Build a group once. It spans everything.
Dynamic, static and custom groups run off the same query builder whether the members are AIX frames, Oracle cores, design seats, S3 buckets or GPU executors.
ITAM, SAM, SaaS, Cloud and AI are not five products bolted together after the fact. They are five views of one asset record — one schema, one owner, one cost, one compliance position.
Certero has built all five in-house since 2007, and they have shared a schema the whole time.
Five signals go in, and one record shape comes out: the same six fields, in the same schema, whatever the asset class. Choose a source and watch the values change while the record does not.
Asset record
AST·DEV·104882AST·LIC·220417AST·SAA·771903AST·CLD·903155AST·AI·556120
Windows 11 laptop, Field Sales, EMEA
Oracle Database Enterprise Edition, processor metric with core factor applied
Collaboration application, organisation seat on the editor tier
Compute instance, stopped but not deallocated
Training executor on a GPU instance, running a hyperparameter sweep
The same six fields on every asset class: Owner · Cost · Compliance · Lifecycle · Discovered by · Governed by. Example values; the schema is the point.
Dynamic, static and custom groups run off the same query builder whether the members are AIX frames, Oracle cores, design seats, S3 buckets or GPU executors.
There is no connector between our own products, because there is nothing to connect. Start with one discipline and grow into five; each one reads the records the last one already wrote.
Zones segment the data, Reporting Levels scope the view, RBAC decides the actions, and every discipline writes its evidence to the same place.
Most platforms have an agent and an apology. CerteroX has ten discovery methods, and every one of them lands in the same tables, so what discovery finds is already the record governance acts on.
Showing all ten discovery methods
A native agent for Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris. One agent and one schema, with non-persistent VDI support that holds a pooled desktop to a single record across sessions.
A single executable you can fire from a login script, an existing management tool or a change window. It runs once, writes its inventory and exits, leaving nothing installed and no listening port behind.
For environments where an agent will never be approved. The host is queried remotely and the result lands in exactly the same inventory tables as an agent scan.
Capture inventory on a machine with no route to the platform, carry the file out, import it. Air-gapped enclaves and isolated OT networks stop being permanent blind spots.
Sweeps a class-C subnet in under five seconds, then probes port 22 to establish where an agent could actually be deployed. You find the machines before you own them.
Users, groups, computers, sites and subnets imported and kept current, giving Reporting Levels, licence assignment and ownership the organisational structure they all run on.
SCCM, Intune, LANDesk and Altiris data imported and reconciled against everything else, with duplicate system detection and stale device archiving on top.
Hypervisor, cloud and SaaS vendor APIs pulling the authoritative resource, user and licence lists from AWS, Azure, Google Cloud, VMware, Entra ID, Okta and the rest.
A browser extension recording SaaS domains in use, time-on-app and per-user attribution. It is the one signal that reaches an application IT never provisioned and finance never coded.
First-used and last-used tracking on executables, a rolling 90-day % Used metric, Terminal Server and RDS remote usage per device, and a blocked-files log with counts.
Ten methods, one schema.
Every one of these lands in the same inventory tables, so a machine found by a network sweep and the same machine found by the agent resolve to one record.
305
SaaS applications in the average enterprise portfolio.
Identity tells you who could sign in. The vendor tells you what you bought. Only the browser tells you what is actually being used, including the things nobody ever bought.
Signal 01
Entra ID · Okta
Signal 02
47 connectors
Signal 03
Per-user attribution
One application record
Entitled, authenticated and actually used, reconciled to a single owner, a single cost and a single risk position.
Every discipline answers all four, so learning one of them teaches you the other four. Twenty cells below; open any one for the capabilities behind the number.
| Discipline | 01 Visibility | 02 Optimization | 03 Management | 04 Governance |
|---|---|---|---|---|
| ITAM Devices and hardware | ||||
| SAM Licences and entitlement | ||||
| SaaS Management Applications and seats | ||||
| Cloud Management Cloud cost and resources | ||||
| AI Management Models, GPUs and AI seats |
146 named capabilities · 20 cells · one grammar.
Visibility in CerteroX ITAM
8 named capabilities
Explore ITAMOptimization in CerteroX ITAM
6 named capabilities
Explore ITAMManagement in CerteroX ITAM
7 named capabilities
Explore ITAMGovernance in CerteroX ITAM
6 named capabilities
Explore ITAMVisibility in CerteroX SAM
7 named capabilities
Explore SAMOptimization in CerteroX SAM
6 named capabilities
Explore SAMManagement in CerteroX SAM
6 named capabilities
Explore SAMGovernance in CerteroX SAM
6 named capabilities
Explore SAMVisibility in CerteroX SaaS Management
8 named capabilities
Explore SaaS ManagementOptimization in CerteroX SaaS Management
8 named capabilities
Explore SaaS ManagementManagement in CerteroX SaaS Management
7 named capabilities
Explore SaaS ManagementGovernance in CerteroX SaaS Management
8 named capabilities
Explore SaaS ManagementVisibility in CerteroX Cloud Management
8 named capabilities
Explore Cloud ManagementOptimization in CerteroX Cloud Management
10 named capabilities
Explore Cloud ManagementManagement in CerteroX Cloud Management
7 named capabilities
Explore Cloud ManagementGovernance in CerteroX Cloud Management
9 named capabilities
Explore Cloud ManagementVisibility in CerteroX AI Management
8 named capabilities
Explore AI ManagementOptimization in CerteroX AI Management
7 named capabilities
Explore AI ManagementManagement in CerteroX AI Management
7 named capabilities
Explore AI ManagementGovernance in CerteroX AI Management
7 named capabilities
Explore AI ManagementA governance policy is a filter, a scope, an action and a cadence, stored as JSON. It is evaluated every time new data arrives, and it leaves evidence behind whether it fired or not.
