Skip to content

Has the industry created a SAM merry-go-round?

Software asset management needs both technology and skilled people, but the industry has polarised into tools that over-promise and services that bill by the day. A look at why customers keep going round in circles, and what actually breaks the cycle.

First published in April 2018. Revised on migration to reflect what CerteroX ships today.

It is generally agreed that effective software asset management requires a combination of technology — a tool, or several — and process, in the form of services delivered by skilled people, internal or external. The argument is almost never about whether you need both. It is about where the balancing point sits.

The generalised view produces complete polarisation. On one side are tools that over-promise or under-deliver. On the other are service providers who make their margin by creating mystery. It adds up to an odd situation, and it invites playground analogies about see-saws.

Surely the only thing any SAM provider — tool vendor or services outfit — should be focused on is delivering value for money and a customer who is entirely satisfied. The general view among industry commentators is that this is not what happens, and that it is the customer who keeps losing out. That is not acceptable. Rather than a see-saw, the SAM industry has built a merry-go-round, and it is time we all worked together to help customers get off it.

So let us get to the bottom of the problem. Services first.

The services problem

There are numerous examples of service providers delivering a SAM managed service underpinned by a particular tool that they do not come close to fully using. The service may include giving the customer access to the tool, but that access is often superficial. When it comes to the deliverables that matter — the effective licence position, the optimisation work — the provider’s preference is its own time-consuming, manually intensive process: analysing data offline in spreadsheets, producing cost-savings reports by hand.

The situation is more extreme for point-in-time projects, where specialist providers lean even harder on manual work and complex scripting.

Why does this happen? A cynical view is that service provider revenues depend largely on the amount of skilled resource — consultancy days — needed to deliver the engagement. More resource means a higher cost, and that cost is passed to the customer. Why would a provider invest time in understanding and using the automation available in an advanced SAM platform, or in properly teaching the customer to use it, when the reward is a reduced need for their services and lower revenue?

That is the incentive problem. It is not universal, and it is not malicious. But it is structural, and structural problems do not fix themselves.

The tools problem

The other generalised view is that the tools are simply not up to the job. There are plenty of instances where that view holds water, and particular vendors have to take responsibility for the dissonance they have created. Some claims by “leading” tool vendors are quite simply misleading.

It is also alarming that there are tools which profess to be highly automated but in fact depend on back-office teams manually crunching data to populate and hand-crank the system. Then there is implementation. Deploying SAM tools has traditionally been a frustratingly lengthy and complex process, which does not make them a good fit for delivering one-off projects.

So the service providers do have some valid points.

Not every platform is the same

Where the 2018 version of this article was deliberately coy, it is worth being specific instead, because a claim you cannot check is worth nothing.

The difference between platforms shows up in what they can name. Generic software recognition returns “you have 400 installs of Oracle Database”. Publisher-grade recognition returns which options and packs are enabled, with evidence and override, which processor types and core factors apply, and which hosts are covered down by an Enterprise Edition pool. CerteroX SAM resolves titles against the Software Recognition Database — 3.5 million or more normalised publisher, product and version records — and computes the effective licence position continuously: purchased, used, available, required, variance, exposure.

The same distinction applies to breadth. Where the original article treated rich SaaS capability as an emerging differentiator and did not mention cloud at all, CerteroX now covers five asset classes on one data model. CerteroX SaaS Management runs 47 shipping connectors alongside identity provider sync and a browser extension, and detects Shadow AI from application feature tags rather than a hardcoded list. CerteroX Cloud Management runs 26 individually named and individually tunable optimisation checks across twelve cloud and data platforms. CerteroX AI Management governs models, experiments, GPU fleets and AI seats as an asset class in their own right.

None of that removes the need for a skilled consultant or a licensing expert. It does remove a large block of the manual work those experts currently spend their days on, and it improves service levels, quality, value for money and satisfaction in the process.

Getting past the scepticism

The hardest part is not the technology. It is the fear, uncertainty and doubt overwhelming organisations who have had their fingers burnt by hollow vendor promises.

The way past that is insisting on specifics, and insisting on discovery first, because discovery is where the exaggeration usually begins. CerteroX network discovery sweeps a class-C subnet in under five seconds using NetBIOS, SNMP and ICMP, then probes port 22 to establish where an agent can actually be deployed. That is a claim you can time with a stopwatch — which is the point.

Does better technology threaten the service provider?

If the latest technology overcomes any provider reticence about tools that are not up to the job, does it not still present a threat by automating some of what they sell?

That view — if it is genuinely held — is short-sighted. Rather than worrying about lower revenues, or costly consultants sitting on the bench, providers should see the opportunity: better services with less resource, a more attractive proposition, a stronger competitive position, and the capacity to win and support more customers.

Certero’s own SAM managed service is delivered this way, with the full platform behind the consultants rather than a spreadsheet. NHS South West London ICB describes the effect:

Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.

— Reece Emson, ITAM Asset/PSL Manager, NHS South West London ICB

Three to four years of maturity, compressed. That is not consultancy days removed for their own sake. It is consultancy days spent on judgement instead of data entry.

What good looks like

Rather than channelling investment into sales and marketing hype, more vendors should genuinely develop and deliver modern, fit-for-purpose, non-legacy technology. And more service providers should fully adopt that technology, so that customers finally get what they deserve.

If you are on the merry-go-round, the way off is to stop accepting claims you cannot verify — from either side. Ask the tool vendor to walk the automation end to end, in the product rather than on a slide. Ask the service provider which parts of the platform they actually use, and which parts they replicate by hand.

Book a demo and bring the automation claim you least believe.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.