You cannot manage what nobody wrote down
Most organisations that measure for the first time find several times more applications than they expected, and a fifth of their paid seats unused. Fifty notes on building the register, finding what discovery misses, controlling the spend, and closing the access nobody remembered to close.
What this is
Fifty notes on managing software subscriptions and IT assets, written for the people who have to produce the answers rather than for the people selling the platforms.
No vendor material, no product recommendations, no sponsored content.
Four things that hold almost everywhere
The count is always low. Ask how many applications an organisation uses and the answer is usually confident and wrong by a factor of three. Nobody bought most of it centrally.
A fifth to a third of paid seats are unused. Assigned to people who left, or to people who logged in twice a year ago. This is the finding that funds the whole exercise, and it is available from data you already have.
Disabling the directory account is the first step, not the last. Applications with local passwords, OAuth grants, personal access tokens, shared credentials and subscriptions on a departing person's card all survive it.
Software helps with the work and creates none of it. The register, the ownership model and the review cycle are the programme. A platform without them produces a dashboard.
Where to start
Starting from nothing: the foundations, then discovery, then the renewal calendar. The first ninety days need no purchase and no policy.
Already have a register: the unused-licence method and the OAuth grant export. Both take an afternoon and both reliably find something.
About to buy a platform: count your applications first. Under roughly fifty, a spreadsheet genuinely wins.
Every record
All 50 notes, grouped by section, each appearing once. Open a section for descriptions.
Three separate problems share one name, and they need different work. Plus the field that does more than all the others combined: who is accountable for each application still being needed.
- What SaaS Management Actually IsExplainer802
- IT Asset Management, and How It DiffersExplainer764
- The Inventory ProblemProcedure757
- Shadow IT: Why It ExistsAnalysis759
- Ownership: The Field That Makes It WorkProcedure757
- The Application LifecycleReference797
No single source sees your estate. Four sources, each with a different blind spot, plus the reconciliation that is most of the actual work and the gaps that remain after it.
- Discovery Methods, RankedReference707
- The Identity Provider as a Discovery SourceProcedure764
- Expense and Card Data as a Discovery SourceProcedure748
- OAuth Grants: The Source Nobody ChecksProcedure803
- Reconciling Discovery SourcesProcedure766
- What Discovery MissesAnalysis729
Where the money is: unused seats, over-tiered subscriptions, duplicate tools and renewals that arrive unnoticed at a higher price. Most of it is visible from data you already hold.
- Licence Models and What Each Costs YouReference661
- Finding Unused LicencesProcedure740
- Renewal ManagementProcedure696
- Negotiating a RenewalProcedure718
- Auto-Renewal and Notice PeriodsReference713
- Right-Sizing TiersProcedure684
- Consolidating Overlapping ToolsAnalysis713
- Chargeback and ShowbackAnalysis667
The older discipline, and the one organisations are frequently worse at because it lapsed rather than never existed. Including what breaks when you can no longer walk to the device.
- The Hardware Asset RegisterProcedure673
- Procurement and ReceivingProcedure691
- Assignment and TrackingProcedure679
- Refresh Cycles and Replacement PlanningAnalysis680
- Disposal and Data SanitisationProcedure734
- Repairs, Warranty and SparesReference735
- Managing a Distributed FleetAnalysis754
Disabling the directory account closes federated applications and nothing else. Twelve things that survive it, plus the review process that produces removals rather than a certification rate.
- Joiner, Mover, LeaverProcedure683
- Offboarding: What Gets MissedChecklist639
- Orphaned and Dormant AccountsProcedure722
- Admin and Privileged Access in SaaSProcedure722
- Contractors, Vendors and Third PartiesAnalysis697
- Access Reviews That Are Not TheatreProcedure711
- A Departing Employee's DataProcedure769
Reviewing everything to the same depth guarantees nothing gets reviewed. Plus the layer nobody reviews at all: the access your applications have to each other.
- Assessing SaaS Risk ProportionatelyProcedure714
- App-to-App Access and IntegrationsAnalysis746
- Data Residency and Processing LocationReference732
- Vendor Security Due DiligenceChecklist728
- Producing Compliance Evidence From Asset DataProcedure684
- What Incident Response Needs From Asset DataReference666
- Knowing What Data Is WhereProcedure691
The order matters more than the tooling. Discovery first, ownership second, controls last — and the reverse order is why most programmes stall after the first phase.
- The Measures Worth ReportingReference682
- Evaluating a SaaS Management PlatformChecklist714
- Building the Register YourselfAnalysis676
- Rolling Out the ProgrammeProcedure695
- Designing a Request Path People UseProcedure744
- Joining Asset Data to Everything ElseAnalysis694
- Doing This With No Dedicated StaffProcedure670
- What the Register Cannot Tell YouReference653
Terms defined once, plus the ones deliberately avoided here and why.
- GlossaryReference737