Governance capabilities
Governance / Policies
Governance policies
| Policy | Scope | Cadence | State | Open |
|---|---|---|---|---|
| Encryption at rest — Windows endpoints Governance Policy · Zone: Group IT Enforcing 12 open | ||||
| Endpoint protection running Governance Policy · Zone: Group IT Enforcing 0 open | ||||
| Azure VM tag hygiene Tag compliance · Reporting Level: EMEA Enforcing 7 open | ||||
| Unauthorised software prevention Prohibition rule · All zones Enforcing 3 open | ||||
| Resource TTL — non-production Lifecycle constraint · Zone: Engineering Enforcing 1 open | ||||
| Unused licence reclamation, 30+ days Reclamation policy · Zone: Group IT Draft Not evaluated |
6 of 6 · evaluated on every inventory cycle
Illustrative rows. The modules, policy types, scopes and cadences are the real ones.
Policy definition
JSON in · JSON out
Policy definitions export and import as JSON. Review them in a pull request, promote them between environments, and diff what changed, exactly as you treat the rest of your infrastructure.
You build it in the reusable filter builder, the same one the groups run off. Six governance policy types on the cloud side, plus tag correlation rules with effective dates.
It re-evaluates on every inventory cycle, every connector sync and every billing import, so the compliance position is current at whatever moment you look at it.
Resource TTL expires the resource and expense limits stop the pool. Blacklisting blocks the install, reclamation takes the seat back, and revocation kills the OAuth grant.
Constraint violation history, an audit log across every provisioning and deprovisioning step, and a dedicated Auditor role that can read all of it and change none of it.
All 36, named in full
One evidence store
All of it writes to the same evidence store. Zones decide which entity's data you can reach, Reporting Levels decide how far down the organisation you can see, and the Auditor role holds read-only access across the whole of it.
This runs in two directions, both of them audited. Your agents can query the platform through a Model Context Protocol server, and the platform governs the AI your organisation is already using.
ITAM, SAM, SaaS, Cloud and AI Management each expose a Model Context Protocol server, so an agent can ask your technology assets, the licence position and the cloud bill the same question and get three answers that agree.
The in-product conversational assistant answers from your own cost and asset records, the same tables the reports and the policies run on.
Scoped, per-organisation tokens with full tool-call auditing and quota tracking. You can see exactly what your agents asked for, and stop them asking again.
Eight triggers, eleven conditions and thirteen actions on one canvas. Detection is only useful if something happens next.
Model Context Protocol
Every call audited · every call quota-tracked
Workflow canvas
8 triggers · 11 conditions · 13 actions
Trigger 8 available
Condition 11 available
Action 13 available
The highlighted path is one chain. The engine composes any trigger with any condition and any action, and writes every step it took to the audit log.
The awkward questions, answered in full.
Accreditations
Memberships
Technology partnerships
ISO 27001:2022 for information security management, Cyber Essentials Plus at the highest level of the UK NCSC scheme, and a SOC 2 Type 1 attestation. Both FinOps certifications come from the FinOps Foundation — one against CerteroX Cloud Management, one against the managed service — and Linux Foundation membership is at Silver. The Oracle partnership carries third-party tool verifications for Java, Database and Fusion Middleware.
Five products, one platform. Each runs standalone and each is bought separately, but they share one asset model, one access model and one audit trail, so adding the second one adds no integration work.
A device, a licence, a SaaS seat, a cloud resource and an ML executor are all asset records. They carry an owner, a cost, a lifecycle state and a compliance position in the same fields. That means a group, a policy, a permission or a report you build once applies to all of them.
No. Of the ten discovery methods, several need nothing installed on the target at all: agentless inventory, command-line inventory via csinvcli, Network Discovery over NetBIOS, SNMP and ICMP, Active Directory import, and the cloud and SaaS vendor connectors. Where the agent is allowed it goes deeper, but it is never the only way in.
Yes. Standalone inventory captures a system with no route to the platform and imports the file separately, and the whole platform can be deployed on-premises. Secure enclaves and isolated OT networks stop being permanent blind spots.
A read-only Certero API with a documented Power BI data source, raw billing export to external BI, scheduled email reporting, report delivery to Slack and Microsoft Teams, and a Model Context Protocol server for AI agents.
Yes. Every product exposes an MCP server with scoped per-organisation tokens. Every tool call is audited and quota-tracked, so agent access is governed the same way human access is.
Both. The same product, the same data model and the same policy engine, deployed either way.
In practice
What these mechanisms are worth is better told by the organisations running them.
Network Discovery sweeps a class-C subnet in under five seconds. See it run at full scale, then follow a single result all the way through, from the record it lands in to the policy that governs it and the action that closes it.
A fully populated environment and an honest answer, not a gated PDF.