Skip to content

The CerteroX platform

One data model.
Five disciplines.

ITAM, SAM, SaaS, Cloud and AI are not five products bolted together after the fact. They are five views of one asset record — one schema, one owner, one cost, one compliance position.

Certero has built all five in-house since 2007, and they have shared a schema the whole time.

data model
1 data model
disciplines
5 disciplines
discovery methods
10 discovery methods
named capabilities
146 named capabilities
The unified asset model

A device, a licence, a seat, a resource and a modelall resolve to one record.

Five signals go in, and one record shape comes out: the same six fields, in the same schema, whatever the asset class. Choose a source and watch the values change while the record does not.

Asset record

AST·DEV·104882AST·LIC·220417AST·SAA·771903AST·CLD·903155AST·AI·556120

Device Compliant

Windows 11 laptop, Field Sales, EMEA

Owner
Sales Operations, resolved from Active Directory and scoped by Reporting Level
Cost
Cost tab: manual and automatic costing rules, warranty expiry tracked
Compliance
Governance Policy “BitLocker enabled”, re-evaluated every inventory cycle
Lifecycle
In service, with duplicate detection and stale-device archiving applied
Discovered by
Inventory agent · Active Directory import · Network Discovery
Governed by
Zone: Group IT · role-based access control on every device action
Licence Variance

Oracle Database Enterprise Edition, processor metric with core factor applied

Owner
Database Engineering — assignment per device, per processor or per core
Cost
Purchase order, invoice and maintenance held against the agreement
Compliance
Effective Licence Position: purchased, used, available, required, variance, exposure
Lifecycle
Maintenance renewal, end-of-life and end-of-support dates tracked
Discovered by
Inventory agent · file execution metering · options and packs evidence
Governed by
Audit trail across agreements, transactions and exclusions
SaaS seat Reclaim

Collaboration application, organisation seat on the editor tier

Owner
Four owner types: application, business, technical and data owner
Cost
Cost per licensed user versus cost per active user, against an app budget
Compliance
Unused licence, 30+ days of zero usage, queued for reclamation
Lifecycle
Subscription state: purchased, assigned, available, oversubscribed
Discovered by
Identity provider sync · vendor API connector · browser extension
Governed by
Offboarding checklist · OAuth grant risk score, 0 to 100
Cloud resource Violation

Compute instance, stopped but not deallocated

Owner
Assignment rules with nine condition types, resolved to a cost pool
Cost
Daily expense against the pool budget, normalised to the FOCUS spec
Compliance
Tag compliance policy: a required tag is missing, violation recorded
Lifecycle
Resource TTL with automatic lifecycle enforcement
Discovered by
Cloud connector · billing import · FOCUS collector
Governed by
Daily and total expense limits · expense anomaly detection
AI workload Approved

Training executor on a GPU instance, running a hyperparameter sweep

Owner
Dedicated ML/AI cost pool with its own budget and thresholds
Cost
The same 26 optimisation checks that run on any other instance
Compliance
Risk assessment on data sensitivity, GDPR, HIPAA and SOC 2 exposure
Lifecycle
Task, run and runset tracking with model and dataset lineage
Discovered by
Cloud connector · executor telemetry · Shadow AI detection
Governed by
Every agent tool call audited and quota-tracked

The same six fields on every asset class: Owner · Cost · Compliance · Lifecycle · Discovered by · Governed by. Example values; the schema is the point.

Build a group once. It spans everything.

Dynamic, static and custom groups run off the same query builder whether the members are AIX frames, Oracle cores, design seats, S3 buckets or GPU executors.

Adding the next discipline adds no integration work.

There is no connector between our own products, because there is nothing to connect. Start with one discipline and grow into five; each one reads the records the last one already wrote.

One access model, one audit trail.

Zones segment the data, Reporting Levels scope the view, RBAC decides the actions, and every discipline writes its evidence to the same place.

The discovery engine

Ten ways in.One inventory out.

Most platforms have an agent and an apology. CerteroX has ten discovery methods, and every one of them lands in the same tables, so what discovery finds is already the record governance acts on.

Reaches

Showing all ten discovery methods

  • 01 agent · scheduled cycle

    Inventory agent

    A native agent for Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris. One agent and one schema, with non-persistent VDI support that holds a pooled desktop to a single record across sessions.

