Sequentur Blog

Helping you stay ahead of IT challenges

Real-world IT knowledge from engineers solving problems every day.

Practical IT knowledge for businesses that can’t afford downtime

How to manage software licenses and renewals without losing track

Professional,Using,Tablet,With,Virtual,Certificate,,Badge,And,Approval,Seal

Nobody sets out to lose track of their software. It happens the way most operational problems happen, which is one reasonable decision at a time. Someone buys a project management tool for a project. Marketing puts a design subscription on a personal card because getting it through finance would take two weeks. An employee leaves and their accounts get disabled, but the seat they occupied keeps billing. A three-year agreement signed by someone who has since moved on renews automatically, because nobody knew there was a decision to make.

Five years of that, and a 60-person business is paying for somewhere between 40 and 90 different software products, and no single person can name them all. The finance team sees the charges but not what they are for. IT knows what is installed but not what it costs. Department heads know what their team uses but not what the business is paying for it. Every one of those three views is accurate and none of them is complete, which is why the question “what software do we pay for?” is surprisingly hard to answer at most small businesses.

The cost of that is real but it is rarely the headline number. Unused licenses are money, and the money is worth recovering, but the bigger exposure is that you cannot secure, back up, or offboard from systems you do not know exist. A departing employee’s access to a tool nobody in IT knows about does not get revoked. A vendor holding business data under an agreement nobody has read does not get scrutinized. Software sprawl is a spend problem that is also a security problem and a compliance problem, and the fix for all three is the same boring artifact: a list that is actually current.

This article covers how sprawl accumulates and where software hides, how to build a software asset inventory from sources you already have, what to capture for each license and how that relates to the renewal register your budget already needs, how to find the licenses you are paying for and not using, what to do about auto-renewals and notice periods, the shadow IT and personal card problem, what tooling is worth it at small business scale, and how a vCIO or MSP runs this on a client’s behalf.

Short answer

Build one inventory from four sources you already have: the card and bank statements, the identity provider’s application list, the vendor portals you can log into, and a short survey of department heads. Capture the same fields per row that a renewal register captures, with licensed count versus actually used count being the field that pays for the exercise. Give every row a named business owner who is not IT by default. Work the renewal calendar backwards from the notice period rather than the renewal date, because the notice period is the day the decision is actually due. Expect to find five to twenty percent of your software spend going to seats nobody uses, concentrated in departed staff and finished projects. Then keep it current by attaching license changes to your joiner, mover, and leaver process, because an inventory that is rebuilt annually is out of date for eleven months of the year.

Software license management at a glance

QuestionShort version
Who should own the inventory?Finance owns the register. IT maintains the technical detail. A named person owns each row.
How long does a first pass take?Two to four weeks at 50 to 100 staff, most of it waiting on people to reply.
Where is the money usually found?Seats for departed employees and tools bought for a project that ended.
What is the single most useful field?Licensed count versus used count. Nothing else recovers spend as reliably.
What date drives the calendar?The notice period deadline, not the renewal date.
How much spend is typically recoverable?Five to twenty percent of the software line on a first pass.
Do we need a dedicated tool?Below roughly 100 staff, usually not. A maintained spreadsheet beats an abandoned platform.
How often should it be reviewed?Touched at every joiner and leaver. Reviewed properly once a quarter.
What is the most common failure?Building it once, celebrating the savings, and never updating it.
Is this a cost exercise or a security one?Both. You cannot revoke access to a system you do not know exists.

How software sprawl actually happens

It is worth being specific about the mechanisms, because each one needs a different fix and treating them as a single problem called “too many subscriptions” produces a cleanup that does not stick.

Per-seat pricing made buying easy and cancelling hard. Perpetual licenses were a capital purchase with an approval process attached. Subscriptions are an operating expense small enough to sit under whatever threshold requires a second signature, which is exactly what makes them accumulate. A tool at 15 dollars per user per month is an easy yes and a low-priority no, so it gets bought quickly and cancelled never.

Projects end but their tooling does not. A migration, a rebrand, an audit, an office move. Each brings a tool that was genuinely needed for six months. The project closes, the team disperses, and nobody has the specific job of turning the tool off. This is the single most common place the recoverable money sits.

People leave and seats survive them. Offboarding almost always covers the systems IT knows about. The Microsoft 365 offboarding checklist and the broader remote employee IT offboarding checklist handle identity and the primary suite well. What they cannot cover is the tool IT never knew the person had. The account gets orphaned, the seat keeps billing, and in the worse case the access stays live.

