Finding Unused Licences
The largest saving available, from data most organisations already hold. The method takes an afternoon; the argument afterwards takes longer.
Procedure · 740 words
Twenty to thirty percent of assigned seats unused is a common first measurement. Finding them is mechanical; acting on them requires the renewal calendar and an owner.
The method
For each application, pull the assigned user list from the vendor's admin console or your identity provider.
Pull last activity per user. Last login is the usual proxy and it is imperfect — see below.
Classify: never logged in, no activity in ninety days, no activity in thirty days, active.
Compare assigned seats against purchased seats, which are frequently different numbers.
Produce three figures per application: purchased, assigned, actively used.
The gap between purchased and actively used is the opportunity.
Where last login misleads
Integration and API usage may not create a login event. A user who consumes the application entirely through another tool looks dormant.
Mobile applications sometimes maintain sessions for months without a fresh authentication.
Service accounts look permanently dormant and must not be removed.
Seasonal roles. Someone who uses a tool at quarter end looks inactive for eleven weeks of every thirteen.
Check for these before acting, and prefer activity data from the vendor over authentication data from your identity provider where both exist.
Acting on the finding
Never bulk-remove. One wrongly removed account costs more in trust than the licence saves.
Send the list to the application owner, with names and last activity dates, and ask them to confirm.
Give a deadline and a default. "Accounts not confirmed by the 30th will be suspended, not deleted, and can be restored on request." Suspension rather than deletion makes the action reversible and removes most of the objection.
Suspend, wait two weeks, then remove. The people who needed it will surface in the first three days.
Record what happened, so the same accounts are not re-examined next quarter.
Converting removal into money
The step that is frequently missed.
Removing an assigned seat does not reduce the bill unless the purchased quantity is reduced, and that usually requires a contract action at renewal.
So the sequence is: reclaim seats now, record the reduced requirement, and act on it at renewal.
Maintain a running figure per application: seats we are paying for that we do not need. This number is the input to the renewal conversation and it has to be accumulated over the term rather than discovered in the final week.
The recurring cycle
Quarterly per application, or monthly for the largest.
Automate the extract, because doing it by hand once produces a saving and doing it on a schedule produces a programme.
Report the trend, not just the level. Unused seats creeping back up between reviews indicates the joiner process assigns access by default rather than on request.
The default-access problem
Where new joiners are automatically granted every application, unused seats regenerate continuously.
Check how access is assigned. Role-based provisioning that grants a standard bundle is convenient and expensive.
Split the bundle: a small universal set, and everything else on request.
Measure the effect on assigned-versus-used six months later. This is usually a larger structural saving than any individual reclamation exercise.
The suspension notice
The wording that produces cooperation rather than escalation, since the mechanism matters more than the analysis.
Name the application and the date of last activity, specifically.
Say what will happen and when: suspension, not deletion, on a stated date.
Say how to keep it: one reply, no justification required.
Say how to get it back: restoration on request, same day.
Copy the manager, not for enforcement but because they frequently know the person moved role.
Give two weeks.
Almost all objections arrive in the first three days, and almost all of them are legitimate — an API user, a seasonal role, someone on leave. The remainder is your saving, and it is uncontested because the process was reversible throughout.
The default-access audit
Reclamation is a one-off saving. Fixing how access is granted is a structural one.
Look at what a new joiner receives automatically.
Count the applications in the standard bundle and compare against what a joiner actually uses after three months.
The gap regenerates continuously, which is why unused seats reappear between reviews.
Split the bundle: a small universal set, everything else on request through the fast path.
Measure assigned-versus-used six months later for a cohort of joiners, against a cohort from before the change.
This is usually a larger saving than any single reclamation exercise and it does not need repeating every quarter.