Skip to content

IT Asset Management

Every asset,
every platform,
on one record
of truth.

Discover and inventory every device across Windows, macOS, Linux, AIX, HP-UX, Solaris, mobile, virtual and cloud — with one agent, one schema and no blind spots to explain away.

Systems / LON-SRV-114

1 record
Hostname
LON-SRV-114
Platform
Windows Server 2019
Serial
J7X2QN3
Owner
Infrastructure
Asset tag
FA-20118
Metered
SQL Server · 41d
Evidence method · wrote
  1. 06:14:02 Network scan netbios · ipv4
  2. 06:14:11 Agent os · build
  3. 06:14:19 Agentless serial · bios
  4. 06:14:26 Active Directory ou · owner
  5. 06:14:33 Third-party import asset tag
  6. 06:14:41 File metering usage window

6 of 10 methods · one schema

csinvcli, standalone, cloud connector, browser monitoring had nothing to add on this host. Had they, the fields would have landed in the same record.

Illustrative product interface · sample device record

One agent, one schema

  • Windows
  • macOS
  • Linux
  • IBM AIX
  • HP-UX
  • Solaris
The problem

Same machine, three answers

Your CMDB says one thing, your discovery tool says another, and neither knows about the AIX frames or the Macs that finance bought.

Every audit starts with three weeks of arguing about what you actually own.

  • CMDB

    Last touched by a human

    Hostname
    LON-SRV-114
    Operating system
    Windows Server 2016
    Owner
    Infrastructure
    Status
    In service
    Last seen
    03 Nov 2024
  • Discovery tool

    Knows what answered this morning

    Hostname
    lon-srv-114.corp
    Operating system
    Windows Server 2019
    Owner
    not recorded
    Status
    Responding
    Last seen
    Today, 06:14
  • Finance register

    Holds the asset tag and the write-off

    Asset tag
    FA-20118
    Model
    not recorded
    Owner
    Finance
    Status
    Disposed, 2023
    Location
    Warrington DC
Reconciled
CerteroX · system record duplicate archived · 3 sources merged
Hostname
LON-SRV-114
Alias
lon-srv-114.corp
Operating system
Windows Server 2019
Asset tag
FA-20118
Owner
Infrastructure
Evidence
Agent · today 06:14

Illustrative interface · sample device records

Nobody is wrong on purpose. Each system is right about the part of the machine it can see: the CMDB has the owner, the discovery tool has the operating system, finance has the asset tag.

So the argument is really about which tool gets to be the authority, and it gets settled in a meeting by whoever is trusted most that week.

One schema is what fixes it. Every discovery method writes into the same record, so the CMDB, the network scan and the finance register all end up pointing at one row.

Discovery engine: where every record starts

Watch a subnet answer for itself

Network Discovery sweeps across NetBIOS, SNMP and ICMP, probes port 22 to see where an agent can land, and writes every response straight into the system record. This is that sweep, at the speed it runs.

Discovery / Network sweep / 10.24.7.0/24

Subnet map 256 addresses

Sweep complete: 191 of 256 addresses responded, and 77 of those accept agent deployment.

191
responded
77
port 22 open
4.6s
elapsed
  1. +0.0s icmp echo · 256 sent
  2. +1.4s netbios name query · 191 replies
  3. +2.9s snmp sysDescr · printers, switches
  4. +4.2s tcp/22 probe · 77 open
  5. +4.6s sweep complete · queued for inventory
  • NetBIOS
  • SNMP
  • ICMP
  • port 22 probe
Inventory · written live one schema
Devices identified by the sweep, with the platform, the inventory method that reached them, and their reconciliation state.
Host State
WIN WKS-4471 New
WIN SRV-APP-12 Matched
MAC MBP-DES-08 New
LNX RHEL-DB-03 Matched
AIX AIX-LPAR-02 New
HPX HPUX-FIN-01 New
SOL SOL-ARC-04 New
WIN VDI-POOL-117 Non-persistent
ESX ESX-CL1-N4 New
NET PRN-FL2-07 New
NET SW-CORE-01 Matched
WIN srv-app-12.corp Duplicate
Illustrative product interface · sample hosts and addresses

Sweep. NetBIOS, SNMP and ICMP in one pass, with a port 22 probe marking which of the responders can take the agent.

