Every asset,
every platform,
on one record
of truth.
Discover and inventory every device across Windows, macOS, Linux, AIX, HP-UX, Solaris, mobile, virtual and cloud — with one agent, one schema and no blind spots to explain away.
Systems / LON-SRV-114
1 record- Hostname
- LON-SRV-114
- Platform
- Windows Server 2019
- Serial
- J7X2QN3
- Owner
- Infrastructure
- Asset tag
- FA-20118
- Metered
- SQL Server · 41d
- 06:14:02 Network scan netbios · ipv4
- 06:14:11 Agent os · build
- 06:14:19 Agentless serial · bios
- 06:14:26 Active Directory ou · owner
- 06:14:33 Third-party import asset tag
- 06:14:41 File metering usage window
6 of 10 methods · one schema
csinvcli, standalone, cloud connector, browser monitoring had nothing to add on this host. Had they, the fields would have landed in the same record.
One agent, one schema
- Windows
- macOS
- Linux
- IBM AIX
- HP-UX
- Solaris
Same machine, three answers
Your CMDB says one thing, your discovery tool says another, and neither knows about the AIX frames or the Macs that finance bought.
Every audit starts with three weeks of arguing about what you actually own.
- CMDB
Last touched by a human
- Hostname
- LON-SRV-114
- Operating system
- Windows Server 2016
- Owner
- Infrastructure
- Status
- In service
- Last seen
- 03 Nov 2024
- Discovery tool
Knows what answered this morning
- Hostname
- lon-srv-114.corp
- Operating system
- Windows Server 2019
- Owner
- not recorded
- Status
- Responding
- Last seen
- Today, 06:14
- Finance register
Holds the asset tag and the write-off
- Asset tag
- FA-20118
- Model
- not recorded
- Owner
- Finance
- Status
- Disposed, 2023
- Location
- Warrington DC
- Hostname
- LON-SRV-114
- Alias
- lon-srv-114.corp
- Operating system
- Windows Server 2019
- Asset tag
- FA-20118
- Owner
- Infrastructure
- Evidence
- Agent · today 06:14
Illustrative interface · sample device records
Nobody is wrong on purpose. Each system is right about the part of the machine it can see: the CMDB has the owner, the discovery tool has the operating system, finance has the asset tag.
So the argument is really about which tool gets to be the authority, and it gets settled in a meeting by whoever is trusted most that week.
One schema is what fixes it. Every discovery method writes into the same record, so the CMDB, the network scan and the finance register all end up pointing at one row.
Discovery engine: where every record starts
Watch a subnet answer for itself
Network Discovery sweeps across NetBIOS, SNMP and ICMP, probes port 22 to see where an agent can land, and writes every response straight into the system record. This is that sweep, at the speed it runs.
Discovery / Network sweep / 10.24.7.0/24
Sweep complete: 191 of 256 addresses responded, and 77 of those accept agent deployment.
- 191
- responded
- 77
- port 22 open
- 4.6s
- elapsed
- +0.0s icmp echo · 256 sent
- +1.4s netbios name query · 191 replies
- +2.9s snmp sysDescr · printers, switches
- +4.2s tcp/22 probe · 77 open
- +4.6s sweep complete · queued for inventory
- NetBIOS
- SNMP
- ICMP
- port 22 probe
| Host | Platform | Method | State |
|---|---|---|---|
| WIN WKS-4471 | WIN Windows 11 | Agent | New |
| WIN SRV-APP-12 | WIN Windows Server 2022 | Agent | Matched |
| MAC MBP-DES-08 | MAC macOS 15 | Agent | New |
| LNX RHEL-DB-03 | LNX Red Hat 9 | csinvcli | Matched |
| AIX AIX-LPAR-02 | AIX IBM AIX 7.3 | Agent | New |
| HPX HPUX-FIN-01 | HPX HP-UX 11i v3 | Agentless | New |
| SOL SOL-ARC-04 | SOL Oracle Solaris 11 | Standalone | New |
| WIN VDI-POOL-117 | WIN Windows 10 VDI | Agent | Non-persistent |
| ESX ESX-CL1-N4 | ESX VMware ESXi 8 | Agentless | New |
| NET PRN-FL2-07 | NET Network printer | SNMP | New |
| NET SW-CORE-01 | NET Access switch | SNMP | Matched |
| WIN srv-app-12.corp | WIN Windows Server 2022 | NetBIOS | Duplicate |
Sweep. NetBIOS, SNMP and ICMP in one pass, with a port 22 probe marking which of the responders can take the agent.
