Skip to content
Asset Register

Register  ·  Reference

Glossary

Terms used across these notes, defined once, including the several the industry uses to mean different things and the ones avoided here.

Reference  ·  737 words

Application register — the central list of software the organisation uses, with owner, cost, classification and lifecycle status. The artefact everything else in a SaaS programme references.

Asset tag — a physical label with a unique identifier, applied at receipt. Distinct from the serial number, which the manufacturer assigns.

Break-glass account — a local administrator account kept for emergencies when normal authentication fails. Should be documented, vaulted and monitored.

Chargeback — actually charging software costs to consuming teams' budgets. Distinct from showback, which reports the same figures without moving money.

Discovery — inferring what applications exist, from identity, expense, OAuth and endpoint sources. Never complete.

Dormant account — belongs to a current employee who has stopped using it. A cost problem, distinct from an orphaned account.

Federation rate — the proportion of known applications behind single sign-on. The metric that correlates most strongly with everything else being manageable.

Joiner-mover-leaver — the three events at which access should change. Movers are handled worst, everywhere.

Notice deadline — the date by which a cancellation or reduction must be given, calculated back from the renewal date. The field to sort a renewal calendar on.

OAuth grant — a standing permission for a third-party application to access your data through an API. Persists until revoked and survives password changes.

Orphaned account — belongs to someone no longer with the organisation. A security problem, distinct from a dormant account.

Reconciliation — matching discovery sources against each other and against the register. The bulk of the manual effort in a SaaS programme.

Right-sizing — reducing seat count or tier to actual need. Two separate exercises frequently conflated.

Sanitisation — rendering data on a device unrecoverable before disposal. Deleting files and reinstalling the operating system are not sanitisation.

Shadow IT — applications in use that the organisation has not registered. A symptom of the sanctioned path being slower than the need.

Showback — reporting attributed costs to teams without charging them. Usually sufficient and less distorting than chargeback.

True-up — a reconciliation payment where actual usage exceeded the committed quantity. Common in enterprise agreements and worth forecasting rather than discovering.

Zero-touch enrolment — a device enrolling itself into management on first boot, associating serial to user automatically. The key capability for distributed fleets.

Terms used loosely elsewhere

"Asset" here means something the organisation is accountable for — a device or an application — not everything an accountant would capitalise.

"Licence" is used loosely by vendors to mean a seat, an entitlement or a contractual right. These notes say seat when they mean a per-user allocation.

"Savings" means the bill went down. Anything else is called an opportunity or an avoided cost, and the distinction is deliberate.

"Compliance" means meeting an external obligation, not conformity with an internal policy.

"Coverage" in discovery means the proportion of the estate a source can see, which is never known precisely and should be estimated rather than asserted.

Terms deliberately not used here

Several common terms in this field are avoided in these notes, for reasons worth stating.

"Rationalisation" is used to mean both consolidation and cost-cutting, and the ambiguity is frequently doing work. These notes say consolidation, or say cost reduction.

"Governance" covers everything from an approval form to a committee structure. These notes name the specific mechanism instead.

"Optimisation" usually means removing seats. Said plainly, it is easier to check whether it happened.

"Visibility" is a property of dashboards; the useful version is a register with fields somebody maintains.

"Single pane of glass" describes an aspiration rather than a capability, and organisations that pursue it tend to buy a second system alongside the first.

Sources and further reading

These notes are written from general practice rather than from any single framework, and several bodies of work are worth reading directly.

Formal asset management standards for the lifecycle model and the vocabulary, which are useful even where the process weight is not.

Your own vendors' administrative documentation, which is the authoritative source on what each platform actually exposes and is consistently better than secondary summaries.

Identity platform documentation on provisioning, deprovisioning and OAuth application controls, which changes frequently.

Data protection guidance from your jurisdiction's regulator, for the residency, retention and monitoring questions.

Peer practitioners. Most of what works in this field is transmitted between people doing the job rather than published, and the specifics of what a given vendor will concede at renewal are not written down anywhere.