Skip to content

Resources

The writing.
The docs.
The numbers.

Posts on licensing mechanics, cloud waste and audit defence. The documentation that ships with the platform. A glossary of the terms that decide what you owe.

The published customer stories, every connector we ship and a calculator that runs on your own numbers. Free to read, link to and quote.

The blog

205 posts on
the hard parts.

Licensing mechanics, cloud waste, audit defence and shadow AI, across ITAM, SAM, SaaS, cloud cost and AI governance. In as much depth as the subject needs, and the list is still growing.

Filter by topic (licensing, SaaS, cloud cost, AI governance), or start at the newest post and read straight down.

Straight to it

The documentation
is the product tour.

The fastest way to judge a platform is to read what its engineers wrote for the people who have to run it. So that is what we point you at: the live reference, one click away.

Capability index 148 named capabilities · 5 products · 4 layers each

Pick a product to see its four layers and the capabilities documented under each one.

CerteroX ITAM IT Asset Management

01 Visibility

Find everything, including the things nothing else finds.

  • Network Discovery across NetBIOS, SNMP and ICMP
  • Native inventory agent for Windows, macOS, Linux, AIX, HP-UX and Solaris
  • Agentless and command-line inventory (csinvcli) for locked-down environments
  • Standalone inventory for air-gapped and offline systems
  • 8 documented

02 Optimization

Turn the inventory into decisions, not just a list.

  • Hardware warranty retrieval and expiry tracking
  • Cost tabs with manual and automatic costing rules
  • Dynamic, static and custom groups via query builder or SQL
  • Trend charts, KPIs and threshold alerts
  • 6 documented

03 Management

Act on your assets from the same console that sees them.

  • Software distribution for MSI, EXE and Click-to-Run packages
  • Agent auto-update as a single global setting, applied on the next collection
  • Platform upgrade as a versioned action, with an optional database backup retained
  • Windows 11 upgrade orchestration
  • 9 documented

04 Governance

Prove everything is under control, continuously.

  • Governance Policies — compliance-as-code with a reusable filter builder
  • Policy examples: BitLocker enabled, Defender running, Azure VM tag hygiene
  • Zones for multi-entity data segmentation
  • Reporting Levels enforcing organisational unit or location visibility
  • 6 documented

Four layers, five asset classes, one data model. The reference documents every one of them, from configuration and connectors to the licence engines and the API.

Open the documentation (opens in a new tab)
Case studies

What it looked like
for them.

From NHS trusts and an ambulance service to a global legal firm and a major automotive group. What each one was up against, what they measured afterwards, and the full account behind it.

  • Healthcare

    “Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.”

    Reece Emson, ITAM Asset/PSL Manager
    Microsoft compliance risk mitigated
    £100k Microsoft compliance risk mitigated
    of SAM maturity accelerated
    3–4 yrs of SAM maturity accelerated
  • Emergency services

    “The tool has truly transformed how we work, making life a lot easier with complete visibility of assets and automation removing the need for manual intervention.”

    Andy Marrs, IM&T Security & Resilience Manager
    sites brought into view
    130 sites brought into view
  • Healthcare

    “When we reviewed the responses to the initial RFP, Certero offered the best solution for our requirements.”

    Project Management Office Lead
    devices under management
    5,500+ devices under management
  • Legal

    “My advice to other organizations contemplating RFP’s for ITAM and SAM is: just take Certero.”

    Technology Process Manager
    devices
    4,000 devices
Glossary

Twenty-two terms,
defined properly.

Each entry says what the term means, then what people usually get wrong about it, because the second part is the part that costs money. The whole list is searchable and filterable, and every entry has a link of its own.