Procurement friction pushes spending onto personal cards. This is the one people are least comfortable naming. If getting a 20 dollar subscription approved takes three weeks and two forms, a motivated employee expenses it instead. They are not being devious, they are routing around a process that costs more than the thing it governs. That produces spend that never appears in any IT system, under agreements nobody reviewed.

Nobody owns the renewal. Contracts get signed by whoever ran the evaluation. Two years later that person is in a different role or a different company, the renewal notice goes to an unmonitored inbox, and the agreement rolls over. Inaction becomes a decision, and the decision is always “yes, at whatever the new price is.”

The four places software hides

Most businesses looking for their software list start in the wrong place, which is IT. IT has the most accurate view of what is installed and the least accurate view of what is paid for. These four sources between them find nearly everything, and three of them do not require anyone’s cooperation.

Financial records. Twelve to eighteen months of credit card statements, bank statements, and accounts payable, filtered for anything that looks like a vendor. This is the most complete source you have, because everything that costs money eventually shows up here. It is also the most tedious, and it is where the tools bought on departmental cards surface. Eighteen months rather than twelve matters, because annual subscriptions only appear once.

The identity provider. If you are on Microsoft 365, the admin center and the enterprise applications list in Entra ID will show you every application anyone has signed into with their work account. This catches single sign-on and “sign in with Microsoft” tools that never generated an invoice your finance team recognized. It is the fastest way to discover free-tier tools holding business data, which cost nothing and still carry every security and compliance obligation a paid tool does.

Vendor portals. For each vendor already known, log in and read the actual subscription: the tier, the seat count, the renewal date, the term, and the notice period. Do not take the invoice’s word for the seat count. Invoices tell you what you are billed for, not how many of those seats have a human behind them.

Department heads. A short, specific survey beats a general one. Ask each manager what software their team uses weekly, what they would notice was gone tomorrow, and what they pay for personally and expense. That third question needs to be asked without consequence attached, or the answer will be “nothing.” This is the only source that finds tools with no card trail and no corporate sign-in.

Run all four and reconcile. The gaps between them are informative in themselves: something in the identity provider with no financial record is a free tier or someone else’s card. Something in the financial records with no sign-in activity is a candidate for cancellation today.

What to capture for each license

Your annual budget cycle already needs a renewal register, and it defines the core fields: vendor and product, annual cost, renewal date, notice period, licensed count versus used count, internal owner, business justification, and auto-renew status. Use exactly those fields. Do not build a parallel list with different columns, because two lists that disagree are worse than one list that is incomplete.

The software asset inventory is that register plus the operational detail the budget does not need. The register answers “what will next year cost.” The inventory answers “what do we run, who can get into it, and what happens if it goes away.” Add these:

Additional fieldWhy it matters operationally
License modelPer user, per device, perpetual, concurrent, or consumption. It decides what happens when headcount changes.
Data classificationWhether the tool holds customer data, financial records, or regulated information. Drives review depth.
Authentication methodSingle sign-on, or local accounts with their own passwords. Local accounts are the offboarding risk.
Admin contact and billing contactThe two are often different people, and neither is always still employed.
Contract locationWhere the signed agreement actually is. “In someone’s email” is a finding.
IntegrationsWhat it reads from and writes to. Determines whether removing it is simple or a project.
Replacement candidateIf this were cut, what absorbs the work. Turns “we cannot cancel it” into a comparison.

The “business justification” field deserves particular attention, because it is the one that does the quiet work. One sentence, written by the named owner, explaining what the business loses without it. If nobody will write that sentence, the finding is not that the documentation is incomplete. The finding is that the tool has no owner, and an unowned tool is a cancellation candidate.

Licensed versus used: where the money is

This is the field that pays for the whole exercise, and getting it right means being precise about what “used” means.

Licensed count comes from the invoice or the vendor portal. Used count needs an activity source, and the standard for most tools is last sign-in date. A seat with no sign-in in 90 days is not in use, whatever anyone says about needing it occasionally. Microsoft 365 reports this natively, Google Workspace does, and most mainstream SaaS vendors expose it somewhere in an admin panel. For tools that do not, ask the owner for a list of who actually uses it and compare to the seat list.

