Skip to content

Why CerteroX

One platform.
Not a portfolio of
acquisitions.

Five disciplines (ITAM, SAM, SaaS, Cloud and AI) on one data model, built in one place. Nothing here was bought and bolted on, which is why there is nothing between the products for you to integrate.

  • ITAM Devices
  • SAM Licences
  • SaaS Seats
  • Cloud Resources
  • AI Models

One asset graph · one owner · one console

0 integrations to build between them

The acquisition problem

Five products
can be bought.
One data model
has to be built.

A discipline added by acquisition arrives with its own schema, its own identifiers and its own console. Making those agree is not a feature the vendor ships. It is a project you run, and it does not finish.

You are almost certainly comparing us with a portfolio: asset management sold under several brands at once, one brand per discipline, each carrying the schema and the console it was built with. Underneath the brand names, each product keeps its own identifiers.

So ask the question that decides everything downstream: when two products both discover the same server, which one holds the master record, and what field joins them? Every duplicate asset record and every reconciliation project descends from that one answer.

We are not going to argue with the number. We think it is right. The disagreement is about whether five products that were never designed together can tell you who owns the waste.
29% of cloud spend is wasted — up for the first time in five years

Assembled from products

10 integration surfaces

ITAM SAM SaaS Cloud AI
  • One person becomes five records, with five identifiers
  • A separate login and a separate permission model per product
  • A data model per product, versioned per product
  • An integration tax charged again on every release

Built as one platform

0 integrations to build

ONE SCHEMA ITAM SAM SaaS Cloud AI
  • One person is one record, with one identifier
  • One login, and permissions set once for all five
  • One schema across all five disciplines
  • Adding the next discipline adds no integration work
One data model

One person.
Five asset classes.
One owner.

On one platform, a device found by the agent, the licence installed on it, the SaaS seat held by the same person, the cloud resource they own and the AI model they call are five nodes on one graph. Assembled from five products, the same five are separate records carrying five identifiers, with nothing joining them.

One person, five asset classes

  • Device

    LON-LT-4471 · Windows 11 laptop

    discovered_by Inventory agent, reconciled against the Active Directory import.

    Owner

    USR·4471 · J. Whitfield

    resolved once, on the asset graph

    same owner

    LON-LT-4471

    hostname only, no person on the record

  • Licence

    Visio Professional · per-device entitlement

    entitled_on Installed on that device. Zero executions in the rolling 90-day usage window.

    Owner

    USR·4471 · J. Whitfield

    resolved once, on the asset graph

    same owner

    WHITFIELD_J

    directory account name

  • SaaS seat

    Design collaboration app · editor tier

    assigned_to Identity provider sync, vendor connector and browser extension all agree.

    Owner

    USR·4471 · J. Whitfield

    resolved once, on the asset graph

    same owner

    j.whitfield@

    email address, from the vendor API

  • Cloud resource

    Compute instance · stopped, still allocated

    owned_by Placed in a cost pool automatically, by one of nine assignment rule condition types.

    Owner

    USR·4471 · J. Whitfield

    resolved once, on the asset graph

    same owner

    owner=jwhitfield

    free-text tag, spelled three ways

  • AI workload

    LLM seat + GPU executor on a sweep

    called_by Shadow AI classified from feature tags; the executor gets the same 26 cost checks.

    Owner

    USR·4471 · J. Whitfield

    resolved once, on the asset graph

    same owner

    usr_8812

    vendor-side identifier

Every one of the five records resolves to the same owner, USR·4471 · J. Whitfield, on the asset graph.

Five records, five owner identifiers. Device: LON-LT-4471, hostname only, no person on the record. Licence: WHITFIELD_J, directory account name. SaaS seat: j.whitfield@, email address, from the vendor API. Cloud resource: owner=jwhitfield, free-text tag, spelled three ways. AI workload: usr_8812, vendor-side identifier.

One value, five times. Harvest the unused licence, reclaim the seat, deallocate the instance and revoke the AI grant. One decision about one person, taken once.

