The reasons organisations implement software asset management have changed
radically since adoption began. Internal and external pressures have both acted
on the discipline, and enterprises have continually refined what they expect SAM
to produce as a result.
The important consequence is this: you are never actually finished implementing
SAM. It keeps evolving, and organisations have to recognise that and build for
it if they want the full set of benefits rather than the first one they went
looking for.
SAM and the development of software audits
It could be argued that SAM began with the PC and the arrival of mass-deployed
software across large organisations, which takes us back to the 1980s. The
circumstances and the technology of that period are a long way from where we
are now.
It was not until the early part of this century that SAM became widely known,
with ITIL v2 and its subsequent formalisation — the ISO/IEC 19770-1 process
standard followed in 2006 and remains the benchmark organisations assess
themselves against.
The real accelerator, though, was external: the financial crash of 2008.
Software vendors looking to protect their margins latched onto the fact that it
is easier to extract more revenue from existing customers than to innovate a
product and find new ones.
The instrument they used was their legal right to audit for non-compliance with
licence agreements. Given the complexity of the agreements they had written, and
how easy they had made it for corporate customers to download and install their
software, the results did not disappoint them.
Vendors then took to disguising audit activity by presenting it as a “SAM
programme”. For the uninitiated this attached SAM to cost and pain, which is
the opposite of what the discipline does. That misreading of the word is
probably why many organisations were not early adopters, and why they missed
the benefits for years longer than they needed to.
The growth of SAM and compliance
Eventually organisations stopped treating SAM purely as an audit response
mechanism. It became a defensive discipline aimed at maintaining compliance,
achieved through better control and management. At the same time, the ability
to monitor actual usage improved utilisation, eliminated over-licensing and
significantly reduced cost. That was the point at which organisations realised
SAM delivered value in its own right, independently of anybody threatening
them.
The initial focus was the desktop. Then came enterprise SAM, which brought the
same compliance, cost and utilisation improvements to licensing in the data
centre.
Then cloud arrived. And mobility.
Licence optimisation and the cloud
In its simplest form, the easiest way to stay compliant is to buy more licences
than you need. This makes you popular with your software vendors. It is also an
expensive way to run an organisation.
Subscription software makes the temptation sharper. All the major vendors have
moved to subscription models, some more aggressively than others, and the model
makes compliance easier for them to enforce: users cannot access the software
without a valid licence. Few organisations want to stop employees doing their
jobs for want of access to something critical, so the safe move is to
over-provision — and the cost of that lands every month rather than once.
Meanwhile, despite what the vendors say, there will always be locally installed
software that needs managing. Cloud did not make licence management and
optimisation go away. It made both more varied and more complex. Licence
optimisation will remain a primary driver for SAM for exactly that reason.
So the organisations with the highest SAM maturity are the ones running a
recognised, fully used, tool-based capability that maintains compliance,
eliminates risk, controls cost and optimises utilisation across everything they
own — desktop, data centre and mobile, on-premises, cloud or hybrid.
SAM and the data it produces
When a SAM programme is done properly — and we do not mean using something like
SCCM to produce the bare minimum — it produces a large volume of detailed data
that can be used to change how IT is used, and how the business runs.
The value is in the combination. Not just what software is installed, but what
is used, by whom, on what hardware, and when it was last opened. That is what
lets you understand where your technology investment is actually going and
rationalise it: buying and running what you need, no more and no less.
The best tooling does not stop at software and licensing. It captures detailed
hardware inventory for the machines the software sits on, and organisations
increasingly use that data to make decisions about future technology
investment. Cloud migration, mobility, security and data management strategies
are all underpinned by accurate information about the deployment, nature and
utilisation of what already exists.
SAM data also feeds IT service management, so faults and issues can be pinpointed
against a real record of what is installed rather than a CMDB entry somebody
updated by hand two years ago.
That was the argument in 2016, framed around big data and a coming wave of
connected devices. The argument held. What changed is the shape of the asset
base it has to describe.
What the discipline now has to cover
The asset classes multiplied. Devices, on-premises software and data centre
licensing are still there. SaaS subscriptions, cloud resources and — most
recently — AI have been added to the same bill, usually bought by different
people, on different terms, with different renewal dates.
Being specific about what that requires today is more useful than another round
of predictions.
Devices, on every platform. CerteroX ITAM runs ten discovery methods — agent,
command line, agentless, standalone, Active Directory, network scan, third-party
import, cloud connectors, browser monitoring and file metering — into one schema.
Six operating system families get the same native agent: Windows, macOS, Linux,
AIX, HP-UX and Solaris. Network Discovery sweeps a class-C subnet in under five
seconds before anything is deployed.
Software recognition and entitlement. CerteroX SAM resolves installed titles
against the Software Recognition Database, over 3.5 million normalised publisher,
product and version entries, with release date, end-of-support and
extended-support dates alongside. Usage is metered at file level with first-used
and last-used tracking and a percentage-used figure over a rolling ninety-day
window. The effective licence position — purchased, used, available, required,
variance, exposure — is computed continuously rather than reconciled the week
the audit letter arrives.
SaaS, including what nobody told you about. CerteroX SaaS Management
converges three discovery signals: identity provider sync from Entra ID and Okta,
vendor API connectors across 47 shipping integrations, and a browser extension.
Behind them sits a catalogue of more than 35,000 applications. Unused licences
are flagged at thirty days of zero usage, and overlapping applications are ranked
by recoverable saving.
Cloud. CerteroX Cloud Management runs twenty-six named, individually tunable
recommendation checks across twelve cloud and data platforms, ingests the FinOps
Open Cost and Usage Specification natively, and enforces policy — resource TTL,
expense limits, tag compliance, anomaly detection — rather than only reporting on
it. Certero’s average cloud cost saving across environments under management is
38%.
AI. CerteroX AI Management treats models, experiments, GPU compute and AI
seats as one governed asset class. Shadow AI is detected from application feature
tags rather than a fixed list, so the detection set keeps up on its own, and the
same twenty-six cost checks apply to ML executors because they are cloud
instances like any other.
The point is not the feature list. It is that all five sit on one data model, so
a question that crosses them — what did this business unit spend on software last
quarter, across licences, subscriptions and compute — is a query rather than a
project.
If you have not started on SAM because you have not been audited and do not
particularly fear being audited, that is now the weaker reason to stay out. The
audit risk has not gone anywhere, but the data is the better argument. Nobody
rationalises what they cannot see.