Identify. Every response resolves to a platform and to the inventory method that can reach it, whether that is the agent, agentless, csinvcli, standalone or SNMP.
Reconcile. New devices are created, known ones matched, duplicates flagged and archived, non-persistent VDI sessions handled as sessions.
Four layers, each only as good as the one beneath it
Discovery creates the record, costing makes it useful, distribution acts on it and policy proves it. Take away any one layer and the layer above it stops being trustworthy.
identityplatformownercostevidence
29 named capabilities
-
Find everything, including the things nothing else finds.
Creates the record
- Network Discovery across NetBIOS, SNMP and ICMP
- Native inventory agent for Windows, macOS, Linux, AIX, HP-UX and Solaris
- Agentless and command-line inventory (csinvcli) for locked-down environments
- Non-persistent VDI inventory support
4 more in this layer Show fewer
- Standalone inventory for air-gapped and offline systems
- Active Directory import of users, groups, computers, sites and subnets
- Duplicate system detection and stale device archiving
- SNMP printer consumables, page counts, switch port and routing tables
-
Turn the inventory into decisions, not just a list.
Prices the record
- Hardware warranty retrieval and expiry tracking
- Cost tabs with manual and automatic costing rules
- Dynamic, static and custom groups via query builder or SQL
- Read-only Certero API with a documented Power BI data source
2 more in this layer Show fewer
- Trend charts, KPIs and threshold alerts
- Personal and role-shared dashboards
-
Act on your assets from the same console that sees them.
Acts on the record
- Software distribution for MSI, EXE and Click-to-Run packages
- Platform upgrade as a versioned action, with an optional database backup retained
- Windows 11 upgrade orchestration
- SCCM interface — import and drive SCCM applications, packages and jobs
5 more in this layer Show fewer
- Agent auto-update as a single global setting, applied on the next collection
- WSUS-integrated patch management with downstream server support
- Mobile device management for iOS and Android, including Apple DEP
- App-Centre self-service portal with manager approval chains
- Passworks self-service password reset for Windows and macOS
-
Prove everything is under control, continuously.
Proves the record
- Governance Policies — compliance-as-code with a reusable filter builder
- Zones for multi-entity data segmentation
- Reporting Levels enforcing organisational unit or location visibility
- Role-based access control with granular permissions
2 more in this layer Show fewer
- Policy examples: BitLocker enabled, Defender running, Azure VM tag hygiene
- JSON export and import of policy definitions
- discovery methods
- 10
- operating system families
- 6
- to sweep a class-C subnet
- <5s
- named system connectors
- 28
Three things that are hard to build
All three are expensive to engineer and easy to leave off a datasheet, so they tend to surface once the rollout is under way.
- 01
Unix and mainframe-adjacent platforms are first-class
AIX, HP-UX and Solaris get the same native agent, the same inventory cycle and the same licence engine as Windows. Most platforms treat them as an integration problem. We treat them as an operating system.
6 OS families, one agent
- 02
Discovery before deployment
Network Discovery sweeps a class-C subnet in under five seconds using NetBIOS, SNMP and ICMP, then probes port 22 to work out where the agent can actually be deployed. You find the machines before you own them.
<5s per /24 subnet
- 03
One agent, ten methods
Agent, command-line, agentless, standalone, AD, network scan, third-party import, cloud connector, browser monitor and file metering all land in one schema. Whichever one reached the machine, the asset comes out the same shape, with the method that found it kept alongside the evidence.