Five values, one person. Before anyone can act, something has to match them, and keep matching them every time a record changes in any of the five products.

These identifiers are illustrative sample records.

Both owner states are shown above: unified first, then the identifiers the same person carries when the five disciplines were bought separately.

Resolved.
Active Directory, the identity provider and the vendor connector converge on one user, once.
Joined.
The licence knows the device. The device knows the owner. The owner holds the seat and the instance.
Actionable.
Four tickets in four tools become one decision.
An honest comparison

Capability by capability.

Fourteen capabilities in four groups, and the right-hand column is an architecture: what a portfolio assembled from separately built products does, whoever sells it.

Capability comparison between CerteroX and a typical suite assembled from separately built products.
Capability CerteroX One platform, five disciplines Typical acquired suite The architectural pattern, not a named product
Architecture
Unified data model One schema across ITAM, SAM, SaaS, Cloud and AI. A device, the licence against it, the seat, the resource and the model resolve to one asset graph with one owner. A data model per product. The join between them is a reconciliation layer somebody has to build, own and re-run, usually forever.
Discovery methods Ten, landing in one schema: agent, command-line (csinvcli), agentless, standalone, network scan, Active Directory, third-party ITAM import, cloud and SaaS connectors, browser monitoring, file metering. Discovery arrives with each product. Two products that both find a device produce two device records, and de-duplication becomes a standing project.
Consoles and permissions One console, one login, one role-based access model, with Zones for multi-entity data and Reporting Levels restricting visibility by organisational unit or location. One console per brand in the portfolio is the usual arrangement, a portal in front of them, and a permission model inside each.
Depth where it hurts
Unix and datacentre platforms Native inventory agent for IBM AIX, HP-UX and Oracle Solaris: six operating system families on the same inventory cycle and the same licence engine as Windows, macOS and Linux. A separate module, a partner tool or a script drop, wherever the discipline arrived separately. Rarely the same agent, and rarely the same licence engine.
Oracle options and core factors All six of the places an Oracle finding hides are modelled in the licence engine. Each one carries the evidence that produced it and a manual override for when your contract says otherwise. Install counts and editions are the easy part. The audit finding lives in the options, the core factors and the cover-down logic.
Oracle’s own position on the tool Verified by Oracle License Management Services. Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools. A short published list, and whether the tool you are comparing appears on it takes an afternoon to establish.
IBM sub-capacity PVU and Virtual Processor Core metrics, an ILMT connector with compliance gap analysis, scored bulk Component Resolution, and the ≤30-minute inventory cycle sub-capacity licensing requires. An ILMT import, wherever the tool carries no IBM licence engine of its own. The gap between what ILMT reports and what you are entitled to is the part that decides the invoice.
SAP named users A non-invasive ABAP connector reads named users de-duplicated across systems, roles, engines and authorisations, and priority-ordered Analysis Rules propose current, suggested and optimal licence types. A separately licensed module where SAP was not part of the original product, or a partner engagement scoped as a project.
The newer asset classes
SaaS discovery Forty-seven connectors and three converging signals (identity provider, vendor APIs and a browser extension), so an application is found whether or not it touched SSO. One signal in the common configuration: the identity provider, or an expense feed. Whatever touches neither stays invisible.
Shadow AI detection Classified from application feature tags in the catalogue rather than a hardcoded list, then ranked by the share of your organisation using each tool. Detection generally runs off a maintained list of known AI applications. New tools appear when the vendor adds them.
Named cloud recommendations Twenty-six named, individually tunable checks across twelve cloud and data platforms, each with its own thresholds, pool exclusions and account skips. FOCUS ingested natively. A savings figure, arriving without the named check that produced it or the threshold that check used.
MCP server per product Every CerteroX product exposes a Model Context Protocol server, with scoped per-organisation tokens and every agent tool call audited and quota-tracked. Emerging. Ask what your agents can query today, and what is written down afterwards.
Expansion and ownership
Adding the second discipline The second discipline runs on the platform the first one is already on. There is no integration project between them, so no integration project to pay for. Priced per product. Ask what the second and third cost together, and who pays for the work between them.
Ownership model Certero Limited, company number 06387180, England and Wales. Independent since 2007. Portfolio ownership follows investment cycles. Which brands sit together is decided by who bought whom.