    6 OS families VDI-aware
  • 02 csinvcli · scripted run

    Command-line inventory

    A single executable you can fire from a login script, an existing management tool or a change window. It runs once, writes its inventory and exits, leaving nothing installed and no listening port behind.

    csinvcli No install
  • 03 remote credentialed query

    Agentless inventory

    For environments where an agent will never be approved. The host is queried remotely and the result lands in exactly the same inventory tables as an agent scan.

    No agent
  • 04 offline capture · manual import

    Standalone inventory

    Capture inventory on a machine with no route to the platform, carry the file out, import it. Air-gapped enclaves and isolated OT networks stop being permanent blind spots.

    Air-gapped Offline
  • 05 NetBIOS · SNMP · ICMP

    Network Discovery

    Sweeps a class-C subnet in under five seconds, then probes port 22 to establish where an agent could actually be deployed. You find the machines before you own them.

    <5s per class-C Port 22 probe
  • 06 directory sync

    Active Directory import

    Users, groups, computers, sites and subnets imported and kept current, giving Reporting Levels, licence assignment and ownership the organisational structure they all run on.

    Users · groups · sites
  • 07 connector · scheduled

    Third-party ITAM import

    SCCM, Intune, LANDesk and Altiris data imported and reconciled against everything else, with duplicate system detection and stale device archiving on top.

    28 system connectors
  • 08 vendor API · authoritative

    Cloud and SaaS connectors

    Hypervisor, cloud and SaaS vendor APIs pulling the authoritative resource, user and licence lists from AWS, Azure, Google Cloud, VMware, Entra ID, Okta and the rest.

    47 SaaS connectors 12 cloud platforms
  • 09 extension · per-user

    Browser monitoring

    A browser extension recording SaaS domains in use, time-on-app and per-user attribution. It is the one signal that reaches an application IT never provisioned and finance never coded.

    Shadow IT Shadow AI
  • 10 AppsMonitor · continuous

    File execution metering

    First-used and last-used tracking on executables, a rolling 90-day % Used metric, Terminal Server and RDS remote usage per device, and a blocked-files log with counts.

    90-day window RDS-aware
  • Ten methods, one schema.

    Every one of these lands in the same inventory tables, so a machine found by a network sweep and the same machine found by the agent resolve to one record.

  • 305

    SaaS applications in the average enterprise portfolio.

SaaS discovery

Three signals, and none of them is enough on its own.

Identity tells you who could sign in. The vendor tells you what you bought. Only the browser tells you what is actually being used, including the things nobody ever bought.

Signal 01

Identity provider

Entra ID · Okta

Proves
Who exists, who can sign in, who has MFA enrolled, and which high-value applications sit outside SSO entirely.
Blind to
Anything bought on a corporate card, and how much of a seat is really used.

Signal 02

Vendor API connector

47 connectors

Proves
The authoritative user and licence list, straight from the vendor: seat tier, assigned, available, oversubscribed, spend.
Blind to
Any application you have no contract with, which is most of the shadow IT problem.

Signal 03

Browser extension

Per-user attribution

Proves
Actual use: SaaS domains, time-on-app and who opened what, across every application the browser touches, the AI ones included.
Blind to
Server-to-server integrations and desktop-only applications.

One application record

Entitled, authenticated and actually used, reconciled to a single owner, a single cost and a single risk position.

VMOG applied

The same four pillars.
Five times over.

Every discipline answers all four, so learning one of them teaches you the other four. Twenty cells below; open any one for the capabilities behind the number.

Visibility
Find it, and know exactly what it is.
Optimization
Decide what to keep, cut, resize or move.
Management
Act on it from the console that sees it.
Governance
Prove it is under control, continuously.
Named capabilities by discipline and VMOG pillar. Select a cell to read the capabilities it contains.
Discipline 01 Visibility 02 Optimization 03 Management 04 Governance
ITAM Devices and hardware
SAM Licences and entitlement
SaaS Management Applications and seats
Cloud Management Cloud cost and resources
AI Management Models, GPUs and AI seats

146 named capabilities · 20 cells · one grammar.

Visibility in CerteroX ITAM

Find everything, including the things nothing else finds.

