Thirty years of enterprise IT, distilled into something you can use on Monday morning.
Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Host Bill Van Nort has led IT asset management, end-user computing, and workplace technology at large organizations across banking, mortgage, and automotive, reclaimed millions in software spend, and survived audits from the biggest publishers on the planet.
No vendor pitches disguised as advice. No jargon for its own sake. When something is an opinion, he says so. When the honest answer is "it depends," he tells you what it depends on.
New episodes cover the fundamentals that never change: know what you have, know where it is, know what it costs, know when it leaves.
Hey everybody and welcome back to the Operational ITAM podcast.
I'm Bill Van Nort and this is episode 3, the one I told you to bring your skepticism to.
I hope you packed it because today we cross over to the intangible side of the
house, software asset management, licenses, entitlements, audits,
and the publishers who profit from your confusion.
If you're joining us for the first time, welcome. Genuinely glad you're here.
I'd suggest starting with episodes one and two, because we build on each other around here.
But if you want to jump in the deep end with us today, hey, I admire the confidence. Come on in.
Good morning, good afternoon, or good evening, wherever you happen to be listening from.
This is the operational ITAM podcast, the show where we take the unglamorous
machinery of enterprise technology and make it make sense.
I'm your host, Bill, and today's episode might be the most expensive one we ever do.
Not for you, for the publishers, once you learn what I'm about to teach you.
Welcome in. Grab your coffee, grab your headphones, and let's get into it.
So, last episode we walked the hardware lifecycle gate by gate.
Seven gates, seven failure modes, one discipline. Custody.
The record follows the asset.
And here's the thing about hardware. For all its problems, hardware has one enormous advantage.
You can touch it. You can put a tag on it. You can, in a pinch,
walk into a stock room and count it.
Software has none of those advantages. You can't touch it. You can't tag it.
And here's the part that changes everything. You don't even own it.
Let me say that again because it's the foundation of this entire episode.
When your company buys software, it does not buy software. It buys a right.
A narrowly defined, contractually bounded, publisher-authored right to use software
in a specific way, measured by a specific metric, under conditions written by the seller's lawyers.
That document is called a license, and the rights it grants you are called entitlements.
And the distance between what you're entitled to do and what you're actually doing?
That distance is measured in dollars, sometimes millions of them.
I know because I've recovered millions of them, and I've watched other organizations
pay millions of them to publishers at settlement tables with very unhappy CFOs in the room.
So today we're learning to measure that distance.
Software Everything in this field gets a three-letter acronym,
it's practically a bylaw, is the discipline of managing software entitlements
and software deployments across
their lifecycle, and continuously reconciling one against the other.
Hardware Asset Management was a custody discipline. Software Asset Management
is a bookkeeping discipline. And I mean that literally.
Here's the mental model I want you to carry out of this episode.
Picture an old-fashioned ledger. Double entry. Two columns.
On the left side, everything you're entitled to use. On the right side,
everything you're actually using.
SAM is the practice of keeping both columns accurate and comparing them. Constantly.
That comparison has a formal name. The Effective License Position, or ELP.
Write that down, because the ELP is to software what the physical inventory
count is to hardware. It is the moment of truth.
Let's build the ledger, one side at a time. Side 1. Entitlements.
What you have the right to use.
An entitlement is born the same place a hardware asset record is born.
Remember gate 2? At the purchase.
But an entitlement is more demanding than a hardware record,
because an entitlement is only as good as its proof.
Here's what must be captured. The product. The version and addition.
The quantity. The license metric. Hold that thought. We're coming back to metrics.
The purchase order, the agreement it was purchased under, the reseller,
the dates, and the proof of purchase itself.
Contracts, order forms, invoices, the actual paper.
And here's how it fails. The proof is scattered. Some of it's in procurement
system, some of it's in a filing cabinet from an acquisition eight years ago,
some of it's in the inbox of a person who retired.
I have personally watched a company repurchase licenses it already owned,
paid twice for the same rights, because nobody could produce the evidence from the first purchase.
In an audit, an entitlement you can't prove is an entitlement you don't have.
The publisher's auditor is not going to take your word for it. Would you?
Now, the metrics. This is where software licensing earns its reputation.
Hardware gets counted in units. Simple. Software gets counted in whatever unit
of measure the publisher's revenue strategy requires this year.
Per device, per named user, per concurrent user, per processor,
per core, and cores come with counting rules, and the counting rules come with
exceptions, and the exceptions come with footnotes.
Per server, per virtual machine, and the newest arrival, the one we'll talk
about after the break, per employee, as in every single one,
whether they use the product or not.
Each metric is a different unit of measure, which means each product in your
estate is being counted in a different currency, and your ledger has to speak
all of them. That is the job.
Nobody said it was a small one.
Side 2. Deployments. What you're actually using.
This side of the ledger comes from discovery. Your endpoint management platform.
Your server inventory. Your cloud consoles. Telling you what's installed and running.
