Most organisations know roughly what they spend on software. Far fewer can say
what portion of it is doing nothing.
The evidence on that gap is not subtle. 46% of SaaS licences go unused — the
average organisation actually uses 54% of what it pays for. On the
infrastructure side, wasted cloud spend runs at 29%, up for the first time in
five years.
Neither of those is a compliance problem. Nobody is going to audit you for
paying for seats nobody opened. They are optimisation problems, and they are
where the recoverable money is.
What software licence optimisation actually is
Software licence optimisation goes beyond compliance. Compliance asks a defensive
question — are we entitled to what we are running? Optimisation asks a
commercial one — of everything we are entitled to and running, what do we
actually need?
It covers the whole life of a licence: what you buy, how it is allocated, how it
is used, what happens when someone leaves or a project ends, and what you renew.
It grew out of software asset management, and it uses the same underlying data,
but the objective is different. SAM protects you. Optimisation pays for itself.
The effective licence position is a milestone, not the destination
A common mistake is to treat reaching an effective licence position as the end of
the work. It is an important milestone — it proves compliance, and it is your
defence against audits that have not become less aggressive with time — but it is
a means to an end rather than the end itself.
An ELP tells you where you stand. On its own it does not tell you what to stop
buying, which seats to reclaim, which edition you are over-provisioned on, or
which agreement you should not renew in its current shape. Those decisions need
the same data, pointed at a different question.
The six steps
Broadly, optimisation breaks down like this.
1. Discover and inventory everything
The old adage applies: if you cannot measure it, you cannot manage it. This is
the step everything else rests on, and the one most often done badly, because
partial discovery produces a position that is confidently wrong.
In practice that means several collection methods feeding one schema — network
discovery, a native agent, agentless and command-line collection for locked-down
machines, standalone inventory for air-gapped systems, directory import, and
connectors into virtualisation and cloud platforms. CerteroX ITAM runs ten
discovery methods across six operating system families into a single data model,
which matters mainly because there is then nothing to reconcile between them.
2. Normalise the hardware and software
Raw inventory is unusable. The same product appears under a dozen publisher and
version strings, and half of what is installed is not licensable at all.
Normalisation reduces that to a standardised list of publishers, products and
versions, with licensable products separated out and install counts you can
stand behind.
This is the step you cannot sensibly do by hand. CerteroX resolves recognition
against the Software Recognition Database — over 3.5 million titles — with
centrally maintained categorisation, release dates, and end-of-support and
extended-support dates.
3. Understand your entitlement
What you own, under which agreements, and which versions and editions those
entitlements actually permit. This is the side of the equation that lives in
contracts, purchase orders and vendor portals rather than in the network, and it
is usually the messier half: agreements, transactions, maintenance, suppliers,
subscription flags and expiry dates all have to be captured and kept current.
4. Compare the two
Entitlement against normalised deployment gives you the effective licence
position. The useful version of that is not a single compliance verdict but a
breakdown — purchased, used, available, required, variance and exposure — because
those are different problems with different remedies. Being over-licensed and
being under-licensed both cost money; only one of them shows up in an audit.
And it should be continuous. A position computed once is a snapshot of a day.
5. Apply your product use rights
This is where a lot of the value sits, and where most organisations leave money
on the table. Upgrade and downgrade rights, second use, multiplexing rules,
virtualisation and cluster provisions, and the exclusions that mean a device
should never have been counted in the first place.
CerteroX SAM handles downgrade rights and second-use entitlement explicitly,
provides an Exclude From Licensing workflow for MSDN, development, training and
second-use devices, and applies Access Control rules for RDS, Citrix and VDI
streamed applications. For more on what these rights are and how they work, see
Understanding Your Software Use Rights.
6. Automate the controls
Optimisation that depends on someone running an exercise every year decays back
to where it started. The controls have to be standing ones: rules covering
software acquisition, permitted and prohibited applications, reclamation of
unused installs, and what happens when a device or a person leaves.
Governance Policies express these as compliance-as-code with a reusable filter
builder, so the rule persists and enforces rather than living in a runbook. And
usage metering — first used, last used, and a percentage-used metric over a
rolling ninety-day window — is what tells you which installations are candidates
for harvesting rather than which ones merely look quiet.
What has changed since this was written
The six steps above still hold, but in 2016 they described an on-premises
problem. They no longer do, and the difference matters.
A large and growing share of software spend never touches a device you own. It
is bought on a card by a department, provisioned through an identity provider,
and billed monthly. Traditional discovery cannot see it, because there is
nothing installed to discover. That is why the figure above is what it is: 46%
of SaaS licences unused is not a licensing failure, it is a visibility failure
that becomes a billing failure.
The equivalent of steps one and two for SaaS is three converging discovery
signals — identity provider sync from Entra ID and Okta, connectors pulling
authoritative user and licence lists directly from the vendor, and a browser
extension that catches applications nobody told anyone about. CerteroX SaaS
Management ships 47 connectors today, against a catalogue of over 35,000
applications.
The equivalent of steps five and six is different too. There are no downgrade
rights to apply; instead there is unused licence detection at thirty-plus days of
zero usage, application rationalisation ranked by recoverable saving, renewal
tracking with utilisation rates attached, and offboarding you can prove
completed — including the licences a departed employee still holds and the
monthly cost of leaving them open.
And AI has become its own line item, split across SaaS seats, cloud GPU spend and
tools nobody has declared. Shadow AI detection classifies AI tools from
application feature tags rather than a fixed list, so the detection set grows on
its own, and ranks adoption risk by the share of your organisation using each
tool.
Implementing it
The reason to do this work is not that audits are frightening. It is that a
meaningful percentage of what you are paying for is not being used, and the only
thing standing between you and that money is data you do not currently have.
Start with discovery, because everything else is unreliable without it. Get
normalisation right, because install counts you do not trust produce decisions
nobody will act on. Then make the controls standing rather than periodic, so the
savings do not quietly reverse over the following eighteen months.
If you want to talk through where the waste usually hides, and whether
that matches what you are seeing, get in touch.