Software asset management is the business practice of managing and optimising
the purchase, deployment, maintenance, utilisation and eventual disposal of
software. That sentence sounds administrative. It is not.
Every one of those stages runs into terms set by the software publisher, and
those terms are legally binding. They decide what you pay, what you are allowed
to do with what you bought, and whether the commercial benefits of a volume
agreement are available to you at all.
Get it wrong in the other direction and you are non-compliant: short of the
licences you need to cover the software you have deployed, regardless of whether
anyone is actually using it. That is the asymmetry at the heart of the
discipline. Deployment creates liability. Usage does not reduce it.
So software asset management is technically and commercially difficult, and it
carries real legal and financial risk, because if software is left unmanaged
there are very few hard barriers stopping costs from running away. Publishers
know this. It is why their End User Licence Agreements almost always reserve a
right to audit you periodically.
And if the financial governance case is not enough, consider the security one:
not knowing what software is deployed across your infrastructure is not only a
licensing problem.
Controlling all of that takes people, process and technology together. Here is
what the SAM manager does with each of them.
They run the SAM programme and hold the compliance position
The clue is in the title. The SAM manager is accountable for the software asset
management programme.
How that programme operates varies enormously with the size of the business and
the maturity of the function. Some run on in-house licensing subject matter
experts. Many bring in specialist skills from external consultants, either
temporarily to answer a specific question or on a long-term basis.
An effective licence position engagement, for example, establishes where you
stand with one publisher: your compliance position, your exposure and your
overspend, with guidance on what to do about both. A managed service does the
same thing continuously, so you can measure whether risk and cost are actually
falling rather than assuming they are.
Each major publisher demands its own expertise. Microsoft server licensing, the
Oracle options and packs question, IBM sub-capacity, SAP named-user
classification — these are not one skill set. The SAM manager is either the
subject matter expert or the person who knows when to bring one in.
Whichever route is taken, the primary objective is unchanged: the software
deployed across the organisation is adequately covered by the organisation’s
licence entitlement. Being compliant means you are not exposed if — realistically,
when — a publisher audits you, and it means you negotiate from a position of
knowledge rather than hope.
The same work prevents waste in the opposite direction. Organisations routinely
buy licences nobody uses. That waste is easiest to quantify in SaaS, where 46%
of licences go unused and the average organisation uses 54% of what it pays for.
Installed software has the same problem. It is simply harder to see without
usage metering.
A good SAM manager makes sure that when a renewal comes round, the business is
in the best possible shape to negotiate and to source only what it genuinely
needs — avoiding audit risk and unnecessary spend at the same time.
They prioritise risk
There is a great deal of software in any organisation. There are not many
publishers that matter commercially.
Most businesses have a handful of Tier 1 publishers — typically Microsoft,
Adobe, Oracle, IBM and SAP — where the majority of the cost and almost all of
the audit risk sits. The SAM manager knows which of those to work on, and in
what order, weighing potential expense against likelihood of scrutiny. The
sequence is often set for them by an audit request or a renewal cycle rather
than chosen freely.
They campaign for software as a business issue
Software asset management only works if the surrounding business processes hold.
That makes the SAM manager the standing voice of reason about what software the
business uses and how it is consumed.
Most organisations have learnt at least once that you cannot consume software
without understanding how it will be paid for. Publishers understand this
better than their customers do, which is why audits arrive at moments of
disruption — a merger, a divestment, a major migration — when control is
weakest.
The SAM manager’s job is to be ahead of that: talking to senior stakeholders,
making sure the commercial consequences of a technical decision are understood
before the decision is made rather than after the invoice.
That is also where SAM meets procurement. Knowing what the organisation needs to
buy in order to serve its strategy is the SAM manager’s contribution. Procurement
can then go to market knowing precisely what is required, instead of renewing
what was bought last time.
The oldest problem in software asset management is knowing what is out there,
who uses it and who does not. For years that problem was compounded by tooling:
either there was no discovery and inventory at all, or there were several
overlapping tools and no agreed view between them.
The historical consequence was that most of a SAM manager’s time went on
exporting data from one or more inventory tools, de-duplicating it, cleansing it
and formatting it into something that resembled reality. It is why manual SAM
services have traditionally produced only a handful of effective licence position
reports a year. The report was expensive to make, so it was made rarely, and it
was out of date the week it landed.
That is not the constraint any more, and the SAM manager’s relationship with
tooling has changed accordingly. What the role now expects from a platform:
One inventory, not several to reconcile. CerteroX ITAM lands ten discovery
methods — agent, command line, agentless, standalone, Active Directory, network
scan, third-party import, cloud connector, browser monitoring and file metering —
into a single schema, with native agents across Windows, macOS, Linux, AIX,
HP-UX and Solaris. There is no reconciliation project because there is nothing
to reconcile.