8 named capabilities

Explore ITAM
  • Network Discovery across NetBIOS, SNMP and ICMP
  • Native inventory agent for Windows, macOS, Linux, AIX, HP-UX and Solaris
  • Agentless and command-line inventory (csinvcli) for locked-down environments
  • Standalone inventory for air-gapped and offline systems
  • Active Directory import of users, groups, computers, sites and subnets
  • Non-persistent VDI inventory support
  • Duplicate system detection and stale device archiving
  • SNMP printer consumables, page counts, switch port and routing tables

Optimization in CerteroX ITAM

Turn the inventory into decisions, not just a list.

6 named capabilities

Explore ITAM
  • Hardware warranty retrieval and expiry tracking
  • Cost tabs with manual and automatic costing rules
  • Dynamic, static and custom groups via query builder or SQL
  • Trend charts, KPIs and threshold alerts
  • Personal and role-shared dashboards
  • Read-only Certero API with a documented Power BI data source

Management in CerteroX ITAM

Act on your assets from the same console that sees them.

7 named capabilities

Explore ITAM
  • Software distribution for MSI, EXE and Click-to-Run packages
  • Windows 11 upgrade orchestration
  • SCCM interface — import and drive SCCM applications, packages and jobs
  • WSUS-integrated patch management with downstream server support
  • Mobile device management for iOS and Android, including Apple DEP
  • App-Centre self-service portal with manager approval chains
  • Passworks self-service password reset for Windows and macOS

Governance in CerteroX ITAM

Prove everything is under control, continuously.

6 named capabilities

Explore ITAM
  • Governance Policies — compliance-as-code with a reusable filter builder
  • Policy examples: BitLocker enabled, Defender running, Azure VM tag hygiene
  • Zones for multi-entity data segmentation
  • Reporting Levels enforcing organisational unit or location visibility
  • Role-based access control with granular permissions
  • JSON export and import of policy definitions

Visibility in CerteroX SAM

Know what is installed, what is running, and what is merely sitting there.

7 named capabilities

Explore SAM
  • Software Recognition Database with centrally maintained title categorisation
  • Software Recognition Service — release date, end of support and extended support dates
  • Software Identification (SWID) tags with UNSPSC classification
  • AppsMonitor file-based usage metering with first-used and last-used tracking
  • % Used utilisation metric over a rolling 90-day window
  • Terminal Server and RDS remote-usage tracking per device
  • Publisher normalisation and version recognition

Optimization in CerteroX SAM

Harvest what nobody uses before you buy what nobody needs.

6 named capabilities

Explore SAM
  • Effective Licence Position: purchased, used, available, required, variance, exposure
  • Overspend and additional-licence-required calculation
  • Downgrade rights and second-use entitlement handling
  • Exclude From Licensing workflow for MSDN, dev, training and second-use devices
  • Access Control rules for RDS, Citrix and VDI streamed-application licensing
  • Blocked Files log with per-user and per-device block counts

Management in CerteroX SAM

Hold entitlement, contract and evidence in one place.

6 named capabilities

Explore SAM
  • Licences, transactions, agreements, maintenance, suppliers and publishers
  • Assignment types: per device, per processor, per core
  • Microsoft Licence Statement (MLS) import
  • Volume licence, retail, OEM and FPP transaction capture
  • Subscription flags with expiry tracking
  • Purchase order and invoice financial capture

Governance in CerteroX SAM

Defensible, evidenced, and ready before you are asked.

6 named capabilities

Explore SAM
  • Continuous compliance position rather than point-in-time reconciliation
  • End-of-life and end-of-support lifecycle tracking
  • Application blacklisting and prohibition rules
  • Audit trail across agreements, transactions and exclusions
  • Governance Policies for unauthorised software prevention
  • Reporting Levels restricting visibility by organisational unit or location

Visibility in CerteroX SaaS Management

Every application, sanctioned or not, with the evidence of who uses it.

8 named capabilities

Explore SaaS Management
  • Browser extension detecting SaaS domains, time-on-app and per-user attribution
  • Identity provider sync from Entra ID and Okta including MFA enrolment
  • Connector sync pulling authoritative user and licence lists from the vendor
  • OAuth grant discovery for consented third-party applications
  • Shadow AI Dashboard with three-tier adoption risk model
  • Executive Dashboard rolling up apps, users, spend and trend
  • Usage Summary with Active Usage Rate and power-user identification
  • SSO Coverage widget with a ranked list of high-value gap applications

Optimization in CerteroX SaaS Management

Stop paying for seats nobody has opened since March.

