Skip to content

How ITAM, SAM, SaaS and Cloud Solutions Can Give You Visibility Over Remote Workforces

Remote and hybrid working scattered devices, licences and cloud instances well beyond the corporate network. A walk through the four problems that creates — visibility, security, licensing and cloud cost — and what it takes to close each one.

Remote working moved from an exception to a default faster than anyone planned for. Most organisations were nowhere near ready for the mass migration of staff from the office to their living rooms, and then did it anyway, in weeks.

What has proved harder to finish is the part underneath: keeping full visibility of the hardware and software those people are using, wherever it now sits.

This article looks at the challenges that come with a distributed workforce, and at what ITAM, SAM, SaaS and cloud management have to do to close them.

The challenges of remote working

Plenty of organisations made the transition to remote and hybrid models without much drama. The difficulty lands on those that had not prepared their technology assets for it — where the tooling assumed devices would be on the corporate network, in an office, most of the time.

Maintaining visibility

The immediate pressure is the volume of new software requests. Remote working creates real needs, and meeting them puts strain on IT: managing requests, approving software, installing it on machines nobody can walk over to. The harder part is understanding what each team actually requires, making sure each application is properly sanctioned, and keeping it visible and under control.

Put simply: you cannot manage what you own — track and approve licences, oversee cloud resources, identify and block security risks — if you do not know what you have or where it is.

During the first lockdowns, organisations bought IT assets quickly to keep people working. That was the right call. The consequence was that a large share of those new assets were not visible on the network at all, so nobody could see how they were being handled. That gap is a security problem before it is an administrative one: if you cannot tell whether a machine is patched or running anti-malware, you are missing a link in the chain, and the whole business is exposed through it.

Closing it is a discovery problem, and discovery is the thing most affected by people not being in the building. CerteroX ITAM uses ten methods that all land in one schema: a native inventory agent for Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris; agentless and command-line collection (csinvcli) for locked-down machines; standalone inventory for air-gapped and offline systems; Active Directory import; network scanning; third-party ITAM import; cloud and SaaS connectors; browser monitoring; and file metering. An agent-based record follows the device rather than the subnet, which is the difference between an inventory that survives a year of home working and one that quietly decays.

For the machines you do not know about yet, Network Discovery sweeps a class-C subnet in under five seconds across NetBIOS, SNMP and ICMP, then probes port 22 to establish where an agent can actually be deployed. You find the devices before you own the problem.

Because the data is collected and reconciled automatically into one record, IT teams do not fall back on spreadsheets and manual tracking — which is what happens, reliably, the moment the tool stops reaching half the fleet.

Dealing with security

Security risk is a function of visibility: if you cannot see it, you do not know what it is doing.

Remote working has only sharpened this. Every device that joins the network is a potential vulnerability, and this goes well beyond laptops. As remote setups become permanent, smartphones, tablets and a long list of internet-enabled devices attach themselves to corporate systems, and IT needs to see all of them to understand what has been introduced. Mobile is part of the same record here: CerteroX ITAM manages iOS and Android devices directly, including Apple DEP enrolment, rather than treating them as a separate inventory to reconcile later.

Large-scale incidents — the 2017 ransomware attack that took NHS systems offline across the UK is the obvious example — make the same point each time: partial visibility behaves like no visibility. If you cannot see every device on the network, an attacker only needs the ones you cannot.

The useful capability here is not a longer device list. It is a policy that fires when a device drifts. CerteroX ITAM’s Governance Policies express compliance as code, using a reusable filter builder, with examples that map directly to this problem: BitLocker enabled, Defender running, tag hygiene on cloud VMs. Policy definitions export and import as JSON, so the rules are reviewable and portable rather than locked in one administrator’s head. File metering and usage monitoring fill in the detail underneath — what is actually installed and actually being run on a machine, not what the build image said should be there.

Licensing and auditing

A fluctuating workforce makes over-licensing routine. Starter and leaver processes go lax under pressure, and organisations end up paying for licences nobody is using. The waste is easiest to size on the SaaS side: 46% of SaaS licences go unused, and the average organisation uses 54% of what it buys.

The subtler issue is entitlement during the move from office to home. Do all your licences carry the same user rights? Are entitlements transferable? In some cases, licences bought for use in an office cannot lawfully be used remotely, which leaves the organisation open to scrutiny and to cost. It is worth checking entitlements before making changes rather than after — and that is only possible if you can see what you have.

One scenario deserves particular attention: applications installed at server level, where access rather than use creates the liability. Everyone who can reach the server could theoretically reach the application. Under device-based licensing this produces a genuinely expensive trap. If one person needs Microsoft Project on a Citrix farm that a thousand users can reach, all thousand need licensing to stay compliant — whether they ever open it or not. Publishers find this pattern reliably at audit.

