Skip to content
Asset Register

Register  ·  Programme

Rolling Out the Programme

The order matters more than the tooling. Discovery first, ownership second, controls last — and the reverse order is why programmes stall.

Procedure  ·  695 words

Programmes fail by starting with the control rather than the inventory, which produces resistance before there is anything to resist for.

The sequence

One: discover. Identity provider, expense data, OAuth grants. No policy changes, no announcements. Establish what exists.

Two: build the register. Reconcile, deduplicate, record the ten fields.

Three: assign ownership. Name a person per application and tell them.

Four: produce the first finding. Unused seats, or a duplicate, or a renewal about to happen at a higher price. Something concrete and financial.

Five: act on renewals. The calendar, the ninety-day cadence. This is where the money is and it requires no policy.

Six: introduce the request path, made genuinely fast.

Seven: add controls. Payment method conditions, OAuth restrictions, SSO requirements.

Most programmes start at seven, which is a policy announcement with no data behind it and no demonstrated value.

Why the order matters

A finding funds the programme. Discovery that produces a saving in month two buys the credibility for everything after.

Ownership before control. Asking an owner to confirm seats is collaborative; imposing a control on an unowned application is an edict from nowhere.

Controls after the fast path exists. Restricting purchases before there is a working alternative produces exactly the shadow IT the programme is meant to reduce.

The first ninety days

Weeks one to three: pull the three data sources, reconcile, build the register.

Weeks four to six: assign owners, tell them, ask the three quarterly questions once.

Weeks seven to nine: unused seat analysis on the ten largest applications; build the renewal calendar sorted by notice date.

Weeks ten to twelve: act on the first renewal, report the first saving, propose the request path.

Nothing in that requires a purchase, and it produces a register, an ownership model, a renewal calendar and a number.

Who to bring in, and when

Finance, first. They hold the expense data, they benefit most obviously, and the payment-method control is theirs.

Security, early. The OAuth findings and the administrator lists are theirs and they are usually the most alarming output.

Team leaders, at ownership. Not before, because there is nothing to say yet.

Executive, at the first saving, with the number.

HR, at the offboarding work, which is where the leaver trigger lives.

What produces resistance

Removing tools people use, before demonstrating any benefit.

Bulk-removing accounts without confirmation.

A slow approval process introduced as the only route.

Reporting on teams before talking to them.

Framing it as a cost-cutting exercise, which makes every owner defensive about their own application.

What builds support

The first saving, attributed to the team that acted on it.

Removing a tool nobody wanted to pay for.

Finding a licence someone was about to buy that the organisation already had.

Fixing an offboarding gap before it causes an incident.

Fast answers to requests, which is what people actually want from the process.

The first finding, chosen carefully

The first result the programme reports sets how everything after it is received.

Pick something financial and uncontested. A duplicate subscription, a renewal about to increase, seats belonging to people who left.

Not a policy violation, and not something that requires taking a tool away from a team.

Attribute it to the team that acted, not to the programme.

Quantify it in currency, annually.

Verify it in the ledger before reporting it, which is what distinguishes a saving from an opportunity.

Report it to finance first. They fund the next phase, and a verified number from them carries further than the same number from IT.

What to do when it stalls

Most programmes stall after the discovery phase, and the causes are a short list.

No owner for the register, so it stops being refreshed. Name someone with allocated time.

No finding reported, so nobody sees value. Find one and report it.

Controls introduced too early, producing resistance. Withdraw them and rebuild through the renewal work.

Ownership assigned but never exercised, so it means nothing. Send the quarterly email.

The sponsor moved on. Re-establish with whoever benefits most, usually finance.

Diagnose which one it is before proposing more tooling, since a platform purchased to restart a stalled programme usually stalls with it.