8 named capabilities

Explore SaaS Management
  • Unused licence detection at 30+ days of zero usage
  • App Rationalization — overlap detection ranked by recoverable saving
  • Upcoming renewals with days-to-renewal and utilisation rate
  • Actions: reclaim, reassign, downgrade tier, archive, remind, dismiss
  • Optimization Score from 0 to 100 across utilisation, response and adherence
  • Cost per licensed user versus cost per active user
  • Realized savings, realized avoidance and ROI by fiscal quarter
  • Bulk deprovision wizard for multi-select offboarding

Management in CerteroX SaaS Management

Automate the busywork between discovery and resolution.

7 named capabilities

Explore SaaS Management
  • Workflow engine: 8 triggers, 11 conditions, 13 actions on one canvas
  • Provisioning and deprovisioning across Entra, Okta, Google, M365 and more
  • Four owner types: application, business, technical and data owner
  • Subscription lifecycle with purchased, assigned, available and oversubscribed
  • Custom fields on applications, subscriptions and users
  • Data Agents and Reporting Agents on schedules
  • Report delivery to Slack and Microsoft Teams

Governance in CerteroX SaaS Management

Close the loop and keep the receipt.

8 named capabilities

Explore SaaS Management
  • Offboarding checklist per user with per-licence revocation status
  • Wasted spend metric for licences still held by departed users
  • OAuth grant risk scoring on sensitivity, scope, consent and dormancy
  • One-click grant revocation, also available as a workflow action
  • Risk assessment on data sensitivity, compliance and business criticality
  • Audit log covering every provisioning and deprovisioning step
  • Six-tier role model including a dedicated Auditor role
  • Per-application budgets with warning and critical thresholds

Visibility in CerteroX Cloud Management

One cost model across every provider, in an open standard.

8 named capabilities

Explore Cloud Management
  • Cost Explorer by owner, pool, service, region, account and day
  • Interactive geographic Cost Map
  • Resource inventory across 12 first-class resource types
  • Kubernetes cost and utilisation by namespace, node and service
  • Reserved Instance and Savings Plan coverage analysis
  • Inter-region data transfer and traffic expense breakdown
  • Native FOCUS support — the FinOps open cost and usage specification
  • Raw billing export to external BI, plus scheduled email reporting

Optimization in CerteroX Cloud Management

Twenty-six named checks, every one of them tunable.

10 named capabilities

Explore Cloud Management
  • Abandoned instances, images, load balancers, S3 buckets and Kinesis streams
  • Obsolete images, IPs, snapshots and snapshot chains
  • Instance rightsizing and underutilised RDS detection
  • Instances stopped but not deallocated, and volumes long unattached
  • Instance generation upgrade and cross-region migration opportunities
  • Reserved Instance and Savings Plan purchase opportunities
  • Short-living instances flagged as spot and preemptible candidates
  • Kubernetes rightsizing and object-storage duplicate finder
  • VM power schedules for automated start and stop
  • Per-check thresholds, pool exclusions and account skips

Management in CerteroX Cloud Management

Allocation and ownership that keep themselves current.

7 named capabilities

Explore Cloud Management
  • Cost pools typed as budget, business unit, team, project, CI/CD or asset
  • Assignment rules with nine condition types for automatic ownership
  • Virtual tagging computed independently of cloud-native tags
  • Shareable environments with booking, SSH keys and CI/CD webhooks
  • Slack bot for pool alerts, TTL management and expense tracking
  • Three built-in roles across five permission groups
  • Thirty-plus notification templates with custom SMTP and branding

Governance in CerteroX Cloud Management

Policy that fires before the invoice does.

9 named capabilities

Explore Cloud Management
  • Expense anomaly detection against a rolling daily average
  • Expiring and recurring budget policies
  • Resource count anomaly detection and resource quota policies
  • Tag compliance: required tags, prohibited tags and correlation rules
  • Resource TTL with automatic lifecycle enforcement
  • Total and daily expense limits per resource or pool
  • Constraint violation history and detected-constraints tracking
  • Security signals: inactive IAM users, unused console access, open security groups
  • Pool-based showback and chargeback with forecast-aware overspend states

Visibility in CerteroX AI Management

Every AI tool in use is found and put on a record.