The control for it is access control, and it needs to produce evidence, not just intent. CerteroX SAM applies Access Control rules to RDS, Citrix and VDI streamed-application licensing, restricting usage per user and per device, with a Blocked Files log recording per-user and per-device block counts. That log is the point: it demonstrates the restriction was in force, which is what an auditor is actually asking for. Alongside it, the Exclude From Licensing workflow handles MSDN, development, training and second-use devices properly instead of leaving them in the count.

Audits did not stop. Whether or not their number rises, the letter still arrives, and the difference is whether you are computing your position continuously or reconstructing it under a deadline. CerteroX SAM maintains a continuous effective licence position — purchased, used, available, required, variance and exposure — with downgrade rights, second-use entitlement and per-core, per-processor and per-device assignment handled in the engine rather than in a spreadsheet appended to it.

Containing the cloud

Cloud IaaS, PaaS and SaaS made the shift to remote working possible: the applications stay put even when the people and the devices do not. But a cloud environment that cannot be non-compliant can still be badly wrong. One of the larger problems created by the rush to remote working was hasty cloud adoption, and the waste that came with it. Across the market, 29% of cloud spend is wasted, and that share rose for the first time in five years.

Four failure modes account for most of it.

Shadow IT. Cloud systems bought without the IT department’s approval, or deployed by other departments on their own initiative. The cost is unregulated because nobody is looking at it. CerteroX SaaS Management addresses this directly — identity provider sync, 47 vendor connectors and a browser extension converging on one list of what is genuinely in use, resolved against a catalogue of more than 35,000 applications.

Bill shock. Costs change unexpectedly, usually because people signed up for capacity without planning for it. The counter is not a monthly report but a policy that fires first: CerteroX Cloud Management runs expense anomaly detection against a rolling daily average, expiring and recurring budget policies, and total and daily expense limits per resource or pool.

Toxic consumption. Resources bought and then left unmanaged. Someone spins up a workload in AWS to test a database version and never powers it down. This is the largest single category of avoidable cloud cost, and it is why the optimisation engine names its checks instead of reporting a total: abandoned instances, images, load balancers, S3 buckets and Kinesis streams; obsolete images, IPs, snapshots and snapshot chains; instances stopped but not deallocated; volumes long unattached. Twenty-six named checks in all, each with its own thresholds, pool exclusions and account skips. Resource TTL then enforces a lifecycle automatically, so the same resource does not come back next month.

Cloud sprawl. The uncontrolled spread of instances, services and providers — a developer launching a workload in one account when the capacity already exists in another, or when an existing agreement would have priced it better. Cost pools typed as budget, business unit, team, project, CI/CD or asset, with assignment rules that allocate ownership automatically across nine condition types, are what stop the sprawl becoming anonymous. Virtual tagging computes allocation independently of cloud-native tags, so an untagged resource is not an unowned one.

CerteroX Cloud Management covers twelve cloud and data platforms and ingests the FinOps Open Cost and Usage Specification natively, so the cost model stays portable rather than locked in a vendor schema. Across cloud environments under management, the average saving is 38%.

What one platform changes

We have set out the core problems of remote working through an ITAM, SAM, SaaS and cloud lens. The resolution has less to do with any single feature than with where the data lives.

First, the tooling has to work when the people running it are not in the office either. Deploying, configuring and reporting all have to be possible remotely, and delegation has to be safe: CerteroX uses role-based access control with granular permissions, Reporting Levels that restrict visibility by organisational unit or location, and a read-only API with a documented Power BI data source, so routine reporting can continue without anyone logging in.

Second, and more consequentially, all five disciplines read from one asset model. Discovery, licence reconciliation, SaaS management, cloud cost and AI governance are not five products stitched together by integrations; they are one data source with five interfaces onto it. That is what makes a question like “which of the devices we shipped to home workers are unpatched, over-licensed and duplicated by a SaaS subscription somebody expensed” answerable at all.

The practical effect is that reporting stops being an assembly job. The data is already reconciled, so the report takes minutes rather than a fortnight of exports.

What does this mean for the future?

Remote and flexible working is now simply how a large share of the workforce operates. That makes ITAM, SAM, SaaS and cloud management more important, not less, as organisations try to hold service levels while operating more efficiently.

It also means complete visibility is the baseline rather than the goal. IT leaders need enough insight to be confident that staff have the tools to do their jobs, and that those tools are not creating unnecessary cost or unnecessary risk on the way.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.