Skip to content
Asset Register

You cannot manage what nobody wrote down

Most organisations that measure for the first time find several times more applications than they expected, and a fifth of their paid seats unused. Fifty notes on building the register, finding what discovery misses, controlling the spend, and closing the access nobody remembered to close.

What this is

Fifty notes on managing software subscriptions and IT assets, written for the people who have to produce the answers rather than for the people selling the platforms.

No vendor material, no product recommendations, no sponsored content.

Four things that hold almost everywhere

The count is always low. Ask how many applications an organisation uses and the answer is usually confident and wrong by a factor of three. Nobody bought most of it centrally.

A fifth to a third of paid seats are unused. Assigned to people who left, or to people who logged in twice a year ago. This is the finding that funds the whole exercise, and it is available from data you already have.

Disabling the directory account is the first step, not the last. Applications with local passwords, OAuth grants, personal access tokens, shared credentials and subscriptions on a departing person's card all survive it.

Software helps with the work and creates none of it. The register, the ownership model and the review cycle are the programme. A platform without them produces a dashboard.

Where to start

Starting from nothing: the foundations, then discovery, then the renewal calendar. The first ninety days need no purchase and no policy.

Already have a register: the unused-licence method and the OAuth grant export. Both take an afternoon and both reliably find something.

About to buy a platform: count your applications first. Under roughly fifty, a spreadsheet genuinely wins.

Every record

All 50 notes, grouped by section, each appearing once. Open a section for descriptions.

Foundations

6  ·  4,636 words

Three separate problems share one name, and they need different work. Plus the field that does more than all the others combined: who is accountable for each application still being needed.

Discovery

6  ·  4,517 words

No single source sees your estate. Four sources, each with a different blind spot, plus the reconciliation that is most of the actual work and the gaps that remain after it.

Licences and spend

8  ·  5,592 words

Where the money is: unused seats, over-tiered subscriptions, duplicate tools and renewals that arrive unnoticed at a higher price. Most of it is visible from data you already hold.

Hardware assets

7  ·  4,946 words

The older discipline, and the one organisations are frequently worse at because it lapsed rather than never existed. Including what breaks when you can no longer walk to the device.

Access and leavers

7  ·  4,943 words

Disabling the directory account closes federated applications and nothing else. Twelve things that survive it, plus the review process that produces removals rather than a certification rate.

Security and compliance

7  ·  4,961 words

Reviewing everything to the same depth guarantees nothing gets reviewed. Plus the layer nobody reviews at all: the access your applications have to each other.

Running the programme

8  ·  5,528 words

The order matters more than the tooling. Discovery first, ownership second, controls last — and the reverse order is why most programmes stall after the first phase.

Reference

1  ·  737 words

Terms defined once, plus the ones deliberately avoided here and why.