22 terms

CAL Client Access Licence SAM
A licence that permits a user or a device to access a licensed server product; the server licence alone does not grant anyone the right to use it. You choose per user or per device based on the access pattern: shift workers sharing a terminal favour device CALs, while one person on a laptop, a phone and a desktop favours user CALs. External-facing systems usually need an external connector instead, and forgetting that is a common way to under-license a public-facing service.
Core factor SAM
A multiplier Oracle applies to each physical core to work out how many processor licences a server needs, published as a table keyed on processor family. A chip with a factor of 0.5 needs half a licence per core; one with a factor of 1.0 needs a full one. It is the single most common source of Oracle miscounting, because the factor changes with the silicon and nobody updates the calculation when the hardware is refreshed.
Downgrade rights SAM
The contractual right to run an earlier version, or sometimes a lower edition, of a product you have licensed at a higher level. Handled properly they are one of the cheapest compliance wins available, because a newer entitlement can cover an older installation you were about to buy again. Handled sloppily they are a reporting mess, since the tool has to know the entitlement is being consumed by an install that does not match its version.
ELP Effective Licence Position SAM
The calculated difference between what you are entitled to run and what you are actually running, for one publisher, at one moment. The arithmetic comes last: a real ELP applies downgrade rights, second-use rights, exclusions, virtualisation rules and per-publisher metrics first. If your ELP is produced once a year in a spreadsheet, it is a snapshot of a position you had while somebody was still typing.
FinOps Cloud
The operating model that makes cloud spend a shared engineering and finance responsibility. It runs on a loop of inform, optimise and operate: show teams what they cost, give them the changes worth making, then make the good behaviour the default. Done properly it changes who gets to approve a resource before it exists.
FOCUS FinOps Open Cost and Usage Specification Cloud
An open specification published by the FinOps Foundation that defines a common schema for cloud cost and usage data: consistent column names, consistent semantics, consistent handling of discounts and amortisation. Its value is portability: when every provider emits the same shape of data, comparing across clouds stops being a normalisation project and your cost history stops being hostage to one vendor’s export format.
ITAM IT Asset Management ITAM
The practice of knowing what physical and virtual technology your organisation holds, who has it, what it cost, and when it stops being supported. Most of the work is reconciliation: deciding which of three disagreeing sources is right. The test of a mature ITAM function is not whether it has a record for every device, but whether anyone outside IT trusts that record enough to spend money against it.
Licence harvesting SAM
Recovering licences from users who no longer need them and returning them to a pool for reassignment, so the next request costs nothing. It requires usage evidence over a defensible window, an agreed threshold, and a route back to the user if the reclamation was wrong. Harvesting is where SAM stops being a compliance function and starts paying for itself, and its value peaks in the quarter before a renewal or true-up.
MCP Model Context Protocol AI
An open protocol for connecting AI assistants to external systems through a defined set of tools, so a model can query real data instead of guessing from what it was trained on. For asset management the significance is governance: an MCP server turns everything you own into something an agent can ask questions of, which puts the interesting controls on scoped tokens, per-call auditing and quotas.
Offboarding gap SaaS
The distance between a person leaving and every one of their accounts, licences and third-party grants actually being closed. Directory access usually ends on day one; the subscriptions bought outside procurement can survive for months, still billing and still holding an OAuth grant with read access to company data. It is measurable, in the licences still assigned to departed users and their monthly cost, which makes it one of the few governance problems you can put a number on immediately.
PVU Processor Value Unit SAM
IBM’s capacity-based licensing unit, where each processor core is assigned a value depending on its architecture and model, and your requirement is the sum across every core the software could run on. The consequence people miss is that PVU counts follow the hardware: put a modest IBM product on a large modern host and the requirement grows even though nothing about the application changed. Sub-capacity licensing exists to soften exactly this, on conditions.
Reserved instances Cloud
A commitment to a level of cloud consumption over one or three years in exchange for a substantial discount on the on-demand rate. The discount is real; the trap is that the commitment outlives the architecture that justified it, and coverage bought on a good forecast becomes waste after a migration. Buy them against the workload floor you are confident about. Rightsize before you commit, or you lock in the oversizing for three years.
Rightsizing Cloud
Matching the size of a provisioned resource to its observed usage rather than to the number someone typed at creation. It is the highest-yield cloud saving and the most frequently deferred, because the saving lands in one budget and the risk of a smaller instance lands with someone else. Good rightsizing quotes the observation window and the peak alongside the average: an instance that idles all month and saturates on the last Friday is correctly sized.
SaaS Management SaaS
Discovering, costing and governing the subscription applications your organisation uses, including the ones procurement never saw. It differs from classic SAM in one structural way: the vendor holds the meter, so discovery comes from identity providers, vendor APIs and the browser, where an agent on a device would find nothing. The recurring failure mode is the long tail of single-department tools that renew silently on a card.
SAM Software Asset Management SAM
The discipline of matching what software is installed and used against what you are contractually entitled to run. It sits on top of ITAM: without a trustworthy device inventory there is nothing to license against. SAM is where the money is, because publisher licensing metrics are deliberately intricate and the gap between a naive install count and a correctly computed position is where audit findings live.
Shadow AI AI
Shadow IT’s faster, sharper variant: employees using AI tools that were never approved, and often never bought. Two things make it a different problem. Exposure is instantaneous, because a single prompt can move confidential material outside your control with no file transfer to detect. And AI increasingly lives inside applications you already sanctioned, so the approval covers the application and stops at the feature. Discovery has to come first, because you cannot write policy for a population you have not measured.
Shadow IT SaaS
Technology bought and run by a team without going through IT or procurement. It is usually a symptom: people route around a process that is slower than their deadline. The real cost is the duplicated capability, the data sitting outside your retention policy, and the account nobody remembers to close when the person leaves.
Showback vs chargeback Cloud
Two ways of attributing shared technology cost to the teams causing it. Showback reports what a team consumed without moving money; chargeback actually bills the team’s budget. Showback changes behaviour through visibility and is far easier to introduce; chargeback changes behaviour through consequence but demands allocation accurate enough to survive an argument with a finance business partner. Most organisations should run showback until the allocation stops being disputed, then decide whether chargeback adds anything.
Sub-capacity licensing SAM
Licensing a product for the virtual capacity it can actually consume. The default is the full physical capacity of the host underneath it. Sub-capacity is almost always cheaper and almost always conditional: publishers grant it only where an approved measurement tool is deployed, kept current, and reporting on an agreed cycle. Fail the conditions and the entitlement quietly reverts to full capacity, which is how a saving becomes a finding.
SWID tag Software Identification tag SAM
A small structured file a publisher ships alongside its product, standardised as ISO/IEC 19770-2, declaring precisely what the software is: name, version, publisher and edition. Where a tag is present it removes the guesswork from software recognition, because you are reading the publisher’s own declaration. Everywhere else, identity has to be inferred from a registry key or a file path. Adoption is uneven, so tags improve recognition without replacing it.
True-up SAM
The periodic reconciliation under a volume agreement where you declare the licences you consumed beyond your baseline and pay for them. It is designed to be an administrative formality, and it becomes expensive when the declaration is assembled from memory. A true-up is also the one moment where harvesting unused licences directly reduces an invoice, which is why the work belongs in the quarter before it falls due.
UNSPSC United Nations Standard Products and Services Code SAM
A hierarchical classification scheme for products and services, used in asset management to give every recognised software title a consistent category independent of what its publisher happens to call it. Its practical value is aggregation: it lets you ask how much you spend on database software across the whole organisation without first agreeing whether a given product counts as one. A UNSPSC code is a category, and it carries no entitlement.
How we think about it