Recognition, not a list of file names. Discovery tells you a binary exists.
CerteroX SAM resolves it against the Software Recognition Database of more than
3.5 million titles, so what you get back is a named publisher, product, version
and edition. In an audit, that distinction is the difference between arguing
your position and conceding it.
Evidence of use, not just installation. File-based usage metering records
first-used and last-used dates and computes a percentage-used metric over a
rolling 90-day window, including Terminal Server and RDS remote usage per
device. That is what turns “we have 400 installs” into “we need 260 licences and
can harvest the rest”.
A licence position that is current. Purchased, used, available, required,
variance and exposure are computed continuously rather than assembled for a
quarterly report. Downgrade rights, second-use entitlement, and exclusions for
MSDN, development, training and second-use devices are handled inside the
calculation rather than in a spreadsheet beside it.
The practical effect is that far less of the role is data preparation. That is a
significant time saving, and it accelerates the point at which a SAM programme
starts returning value — which leads directly to the next part of the job.
They are the source of understanding for the organisation’s software
Not from anything mystical. From the people, processes and technology that make
the function work.
A SAM manager needs to be able to answer questions like: what software do we
need to buy? What are we not using? If we make this change, what happens to the
cost? Those are not licensing questions. They are business questions that happen
to require licensing knowledge to answer.
Done properly, software asset management means you can predict your software
costs rather than discover them. It means you can identify everything installed
and, by extension, where company data sits and where your known vulnerabilities
are.
It also means having a plan — that investments in software are deliberate and
return value, rather than accumulating by default.
The SAM manager holds that knowledge and, crucially, has to be able to
communicate it well enough to influence decisions. Above all, the role exists to
eliminate the expensive, disruptive surprises that arrive when software is left
unmanaged.
There is a wider benefit here that is easy to miss. The same understanding of
what software is deployed serves other teams. Security wants to know where the
vulnerabilities are across everything you own. Service management wants a single
reliable record of the infrastructure and an accurate answer to what a piece of
discovered software really is. The SAM function produces both as a by-product.
The remit has grown
This article was written when software asset management still largely meant
installed software. That is no longer the boundary of the role, and any
description of the job that stops at the network scan is out of date.
SaaS. Applications are now bought by departments, on cards, without asking.
CerteroX SaaS Management converges three independent discovery signals —
identity provider sync from Entra ID and Okta, authoritative user and licence
lists pulled through 47 vendor connectors, and a browser extension that detects
SaaS domains with per-user attribution — and resolves what it finds against a
catalogue of more than 35,000 applications. Unused licences are flagged at 30 or
more days of zero usage, and the actions to deal with them are built in.
Cloud. Consumption billing behaves nothing like a licence, but it lands on
the same person’s desk. CerteroX Cloud Management applies 26 named,
individually tunable optimisation checks across twelve cloud and data platforms,
with budget and policy controls that fire before the invoice does.
AI. The newest asset class, and the one arriving fastest with the least
procurement involvement. AI tools are classified from application feature tags
in the catalogue rather than a fixed list, so the detection set grows without
maintenance, and adoption risk is ranked by the share of the organisation using
each tool.
None of this replaces software asset management. The publisher audits have not
stopped and the entitlement mathematics on Oracle, IBM and SAP is unchanged.
What has changed is that the software asset manager is now accountable for
several categories of spend that no network scan will ever find.
How to become a SAM manager
Like any role built on skills and experience, it is hard to know where to start.
Learn the publishers. Microsoft, Oracle, SAP and IBM all publish licensing
training, and their own material is the right place to begin — it is the
authority on the terms you will be arguing about. Start with whichever publisher
represents the largest share of your organisation’s spend, because that is where
your first real problem will come from.
Learn the discipline, not just the vendors. The principles of software asset
management and of IT asset management more broadly; how mergers, acquisitions
and divestitures change a licence position; how virtualisation and cloud hosting
change what is licensable. Vendor knowledge without the surrounding discipline
produces someone who can read a EULA but cannot run a programme.
Get access to real data early. Licensing theory is unfalsifiable until you
apply it to your own environment. The fastest way to learn is to compute an
effective licence position for one publisher and defend every number in it.
Getting help
You no longer have to be the expert in everything yourself. An independent
managed service can supply the skilled people, the process and the technology as
a working extension of your team — and hand a mature programme back to you once
control is established.
If you would like help with hardware, software, SaaS, cloud or AI management,
get in touch.