Ask your software-asset team for the artifact they are proudest of, and they will hand you the effective license position: every entitlement reconciled against every install and every usage record, across licensing models of deliberate byzantine complexity, into a defensible statement of exactly where you stand. It is the hardest document in IT asset management, and producing it well is genuine craft. Now read it again and notice the tense — every verb in it is past tense. The installs occurred. The seats were assigned. The over-deployment exists. And now you know.
What software asset management gets right
Start with what the software-asset-management vendors get right, because it is substantial. Discovery at estate scale is genuinely hard: agent and agentless scanning across data centers, endpoints, clouds, and SaaS; normalization of raw signals against vast product catalogs; deduplication of overlapping sources into one coherent inventory. That is unglamorous engineering done well, over decades.
And the reconciliation built on top of it is harder still. Vendor licensing models are byzantine on purpose — processor and core metrics that shift under virtualization, named-user tiers with overlapping rights, indirect-access rules that quietly turn an integration into a licensing event. Computing a defensible position across that terrain is real expertise, and it has saved enterprises from real audit exposure. Anyone who dismisses this work has never sat across the table from a vendor auditor. The category's assurance story — the effective license position, true-up preparation, audit defense — deserves the trust it has earned.
Look at the grammar of the deliverable
Now look at the grammar of the deliverable. The position describes what already happened. It is a statement about the past, produced after the consuming events it measures — and that is not a flaw in anyone's implementation. It is the definition of reconciliation. You cannot reconcile events that have not happened yet.
Enforcement would be the same rule with a different tense. Instead of the deployment exceeded entitlement, and now you know, the present-tense version reads: the assignment that would exceed entitlement is refused when it is attempted. Same entitlement data. Same licensing logic. A different moment of application. A report tells you how far past the line you drifted; a gate is the line.
Listen to what the category calls an over-deployment when it finds one: a finding. An optimization opportunity. Something to remediate. The vocabulary concedes the tense. The event that created the exposure was never a candidate for refusal, because the system that knew the rule was not standing where the event happened.
An architectural observation, not a product criticism
This is an architectural observation, not a product criticism, and it holds regardless of any roadmap. The discovery and inventory tools sit beside the estate and observe it. The estate changes on its own schedule — an admin assigns seats in a vendor console, a build system spins up licensed cores, a business unit buys a SaaS tier on a corporate card — and the tool finds out at the next scan. The inventory is a snapshot kept honest by re-scanning. The license position is a report reconciled after the installs. The reclamation is a recommendation an admin implements in some other console, which a later scan will verify.
The strongest counterargument comes from the workflow-of-record pattern: unify the asset record with the asset workflows on one platform, so the record and the action live together. That is genuinely the right ambition — and for the asset classes and integrations such a platform directly controls, it is real. Provisioning executes, license assignment executes, the record updates. But look at the mechanism underneath. The record is a CMDB kept accurate by discovery, normalization, and reconciliation — an admission, built into the architecture, that the estate changes outside the record and must be perpetually re-synced. The actions reach cloud, SaaS, and procurement estates as integration calls into consoles the platform does not govern. And nothing in the pattern prevents an asset state change that bypasses the workflow entirely; the scan simply catches it later.
Accuracy by reconciliation is a treadmill. The better you run it, the shorter the interval between reality and the record — but the interval never reaches zero, because the architecture placed the tool beside the estate instead of in the path of change.
Put the rule where the event happens
Entroid takes the opposite architectural position: put the rule where the event happens. On the fabric, an entitlement is not a row computed by reconciliation — it is a governed object in the Semantic Ontology, with a defined pool, defined rights, and defined relationships to the people and systems entitled to consume it. A license or seat assignment is not something that occurs in a vendor console and gets discovered later — it executes as a Deterministic Workflow action, and the check against the entitlement object runs inline, before execution, as part of the action itself. Governance is not a review stage bolted on after the fact; it is a property of the runtime.
- The over-entitlement assignment cannot silently complete. The inline gate means a consuming event either passes, or becomes an approval and procurement flow, or is refused with a recorded reason. There is no path on the fabric where it just happens and surfaces in next quarter's report.
- The position is true by construction. Every consuming event passed the gate, so record and reality cannot diverge for actions on the fabric. There is nothing to reconcile, because nothing changed outside the record.
- Every decision is evidence. The fabric writes an immutable per-action audit — including the refusals. A prevented exposure is an auditable event, not an absence.
And because Connectors are the only primitive that touches external systems, the execution in the vendor's own estate travels through the same governed path that recorded the decision. To be precise about the claim: this is not a report of outcomes delivered somewhere — it is a statement of what the design makes structurally true. The state change is the governed action, which is why the record cannot trail it.
One flow, offered to show the mechanics
Consider a single flow — hypothetical by design, offered to show mechanics, not a case study. An engineer requests a seat on an analytics suite whose entitlement pool is fully consumed.
In the reconcile-and-report world, an admin grants the seat in the vendor's console because the request is urgent and the console permits it. The position quietly goes negative. The discrepancy surfaces at the next reconciliation as a finding, ages in a remediation queue, and matures into true-up exposure that a negotiation team inherits at renewal. Every tool in the chain worked exactly as designed.
On the fabric, the request is a workflow action, and the inline check finds the pool exhausted — so the assignment does not execute. Instead, the workflow routes. It can surface reclaim candidates, because seat-to-usage relationships live in the ontology, and reclaim a dormant seat as a governed action through the Connector before completing the assignment against freed capacity. It can route to the budget owner as a first-class human decision — human-in-the-loop is a primitive here, not an email thread — with the incremental cost attached; approval triggers procurement, the entitlement object is updated, and only then does the assignment execute. Or it refuses, with the reason recorded. In every branch, the position never went negative. The audit exposure was prevented at origin — and the audit trail contains the prevention itself.
Where reconciliation still earns its keep
None of this makes reconciliation obsolete, and pretending otherwise would be its own over-claim. An enterprise adopting the fabric has an estate that predates it: legacy installs, entitlements bought a decade ago under contracts nobody fully remembers, devices and business units mid-migration. For every consuming event that still happens outside the governed path, discovery and reconciliation remain the honest instruments — and a vendor audit will always demand historical positions that no gate can retroactively construct. Entroid does not require a rip-and-replace to make this real: it runs over the existing estate through governed Connectors, and the practical sequencing question for a CIO is which consuming events move onto governed paths first. The rational answer is usually the ones carrying the largest audit exposure.
What changes is the trajectory. In the reconcile-and-report model, drift is the permanent operating condition, and the tooling's job is to measure it faster and more precisely — a treadmill you fund forever. On the fabric, drift is a perimeter, and every lifecycle action that moves onto a governed path shrinks it. The compliance review changes tense along with the architecture: the question stops being how far past the line did we drift last quarter and becomes what did the gate refuse, and what did we choose to buy. One is forensics. The other is governance.
A license position tells you how far past the line you drifted. A gate is the line.
See what this looks like for your enterprise.
Not a demo. A strategic conversation about how your enterprise could operate
when every process runs on one governed fabric.
