The right to use software does not come from having installed it. It comes from the agreement, and the agreement is where the detail lives: what you may install, where, how many times, and what counts as one use.
There are a great many possible arrangements, but a small number of scenarios recur across nearly every major publisher — Microsoft, Adobe, Oracle, IBM and the rest. Understanding these six covers most of what will ever be argued about in an audit.
Upgrade
The right to install the latest version of a product at no additional cost.
Straightforward in principle, awkward in practice, because it is rarely uniform. Some of your licences sit under active maintenance and carry the right; some do not. In a portfolio of any size those two populations are mixed together, bought at different times through different agreements, and nobody can tell them apart by looking at the installs.
That is a data problem rather than a licensing problem. CerteroX SAM holds licences, transactions, agreements, maintenance, suppliers and publishers in one place, with subscription flags and expiry tracking, so an upgrade right is a property of the entitlement record rather than something reconstructed from purchase orders. The Effective Licence Position — purchased, used, available, required, variance and exposure — is computed continuously against that record, so upgrading a population tells you immediately whether you have moved into exposure.
Downgrade
The right to buy a later version of a product, usually the current one, and deploy an earlier version instead.
You will use this more than you expect. The standard case is a desktop build that depends on a version you can no longer purchase: you buy current, you deploy the older release, and the two have to reconcile. The same applies on servers where an application is only certified against an earlier database or operating system release.
Downgrade rights are handled explicitly in the licence engine rather than being netted off in a spreadsheet, so an older install consuming a newer entitlement resolves correctly instead of appearing as both a shortfall on the old version and a surplus on the new one.
Virtualisation rights
Certain entitlements allow software to run on more than one virtual machine while consuming a single licence.
This is the one most often stated too broadly. Virtualisation does not, by itself, mean many guests count as one licence. The right comes from the specific entitlement you hold and usually depends on the edition, on how the host is licensed, and on whether the workload is constrained to hardware the publisher recognises as partitioned. Datacenter-style editions licensed across every physical core in the host are the clearest example of the right existing; standard editions with a fixed number of permitted instances are the clearest example of it being bounded.
Oracle adds its own dimension with hard and soft partitioning, which decides whether limiting a workload to a subset of a cluster limits your liability or does nothing at all.
This is why virtualisation rights cannot be assessed from an install list. They need the host, cluster and guest relationships. CerteroX connects to VMware, Hyper-V, Citrix XenServer, IBM HMC, Oracle VM, Red Hat oVirt and Nutanix, and the Oracle engine models processor types, core factors, licence pools with hosting rights and geographic rules, and cover-down logic for Enterprise Edition. IBM sub-capacity is covered with PVU and Virtual Processor Core metrics and an ILMT connector, including the 30-minute inventory cycle sub-capacity licensing actually requires.
Secondary use
The right to install an application on a primary machine and a second one — classically a desktop and a laptop — and count a single licence used.
Common, valuable, and a frequent source of overstated liability, because a tool that counts installs will count two. The Exclude From Licensing workflow covers second-use devices alongside MSDN, development and training machines, so those installs stay visible in the inventory without inflating the requirement, with the exclusion recorded in the audit trail rather than applied invisibly.
The same principle extends to streamed and published applications. Access Control rules handle RDS, Citrix and VDI so that access is licensed the way the publisher counts it, and non-persistent VDI is inventoried without generating a fresh device record every session.
Disaster recovery
The right to have software installed on a live server and a standby server at the same time, consuming the licence of the live one only.
The condition attached to this is the part people forget: the standby must genuinely be standby. Once it is doing work — serving reads, being tested beyond permitted periods, running in an active-active pair — the right usually lapses and the second instance becomes licensable. Several publishers also make fail-over rights conditional on active maintenance or Software Assurance. Check yours; the wording varies, and it has tightened over time.
Because both halves of a DR pair look identical to discovery, the distinction has to be recorded deliberately. It is a governance decision, not something an agent can infer.
Multiple installations
The right to install the same application on one device several times — commonly different versions — and count one licence.
This is the scenario where measurement quality decides the answer. Tools that recognise software by scanning for files have a well-known habit of reading an unclean uninstall, where fragments were left behind, as another live installation. The licence position then shows a shortfall that does not exist, and somebody spends a fortnight proving a negative.
Recognition is the fix, and it is a data asset rather than a feature. The Software Recognition Database holds 3.5 million+ titles with centrally maintained categorisation, publisher normalisation and version recognition, so an install resolves to a known product and version rather than to a filename. Alongside it, Software Identification (SWID) tags with UNSPSC classification, duplicate system detection and stale device archiving keep the device population clean, and AppsMonitor meters actual usage with first-used and last-used tracking and a % Used figure over a rolling 90-day window — so a remnant that has never been run is visible as exactly that.
The common thread
Every one of these six scenarios has the same shape. The install is not the licence event. Something else is — an entitlement you hold, a condition you meet, a relationship between machines, or a fact about how the software is actually used.
That is why a licence position built from an install count is wrong in both directions at once: overstated where use rights would have covered you, understated where a configuration change quietly made more hardware licensable. You need the entitlement, the topology and the usage in the same model.
If you have a question about a specific agreement or a use right you are not sure applies, book a demo and put it to a technical person with the product open.