Identify. Every response resolves to a platform and to the inventory method that can reach it, whether that is the agent, agentless, csinvcli, standalone or SNMP.

Reconcile. New devices are created, known ones matched, duplicates flagged and archived, non-persistent VDI sessions handled as sessions.

Visibility through to governance

Four layers, each only as good as the one beneath it

Discovery creates the record, costing makes it useful, distribution acts on it and policy proves it. Take away any one layer and the layer above it stops being trustworthy.

One system record

identityplatformownercostevidence

29 named capabilities

  1. Find everything, including the things nothing else finds.

    Creates the record

    • Network Discovery across NetBIOS, SNMP and ICMP
    • Native inventory agent for Windows, macOS, Linux, AIX, HP-UX and Solaris
    • Agentless and command-line inventory (csinvcli) for locked-down environments
    • Non-persistent VDI inventory support
    4 more in this layer Show fewer
    • Standalone inventory for air-gapped and offline systems
    • Active Directory import of users, groups, computers, sites and subnets
    • Duplicate system detection and stale device archiving
    • SNMP printer consumables, page counts, switch port and routing tables
  2. Turn the inventory into decisions, not just a list.

    Prices the record

    • Hardware warranty retrieval and expiry tracking
    • Cost tabs with manual and automatic costing rules
    • Dynamic, static and custom groups via query builder or SQL
    • Read-only Certero API with a documented Power BI data source
    2 more in this layer Show fewer
    • Trend charts, KPIs and threshold alerts
    • Personal and role-shared dashboards
  3. Act on your assets from the same console that sees them.

    Acts on the record

    • Software distribution for MSI, EXE and Click-to-Run packages
    • Platform upgrade as a versioned action, with an optional database backup retained
    • Windows 11 upgrade orchestration
    • SCCM interface — import and drive SCCM applications, packages and jobs
    5 more in this layer Show fewer
    • Agent auto-update as a single global setting, applied on the next collection
    • WSUS-integrated patch management with downstream server support
    • Mobile device management for iOS and Android, including Apple DEP
    • App-Centre self-service portal with manager approval chains
    • Passworks self-service password reset for Windows and macOS
  4. Prove everything is under control, continuously.

    Proves the record

    • Governance Policies — compliance-as-code with a reusable filter builder
    • Zones for multi-entity data segmentation
    • Reporting Levels enforcing organisational unit or location visibility
    • Role-based access control with granular permissions
    2 more in this layer Show fewer
    • Policy examples: BitLocker enabled, Defender running, Azure VM tag hygiene
    • JSON export and import of policy definitions
The engine, in numbers
discovery methods
10
operating system families
6
to sweep a class-C subnet
<5s
named system connectors
28
Where we differ

Three things that are hard to build

All three are expensive to engineer and easy to leave off a datasheet, so they tend to surface once the rollout is under way.

  1. 01

    Unix and mainframe-adjacent platforms are first-class

    AIX, HP-UX and Solaris get the same native agent, the same inventory cycle and the same licence engine as Windows. Most platforms treat them as an integration problem. We treat them as an operating system.

    6 OS families, one agent

  2. 02

    Discovery before deployment

    Network Discovery sweeps a class-C subnet in under five seconds using NetBIOS, SNMP and ICMP, then probes port 22 to work out where the agent can actually be deployed. You find the machines before you own them.

    <5s per /24 subnet

  3. 03

    One agent, ten methods

    Agent, command-line, agentless, standalone, AD, network scan, third-party import, cloud connector, browser monitor and file metering all land in one schema. Whichever one reached the machine, the asset comes out the same shape, with the method that found it kept alongside the evidence.