Every claim in the CerteroX column is a named capability we will demonstrate in the product, cell by cell, on request.

Take these into every demo.
Including ours.

Five questions that separate one asset graph from five that have to be reconciled. Put them to us first. We will answer every one on screen, in the product, and then in writing.

Ask both of us these, in writing

  1. 01 Is a device found by two of your products one record or two, and which field joins them?
  2. 02 Which of your products holds the AIX, HP-UX and Solaris inventory, and is it the same agent?
  3. 03 Show the Oracle options and packs evidence, and the core factor applied, on one host.
  4. 04 Show the gap between the ILMT position and the entitlement, in the product.
  5. 05 How many consoles and permission models will my team hold logins for?
Depth where it hurts

The publishers that actually bite.

Depth in Oracle, IBM, SAP and Microsoft server licensing is years of entitlement maths, and it only pays off in the room where the audit is settled.

Verified by the publisher

Oracle LMS/GLAS verified

Verified by Oracle License Management Services. Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools.

Every SAM tool can produce an Oracle number. In an Oracle engagement the only question that matters is whose number is accepted — and that is settled long before anyone opens a spreadsheet. Each option and pack finding carries the evidence that produced it and a manual override for the cases your contract already decided.

Modelled in the licence engine

  • Options and packs, with evidence and manual override
  • Processor types and core factors applied per host
  • Licence pools with hosting rights and geographic rules
  • Cover-down logic for Enterprise Edition
  • Uncapped quantity for unlimited agreements
  • E-Business Suite responsibilities

Reads from

  • Oracle Database
  • Oracle VM
Publisher licence engine

IBM sub-capacity without the ILMT theatre

Sub-capacity is the difference between licensing the cores a workload uses and licensing every core it could run on.

It is also the entitlement most often lost on a technicality. Sub-capacity licensing requires an inventory cycle of thirty minutes or less; miss it and the position reverts to full capacity for the whole period.

Modelled in the licence engine

  • PVU and Virtual Processor Core metrics
  • ILMT connector with compliance gap analysis
  • Component Resolution, scored and bulk-appliable
  • The ≤30-minute inventory cycle, enforced
  • Assignment per device, per processor and per core
  • A continuous position, not a point-in-time reconciliation

Reads from

  • IBM ILMT
  • IBM HMC
Publisher licence engine

SAP without touching production

An SAP licence type is decided by the authorisations a user holds.

Those authorisations live in the system you are least allowed to disturb, so nothing is installed there to read them. Because the licence type is proposed rather than assumed, you can see what a reclassification would cost and what it would save before anyone signs it off.

Modelled in the licence engine

  • Non-invasive ABAP connector
  • Named users de-duplicated across systems
  • Roles, role groups, engines and authorisation definitions
  • Priority-ordered Analysis Rules
  • Current, suggested and optimal positions side by side
  • Audit trail across agreements, transactions and exclusions

Reads from

  • SAP
Publisher licence engine

Microsoft server licensing that understands cores

The Microsoft exposure sits in the server room, where one badly described cluster licences far more cores than it will ever run.

What decides the number is whether the tool knows which hosts a workload can move to, and whether entitlement came from Microsoft’s own record or from a spreadsheet somebody maintains. The Microsoft Licence Statement imports directly into the licence engine.

