Five disciplines (ITAM, SAM, SaaS, Cloud and AI) on one data model, built in one
place. Nothing here was bought and bolted on, which is why there is nothing between
the products for you to integrate.
Five products can be bought. One data model has to be built.
A discipline added by acquisition arrives with its own schema, its own identifiers and its own console. Making those agree is not a feature the vendor ships. It is a project you run, and it does not finish.
You are almost certainly comparing us with a portfolio: asset management sold under
several brands at once, one brand per discipline, each carrying the schema and the
console it was built with. Underneath the brand names, each product keeps its own
identifiers.
So ask the question that decides everything downstream:
when two products both discover the same server, which one holds the master
record, and what field joins them? Every duplicate asset record and every reconciliation project descends from that one
answer.
We are not going to argue with the number. We think it is right. The
disagreement is about whether five products that were never designed
together can tell you who owns the waste.
29% of cloud spend is wasted — up for the first time in five years
Assembled from products
10 integration surfaces
One person becomes five records, with five identifiers
A separate login and a separate permission model per product
A data model per product, versioned per product
An integration tax charged again on every release
Built as one platform
0 integrations to build
One person is one record, with one identifier
One login, and permissions set once for all five
One schema across all five disciplines
Adding the next discipline adds no integration work
One data model
One person. Five asset classes. One owner.
On one platform, a device found by the agent, the licence installed on it, the SaaS seat held by the same person, the cloud resource they own and the AI model they call are five nodes on one graph. Assembled from five products, the same five are separate records carrying five identifiers, with nothing joining them.
One person, five asset classes
Asset classRecordOwner
Device
LON-LT-4471 · Windows 11 laptop
discovered_by
·
Inventory agent, reconciled against the Active Directory import.
Owner
USR·4471 · J. Whitfield
resolved once, on the asset graph
↳ same owner
LON-LT-4471
hostname only, no person on the record
Licence
Visio Professional · per-device entitlement
entitled_on
·
Installed on that device. Zero executions in the rolling 90-day usage window.
Owner
USR·4471 · J. Whitfield
resolved once, on the asset graph
↳ same owner
WHITFIELD_J
directory account name
SaaS seat
Design collaboration app · editor tier
assigned_to
·
Identity provider sync, vendor connector and browser extension all agree.
Owner
USR·4471 · J. Whitfield
resolved once, on the asset graph
↳ same owner
j.whitfield@
email address, from the vendor API
Cloud resource
Compute instance · stopped, still allocated
owned_by
·
Placed in a cost pool automatically, by one of nine assignment rule condition types.
Owner
USR·4471 · J. Whitfield
resolved once, on the asset graph
↳ same owner
owner=jwhitfield
free-text tag, spelled three ways
AI workload
LLM seat + GPU executor on a sweep
called_by
·
Shadow AI classified from feature tags; the executor gets the same 26 cost checks.
Owner
USR·4471 · J. Whitfield
resolved once, on the asset graph
↳ same owner
usr_8812
vendor-side identifier
Every one of the five records resolves to the same owner, USR·4471 · J. Whitfield, on the asset graph.
Five records, five owner identifiers. Device: LON-LT-4471, hostname only, no person on the record. Licence: WHITFIELD_J, directory account name. SaaS seat: j.whitfield@, email address, from the vendor API. Cloud resource: owner=jwhitfield, free-text tag, spelled three ways. AI workload: usr_8812, vendor-side identifier.
One value, five times. Harvest the
unused licence, reclaim the seat, deallocate the instance and revoke the AI grant. One
decision about one person, taken once.
Five values, one person. Before
anyone can act, something has to match them, and keep matching them every time a record
changes in any of the five products.
These identifiers are illustrative sample records.
Both owner states are shown above: unified first, then the identifiers the same person
carries when the five disciplines were bought separately.
Resolved.
Active Directory, the identity provider and the vendor connector converge on one user, once.
Joined.
The licence knows the device. The device knows the owner. The owner holds the seat and the instance.
Actionable.
Four tickets in four tools become one decision.
An honest comparison
Capability by capability.
Fourteen capabilities in four groups, and the right-hand column is an architecture: what a portfolio assembled from separately built products does, whoever sells it.
Capability comparison between CerteroX and a typical suite assembled from separately built
products.
Capability
CerteroXOne platform, five disciplines
Typical acquired suiteThe architectural pattern, not a named product
Architecture
Unified data model
One schema across ITAM, SAM, SaaS, Cloud and AI. A device, the licence against it, the seat, the resource and the model resolve to one asset graph with one owner.
A data model per product. The join between them is a reconciliation layer somebody has to build, own and re-run, usually forever.
Discovery methods
Ten, landing in one schema: agent, command-line (csinvcli), agentless, standalone, network scan, Active Directory, third-party ITAM import, cloud and SaaS connectors, browser monitoring, file metering.
