An earlier article looked at
the issues behind IT asset identification
— the discovery and inventory problem. This one assumes you have addressed that,
and moves on to the harder half: controlling, managing and tracking the assets
once you can see them.
Control is a process problem
The difficulty here is not detection. It is process. You need to track an asset
across its whole lifecycle, from acquisition to disposal, and the failures
overwhelmingly cluster at the two ends — for the assets themselves, and for the
people who use them.
The middle of an asset’s life is mostly fine. It is the beginning and the end
that leak money.
Authorisation, and the shadow IT that follows
Start with the assets. The first question is how a new one gets authorised.
Hardware tends to be well controlled, mostly by accident: configuring and
connecting a new machine to a corporate network is hard enough that it forces a
conversation. Software is a different matter. Users are entirely comfortable with
the App Store and Google Play, and that expectation has transferred to corporate
devices. The ability to acquire and install software without asking anyone is
now normal behaviour, not deviant behaviour.
That shadow IT opens the organisation to two costs at once. Unpatched
third-party software is an obvious security exposure. Unlicensed software is an
audit finding waiting to be written up. Both are expensive, and neither shows up
in a request queue, because no request was ever made.
Fighting the app store model does not work. Adopting it does. A corporate app
store lets people get software quickly, which is what they actually want, while
routing every request through authorisation that IT controls.
What a corporate app store changes
The immediate benefit is installation. Rather than a queue of manual builds,
software is delivered automatically, with no user or engineer involvement in the
common case.
The larger benefit is the other end of the lifecycle. A great deal of software
spend is wasted on licences nobody is using. Someone changes role. A project
finishes. The software stays installed, and the licence stays consumed.
You need to identify that and act on it under published policy — software removed
automatically after a defined period of non-use, or a removal request raised
after a shorter one. Re-harvesting the licence and reassigning it where it is
actually needed is what stops you buying capacity you already own.
In CerteroX ITAM this is the App-Centre self-service portal, with manager
approval chains, sitting on top of software distribution for MSI, EXE and
Click-to-Run packages. Requests are made where people expect to make them, the
approval happens where governance expects it to happen, and delivery is
automatic.
The measurement underneath it is the part that makes the policy defensible.
CerteroX SAM meters file-based usage with first-used and last-used tracking, and
reports a % Used figure over a rolling 90-day window. CerteroX SaaS Management
flags unused licences at 30 or more days of zero usage. When you reclaim
something, you are reclaiming it on evidence rather than on an assumption about
who probably does not need it.
The people end of the lifecycle
Assets are only half of it. You also need to know exactly which users exist on
your network.
Starters who never actually start, and leavers who go suddenly, both create the
same residue: hardware and software sitting unused across the organisation,
still costing money and, in the leaver’s case, still holding access.
This has become significantly harder than it was, because the applications a
person accumulates are no longer all on a device you can collect. Their Microsoft
365 licence gets removed on day one. The seats they hold in a dozen SaaS
applications, and the OAuth grants they consented to on behalf of the company,
often do not.
CerteroX SaaS Management addresses this directly:
- An offboarding checklist per user, showing every licence they hold, the
connector status behind each one, and whether revocation is pending, in
progress or complete. You can prove the offboarding finished rather than assume
it did.
- A wasted-spend metric for licences still held by departed users, with the
estimated monthly cost of whatever remains open.
- A bulk deprovision wizard for multi-select offboarding, which is what you
need after a restructure rather than a leaver.
- OAuth grant discovery and revocation. Consented third-party applications
are found, scored from 0 to 100 on sensitivity, scope, consent and dormancy,
and can be revoked in one click or as a workflow action.
- A workflow engine with triggers, conditions and actions covering
provisioning and deprovisioning across Entra ID, Okta, Google Workspace,
Microsoft 365 and more — so the leaver process runs itself and logs that it
did.
- An audit log covering every provisioning and deprovisioning step, which is
what turns “we offboard people properly” into something you can hand to an
auditor.
Where this leaves you
Controlling your technology assets is fundamentally about having the right
processes for both the assets and the people — and then backing those processes
with tooling that executes them without anyone remembering to.
Get the authorisation route right at the front, get the reclamation and
offboarding right at the back, and the tracking in between stops being a
reconciliation exercise. It becomes a record that is already correct.
Book a demo, or read more about CerteroX ITAM and
CerteroX SaaS Management.