Skip to content
Asset Register

Register  ·  Programme

The Measures Worth Reporting

A short set that shows whether the programme is working, and the longer set that fills dashboards and demonstrates activity.

Reference  ·  682 words

Asset management generates a great deal of countable activity. Only some of it indicates that anything is improving.

The measures that matter

Applications discovered but not registered. The gap between what exists and what is managed. Should trend to near zero and never reach it.

Unowned applications. A rising count means the ownership process has stopped working.

Unused seats and their value, by application. This funds the programme.

Renewals with a decision made before the notice deadline, as a proportion. The measure of whether renewal management works.

Orphaned accounts found per quarter. The audit of offboarding.

Federation rate — proportion of applications behind single sign-on. Correlates with everything else getting easier.

Devices not checked in for thirty days, and devices not encrypted. The two hardware measures that matter.

Overdue vendor reassessments.

Eight measures. They fit on one page and each one names a specific failure when it moves the wrong way.

The measures that mislead

Total application count. Rising is not bad; unmanaged applications rising is bad.

Total spend. Rising with headcount is expected. Spend per head is the useful version.

Number of assets tracked, which measures the register's size rather than its accuracy.

Tickets closed.

Percentage of assets audited, without saying what the audit found.

Access reviews completed, without the removal rate, which is the theatre described elsewhere.

Reading them together

Discovery gap falling while application count rises: the programme is keeping up with growth.

Unused seats falling and spend per head flat: reclamation is working and being offset by new purchases, which is worth investigating.

Orphan count falling: offboarding is improving.

Federation rate rising: every future problem gets easier.

Access review removal rate near zero: the review is not working, whatever the completion rate says.

What to report to whom

Finance: spend, spend per head, savings realised, renewals ahead, chargeback if operated.

Security: federation rate, orphaned accounts, privileged access counts, unassessed applications holding sensitive data, unencrypted devices.

Operations: device counts by status, refresh forecast, support load by model.

Executive: total spend and trend, savings realised, the two or three material risks, and what remains unaddressed.

Each is a page. A single dashboard for all four serves none of them.

The savings claim

Be careful here, because credibility depends on it.

Realised savings: the bill actually went down. Claim these.

Avoided cost: a renewal reduced from what was proposed. Claim these separately and label them.

Theoretical savings: unused seats identified but not yet removed. Do not claim these as savings; report them as an opportunity with a date.

Programmes that claim the third as the first lose credibility with finance permanently the first time someone checks the general ledger.

The annual view

What was found, what was fixed, what it saved.

What the estate looks like now against a year ago, using a register snapshot.

What the programme cannot currently see, which is the honest section and the one that justifies the next investment.

The one-page monthly report

Eight numbers, a short comment on each, and nothing else.

Applications registered, and the discovery gap.

Unowned applications.

Unused seats and their annual value.

Renewals with a decision made before the notice deadline, as a proportion.

Orphaned accounts found this period.

Federation rate.

Devices not checked in for thirty days, and unencrypted devices.

Overdue vendor reassessments.

A sentence per number, naming what moved and why. Trends matter more than levels, and a number with no comment gets ignored within three months.

Presenting a number you cannot fully support

Most asset figures are estimates, and how they are presented determines whether the register stays credible.

State the sources the figure is built from.

State the known blind spots, briefly.

Give a range where a range is honest, rather than a midpoint.

Put the caveat in the report, not in the covering email, because the report is what circulates.

Update the figure when coverage improves, and explain that a rise reflects better discovery rather than a worse estate.

A programme caught presenting a precise number it could not support loses the argument on every subsequent number, which is a much larger cost than the imprecision.