And if you remember episode 1, I told you your endpoint management platform
already knows what's connected.
That's still true, and this is where that data goes to work.
But raw discovery data is a crime scene. It has to be normalized before it means anything.
Here's what I mean. Ask a discovery tool what's installed, and it will tell
you the same product 40 different ways.
Different casing, different version strings, different bundle names,
publisher names spelled six ways.
Normalization is the unglamorous, essential work of translating that chaos into a clean statement.
This product, this edition, this version, this many installs.
No normalization, no ledger. Just noise with a user interface.
And there's one more layer, and it's where the money hides. Installed is not the same as used.
A copy of an expensive engineering application sitting untouched on a laptop
for 11 months is a deployment on your ledger and a waste in your budget.
Metering, measuring actual usage, not just presence, is how you find those.
Remember the ghost from episode 2? Records without devices, still drawing a salary?
Software has ghost too. We call it shelfware. Licenses purchased,
deployed maybe, used never.
Hold that thought too, because after the break, I'm going to put numbers on
it. And the numbers are worse than you think.
So entitlements on the left, normalized deployments on the right.
Now the reconciliation. product by product, metric by metric, you compare.
Three outcomes are possible. Outcome one, the columns balance.
Enjoy the moment, frame it.
Outcome two, you're over-licensed. You own more than you use.
That's shelfware, and it's not a compliance problem, it's a savings problem.
Those are dollars on the table at your next renewal, if you have the data to
prove it, and the spine to act on it.
Outcome three, you're under licensed. You're using more than you own.
That's a compliance gap. And a compliance gap is a debt. You may not know the amount yet.
You may not know the due date, but somebody is going to collect it.
And next, I'll introduce you to the collectors.
If you're enjoying the show, do me a favor, like and subscribe,
post your comments, and share this one with whoever handles your next software renewal.
Trust me, they either already know all this, or they really need to.
Alright, now on to the collectors. Let's talk about audits.
Here's the fact of life. Nobody puts on the sales slide. Buried in virtually
every enterprise software agreement you have ever signed is an audit clause.
It grants the publisher the right to verify your usage against your entitlements,
usually with 30 or 45 days' notice, sometimes through a designated third-party audit firm.
You agreed to it. Everyone agrees to it. It's about as negotiable as gravity.
And here's my opinion, clearly labeled as an opinion, per the House rules,
though it's an opinion with three decades of scar tissue behind it.
For certain publishers, the audit is not a compliance function. It's a sales function.
The audit letter arrives, mysteriously, in the quarter before your renewal.
The findings arrive with an eye-watering number attached. And then,
what a coincidence, the number can shrink dramatically if you'd like to sign
a bigger agreement, a longer term, maybe a nice cloud commitment.
That's not an audit. That's a negotiation that opens with a subpoena.
I've survived audits from the biggest publishers on the planet.
I'll teach you the full defense playbook in an upcoming two-parter,
from the moment the letter lands to the handshake at settlement.
Today, I just need you to understand the exposure. And there is no better teacher
right now than two current events. Skepticism ready? Good.
Current event number one, Oracle and Java. For most of its life,
Java was treated like air, free, everywhere, unremarkable.
It's in your applications, your appliances, your middleware,
tucked into installers nobody remembers running.
Then the licensing changed, and in 2023, it changed in a way this industry had never seen.
Oracle moved Java to what they call the Java SE Universal subscription, priced per employee.
Not per user of Java, not per installation, per employee, full-time,
part-time, contractors, everyone on the roster, whether they've ever touched Java or not.
Sit with that math. 10,000 employees and 100 servers running Java?
You're paying for 10,000.
The install count is almost irrelevant. The head count is the meter.
It is the most aggressive metric change in enterprise software in my three decades,
and right now, this year, the enforcement wave is cresting.
The friendly emails asking to discuss your Java usage have matured into formal
audit letters, addressed to CIOs and CFOs by name.
And here's the detail that should raise the hair on your neck.
One known trigger is Oracle's own download logs.
They know which companies downloaded Java from their website.
They've had years to gather that data.
The letter isn't a fishing trip. They already know the fish is in the boat.
Now the SAM response, and notice it's just our ledger doing its job.
Right column first. Discover every Java installation in the estate and identify
which distribution it is,
because Oracle's JDK is licensable, and the open-source OpenJDK builds from
other providers are not.
That distinction is the entire ballgame, and it lives in your normalization data.
Then the left column. What, if anything, are you entitled to?
And then the strategic decision, because for a lot of organizations,
the honest answer to this metric is an exit.
Migrate to a supported OpenJDK distribution, document the migration,
and decline to pay a per-employee toll for a runtime that lives on a minority of your machines.
That's not a loophole, that's asset management. Current event number two, Broadcom and VMware.
If your data center runs VMware, and statistically it does, you already know
this story, probably from painful first-hand experience.
Broadcom acquired VMware and, in short order, ended perpetual licensing entirely.