Three patterns show up nearly every time:

Ghost seats. Departed employees still occupying a paid license. The account may be disabled and the seat still billed, because disabling an account and removing a license are two separate actions in most platforms. In Microsoft 365 specifically, removing a license the wrong way destroys data, which is why how to add and remove Microsoft 365 licenses without losing data is worth reading before you start reclaiming seats.

Over-tiering. Everyone on the premium tier because it was simpler to buy one SKU than to work out who needs what. This is usually the largest single number in the exercise and the one people resist most, because right-sizing feels like taking something away. It is also well-trodden ground for the biggest line item most businesses have, covered in how to reduce your Microsoft 365 costs without losing features and in Microsoft 365 licensing explained.

Duplicate capability. Three tools that do overlapping work because three departments solved the same problem independently. Two file sharing platforms, two e-signature tools, two video conferencing accounts. Consolidation here saves money but the real gain is fewer places business data lives.

Five to twenty percent of the software line is the realistic first-pass recovery at small business scale, concentrated in the first two patterns. Treat anything above that as a signal to check your numbers rather than as a win, because the most common way this exercise goes wrong is cancelling something that turns out to be load-bearing.

Work the calendar backwards from the notice period

The renewal date is not the deadline. The notice period deadline is, and the gap between them is where businesses lose a year of spend on a tool they had already decided to drop.

A typical annual agreement requires 30 to 60 days written notice of non-renewal. Some require 90. A few require notice in a specific form, to a specific address, and an email to your account manager does not satisfy it. That clause was visible at signing, which is the argument for reading exit provisions before you sign in the first place, covered in how to evaluate technology vendors as a small business.

Practically, this means every row in the register gets a second date: the decision date, which is the renewal date minus the notice period minus two weeks of slack for the internal conversation. Put the decision dates in a shared calendar with the owner named, not the renewal dates. Anything with a term longer than a year gets a calendar entry the moment it is signed, because nobody remembers a 2029 renewal in 2026.

Then order the register by decision date and work it as a rolling queue. Four or five renewals a quarter reviewed properly is sustainable. Forty renewals reviewed in December is not, which is why the annual review model quietly turns into rubber-stamping.

Auto-renewal makes inaction a decision

Auto-renewal is not inherently bad. For genuinely core systems it prevents an accidental lapse in something the business depends on, and that is a real benefit. The problem is auto-renewal on tools whose value nobody has assessed recently, where it converts “we never got around to discussing it” into “we agreed to another year at the new price.”

The rule worth adopting is that auto-renewal is acceptable where there is a named owner and a documented justification, and unacceptable where either is missing. That turns the auto-renew field into a useful signal rather than a piece of trivia: any row with auto-renew on and no owner is the shortest list worth acting on this week.

Price increases deserve a word here too. Assuming flat renewal pricing has been a losing bet for several years across most of the SaaS market. Where you have a contracted rate, it holds. Where you do not, a renewal is a price change you have not been told about yet, and reviewing the renewal is the only opportunity to negotiate it. Multi-year commitments in exchange for price protection can be a good trade for genuinely core systems and a bad one for anything you might replace, which is a judgment call the business owner should make rather than IT.

Shadow IT and the personal credit card problem

The instinct when discovering software on personal expense reports is to prohibit it. That is the wrong move, and it fails predictably, because the behavior is a symptom of procurement friction rather than of employees being careless. Ban it without fixing the friction and the spending does not stop, it just stops being visible.

What works better is a fast lane. A low threshold, say under a few hundred dollars a year, where an employee can get a tool approved in a day or two through a short form that captures the four things you actually need: what it is for, whether it will hold customer data, who else will use it, and what it costs. That is enough to get the tool into the register on day one, and it removes the incentive to route around the process. For AI tools specifically the data questions are sharper than for ordinary software, and how to evaluate whether an AI tool is safe for your business to use covers the extra ground that needs.

Pair the fast lane with an amnesty when you first build the inventory. State plainly that anything disclosed now gets absorbed into the register with no blame attached, and mean it. The first inventory is the only chance to get honest answers, and one person getting a hard time for a design subscription guarantees the rest stays hidden.

The security half of this matters more than the spend. Tools bought personally usually use personal or local credentials rather than company single sign-on, which means they survive offboarding. A password manager with company-owned vaults is the practical control here, because it gives shared credentials somewhere to live that does not depend on one person’s memory or their personal browser.

Deciding what to do with what you find

Every row in the finished inventory resolves to one of five outcomes. Naming them prevents the common failure mode, which is producing a detailed inventory and then acting on none of it.

