Why SaaS is not the end of SAM
SaaS removes the under-licensing risk, not the discipline. The question stops being "am I compliant?" and becomes "am I using what I pay for, and does the leaver still have access?"
- SAM
- SaaS
- Governance
Software is an asset with unusual properties — it can be acquired by anyone in seconds, it leaves no physical trace, and the paperwork proving you are entitled to it is easy to lose. Each of those is a distinct commercial risk.
The title looks like a strange question. Software is not explosives. Nobody has ever been hurt by a licence agreement.
But software is an asset, and like any asset it carries obligations. Manage it badly and the consequences are unbudgeted costs, awkward conversations with finance, and in the worst cases penalties. What makes software distinctive is that it has properties no physical asset has, and it is exactly those properties that create the risk. Worth looking at them individually.
Software licensing terms are complex, inconsistent between publishers, and in places deliberately ambiguous. People who do this for a living still find them hard. The terms have not become simpler over time; if anything the arrival of subscription, hybrid and cloud entitlement models has added layers rather than removed them.
Organisations therefore breach agreements they had no intention of breaching, through misunderstanding rather than intent. Neither misunderstanding nor ignorance is a defence when the publisher’s auditors arrive. The uncomfortable truth is that “we did not realise” is the most common cause of an audit finding and the least useful thing to say once you have one.
The practical response is unglamorous. Read the terms that apply to the products where the money is concentrated. Get the entitlement rules encoded somewhere durable rather than held in one person’s head. And put the controls in place that stop accidental breach happening in the first place, which brings us to the next one.
If you hold a volume licensing agreement, the publisher has gone to some trouble to make installation frictionless for your people. That is not generosity. The easier the software is to obtain, the more of it ends up installed, and every installation is something you must be able to prove entitlement to.
The result is predictable. Software gets installed by people who genuinely needed it, by people who thought they might need it, and by people who were evaluating something and forgot about it. None of them thought they were creating a liability. All of them did.
The control is policy at the point of installation. In CerteroX SAM and CerteroX ITAM that is Governance Policies — compliance-as-code, built with a reusable filter builder, exported and imported as JSON so a policy set can be version-controlled and reviewed rather than reconstructed from memory. Alongside it sit application blacklisting and prohibition rules for software that should never be present, and a Blocked Files log recording exactly what was stopped, with per-user and per-device block counts.
That last part is the one organisations most often lack. Having a control is half of it. Being able to demonstrate the control was in force, on specific dates, against specific machines, is the half an auditor cares about.
Proof of entitlement is what stands between you and a finding. It is also, in most organisations, distributed across email archives, procurement systems, three shared drives and a filing cabinet nobody has opened since a previous reorganisation.
There is a second version of the same problem at the other end of the asset lifecycle. Hardware gets disposed of. The licence installed on it frequently goes with it, unrecovered and unreused, and you buy it again.
Both compound quietly. Neither shows up until you need the evidence.
The fix is a process point and a tooling point. Centralise entitlement — licences, transactions, agreements, maintenance, suppliers, publishers, purchase orders and invoices — in one place that produces the evidence on demand rather than after a three-week search. And make licence recovery part of the disposal process rather than an afterthought, so retired hardware releases its entitlement back into the pool.
This piece was written when unauthorised software meant an installer someone ran. That channel still exists and still matters. But it is no longer the main way software enters an organisation without anyone deciding it should.
Today it enters through a browser tab and a corporate card. There is nothing to install, nothing for a discovery agent to find on disk, and no procurement step to intercept. The average enterprise portfolio now runs to 305 SaaS applications — a number that no organisation reaches deliberately.
CerteroX SaaS Management addresses this with three converging discovery signals rather than one: a browser extension detecting SaaS domains with time-on-app and per-user attribution, identity provider sync from Entra ID and Okta, and connectors pulling authoritative user and licence lists from forty-seven vendors. What one signal misses, another catches.
Two related risks come with it. OAuth grants — the “sign in with” consent someone clicked two years ago — are discovered and scored from 0 to 100 on data sensitivity, scope breadth, consent age and dormancy, and can be revoked in one click or automatically by workflow. And AI tools are classified from application feature tags in the catalogue rather than a fixed list, so the Shadow AI board surfaces them ranked by the share of the organisation using each one, without waiting for someone to add the newest model to a blocklist.
Then there is the leaving process. Someone departs, their identity provider account is disabled on day one, and their seats on half a dozen applications carry on billing. CerteroX SaaS Management keeps a per-user offboarding checklist showing every licence held, the connector status behind it, whether revocation is pending, in progress or complete, and the estimated monthly cost of whatever is still open.
Software risk is not exotic. It comes from three ordinary properties: the terms are hard to read, the software is easy to acquire, and the proof is easy to lose. Each has a control, and none of the controls is difficult once you have decided to have them.
What has changed is where the software lives. The discipline is the same. It just has to reach further than it used to.
To see how Shadow AI and unapproved SaaS surface in one inventory, book a demo.
Other posts covering the same ground.
SaaS removes the under-licensing risk, not the discipline. The question stops being "am I compliant?" and becomes "am I using what I pay for, and does the leaver still have access?"
Audits rarely arrive at random. Ten patterns that reliably attract a vendor's attention — from a drop in support spend to a reseller who thinks there is a deal in it — and what to have in place before any of them apply to you.
Acquisition is the first step in software asset management, which makes it the one where mistakes compound. Buying outside the agreement, buying through the wrong reseller, and deploying the wrong version to the wrong device all start here.
Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.
No gated download at the end of it.