Subscription only. 160 products collapsed into a handful of bundles.
Pricing moved to per core, with a 16 core minimum per processor,
whether your processor has 16 cores or not.
Customers opening renewal quotes have reported multiples, not percentages,
multiples of their previous costs.
And customers running on old perpetual licenses with expired support have received
cease and desist letters over patches.
Audit activity is up. Compliance reporting obligations are tighter.
Here's the lesson, and it's bigger than either vendor. The metric can change underneath you.
You can be perfectly compliant, perfectly optimized, and a strategy decision
in someone else's boardroom redraws your entire cost model overnight.
Java's meter became your org chart. VMware's meter became your core count,
with a minimum you don't control.
The only defense is the ledger. Know your entitlements, know your deployments,
know your contract terms, before the letter arrives.
Because every one of these situations is negotiable, but only for the customer
who shows up with evidence.
The customer who shows up with a shrug pays list price, or worse.
One more stop before we close the ledger, SaaS. Because I can hear somebody
out there saying, Bill, this is all legacy stuff.
We're a cloud company. We subscribe to everything. Audits can't touch us.
Congratulations. You've traded the compliance problem for a waste problem,
and the waste problem might be bigger.
Here's the current state of play, and these numbers are recent research, not folklore.
The average organization now runs roughly 300 SaaS applications.
Industry studies put unused or underutilized SaaS licenses somewhere between 30 and 50 percent.
One 2026 analysis found the average organization actively using barely half
the licenses it pays for, with the waste at large enterprises measured in the
tens of millions of dollars.
Per year. Per company. Where does it come from?
You already know, because it's the same failure modes wearing new costumes.
Remember gate six, recovery, the most broken stage in the hardware life cycle?
The employee leaves, the laptop never comes back? Same thing happens with SaaS
seats, except worse, because there's no physical object to miss.
The person departs, the single sign-on gets disabled, and the 11 paid subscriptions
attached to that person just keep renewing.
Quietly. Forever.
That's a ghost with a credit card. And Shadow IT.
Remember the request that happens outside the process? A department swipes a
card, a tool appears, it auto-renews for years, and your ledger never hears about it.
The fix is not exotic. Tie license recovery to offboarding, the same way we
tied device recovery to offboarding.
No departure ticket closes until the seats are reclaimed.
Meter actual usage before every renewal,
and walk into that renewal with utilization data instead of vibes.
30% of your seats untouched in 90 days is not trivia. It's your negotiating position.
Alright, let's extend the library one more time because it's earned its place on this show.
If the estate is a library, then software is the strangest section in the building,
because none of these books are yours.
Every volume on these shelves is on loan from the publisher,
and every loan has terms.
Some books you can lend to anyone in the building. Some are chained to a single desk.
Some are priced by how many people work in the building, whether they read or
not. And yes, that's as absurd in the library as it is in your data center.
Entitlements are the loan agreements in the file cabinet. Discovery is walking
the shelves to see what's actually there.
The ELP is comparing the two. And an audit? An audit is the publisher walking
in unannounced, asking to see the file cabinet, and charging you retroactive
late fees for every book you can't produce paperwork for.
The books were never yours, the records are. Guard them accordingly.
One closing principle, in the spirit of the ones that closed the last two episodes.
Hardware asset management is a custody discipline. At every moment,
one accountable party holds the asset, and the record says so.
Software asset management is an evidence discipline. At every moment,
for every product, you can produce proof of what you own and proof of what you're
using, and you know the difference between them.
Custody for the tangible. Evidence for the intangible. Every audit you'll ever
face. Every renewal you'll ever negotiate.
Every dollar you'll ever reclaim.
All of it resolves to those two proofs. Keep the ledger and the ledger keeps you.
Class dismissed. And here's your homework.
This one has a due date and the due date is before Oracle's letter shows up.
Pick one publisher. Just one. And if you can't decide, make it Java.
This week, pull two lists. List one. Every installation of that publisher's
products your discovery tools can see.
List 2. Every entitlement you can actually prove. Real documents,
in hand. Not, I think we bought that.
Put them side by side. One product, one row. One honest comparison.
That's your first effective license position, and I promise you,
it will teach you more about your program in one page than any maturity assessment ever will.
If the columns balance, congratulations, and frankly, I'd like to shake your hand.
If they don't, well, now you know which episodes are coming next.
And that's exactly the tease. Next episode, we begin the audit defense two-parter
I promised back in episode one.
The letter has landed. It's addressed to your CIO. The publisher wants an answer in 45 days.
What you do in the first week determines what you pay in the last one.
And almost everybody plays that first week wrong. Do not miss it.
That's today's episode. You now understand the ledger, entitlements on the left,
deployments on the right, and the truth in between.
That's software asset management. Not all the details, but enough to be dangerous
in the best possible way.
I'm Bill Van Nort. This is the Operational ITAM Podcast. Keep your receipts,
and I'll talk to you next week. Take care.