Skip to content

Understanding IT Asset Control – Tracking IT Assets

Discovery tells you what exists. Control is a process problem, and it breaks at the two ends of the lifecycle — how assets get authorised, and what happens when a person leaves. What to automate at each end.

An earlier article looked at the issues behind IT asset identification — the discovery and inventory problem. This one assumes you have addressed that, and moves on to the harder half: controlling, managing and tracking the assets once you can see them.

Control is a process problem

The difficulty here is not detection. It is process. You need to track an asset across its whole lifecycle, from acquisition to disposal, and the failures overwhelmingly cluster at the two ends — for the assets themselves, and for the people who use them.

The middle of an asset’s life is mostly fine. It is the beginning and the end that leak money.

Authorisation, and the shadow IT that follows

Start with the assets. The first question is how a new one gets authorised.

Hardware tends to be well controlled, mostly by accident: configuring and connecting a new machine to a corporate network is hard enough that it forces a conversation. Software is a different matter. Users are entirely comfortable with the App Store and Google Play, and that expectation has transferred to corporate devices. The ability to acquire and install software without asking anyone is now normal behaviour, not deviant behaviour.

That shadow IT opens the organisation to two costs at once. Unpatched third-party software is an obvious security exposure. Unlicensed software is an audit finding waiting to be written up. Both are expensive, and neither shows up in a request queue, because no request was ever made.

Fighting the app store model does not work. Adopting it does. A corporate app store lets people get software quickly, which is what they actually want, while routing every request through authorisation that IT controls.

What a corporate app store changes

The immediate benefit is installation. Rather than a queue of manual builds, software is delivered automatically, with no user or engineer involvement in the common case.

The larger benefit is the other end of the lifecycle. A great deal of software spend is wasted on licences nobody is using. Someone changes role. A project finishes. The software stays installed, and the licence stays consumed.

You need to identify that and act on it under published policy — software removed automatically after a defined period of non-use, or a removal request raised after a shorter one. Re-harvesting the licence and reassigning it where it is actually needed is what stops you buying capacity you already own.

In CerteroX ITAM this is the App-Centre self-service portal, with manager approval chains, sitting on top of software distribution for MSI, EXE and Click-to-Run packages. Requests are made where people expect to make them, the approval happens where governance expects it to happen, and delivery is automatic.

The measurement underneath it is the part that makes the policy defensible. CerteroX SAM meters file-based usage with first-used and last-used tracking, and reports a % Used figure over a rolling 90-day window. CerteroX SaaS Management flags unused licences at 30 or more days of zero usage. When you reclaim something, you are reclaiming it on evidence rather than on an assumption about who probably does not need it.

The people end of the lifecycle

Assets are only half of it. You also need to know exactly which users exist on your network.

Starters who never actually start, and leavers who go suddenly, both create the same residue: hardware and software sitting unused across the organisation, still costing money and, in the leaver’s case, still holding access.

This has become significantly harder than it was, because the applications a person accumulates are no longer all on a device you can collect. Their Microsoft 365 licence gets removed on day one. The seats they hold in a dozen SaaS applications, and the OAuth grants they consented to on behalf of the company, often do not.

CerteroX SaaS Management addresses this directly:

  • An offboarding checklist per user, showing every licence they hold, the connector status behind each one, and whether revocation is pending, in progress or complete. You can prove the offboarding finished rather than assume it did.
  • A wasted-spend metric for licences still held by departed users, with the estimated monthly cost of whatever remains open.
  • A bulk deprovision wizard for multi-select offboarding, which is what you need after a restructure rather than a leaver.
  • OAuth grant discovery and revocation. Consented third-party applications are found, scored from 0 to 100 on sensitivity, scope, consent and dormancy, and can be revoked in one click or as a workflow action.
  • A workflow engine with triggers, conditions and actions covering provisioning and deprovisioning across Entra ID, Okta, Google Workspace, Microsoft 365 and more — so the leaver process runs itself and logs that it did.
  • An audit log covering every provisioning and deprovisioning step, which is what turns “we offboard people properly” into something you can hand to an auditor.

Where this leaves you

Controlling your technology assets is fundamentally about having the right processes for both the assets and the people — and then backing those processes with tooling that executes them without anyone remembering to.

Get the authorisation route right at the front, get the reclamation and offboarding right at the back, and the tracking in between stops being a reconciliation exercise. It becomes a record that is already correct.

Book a demo, or read more about CerteroX ITAM and CerteroX SaaS Management.

Related reading

Other posts covering the same ground.

  • Certero Insider Newsletter – July 2025

    The licensing changes that mattered in June and July 2025 — Microsoft Product Terms, the return of the SAMOSA Act, the end of the Microsoft 365 nonprofit grant, Adobe's AI credit cuts, a Dutch ruling against Broadcom, and rising Oracle Java audit activity.

    • ITAM
    • SAM
    • SaaS
    • Governance
    10 min
  • Software Asset Management Plan

    A six-step plan for building a SAM programme that covers on-premises, SaaS and cloud as one problem rather than two — scope, maturity, people and technology, accountability, and what to do first.

    • ITAM
    • SAM
    • SaaS
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.