Skip to content

Technology or Service: What's the fastest route to SAM success?

Four ways to structure a software asset management programme — buy and run it, buy and wrap a service around it, outsource onto someone else’s technology, or outsource onto the provider’s own. What each one actually costs you in time, skills and accountability.

There are many triggers that make stakeholders decide it is time to invest in software asset management. Perhaps you are being audited, or worried that you soon will be. Perhaps you need to support a digital transformation or an application migration. Perhaps you have simply concluded that technology spending needs to be optimised and better governed.

Whatever the driver, the fundamental choice is the same: do you go it alone and take on the staff and technology you need, do you outsource the problem to a services partner, or do you do some of both?

In reality the devil is in the detail, and setting yourself up for success is considerably harder than that framing suggests. SAM can be approached in many ways and there is no arrangement that suits everyone. But how you choose to tackle it determines your programme’s cost, its timeline and whether it succeeds at all, so the evaluation is worth doing properly.

Four basic options for your SAM programme

There are nuances and subtleties that create plenty of additional considerations, but the basic options distil down to four:

  1. Buy a SAM tool and run it yourself.
  2. Buy a SAM tool and have a third party provide a full or partial service around it.
  3. Contract SAM managed services from a supplier who uses third-party technology — that is, not their own.
  4. Contract a full or partial SAM managed service from a supplier using their own technology.

1. Buy a tool and run it yourself

This gives you the most control and keeps the knowledge in-house, which matters because SAM knowledge compounds. The person who understands why a particular Oracle host is licensed the way it is becomes more valuable every year they stay.

The cost is that you are hiring for a scarce skill set and then keeping those people current. Publisher licensing rules change, and a tool only produces a defensible position if someone knows what the output means. The common failure is not the technology — it is a well-implemented platform quietly producing reports that nobody has the standing to act on.

Choose this if SAM is a permanent function for you, you already have or can recruit licensing expertise, and you need the institutional knowledge to stay inside the organisation.

2. Buy a tool and wrap a service around it

A middle path. You own the platform and the data; a partner supplies the specialist effort, either continuously or for the difficult set pieces — an Oracle certification, an audit response, a migration.

The advantage is that you get expertise without a permanent headcount, and you keep the asset. The risk is the seam: two organisations, one dataset, and an unclear boundary about who is accountable for the licence position. Write that boundary down before you start, in the same document as the deliverables.

Choose this if you want to own the capability long term but need help reaching a credible position faster than hiring allows.

3. Outsource onto third-party technology

The supplier runs the programme, using a tool they did not build.

This can work well, and it widens the field of providers. But it introduces a three-party dependency: you, the service provider, and the vendor whose product they are operating. When something in the data is wrong — a publisher not recognised correctly, a virtualisation topology not modelled properly — the fix sits with a vendor you have no contract with, and your provider is in the same support queue as everyone else.

Ask two questions before committing. Where does the data live at the end of the term, and can you take it with you? And what is the escalation path when the limitation is in the product rather than the service?

4. Outsource onto the supplier’s own technology

The supplier runs the programme on a platform they build and control.

The structural advantage is that there is one accountable party. If the licence position is wrong, there is nobody to point at. It also removes the escalation seam: a gap in recognition or a publisher rule that needs modelling is a change to a product the same organisation owns, not a support ticket into a third party.

The trade to watch is exit. A managed service on the provider’s own platform is the arrangement most likely to leave you dependent, so the important commercial questions are about the end of the relationship rather than the start. Can the service convert to a tool you run yourself, without re-implementing? Does the data model survive the transition, or does the position have to be rebuilt?

Where Certero sits

Certero is in the fourth category, and can also operate in the first two, because the tools and the service are the same organisation.

CerteroX SAM is a platform you can buy and run yourself: publisher-grade licence engines for Microsoft, Oracle, IBM, SAP, Adobe and Salesforce; a continuously computed effective licence position covering purchased, used, available, required, variance and exposure rather than a point-in-time reconciliation; software usage metering over a rolling ninety-day window so harvesting decisions rest on evidence; and enforcement of the thirty-minute inventory cycle that IBM sub-capacity licensing actually requires. Certero is also a verified third-party tool vendor with Oracle License Management Services.

The same platform underpins Certero’s SAM managed service, which is the answer when the licensing expertise is the constraint rather than the technology. NHS South West London ICB’s ITAM Asset/PSL Manager, Reece Emson, describes the effect on timeline: “Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.”

Choosing

The fastest route is not the same for everyone, and the honest test is not which option is best in the abstract. It is which constraint is actually binding on you.

If the constraint is skills, a service gets you a defensible position sooner than recruitment will. If the constraint is control — regulatory, contractual, or simply that the data cannot leave — buy the tool and staff it. If the constraint is a single event with a date on it, such as an audit or a ULA certification, scope a partial service around that event rather than restructuring the whole function to survive it.

What does not work is choosing a shape before you have decided who owns the licence position. Everything else follows from that.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.