DispositionWhen it applies
Keep as isUsed, owned, justified, priced correctly. Most rows, and that is fine.
Right-sizeThe tool stays, the seat count or tier drops to match actual use.
ConsolidateOverlapping capability with another tool. One survives, the work moves.
CancelNo owner, no justification, or no meaningful use. Check for data first.
EscalateBusiness-critical, expensive, or contractually awkward. Needs a leadership decision.

Two cautions before cancelling anything. First, get the data out, and confirm you have it in a usable form before the account closes rather than after. Access usually ends on the termination date regardless of what the invoice period says, and export tooling is frequently worse than it looked. Second, check what integrates with it. The tool nobody logs into may still be the thing that moves records between two systems on a schedule, which is exactly the kind of dependency that is invisible until the day it stops.

Tooling, and whether you need any

Be honest about scale here. Dedicated SaaS management platforms exist, they work, and below roughly 100 staff most of them cost more than they recover. A maintained spreadsheet with the fields above, reviewed quarterly, outperforms an abandoned platform every time, and abandonment is the normal outcome when a tool is bought to solve a discipline problem.

What is worth using is what you already have. The identity provider’s application and sign-in reports are the discovery engine. The Microsoft 365 or Google Workspace admin center gives you licensed versus used for your largest line item for free. Your accounting system’s vendor report is the financial view. If your MSP runs an RMM and PSA stack, the installed-software inventory from the RMM covers the desktop side, which is the half that identity-based discovery misses entirely.

The point at which a dedicated platform starts earning its cost is usually a combination of headcount above roughly 100, a high number of distinct SaaS vendors, and a real compliance driver that requires evidence rather than an assertion. Below that, spend the money on someone’s time to keep the list current instead. The constraint is never the tooling, it is whether anyone owns the upkeep.

Keeping it current

Every software inventory is accurate on the day it is finished. What determines whether it is worth anything is what happens in the following eleven months, and the businesses that succeed here all do the same thing: they attach license changes to events that already happen, rather than scheduling a separate review that competes with real work.

Every joiner triggers a license assignment, which is a row update. Every leaver triggers a reclaim, and the offboarding checklist should be driven from the inventory rather than from memory, which is the single highest-value link between this and everything else. Every mover between departments or roles triggers a review of what they still need, and role changes are where over-tiering quietly accumulates.

Then a real quarterly review: the renewals with decision dates in the coming quarter, any row whose owner has left, anything with no sign-in activity in 90 days, and any new vendor appearing in the financial records that is not yet in the register. That is a 45 minute meeting when the process is working, and it feeds the annual budget cycle directly, since the register is one of its three inputs.

What this actually saves

Setting expectations honestly matters, because this work gets sold on the savings and kept for other reasons.

The first pass typically recovers five to twenty percent of the software line. At a 60-person business spending 90,000 dollars a year on software, that is somewhere between 4,500 and 18,000 dollars annually, recovered mostly from ghost seats and over-tiering. Meaningful, not transformative.

The second year recovers much less, because the obvious waste is gone. If someone is projecting the first year’s savings forward indefinitely, the projection is wrong. What the ongoing discipline produces instead is avoided cost: renewals that get negotiated rather than accepted, tools that get cancelled at the right moment rather than a year late, and headcount growth that does not automatically multiply the premium tier.

The part that does not show up in a spend report is the reason this ends up mattering more than the money. You can offboard properly, because you know every system a person can reach. You can answer a client security questionnaire or an insurance application about where data lives, without guessing. You can scope a migration or an acquisition accurately. And when a vendor has a breach, you can answer “do we use them” in minutes rather than spending a day finding out. For the cloud infrastructure side of the same discipline, cloud cost management covers the consumption-based half of the problem, which behaves differently because it scales with usage rather than headcount.

How a vCIO or MSP handles this for a client

Most small businesses know they should do this and do not, not because it is difficult but because it is nobody’s job and it never becomes urgent. That is precisely the category of work a vCIO engagement exists to absorb.

In practice the provider does the mechanical parts: builds the initial inventory from discovery tooling and financial records, reconciles the sources, produces the licensed versus used analysis, and maintains the renewal calendar so decision dates arrive with lead time attached. They also bring price benchmarking, which is the part an internal team cannot do, because a provider renewing the same products across dozens of clients knows what the real price is rather than what the first quote says.