8 named capabilities

Explore AI Management
  • Shadow AI detection from application feature tags, not a static list
  • AI tool adoption ranked by share of organisation using it
  • ML task, run and runset tracking with console logs and milestones
  • Model registry with versioning, and dataset versioning with lineage
  • Executor visibility — the compute actually running each workload
  • Custom metrics with target values and goal tendency
  • Leaderboards ranking runs and models by metric
  • Spark instrumentation via the Delight agent collector

Optimization in CerteroX AI Management

ML executors land in cost pools with budgets on them.

7 named capabilities

Explore AI Management
  • The full 26-check recommendation engine applied to ML executors
  • GPU and training-instance rightsizing and generation upgrade
  • Short-living executor detection for spot and preemptible migration
  • Dedicated ML/AI cost pools with their own budgets
  • Hyperparameter tuning via reusable runset templates
  • Cross-region and cross-cloud migration opportunities for training workloads
  • AI seat reclamation through the SaaS licence engine

Management in CerteroX AI Management

Runsets provision their own cloud runners and track every run on them.

7 named capabilities

Explore AI Management
  • Runset orchestration that provisions cloud runners on demand
  • Experiment tracking with artifacts, tags, stages and milestones
  • Leaderboard templates for repeatable model comparison
  • Model Context Protocol server exposing the platform to AI agents
  • Scoped, per-organisation MCP tokens with full tool-call auditing
  • In-product conversational assistant over your own cost and asset data
  • External MCP plugin support for calling out to other servers

Governance in CerteroX AI Management

Approve, restrict and evidence AI use before it becomes an incident.

7 named capabilities

Explore AI Management
  • Shadow AI status workflow: managed, blocked or ignored
  • OAuth grant risk scoring for AI tools with data access
  • Risk assessment on data sensitivity, GDPR, HIPAA and SOC 2 exposure
  • Per-application AI budgets with warning and critical thresholds
  • Every AI agent tool call audited and quota-tracked
  • Workflow automation to alert, block or revoke on detection
  • Full audit trail across AI seat provisioning and revocation
Governance

Write the policy once and leave it running.

A governance policy is a filter, a scope, an action and a cadence, stored as JSON. It is evaluated every time new data arrives, and it leaves evidence behind whether it fired or not.

Governance capabilities

  • ITAM 6
  • SAM 6
  • SaaS Management 8
  • Cloud Management 9
  • AI Management 7
  • Named, in total 36

Governance / Policies

Governance policies

Governance policies as listed in the CerteroX console. Illustrative rows.
Encryption at rest — Windows endpoints Governance Policy · Zone: Group IT Enforcing 12 open
Endpoint protection running Governance Policy · Zone: Group IT Enforcing 0 open
Azure VM tag hygiene Tag compliance · Reporting Level: EMEA Enforcing 7 open
Unauthorised software prevention Prohibition rule · All zones Enforcing 3 open
Resource TTL — non-production Lifecycle constraint · Zone: Engineering Enforcing 1 open
Unused licence reclamation, 30+ days Reclamation policy · Zone: Group IT Draft Not evaluated

6 of 6 · evaluated on every inventory cycle

Illustrative rows. The modules, policy types, scopes and cadences are the real ones.

Policy definition

JSON in · JSON out

policy
Encryption at rest — Windows endpoints
type
Governance Policy · compliance as code
scope
Zone: Group IT Reporting Level: EMEA / Manufacturing
filter
os.family is Windows device.type is not Server bitlocker is not Enabled
on match
raise violation notify the resolved owner record evidence, timestamped
cadence
every inventory cycle — continuous

Policy definitions export and import as JSON. Review them in a pull request, promote them between environments, and diff what changed, exactly as you treat the rest of your infrastructure.

  1. Define

    Filter builder

    You build it in the reusable filter builder, the same one the groups run off. Six governance policy types on the cloud side, plus tag correlation rules with effective dates.

  2. Evaluate

    Continuous

    It re-evaluates on every inventory cycle, every connector sync and every billing import, so the compliance position is current at whatever moment you look at it.

  3. Enforce

    Acts, not alerts

    Resource TTL expires the resource and expense limits stop the pool. Blacklisting blocks the install, reclamation takes the seat back, and revocation kills the OAuth grant.