10 methods, 1 schema
Same data model as SAM, SaaS, Cloud and AI Management.
“The tool has truly transformed how we work, making life a lot easier with complete visibility of assets and automation removing the need for manual intervention.”
Published by Certero as an Advanced SAM case study.
- sites brought into view
- 130 sites brought into view
“CerteroX for Enterprise ITAM is well worth the investment.”
Certifications, as published
- ISO 27001:2022
- Information security management (opens in a new tab)
- Cyber Essentials Plus
- Highest level of the UK NCSC scheme (opens in a new tab)
- SOC 2 Type 1
- Attestation
The inventory schema, the connector reference and the read-only API are documented in full.
docs.certero.com (opens in a new tab)It reads what you already run
Directory, endpoint management, every mainstream hypervisor, the two big clouds and the third-party ITAM tools you are trying to retire.
Sixteen of twenty-eight named system connectors
Directory & endpoint
- Active Directory
- Microsoft SCCM
- Microsoft Intune
- WSUS
Virtualisation & hypervisors
- VMware
- Microsoft Hyper-V
- Citrix XenServer
- IBM HMC
- Oracle VM
- Red Hat oVirt
- Nutanix
Cloud, network & third-party ITAM
- AWS
- Microsoft Azure
- Cisco Meraki
- LANDesk
- Altiris
The things people actually ask
Seven answers on discovery coverage, Unix support, VDI, SCCM and getting the data back out. If yours is not here, the technical documentation goes deeper.
- Named system connectors
- 16 of 28
- Technical documentation
- docs.certero.com (opens in a new tab)
- Ask an engineer
- info@certero.com
Do I have to put an agent on everything?
No. There are ten discovery methods and they all land in the same schema: the native agent, the csinvcli command line, agentless inventory, standalone inventory for air-gapped machines, Active Directory import, network scan, third-party ITAM import, cloud connectors, browser monitoring and file metering. Locked-down machines get inventoried without an install.
What actually happens on a network sweep?
Network Discovery sweeps a class-C subnet in under five seconds using NetBIOS, SNMP and ICMP, then probes port 22 to work out where the agent can be deployed. You get the responding hosts, what they claim to be, and a deployable/not-deployable answer, all before you own the machines.
Are AIX, HP-UX and Solaris really first-class, or an integration?
First-class. They run the same native inventory agent as Windows, macOS and Linux, on the same inventory cycle, feeding the same licence engine. SNMP additionally covers printer consumables and page counts, switch port tables and routing tables.
How does it handle non-persistent VDI and duplicate records?
Non-persistent VDI inventory is supported directly, so a pool does not generate a new asset every time a session spins up. Duplicate system detection merges records that describe the same machine, and stale devices are archived rather than silently deleted, so the history survives.
Does this replace SCCM?
It does not have to. The SCCM interface imports SCCM applications, packages and jobs and can drive them from the CerteroX console. Patch management is WSUS-integrated with downstream server support. If you want CerteroX to distribute software itself, it handles MSI, EXE and Click-to-Run packages and Windows 11 upgrade orchestration.
Can I get the data out into our own reporting?
Yes. There is a read-only Certero API with a documented Power BI data source, plus dynamic, static and custom groups built with the query builder or SQL, trend charts, KPIs, threshold alerts and role-shared dashboards.
How do you keep one deployment separated across business units?
Zones segment data by entity, Reporting Levels restrict visibility to an organisational unit or location, and role-based access control sets granular permissions on top. Governance Policies are written once and exported or imported as JSON.
Ten discovery methods.
One record at the end.
The demo opens on a class-C subnet sweep, answering in under five seconds, and then follows what it produces: the Unix host, the VDI sessions and the duplicates already resolved into a single asset.
Nothing to connect, nothing to install. One session, and an engineer who answers.