. SaaS applications and the steady proliferation of cloud
infrastructure did not turn out to be the end of worrying about licensing, as
many assumed.
Cloud licensing has its own well-worn traps. Including Windows Server and SQL
Server licences in the running cost of compute, when existing entitlement could
have been applied instead, is one of the more common — usually the result of
either unfamiliarity with the rules or nervousness about the compliance
conditions attached to using them. Neither is a good reason to pay twice.
The consultant’s job in these environments is largely about showing that the same
outcome can usually be reached several ways, at very different costs: reducing
exposure that already exists, finding optimisation opportunities inside cloud
services, and setting out the different ways a licence requirement can be met
on-premises, in the cloud or across both.
Microsoft licensing in particular keeps getting more complex, and most of that
complexity lives in the data centre. Hybrid use benefits, licensing virtualised
environments correctly, and making sure people are on the right tier of a service
such as Microsoft 365 are all easy to get wrong. Organisations without internal
licensing expertise routinely end up non-compliant, overspent, or both.
There is a subtler version of the same problem. An organisation can be compliant
at the surface — the right number of licences for the number of installs — while
nobody has looked at whether the software deployed to those users is being used
at all. That is why usage evidence matters: CerteroX SAM meters application usage
with first-used and last-used tracking and a percentage-used figure over a rolling
ninety-day window, so harvesting decisions rest on evidence rather than a survey.
On the cloud side, CerteroX Cloud Management applies twenty-six named
optimisation checks across twelve cloud and data platforms, which is what turns
“the bill went up” into a list of specific things to fix.
Cloud migration is also not universal, and probably will not become so. Plenty of
organisations keep legacy applications on-premises because those applications
will not run anywhere else, or because full cloud is more risk than they want.
That hybrid position is likely to persist, with its own costs attached — not
least keeping dedicated gateways available to move data between the two.
Removing the worry
There is a reason to bring in publisher expertise that has nothing to do with
data. Vendor licensing causes genuine stress for the people held responsible for
it, and that should not be underestimated. Being able to ask a specific question
and get a specific answer from someone who has dealt with the same publisher many
times is frequently more useful than another report.
Engaging a subject matter expert as an extension of the SAM team makes sense for
the same reason. The expertise arrives already shaped by years of similar
problems across many organisations, which means it covers the complexity and also
spots the optimisation opportunities — not just in how licences are applied, but
in what concessions are worth asking for at renewal, or during an audit.
In summary
Having a trusted SAM partner means that whatever the publisher, situation or
challenge, there is an available route through it. The emphasis is on delivering
value rather than shipping technology or running a point-in-time engagement that
expires the moment it ends.
Delivering both the technology and the skilled people means you can choose what
you need at any given time and change it as you grow. The value is not only
protection from audit risk. It is the ability to change how licences, software,
hardware and cloud are managed — with open visibility of your own data, and the
freedom to take the reins yourself or hand them over.