IT Asset Management: Discovery Solves Half the Problem

Kognitos
A tall wireframe cylinder beside a stack of misaligned lime discs of similar height, with dimension lines marking each and a beam resting across the top of the wireframe

TL;DR

IT asset management tracks what an organization owns, runs, and is entitled to across its technology estate. Compliance rests on comparing two numbers: what is deployed and what is entitled. Discovery tools answer the first reliably. The second cannot be discovered at all, because entitlement lives in contracts, order documents, and amendments rather than on any machine. That asymmetry is where audit exposure comes from.

Key Takeaways: An effective license position compares deployment against entitlement. Deployment is a technical measurement and largely solved. Entitlement is a documentary reconstruction and largely is not, since no single source proves what you hold. Vendor audits place the burden of proof on the customer under short response clocks. The reconciliation runs both ways, since entitlement above deployment carries recurring support cost.

What is IT asset management?

IT asset management is the practice of tracking and governing an organization’s technology assets across their lifecycle: hardware, software licenses, cloud subscriptions, and the contracts attached to them. It covers acquisition, deployment, maintenance, cost, compliance, and disposal.

Within it sits software asset management, and within that sits the specific discipline this article is about: establishing an effective license position, which is the defensible comparison between what you have deployed and what you are contractually entitled to deploy.

That comparison is the whole game. Everything else in ITAM supports decisions. This one determines financial exposure, because it is the number a software vendor will assert against you.

The two halves

An effective license position requires two inputs, and they are not equally difficult.

Deployment, meaning what is actually installed, assigned, or consumed. This is a measurement problem. Discovery agents scan the estate, inventory tools enumerate installations, and SSO and usage telemetry report consumption. It is technical work with technical answers, and the tooling is mature.

Entitlement, meaning what you are contractually permitted to deploy. This is not a measurement problem. There is nothing to scan. Entitlement exists in master agreements, order documents, reseller invoices, volume licensing agreements, amendments, migration records, and portal PDFs accumulated over years by people who may have left.

The common recommendation is to deploy a SAM tool, run discovery across the estate, and read the compliance dashboard. Discovery answers only the deployment half. The dashboard then compares it against whatever entitlement figure somebody typed in, which is frequently drawn from support renewal quotes and therefore omits unsupported perpetual licenses entirely.

That dashboard produces a confident number built on a reconstructed one.

Why entitlement cannot be looked up

Here is the detail that surprises people new to this, and it is the reason the work is hard rather than merely tedious.

No single document proves your entitlement. Each source proves something different and is silent on the rest.

A master agreement establishes use rights, restrictions, and the audit clause. It does not state the quantities you hold.

A support renewal quote shows what is currently under support. It is not a statement of full entitlement, because perpetual licenses you stopped supporting still carry use rights.

A vendor support portal proves support identifiers and patch access. It does not establish legal use rights or metric definitions.

Order documents and reseller invoices evidence specific purchases, but only the ones you can still locate.

So establishing entitlement means assembling a position from several partial sources, each authoritative for one aspect and misleading if relied on alone. It is a documentary reconstruction, performed under the assumption that whoever built it got every piece.

Add metric complexity on top. Processor-based rules, sub-capacity requirements, virtualization treatment, named user definitions that count non-human devices, indirect access provisions. The definitions are vendor-specific, change between contract versions, and determine the count as much as the hardware does.

What happens when the audit arrives

This asymmetry matters because of how software audits are structured.

Audits are not random. Advisory firms consistently identify the same selection signals: contract age beyond roughly three years without significant new orders, deployment growth outpacing entitlement growth, and renewal posture suggesting reduced spend. Audit activity across major publishers has been increasing, with Microsoft, IBM, SAP, Oracle, Red Hat, and Broadcom all cited as tightening compliance checkpoints.

Response windows are short and contractually fixed. Published notice periods vary by vendor, commonly in the range of fifteen to forty-five days, sometimes followed by a short remediation window. Penalty structures are defined in advance, and under some agreements unlicensed use above a stated threshold triggers premium pricing on the shortfall plus reimbursement of the vendor’s audit costs.

The burden of proof runs one way. The vendor asserts a position derived from deployment data. You are required to disprove it with entitlement evidence you may not be able to assemble in the time available.

Which produces the pattern advisory firms describe consistently: the opening compliance demand is substantially higher than the position the customer can eventually defend, and the gap between the two closes only to the extent entitlement is properly reconciled. IDC analysis has found enterprises routinely discovering gaps in the range of fifteen to thirty percent between entitlements and deployments during formal audits, and much of that gap is data hygiene rather than genuine over-deployment.

The uncomfortable implication is that a meaningful share of audit settlements are paid not because the organization was over-deployed, but because it could not evidence that it was not.

