Skip to content

The Evolution of SAM

Software asset management began as an audit response, became a compliance discipline, then a cost discipline. The data it produces is now the thing that matters most — and the asset classes it has to cover have grown to include SaaS, cloud and AI.

The reasons organisations implement software asset management have changed radically since adoption began. Internal and external pressures have both acted on the discipline, and enterprises have continually refined what they expect SAM to produce as a result.

The important consequence is this: you are never actually finished implementing SAM. It keeps evolving, and organisations have to recognise that and build for it if they want the full set of benefits rather than the first one they went looking for.

SAM and the development of software audits

It could be argued that SAM began with the PC and the arrival of mass-deployed software across large organisations, which takes us back to the 1980s. The circumstances and the technology of that period are a long way from where we are now.

It was not until the early part of this century that SAM became widely known, with ITIL v2 and its subsequent formalisation — the ISO/IEC 19770-1 process standard followed in 2006 and remains the benchmark organisations assess themselves against.

The real accelerator, though, was external: the financial crash of 2008. Software vendors looking to protect their margins latched onto the fact that it is easier to extract more revenue from existing customers than to innovate a product and find new ones.

The instrument they used was their legal right to audit for non-compliance with licence agreements. Given the complexity of the agreements they had written, and how easy they had made it for corporate customers to download and install their software, the results did not disappoint them.

Vendors then took to disguising audit activity by presenting it as a “SAM programme”. For the uninitiated this attached SAM to cost and pain, which is the opposite of what the discipline does. That misreading of the word is probably why many organisations were not early adopters, and why they missed the benefits for years longer than they needed to.

The growth of SAM and compliance

Eventually organisations stopped treating SAM purely as an audit response mechanism. It became a defensive discipline aimed at maintaining compliance, achieved through better control and management. At the same time, the ability to monitor actual usage improved utilisation, eliminated over-licensing and significantly reduced cost. That was the point at which organisations realised SAM delivered value in its own right, independently of anybody threatening them.

The initial focus was the desktop. Then came enterprise SAM, which brought the same compliance, cost and utilisation improvements to licensing in the data centre.

Then cloud arrived. And mobility.

Licence optimisation and the cloud

In its simplest form, the easiest way to stay compliant is to buy more licences than you need. This makes you popular with your software vendors. It is also an expensive way to run an organisation.

Subscription software makes the temptation sharper. All the major vendors have moved to subscription models, some more aggressively than others, and the model makes compliance easier for them to enforce: users cannot access the software without a valid licence. Few organisations want to stop employees doing their jobs for want of access to something critical, so the safe move is to over-provision — and the cost of that lands every month rather than once.

Meanwhile, despite what the vendors say, there will always be locally installed software that needs managing. Cloud did not make licence management and optimisation go away. It made both more varied and more complex. Licence optimisation will remain a primary driver for SAM for exactly that reason.

So the organisations with the highest SAM maturity are the ones running a recognised, fully used, tool-based capability that maintains compliance, eliminates risk, controls cost and optimises utilisation across everything they own — desktop, data centre and mobile, on-premises, cloud or hybrid.

SAM and the data it produces

When a SAM programme is done properly — and we do not mean using something like SCCM to produce the bare minimum — it produces a large volume of detailed data that can be used to change how IT is used, and how the business runs.

The value is in the combination. Not just what software is installed, but what is used, by whom, on what hardware, and when it was last opened. That is what lets you understand where your technology investment is actually going and rationalise it: buying and running what you need, no more and no less.

The best tooling does not stop at software and licensing. It captures detailed hardware inventory for the machines the software sits on, and organisations increasingly use that data to make decisions about future technology investment. Cloud migration, mobility, security and data management strategies are all underpinned by accurate information about the deployment, nature and utilisation of what already exists.

SAM data also feeds IT service management, so faults and issues can be pinpointed against a real record of what is installed rather than a CMDB entry somebody updated by hand two years ago.

That was the argument in 2016, framed around big data and a coming wave of connected devices. The argument held. What changed is the shape of the asset base it has to describe.

What the discipline now has to cover

The asset classes multiplied. Devices, on-premises software and data centre licensing are still there. SaaS subscriptions, cloud resources and — most recently — AI have been added to the same bill, usually bought by different people, on different terms, with different renewal dates.

Being specific about what that requires today is more useful than another round of predictions.

Devices, on every platform. CerteroX ITAM runs ten discovery methods — agent, command line, agentless, standalone, Active Directory, network scan, third-party import, cloud connectors, browser monitoring and file metering — into one schema. Six operating system families get the same native agent: Windows, macOS, Linux, AIX, HP-UX and Solaris. Network Discovery sweeps a class-C subnet in under five seconds before anything is deployed.

Software recognition and entitlement. CerteroX SAM resolves installed titles against the Software Recognition Database, over 3.5 million normalised publisher, product and version entries, with release date, end-of-support and extended-support dates alongside. Usage is metered at file level with first-used and last-used tracking and a percentage-used figure over a rolling ninety-day window. The effective licence position — purchased, used, available, required, variance, exposure — is computed continuously rather than reconciled the week the audit letter arrives.

SaaS, including what nobody told you about. CerteroX SaaS Management converges three discovery signals: identity provider sync from Entra ID and Okta, vendor API connectors across 47 shipping integrations, and a browser extension. Behind them sits a catalogue of more than 35,000 applications. Unused licences are flagged at thirty days of zero usage, and overlapping applications are ranked by recoverable saving.

Cloud. CerteroX Cloud Management runs twenty-six named, individually tunable recommendation checks across twelve cloud and data platforms, ingests the FinOps Open Cost and Usage Specification natively, and enforces policy — resource TTL, expense limits, tag compliance, anomaly detection — rather than only reporting on it. Certero’s average cloud cost saving across environments under management is 38%.

AI. CerteroX AI Management treats models, experiments, GPU compute and AI seats as one governed asset class. Shadow AI is detected from application feature tags rather than a fixed list, so the detection set keeps up on its own, and the same twenty-six cost checks apply to ML executors because they are cloud instances like any other.

The point is not the feature list. It is that all five sit on one data model, so a question that crosses them — what did this business unit spend on software last quarter, across licences, subscriptions and compute — is a query rather than a project.

If you have not started on SAM because you have not been audited and do not particularly fear being audited, that is now the weaker reason to stay out. The audit risk has not gone anywhere, but the data is the better argument. Nobody rationalises what they cannot see.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.