  4. Evidence

    Audit trail

    Constraint violation history, an audit log across every provisioning and deprovisioning step, and a dedicated Auditor role that can read all of it and change none of it.

What each discipline enforces

All 36, named in full

ITAM Prove everything is under control, continuously. 6 named capabilities
  • Governance Policies — compliance-as-code with a reusable filter builder
  • Policy examples: BitLocker enabled, Defender running, Azure VM tag hygiene
  • Zones for multi-entity data segmentation
  • Reporting Levels enforcing organisational unit or location visibility
  • Role-based access control with granular permissions
  • JSON export and import of policy definitions
Visibility
8
Optimization
6
Management
7
Governance
6
CerteroX ITAM
SAM Defensible, evidenced, and ready before you are asked. 6 named capabilities
  • Continuous compliance position rather than point-in-time reconciliation
  • End-of-life and end-of-support lifecycle tracking
  • Application blacklisting and prohibition rules
  • Audit trail across agreements, transactions and exclusions
  • Governance Policies for unauthorised software prevention
  • Reporting Levels restricting visibility by organisational unit or location
Visibility
7
Optimization
6
Management
6
Governance
6
CerteroX SAM
SaaS Management Close the loop and keep the receipt. 8 named capabilities
  • Offboarding checklist per user with per-licence revocation status
  • Wasted spend metric for licences still held by departed users
  • OAuth grant risk scoring on sensitivity, scope, consent and dormancy
  • One-click grant revocation, also available as a workflow action
  • Risk assessment on data sensitivity, compliance and business criticality
  • Audit log covering every provisioning and deprovisioning step
  • Six-tier role model including a dedicated Auditor role
  • Per-application budgets with warning and critical thresholds
Visibility
8
Optimization
8
Management
7
Governance
8
CerteroX SaaS Management
Cloud Management Policy that fires before the invoice does. 9 named capabilities
  • Expense anomaly detection against a rolling daily average
  • Expiring and recurring budget policies
  • Resource count anomaly detection and resource quota policies
  • Tag compliance: required tags, prohibited tags and correlation rules
  • Resource TTL with automatic lifecycle enforcement
  • Total and daily expense limits per resource or pool
  • Constraint violation history and detected-constraints tracking
  • Security signals: inactive IAM users, unused console access, open security groups
  • Pool-based showback and chargeback with forecast-aware overspend states
Visibility
8
Optimization
10
Management
7
Governance
9
CerteroX Cloud Management
AI Management Approve, restrict and evidence AI use before it becomes an incident. 7 named capabilities
  • Shadow AI status workflow: managed, blocked or ignored
  • OAuth grant risk scoring for AI tools with data access
  • Risk assessment on data sensitivity, GDPR, HIPAA and SOC 2 exposure
  • Per-application AI budgets with warning and critical thresholds
  • Every AI agent tool call audited and quota-tracked
  • Workflow automation to alert, block or revoke on detection
  • Full audit trail across AI seat provisioning and revocation
Visibility
8
Optimization
7
Management
7
Governance
7
CerteroX AI Management

One evidence store

All of it writes to the same evidence store. Zones decide which entity's data you can reach, Reporting Levels decide how far down the organisation you can see, and the Auditor role holds read-only access across the whole of it.

AI and automation

AI is built in,
and governed like everything else.

This runs in two directions, both of them audited. Your agents can query the platform through a Model Context Protocol server, and the platform governs the AI your organisation is already using.

An MCP server on every product

ITAM, SAM, SaaS, Cloud and AI Management each expose a Model Context Protocol server, so an agent can ask your technology assets, the licence position and the cloud bill the same question and get three answers that agree.

An assistant over your own data

The in-product conversational assistant answers from your own cost and asset records, the same tables the reports and the policies run on.

Every tool call audited

Scoped, per-organisation tokens with full tool-call auditing and quota tracking. You can see exactly what your agents asked for, and stop them asking again.

Automation that closes the loop

Eight triggers, eleven conditions and thirteen actions on one canvas. Detection is only useful if something happens next.