Discovery arrives with each product. Two products that both find a device produce two device records, and de-duplication becomes a standing project.
Consoles and permissions
One console, one login, one role-based access model, with Zones for multi-entity data and Reporting Levels restricting visibility by organisational unit or location.
One console per brand in the portfolio is the usual arrangement, a portal in front of them, and a permission model inside each.
Depth where it hurts
Unix and datacentre platforms
Native inventory agent for IBM AIX, HP-UX and Oracle Solaris: six operating system families on the same inventory cycle and the same licence engine as Windows, macOS and Linux.
A separate module, a partner tool or a script drop, wherever the discipline arrived separately. Rarely the same agent, and rarely the same licence engine.
Oracle options and core factors
All six of the places an Oracle finding hides are modelled in the licence engine. Each one carries the evidence that produced it and a manual override for when your contract says otherwise.
Install counts and editions are the easy part. The audit finding lives in the options, the core factors and the cover-down logic.
Oracle’s own position on the tool
Verified by Oracle License Management Services. Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools.
A short published list, and whether the tool you are comparing appears on it takes an afternoon to establish.
IBM sub-capacity
PVU and Virtual Processor Core metrics, an ILMT connector with compliance gap analysis, scored bulk Component Resolution, and the ≤30-minute inventory cycle sub-capacity licensing requires.
An ILMT import, wherever the tool carries no IBM licence engine of its own. The gap between what ILMT reports and what you are entitled to is the part that decides the invoice.
SAP named users
A non-invasive ABAP connector reads named users de-duplicated across systems, roles, engines and authorisations, and priority-ordered Analysis Rules propose current, suggested and optimal licence types.
A separately licensed module where SAP was not part of the original product, or a partner engagement scoped as a project.
The newer asset classes
SaaS discovery
Forty-seven connectors and three converging signals (identity provider, vendor APIs and a browser extension), so an application is found whether or not it touched SSO.
One signal in the common configuration: the identity provider, or an expense feed. Whatever touches neither stays invisible.
Shadow AI detection
Classified from application feature tags in the catalogue rather than a hardcoded list, then ranked by the share of your organisation using each tool.
Detection generally runs off a maintained list of known AI applications. New tools appear when the vendor adds them.
Named cloud recommendations
Twenty-six named, individually tunable checks across twelve cloud and data platforms, each with its own thresholds, pool exclusions and account skips. FOCUS ingested natively.
A savings figure, arriving without the named check that produced it or the threshold that check used.
MCP server per product
Every CerteroX product exposes a Model Context Protocol server, with scoped per-organisation tokens and every agent tool call audited and quota-tracked.
Emerging. Ask what your agents can query today, and what is written down afterwards.
Expansion and ownership
Adding the second discipline
The second discipline runs on the platform the first one is already on. There is no integration project between them, so no integration project to pay for.
Priced per product. Ask what the second and third cost together, and who pays for the work between them.
Ownership model
Certero Limited, company number 06387180, England and Wales. Independent since 2007.
Portfolio ownership follows investment cycles. Which brands sit together is decided by who bought whom.
Every claim in the CerteroX column
is a named capability we will demonstrate in the product, cell by cell, on request.
Take these into every demo. Including ours.
Five questions that separate one asset graph from five that have to be reconciled. Put them
to us first. We will answer every one on screen, in the product, and then in writing.
01 Is a device found by two of your products one record or two, and which field joins them?
02 Which of your products holds the AIX, HP-UX and Solaris inventory, and is it the same agent?
03 Show the Oracle options and packs evidence, and the core factor applied, on one host.
04 Show the gap between the ILMT position and the entitlement, in the product.
05 How many consoles and permission models will my team hold logins for?
Depth where it hurts
The publishers that actually bite.
Depth in Oracle, IBM, SAP and Microsoft server licensing is years of entitlement maths, and it only pays off in the room where the audit is settled.
Verified by the publisher
Oracle LMS/GLAS verified
Verified by Oracle License Management Services. Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools.
Every SAM tool can produce an Oracle number. In an Oracle engagement the only question that matters is whose number is accepted — and that is settled long before anyone opens a spreadsheet. Each option and pack finding carries the evidence that produced it and a manual override for the cases your contract already decided.
Options and packs, with evidence and manual override
Processor types and core factors applied per host
Licence pools with hosting rights and geographic rules
Cover-down logic for Enterprise Edition
Uncapped quantity for unlimited agreements
E-Business Suite responsibilities
Reads from
Oracle Database
Oracle VM
Publisher licence engine
IBM sub-capacity without the ILMT theatre
Sub-capacity is the difference between licensing the cores a workload uses and licensing every core it could run on.
It is also the entitlement most often lost on a technicality. Sub-capacity licensing requires an inventory cycle of thirty minutes or less; miss it and the position reverts to full capacity for the whole period.