The reconciliation runs both ways

One point gets lost in audit-focused discussion. The comparison is not only about shortfalls.

Entitlement above deployment is shelfware, and it is not free. Maintenance and support typically run at around a fifth of license value annually, so unused entitlement is a recurring cost that continues until somebody identifies it, and it can generally only be removed before a renewal is signed.

So the same reconciliation that defends against an audit also surfaces recoverable spend, and the second use case is the one that justifies doing it when no audit letter has arrived.

Where the work actually goes

The operational shape is specific and largely clerical.

Someone locates the agreements, which are scattered across contract repositories, shared drives, procurement systems, email, and vendor portals. Someone reads each one and extracts what it actually establishes: use rights, quantities, metrics, restrictions, effective dates, and how later amendments modified earlier terms. Someone reconciles that against deployment data counted the way the vendor counts it, which is not necessarily the way your inventory tool counts it. Someone maintains that position as the estate changes and contracts renew. And when a letter arrives, someone assembles the evidence file line by line against the vendor’s findings.

Almost none of this is engineering or negotiation. It is document location, interpretation, and reconciliation, at a volume that scales with the number of publishers and the age of the estate.

That is why it is usually done once, under pressure, after a notice arrives, which is the most expensive possible moment to start.

Where automation fits

The constraint sits squarely on the entitlement side, which is a document problem rather than a discovery problem.

Automation that can read unstructured documents and reason about their contents addresses it directly: extracting quantities, metrics, and use rights from agreements, order documents, and amendments whatever form they arrive in, resolving how later amendments modify earlier terms, reconciling the assembled entitlement against deployment counts, and maintaining that position continuously rather than reconstructing it under a deadline.

Because the output is used to rebut a vendor’s financial claim, every element must be traceable to the document it came from. An entitlement figure without the order document behind it is not evidence, and in an audit it will be treated as an assertion rather than a defense.

To be clear about scope, Kognitos is not a SAM or discovery platform. It does not scan your estate, maintain publisher-specific licensing rule libraries, or replace the tools that produce deployment data and model complex metrics. Those remain essential, and for major publisher exposure the specialist platforms are the right choice. What Kognitos addresses is the half discovery cannot reach: reading the contractual record and turning it into a documented entitlement position with the evidence attached.

For related material, see our guides on SaaS management, contract lifecycle automation, spend management, IT operations automation, and internal controls. To see how deterministic AI builds an evidenced position from contract documents, book a demo or try the platform.

Getting started

Two exercises worth running before any audit letter arrives.

Pick your largest publisher and try to assemble entitlement from source documents alone. Not from the support renewal quote, and not from the SAM dashboard, but from master agreements, order documents, and amendments. How complete that reconstruction is, and how long it takes, is your actual audit readiness.

Check the reconciliation in the other direction. Identify entitlement above deployment and establish when the next renewal falls. Shelfware can usually only be removed at renewal, so the window to act on it is defined by a date, not by when you notice.

Frequently Asked Questions

IT asset management is the practice of tracking and governing technology assets across their lifecycle, covering hardware, software licenses, cloud subscriptions, and associated contracts, from acquisition through deployment, maintenance, cost management, compliance, and disposal. Within it, software asset management focuses specifically on license compliance and cost.
An effective license position is the defensible comparison between what an organization has deployed and what it is contractually entitled to deploy, for a given publisher. It is the number that determines financial exposure in a vendor audit, because it is the basis on which a compliance claim is either substantiated or rebutted.
Because entitlement does not exist on any machine. Deployment is a measurement problem that discovery agents and inventory tools solve well. Entitlement lives in master agreements, order documents, reseller invoices, volume agreements, and amendments accumulated over years. No single source proves it: a master agreement establishes use rights but not quantities, and a support quote shows what is supported but omits unsupported perpetual licenses.
Advisory firms consistently identify the same selection signals: master agreements more than roughly three years old without significant new orders, deployment growth outpacing entitlement growth, and renewal behavior suggesting the customer intends to reduce spend. Audits are therefore predictable rather than random, and often precede or coincide with a renewal cycle.
Notice periods are set contractually and vary by publisher, commonly falling in the range of fifteen to forty-five days, sometimes followed by a short window to remediate any shortfall. Some agreements also provide that unlicensed use above a stated threshold triggers premium pricing on the shortfall plus reimbursement of the vendor’s audit costs.
Shelfware is entitlement held above actual deployment. It matters because maintenance and support typically run at roughly a fifth of license value annually, so unused entitlement is a recurring cost rather than a dormant asset. It can usually only be removed at a renewal point, which means identifying it after a renewal has been signed defers any saving by a full term.

The next era of financial automation is already in production.

Kognitos turns your biggest bottlenecks into automations, live in hours, not months.