Model Context Protocol

Every call audited · every call quota-tracked

  1. Your AI agent Claude, Copilot, in-house
  2. Scoped MCP token Per organisation, per tool
  3. CerteroX MCP server On every product
  4. Your own data Assets, licences, cost, risk

Workflow canvas

8 triggers · 11 conditions · 13 actions

Trigger 8 available

  • A user leaves the directory
  • A renewal enters its notice window
  • A new AI tool appears in browser data

Condition 11 available

  • 30+ days of zero usage on the seat
  • OAuth grant risk score above threshold
  • Application budget past its warning line

Action 13 available

  • Reclaim the seat
  • Revoke the OAuth grant
  • Post the receipt to Slack or Teams

The highlighted path is one chain. The engine composes any trigger with any condition and any action, and writes every step it took to the audit log.

Architecture

How it deploys, and how your data gets back out.

The awkward questions, answered in full.

Accreditations

  • ISO 27001:2022
  • Cyber Essentials Plus
  • SOC 2 Type 1
  • FinOps Certified Platform
  • FinOps Certified Service Provider
  • ServiceNow Certified App

Memberships

  • Linux Foundation
  • FinOps Foundation

Technology partnerships

  • ServiceNow Partner
  • Microsoft Partner
  • Oracle Partner

ISO 27001:2022 for information security management, Cyber Essentials Plus at the highest level of the UK NCSC scheme, and a SOC 2 Type 1 attestation. Both FinOps certifications come from the FinOps Foundation — one against CerteroX Cloud Management, one against the managed service — and Linux Foundation membership is at Silver. The Oracle partnership carries third-party tool verifications for Java, Database and Fusion Middleware.

Deployment
SaaS, hosted and run by Certero. Or on-premises, in your own datacentre — including networks with no outbound route, where standalone inventory carries the data in by hand.
Single sign-on
ADFS, Microsoft Entra ID, Okta and PingOne.
Access control
Role-based access control with granular permissions. Zones segment data between entities. Reporting Levels restrict visibility to an organisational unit or location. SaaS Management adds a six-tier role model including a dedicated Auditor role; Cloud Management ships three built-in roles across five permission groups.
Data out
A read-only Certero API with a documented Power BI data source. Raw billing export to external BI. Scheduled email reporting, and report delivery to Slack and Microsoft Teams.
Agent access
A Model Context Protocol server on every product, with scoped per-organisation tokens and full tool-call auditing. External MCP plugin support for calling out to other servers.
Open standards
Native FOCUS support, the FinOps Open Cost and Usage Specification. Software Identification (SWID) tags with UNSPSC classification. JSON export and import of policy definitions.
Is CerteroX one product or five?

Five products, one platform. Each runs standalone and each is bought separately, but they share one asset model, one access model and one audit trail, so adding the second one adds no integration work.

What does “one data model” actually mean in practice?

A device, a licence, a SaaS seat, a cloud resource and an ML executor are all asset records. They carry an owner, a cost, a lifecycle state and a compliance position in the same fields. That means a group, a policy, a permission or a report you build once applies to all of them.

Do we have to deploy an agent?

No. Of the ten discovery methods, several need nothing installed on the target at all: agentless inventory, command-line inventory via csinvcli, Network Discovery over NetBIOS, SNMP and ICMP, Active Directory import, and the cloud and SaaS vendor connectors. Where the agent is allowed it goes deeper, but it is never the only way in.

Can it reach air-gapped or heavily restricted systems?

Yes. Standalone inventory captures a system with no route to the platform and imports the file separately, and the whole platform can be deployed on-premises. Secure enclaves and isolated OT networks stop being permanent blind spots.

How does data get out of the platform?

A read-only Certero API with a documented Power BI data source, raw billing export to external BI, scheduled email reporting, report delivery to Slack and Microsoft Teams, and a Model Context Protocol server for AI agents.

Can our own AI agents query it?

Yes. Every product exposes an MCP server with scoped per-organisation tokens. Every tool call is audited and quota-tracked, so agent access is governed the same way human access is.

SaaS or on-premises?

Both. The same product, the same data model and the same policy engine, deployed either way.

In practice

What these mechanisms are worth is better told by the organisations running them.

Read the customer stories
One result, end to end

Watch it find
the machines
nobody has counted.

Network Discovery sweeps a class-C subnet in under five seconds. See it run at full scale, then follow a single result all the way through, from the record it lands in to the policy that governs it and the action that closes it.

A fully populated environment and an honest answer, not a gated PDF.