A continuous position, not a point-in-time reconciliation
Reads from
IBM ILMT
IBM HMC
Publisher licence engine
SAP without touching production
An SAP licence type is decided by the authorisations a user holds.
Those authorisations live in the system you are least allowed to disturb, so nothing is installed there to read them. Because the licence type is proposed rather than assumed, you can see what a reclassification would cost and what it would save before anyone signs it off.
Roles, role groups, engines and authorisation definitions
Priority-ordered Analysis Rules
Current, suggested and optimal positions side by side
Audit trail across agreements, transactions and exclusions
Reads from
SAP
Publisher licence engine
Microsoft server licensing that understands cores
The Microsoft exposure sits in the server room, where one badly described cluster licences far more cores than it will ever run.
What decides the number is whether the tool knows which hosts a workload can move to, and whether entitlement came from Microsoft’s own record or from a spreadsheet somebody maintains. The Microsoft Licence Statement imports directly into the licence engine.
Device CALs, user CALs, named user and external connectors
SQL Server and Windows Server core and processor licensing
Cluster and virtualisation awareness
Microsoft Licence Statement (MLS) import
Exclude From Licensing for MSDN, dev and training devices
Access Control for RDS, Citrix and VDI streamed applications
Reads from
Microsoft SCCM
Microsoft 365
Microsoft Exchange
Six publishers have a publisher-grade licence engine. The entitlement maths and the
evidence behind it are computed continuously, so the position is already current on the
day the letter arrives.
Microsoft · Oracle · IBM · SAP · Adobe · Salesforce
All four publisher engines are listed above: Oracle first, then IBM, SAP and Microsoft.
Proof
Rated by the people using it.
In the 2024 Gartner® Peer Insights™ Voice of the Customer for Software Asset Management Tools, Certero was the only vendor in the category
to achieve the Customers’ Choice position. It is the fourth time customers have
put us there, after 2019, 2020, 2021.
“Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.”
£100k Microsoft compliance risk mitigated
3–4 yrs of SAM maturity accelerated
NHS South West London ICB
Reece Emson, ITAM Asset/PSL Manager
“The tool has truly transformed how we work, making life a lot easier with complete visibility of assets and automation removing the need for manual intervention.”
130 sites brought into view
East of England Ambulance Service
Andy Marrs, IM&T Security & Resilience Manager
“When we reviewed the responses to the initial RFP, Certero offered the best solution for our requirements.”
5,500+ devices under management
Skagit Regional Health
Project Management Office Lead
“My advice to other organizations contemplating RFP’s for ITAM and SAM is: just take Certero.”
4,000 devices
Global legal firm
Technology Process Manager
“CerteroX for Enterprise ITAM is well worth the investment.”
52 dealerships
Major automotive group
IT Asset Manager
“Certero was a breath of fresh air, to see a better product and support, offered at the same price.”
99.9% uptime achieved
Leading technology company
IT Manager
Behind each of these is a full case study covering the environment it started in, what
changed, and what the change was worth.
Four situations in which you should buy something other than CerteroX. We would rather say this on the first call than in month four of an implementation. A vendor who cannot name one is not being straight with you.
01
You only need cloud cost, and nothing else
One cloud, no licensing exposure worth defending, barely any hardware: the provider’s own cost tools are free and a point FinOps product is cheaper. Twenty-six named checks are worth having. You would be buying five disciplines to get them and switching on one.
Buy instead
Your provider’s native cost console, and a single-purpose FinOps product if it is not enough.
02
You have no Unix and no datacentre licensing
Our depth sits where the money is — Oracle options and core factors, IBM sub-capacity, SAP named users, AIX and Solaris inventory. A Microsoft 365 tenant, some laptops and nothing in a rack is paying for engineering it will never open.
Buy instead
A desktop inventory tool alongside the admin centre of the one publisher you actually buy from.
03
You want to sign up with a card and never speak to anyone
There is a deployment. Connectors need credentials, agents need deploying, entitlement needs loading, and the first licence position is only as good as the contracts you can find. We will do that with you. We cannot skip it.
Buy instead
Anything with a public sign-up page. It will do less, and it will do it on Tuesday.
04
You want one vendor for the service desk too
We are not an ITSM platform and are not trying to become one. CerteroX integrates with ServiceNow and leaves it in place. If one vendor for tickets and assets is a hard requirement, we are the wrong shortlist.
Buy instead
The asset module of the ITSM platform you already run, and accept the depth it comes with.
Privately owned and independent since 2007, which means nobody upstairs needs this
quarter’s number badly enough to sell you the wrong thing.
Switching
See the field that joins two records of one machine.
Third-party ITAM import is one of the ten discovery methods. In the session, records that arrived from two separate ITAM tools in the demo environment collapse to a single asset in front of you.