Modelled in the licence engine

  • Device CALs, user CALs, named user and external connectors
  • SQL Server and Windows Server core and processor licensing
  • Cluster and virtualisation awareness
  • Microsoft Licence Statement (MLS) import
  • Exclude From Licensing for MSDN, dev and training devices
  • Access Control for RDS, Citrix and VDI streamed applications

Reads from

  • Microsoft SCCM
  • Microsoft 365
  • Microsoft Exchange

Six publishers have a publisher-grade licence engine. The entitlement maths and the evidence behind it are computed continuously, so the position is already current on the day the letter arrives.

Microsoft · Oracle · IBM · SAP · Adobe · Salesforce

All four publisher engines are listed above: Oracle first, then IBM, SAP and Microsoft.

Proof

Rated by the people using it.

In the 2024 Gartner® Peer Insights™ Voice of the Customer for Software Asset Management Tools, Certero was the only vendor in the category to achieve the Customers’ Choice position. It is the fourth time customers have put us there, after 2019, 2020, 2021.

  • “Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.”
    • £100k Microsoft compliance risk mitigated
    • 3–4 yrs of SAM maturity accelerated

    NHS South West London ICB

    Reece Emson, ITAM Asset/PSL Manager

  • “The tool has truly transformed how we work, making life a lot easier with complete visibility of assets and automation removing the need for manual intervention.”
    • 130 sites brought into view

    East of England Ambulance Service

    Andy Marrs, IM&T Security & Resilience Manager

  • “When we reviewed the responses to the initial RFP, Certero offered the best solution for our requirements.”
    • 5,500+ devices under management

    Skagit Regional Health

    Project Management Office Lead

  • “My advice to other organizations contemplating RFP’s for ITAM and SAM is: just take Certero.”
    • 4,000 devices

    Global legal firm

    Technology Process Manager

  • “CerteroX for Enterprise ITAM is well worth the investment.”
    • 52 dealerships

    Major automotive group

    IT Asset Manager

  • “Certero was a breath of fresh air, to see a better product and support, offered at the same price.”
    • 99.9% uptime achieved

    Leading technology company

    IT Manager

Behind each of these is a full case study covering the environment it started in, what changed, and what the change was worth.

Read the case studies
Honesty

Where we are not the right fit.

Four situations in which you should buy something other than CerteroX. We would rather say this on the first call than in month four of an implementation. A vendor who cannot name one is not being straight with you.

  1. 01

    You only need cloud cost, and nothing else

    One cloud, no licensing exposure worth defending, barely any hardware: the provider’s own cost tools are free and a point FinOps product is cheaper. Twenty-six named checks are worth having. You would be buying five disciplines to get them and switching on one.

    Buy instead

    Your provider’s native cost console, and a single-purpose FinOps product if it is not enough.

  2. 02

    You have no Unix and no datacentre licensing

    Our depth sits where the money is — Oracle options and core factors, IBM sub-capacity, SAP named users, AIX and Solaris inventory. A Microsoft 365 tenant, some laptops and nothing in a rack is paying for engineering it will never open.

    Buy instead

    A desktop inventory tool alongside the admin centre of the one publisher you actually buy from.

  3. 03

    You want to sign up with a card and never speak to anyone

    There is a deployment. Connectors need credentials, agents need deploying, entitlement needs loading, and the first licence position is only as good as the contracts you can find. We will do that with you. We cannot skip it.

    Buy instead

    Anything with a public sign-up page. It will do less, and it will do it on Tuesday.

  4. 04

    You want one vendor for the service desk too

    We are not an ITSM platform and are not trying to become one. CerteroX integrates with ServiceNow and leaves it in place. If one vendor for tickets and assets is a hard requirement, we are the wrong shortlist.

    Buy instead

    The asset module of the ITSM platform you already run, and accept the depth it comes with.

Privately owned and independent since 2007, which means nobody upstairs needs this quarter’s number badly enough to sell you the wrong thing.

Switching

See the field that joins
two records of one machine.

Third-party ITAM import is one of the ten discovery methods. In the session, records that arrived from two separate ITAM tools in the demo environment collapse to a single asset in front of you.

Nothing to connect for the demo, so no credentials, no firewall exception and no security review between you and the product.