What the provider cannot own is the business justification and the disposition decision. Whether a tool is worth its cost is a business judgment, and a provider who cancels things on their own authority is a provider you will eventually have an argument with. The working split is that the provider maintains the register and brings the recommendation with evidence, and a named person on the client side decides. Whether that structure is an engaged vCIO or a hired internal manager is the question worked through in vCIO vs IT manager.

If this is part of your managed services agreement, it is worth confirming what “license management” means in the contract. It sometimes means procurement assistance only, which is the vendor coordination described in managed IT services for small business, and sometimes means full lifecycle ownership including the inventory and the renewal calendar. Those are different scopes at different prices, and what should be in a managed IT services agreement covers how to pin that down.

Common mistakes

1. Treating it as a one-time cleanup project. The inventory is finished and everyone moves on. Eleven months later it is fiction again, and the second cleanup costs as much as the first. The recurring process is the deliverable, not the spreadsheet.

2. Putting the renewal date in the calendar instead of the decision date. The notice period is what makes a cancellation possible, and a reminder that fires on the renewal date fires after the decision was already made for you.

3. Leaving IT as the default owner of every row. IT can tell you what a tool does and what it costs. It cannot tell you whether marketing still needs it. Rows owned by IT by default are rows nobody is really assessing.

4. Cancelling before exporting. Access ends at termination, not at the end of the paid period, and the export function is usually worse than expected. Get the data out, verify it opens, then cancel.

5. Counting licenses instead of measuring use. The seat count from the invoice is the number you are paying for. Without last sign-in data you have a cost list rather than an inventory, and the recoverable money is invisible.

6. Banning personal card purchases without fixing procurement. The spending continues and the visibility does not return. Fix the friction that caused it, and the behavior mostly resolves itself.

7. Ignoring free tools. A free tier holding customer data carries the same security, privacy, and offboarding obligations as a paid one, and it appears in no financial record at all. Discovery through the identity provider is the only thing that finds these.

8. Assuming flat renewal pricing. Where there is no contracted rate, a renewal is a price change you have not seen yet. Budgeting last year’s number and being surprised is the wrong direction to be wrong in.

9. Signing multi-year deals for tools you might replace. Price protection is worth real money on systems you are certain about and is a trap on anything you may want to exit. The discount is compensation for giving up optionality.

10. Letting the inventory live in one person’s spreadsheet. If it sits on a local drive or in a personal account, it disappears with them, and you rebuild from scratch. It belongs somewhere shared, with more than one person who knows where it is.

How this fits the rest of your IT

License management sits between vendor selection and the budget. Evaluating vendors is how a tool arrives, license management is how it is governed while you have it, and the annual budget cycle is where the register turns into a number leadership approves. Whether that number is reasonable for a business your size is the separate question covered in how much should you spend on IT.

It also touches security more than its reputation as an accounting exercise suggests. The inventory is what makes offboarding complete, which is why the Microsoft 365 offboarding checklist and the remote employee offboarding checklist work better driven from a list than from recall. Shared credentials for tools without single sign-on need a password manager rather than a shared inbox. And personal devices running business software are the other half of the same visibility problem, which is what a BYOD policy governs.

Upstream of all of it is strategy. The IT roadmap decides what the business should be running, and aligning IT strategy with business goals is what turns a list of subscriptions into a set of deliberate choices. An inventory is the evidence those conversations need. Without it, both are opinion.

What is next in this series

The next article moves from operational governance to the risk conversation with leadership: how to write a technology disaster recovery plan that leadership will actually approve. Why DR plans written by technical people get quietly ignored in the boardroom, how to reframe recovery in terms leadership responds to – revenue at risk per hour of downtime, client SLA exposure, regulatory consequences – how to get buy-in and budget for the improvements, and what a board-ready DR summary looks like next to the technical implementation plan underneath it.

How Sequentur can help

If you cannot currently answer what software your business pays for, who owns each tool, and what renews in the next 90 days, that is the gap worth closing first. We build the inventory, reconcile it against what you are actually billed, and run the renewal calendar so decisions arrive with time to make them. Schedule a call.

Get the Best IT Support

Schedule a 15-minute call to see if we’re the right partner for your success.

Invalid Email
Invalid Number
Please check the captcha to verify you are not a robot.
Testimonials

What Our Clients Say

Here is why you are going to love working with Sequentur

Need help?

FAQs About Our Managed IT Services