Doing This With No Dedicated Staff
A useful register for an organisation with no asset manager, no platform and no budget. Two hours a month, and it covers most of the value.
Procedure · 670 words
Most of the practice in this field assumes a dedicated function. Most organisations do not have one and still need the answers.
The minimum viable register
A spreadsheet. One row per application, ten columns.
Name, owner, what it does, users, annual cost, renewal date, notice deadline, data classification, SSO yes or no, discovery source.
A second sheet for hardware: tag, serial, model, assigned to, purchase date, warranty expiry, status.
That is the whole system, and it answers most questions asked of a larger one.
The initial build
Half a day: export the application list from your identity provider.
Half a day: export twelve months of card and invoice spend and match it against that list.
Two hours: export OAuth grants from your email and file platform.
Half a day: reconcile the three, deduplicate, fill in owners from memory and by asking.
Two days total produces a register that most organisations of this size have never had.
The monthly routine
Two hours, once a month.
Refresh the three exports and diff against last month. New applications, new spend, new grants.
Look at the renewal sheet: anything with a notice deadline in the next ninety days.
Check for leavers since last month and confirm their access was removed everywhere, not just in the directory.
That is it. Two hours, and it covers discovery, renewals and the offboarding audit.
The quarterly routine
Half a day.
Email every owner the three questions: still needed, right people, data changed.
Pull last-login for the five largest applications and look at dormant seats.
Reconcile the hardware sheet against endpoint management.
Check for accounts with external email domains.
What to skip
Chargeback. Not worth it below a certain size.
A platform. Under roughly fifty applications the spreadsheet genuinely wins.
Formal access review campaigns. The quarterly owner email covers it at this scale.
Elaborate classification. Two levels — sensitive or not — is enough to drive the decisions.
Detailed peripheral tracking.
What not to skip
The renewal calendar, which is where the money is.
Ownership, which is where the decisions come from.
OAuth grants, which is where the data exposure is and which costs two hours.
Offboarding beyond the directory, which is where the security failures are.
Device encryption, which is one setting and the highest-return control available.
The realistic expectation
A small organisation running this routine will find, in the first year: applications nobody uses, at least one duplicate, several renewals it can reduce, a set of OAuth grants that should not exist, and accounts belonging to people who left.
None of that requires a platform, a specialist or a budget. It requires a spreadsheet, two hours a month, and someone whose job it is.
That last one is the actual constraint, and naming a person is the decision that determines whether any of this happens.
The one-page policy
Small organisations need a policy short enough that people read it, which means one page.
Software purchases go through one person, named.
Recurring charges require registration before the card is used.
Company data goes in registered applications only.
Anything holding customer or employee data gets a look before it is used.
Departures: accounts closed everywhere, device returned, grants revoked.
Devices are encrypted and enrolled.
Six rules. Longer policies at this scale are not read and not followed, and an unread policy provides neither protection nor evidence.
The named person
The actual constraint at this scale, and the one decision that determines whether any of it happens.
Two hours a month, allocated, not squeezed into a role that is already full.
A named individual, not a team or a function.
Access to the three data sources, agreed with finance and whoever administers identity.
Authority to ask owners questions and to expect answers.
A route to escalate a renewal decision that needs one.
Somebody senior who reads the monthly page, because a report nobody reads stops being written within a quarter.
Everything else in these notes is method. This is the prerequisite, and programmes fail here more often than anywhere else.