Visibility, Optimization,
Management, Governance.

Four questions, in order. Every asset class we govern, from hardware and software to SaaS, cloud and AI, gets asked all four, and a tool that answers only the first two is a report, not a platform.

  1. Visibility

    What do we actually have?

    The CMDB and the last audit each answer a different question. This one is about what is running right now, on every platform, including the things bought on a card and the things nobody has logged into since March. Visibility is the only pillar where being 90% right is worth almost nothing, because the missing 10% is where the finding, the breach and the renewal shock all live.

    The cost of skipping You optimise a number you cannot defend.

  2. Optimization

    What of it is waste?

    Waste here is a named check with a threshold: the seat unopened for ninety days, the instance stopped but never deallocated, the licence entitlement that already covers the install you were about to buy again. Optimization turns an inventory into a decision, and it is the only pillar that pays for the other three.

    The cost of skipping You have bought a very expensive spreadsheet.

  3. Management

    Who changes it, and how?

    A finding that nobody can act on is a complaint. Management is the layer where a recommendation becomes a reclaim, a deprovision, a power schedule or a purchase order, with an owner attached and a workflow behind it. This is where most tools hand you a CSV and wish you luck.

    The cost of skipping The same findings reappear every quarter.

  4. Governance

    How do we stop it coming back?

    Governance is policy that fires before the invoice does. That means tag rules, resource lifetimes, budget thresholds, unauthorised-software prohibition, an offboarding checklist that has to complete. It is also the pillar that gets cut first when the budget tightens, which is precisely why the waste returns three months after the clean-up project ends.

    The cost of skipping Next year the clean-up project runs again.

Each one depends on the one below it. You cannot optimise what you cannot see, and every saving you make without an owner and a policy behind it has an expiry date. Most tools sell you the first pillar and a chart of the second. CerteroX is built to carry all four across all five asset classes, because the fourth one is where the value stops leaking back out.

When reading stops being enough

Bring the hardest
question you have.

You have read the documentation and you know what the words mean. The next useful step is watching the platform answer it in front of you, whether that is the licence position, the twenty-six checks or the seats nobody has opened in ninety days.

You get a technical person on the call and a written position afterwards.