Skip to content

Understanding software licensing terminology

A plain-English glossary of the terms you meet when you take on software licensing — the disciplines, the contract language, and the newer vocabulary that SaaS, cloud and AI have added to the list.

If you have been handed responsibility for software licensing, the first obstacle is not the licensing. It is the vocabulary. ITAM, SAM, SLO, SLOE, ELP, PVU, EULA, NFR — the acronyms arrive faster than the concepts, and looking them up often makes things worse, because the terms overlap, several were coined by analyst firms to describe adjacent things, and the definitions keep moving.

What follows is a working glossary: what each term means in practice, and why you would care. It is not a formal standard. It is the set of words you need to be able to hold a conversation with a publisher, a reseller or an auditor without losing ground.

The disciplines

ITAM — IT asset management. The management of technology assets across their whole life, from the decision to acquire through deployment, maintenance and disposal. ITAM is concerned with the asset itself: what you own, where it is, what it cost, who has it, what it is worth now, and when it goes. It covers hardware and software, and increasingly cloud resources and subscriptions too.

SAM — software asset management. The part of ITAM that deals with software specifically, and the part where the money and the risk concentrate. SAM covers the same lifecycle — planning, acquisition, deployment, maintenance, retirement — but adds the question hardware never asks: are you permitted to be running this, in this quantity, in this configuration? SAM is where compliance lives.

SLO — software licence optimisation. The practice of reducing what you spend on software without reducing what people can use. In practice it means two things: reclaiming licences from installs nobody uses so they can be reissued instead of repurchased, and stopping the purchase of licences that will not be fully consumed. Optimisation is the upside of SAM; compliance is the downside being managed.

SLOE — software licence optimisation and entitlement. An extension of SLO that includes the entitlement side of the calculation, rather than treating optimisation as a usage exercise alone. The distinction matters because optimisation without entitlement is guesswork: you cannot decide whether to buy, reclaim or leave alone until you know what your existing agreements already permit.

FinOps. The equivalent discipline for cloud spend — the practice of bringing engineering, finance and business teams together to manage variable cloud cost as an ongoing operational concern rather than a monthly surprise. It is not a licensing discipline as such, but it borrows the same instincts and it now sits next to SAM in most organisations that run both.

Entitlement and contract language

Entitlement. Your right of use. Entitlement is what the agreement permits you to do with software you have paid for, and it varies by organisation, by publisher and by contract. It is not the same as the quantity you bought — two organisations holding the same number of licences from the same publisher can have materially different rights depending on what they negotiated.

EULA — end user licence agreement. The document that sets out what you may and may not do with the software. Everyone clicks through it; almost nobody reads it; it is nevertheless the thing you will be held to.

Product use rights. The publisher’s supplementary terms describing how their licences behave in specific situations — virtualisation, clustering, disaster recovery, remote access, geography. These change between contract versions and are where most unexpected non-compliance originates.

SKU — stock keeping unit. A publisher’s product code for a specific orderable item. The same product frequently exists as many SKUs covering different editions, terms, quantities and programmes, which is why matching purchase records to deployment is rarely a straight lookup.

NFR — not for resale. Software supplied for a purpose that excludes production use or redistribution — evaluation, testing, demonstration or training copies. NFR licences are legitimate, but counting them as production entitlement is a common and expensive mistake.

Downgrade and down-edition rights. The right to run an older version, or a lower edition, of software you hold a newer or higher licence for. Applied properly this reduces what you owe; ignored, it inflates your apparent requirement.

Second use. The right for the same person to run the same software on a second device — typically a laptop alongside a desktop — without a second licence. Whether you have it depends on the agreement.

True-up. The reconciliation at the end of a contract period where you declare what you actually deployed and pay the difference. Enterprise agreements are built around it, and it is the moment when an inaccurate licence position becomes a cash outcome.

ELP — effective licence position. The output of the whole exercise: for each product, what you purchased, what is deployed, what is used, what is required after rights and exclusions are applied, and the variance between the two. A positive variance is money you have spent unnecessarily. A negative one is audit exposure. Both are worth knowing before somebody else tells you.

Metrics: what you are actually counting

The unit a licence is measured in decides the whole calculation, and the units are not consistent between publishers.

Per device. One licence per machine, regardless of how many people use it.

Per user, or per named user. One licence per person, regardless of how many machines they use it on.

CAL — client access licence. A licence permitting a device or a user to access a server, held in addition to the licence for the server itself. Microsoft server products are the common case, and CALs come in device and user flavours that you can mix.

Per processor and per core. Server licensing measured against the hardware rather than the people. The complication is that a core is not always a core: publishers apply factors, and the number you owe depends on the processor type as much as the count.

Core factor. A multiplier applied to a physical core count to reach a licensable quantity, which varies by processor family. Oracle’s core factor table is the best-known example, and getting it wrong changes the answer by a large multiple.

PVU and VPC — processor value unit, virtual processor core. IBM’s licensing metrics. PVU applies a per-core value based on the processor, and VPC counts virtual cores. Both are how IBM turns hardware into a number.

Sub-capacity licensing. Licensing a virtualised workload against the capacity it can actually use, rather than the full capacity of the physical host it runs on. It is almost always cheaper — and it is conditional. IBM, for example, requires inventory data collected at least every 30 minutes; without it you are licensed at full capacity whether you intended to be or not.

Cover-down. Where a higher-tier licence covers a lower-tier deployment, so a pool of Enterprise Edition entitlement can satisfy Standard Edition installs. Modelling this properly reduces what you owe.

The vocabulary that came later

The list above would have covered nearly everything in 2016. It does not now, because most new software arrives without being installed.

SaaS. Software delivered as a service and reached through a browser. There is no install to discover, so entitlement comes from the vendor’s own records and consumption is measured as seat activity rather than execution.

Subscription. A time-limited right of use rather than a perpetual one. The practical difference is that the risk inverts: with perpetual licences you worry about deploying more than you bought, and with subscriptions you worry about paying for seats nobody has opened.

Shadow IT. Applications in use across the organisation that IT did not procure and does not know about. It is not usually malice. It is a corporate card, a free tier and a team that needed something on Tuesday.

Shadow AI. The same pattern applied to AI tools, and the more urgent version of it, because the risk is not only spend — it is what is being typed into the tool. Detection is harder than for conventional SaaS, because the set of AI tools grows weekly.

BYOL — bring your own licence. Applying licences you already hold to cloud infrastructure rather than paying the provider’s licence-inclusive rate. Whether you may do this, and on which instance types, is governed by the publisher’s cloud terms and is a recurring source of disagreement.

Reserved instances and savings plans. Cloud commitments exchanged for a lower rate. Economically these behave much like a volume licence agreement: you commit ahead of consumption and you carry the risk of over-committing.

FOCUS. The FinOps Open Cost and Usage Specification — an open standard for cloud billing data, so cost from different providers can be compared in one schema instead of three proprietary ones.

Why the vocabulary matters

None of this is knowledge for its own sake. Every term above is a place where the number changes.

Whether a licence carries downgrade rights, whether a device qualifies for exclusion, whether sub-capacity applies, whether a core factor has been used, whether a SaaS seat has been touched in the last 90 days — each of these moves your position, sometimes by a large amount, and each is decided by a definition rather than an opinion. Knowing the words is what lets you check the arithmetic instead of accepting it.

To see the terms above turned into an actual position rather than a glossary, book a demo.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.