    10 methods, 1 schema

Compare us properly

Same data model as SAM, SaaS, Cloud and AI Management.

Proof

“The tool has truly transformed how we work, making life a lot easier with complete visibility of assets and automation removing the need for manual intervention.”

East of England Ambulance Service Andy Marrs, IM&T Security & Resilience Manager Emergency services
sites brought into view
130 sites brought into view
Read the published case study

“CerteroX for Enterprise ITAM is well worth the investment.”

Major automotive group · 52 dealerships IT Asset Manager
Read the case study

Certifications, as published

SOC 2 Type 1
Attestation

The inventory schema, the connector reference and the read-only API are documented in full.

docs.certero.com (opens in a new tab)
Integrations

It reads what you already run

Directory, endpoint management, every mainstream hypervisor, the two big clouds and the third-party ITAM tools you are trying to retire.

Sixteen of twenty-eight named system connectors

Directory & endpoint

  • Active Directory
  • Microsoft SCCM
  • Microsoft Intune
  • WSUS

Virtualisation & hypervisors

  • VMware
  • Microsoft Hyper-V
  • Citrix XenServer
  • IBM HMC
  • Oracle VM
  • Red Hat oVirt
  • Nutanix

Cloud, network & third-party ITAM

  • AWS
  • Microsoft Azure
  • Cisco Meraki
  • LANDesk
  • Altiris
ITAM questions

The things people actually ask

Seven answers on discovery coverage, Unix support, VDI, SCCM and getting the data back out. If yours is not here, the technical documentation goes deeper.

Named system connectors
16 of 28
Ask an engineer
info@certero.com
Do I have to put an agent on everything?

No. There are ten discovery methods and they all land in the same schema: the native agent, the csinvcli command line, agentless inventory, standalone inventory for air-gapped machines, Active Directory import, network scan, third-party ITAM import, cloud connectors, browser monitoring and file metering. Locked-down machines get inventoried without an install.

What actually happens on a network sweep?

Network Discovery sweeps a class-C subnet in under five seconds using NetBIOS, SNMP and ICMP, then probes port 22 to work out where the agent can be deployed. You get the responding hosts, what they claim to be, and a deployable/not-deployable answer, all before you own the machines.

Are AIX, HP-UX and Solaris really first-class, or an integration?

First-class. They run the same native inventory agent as Windows, macOS and Linux, on the same inventory cycle, feeding the same licence engine. SNMP additionally covers printer consumables and page counts, switch port tables and routing tables.

How does it handle non-persistent VDI and duplicate records?

Non-persistent VDI inventory is supported directly, so a pool does not generate a new asset every time a session spins up. Duplicate system detection merges records that describe the same machine, and stale devices are archived rather than silently deleted, so the history survives.

Does this replace SCCM?

It does not have to. The SCCM interface imports SCCM applications, packages and jobs and can drive them from the CerteroX console. Patch management is WSUS-integrated with downstream server support. If you want CerteroX to distribute software itself, it handles MSI, EXE and Click-to-Run packages and Windows 11 upgrade orchestration.

Can I get the data out into our own reporting?

Yes. There is a read-only Certero API with a documented Power BI data source, plus dynamic, static and custom groups built with the query builder or SQL, trend charts, KPIs, threshold alerts and role-shared dashboards.

How do you keep one deployment separated across business units?

Zones segment data by entity, Reporting Levels restrict visibility to an organisational unit or location, and role-based access control sets granular permissions on top. Governance Policies are written once and exported or imported as JSON.

Start with discovery

Ten discovery methods.
One record at the end.

The demo opens on a class-C subnet sweep, answering in under five seconds, and then follows what it produces: the Unix host, the VDI sessions and the duplicates already resolved into a single asset.

Nothing to connect, nothing to install. One session, and an engineer who answers.