An Inventory That Drifts by Design

Blog · IT Asset & Endpoint

An Inventory That Drifts by Design

By Rohit Gupta8 min read

Short answer

Every asset tool in this category begins with the same confession: the estate must be discovered. Agents crawl, scanners sweep, connectors poll — because assets are created, moved, and retired in consoles the inventory does not control.

Every tool in this category opens with the same confession: the estate must be discovered. Agents crawl the network, scanners sweep subnets, connectors poll cloud and SaaS APIs — because assets are created, moved, and retired in a dozen consoles the inventory does not control. Discovery is the admission that record and reality are two different systems. Everything that follows — normalization, deduplication, reconciliation — is the apparatus for re-synchronizing them, forever.

The category's founding creed is that you cannot manage what you cannot see. Take it seriously — it is true, and it is doing more work than it appears to. Ask why the estate cannot be seen without a discovery apparatus, and the answer turns out to be the architecture of the entire market: assets are born, modified, and retired somewhere else. An engineer provisions a cloud instance from a console the asset tool has never met. A department head adds twenty seats to a SaaS product on a corporate card. Procurement signs an agreement whose entitlements live in a PDF. A laptop ships, is imaged, is handed to a contractor, and comes back carrying software nobody requested. None of these events consulted the inventory first. The inventory finds out later — by crawling, sweeping, and polling.

This is not an implementation gap the next release will close. It is the design premise. These platforms were built for a world in which the record could never be present at the moment of change, and so they became superb at the only thing left: catching up. The category's own language gives it away. Continuous scanning as the foundation. Normalization against vast catalogs. A single, continuously refreshed source of asset truth — where continuously refreshed is the quiet concession that the truth keeps moving and the record keeps chasing it, with freshness measured in scan cycles.

Be fair about what this engineering has achieved, because it is substantial and it is hard.

  • Discovery at estate scale is genuinely difficult, and the leading discovery and inventory tools do it well — agent and agentless scanning that reaches datacenter, endpoint, cloud, and SaaS; normalization against product catalogs spanning enormous publisher and version sprawl; deduplication that turns overlapping signals into one coherent inventory.
  • License reconciliation is real expertise. Computing an effective license position against byzantine vendor licensing models — core factors, named-user tiers, indirect access — is knowledge that took decades to accumulate, and it has saved enterprises from genuine audit exposure.
  • The real-time endpoint platform is not a strawman. The strongest of the endpoint-management platforms genuinely sees and remediates devices in near-real time, closed-loop, at scale. For device state, that is real speed and real action.
  • The workflow-of-record platform has the right ambition. Unifying the asset record with asset workflows on one platform — provisioning, license assignment, a lifecycle that runs from procurement to retirement — is exactly the correct goal, and for the asset classes and integrations it directly controls, the automation is real.

If your estate must be reconstructed from the outside, these are the teams you want reconstructing it. The open question is whether reconstruction is the right architecture at all.

Look at the shape of the loop rather than its speed. Change happens outside; a scan detects it; normalization cleans it; reconciliation computes a position; a report describes it; a recommendation proposes a fix; a human executes the fix in some other console — and change happens outside again. Shrink the scan cycle from weeks to hours to near-real-time and you have made the loop faster. You have not changed its shape. Faster reconciliation is still reconciliation.

Every artifact the category produces carries the same signature. The inventory is a snapshot kept honest by re-scanning. The license position is a report computed after the installs already happened. The reclamation is a recommendation an admin implements somewhere the tool does not govern. Between the change and the record there is always an interval, and in that interval the estate runs ungoverned — unlicensed software installed, an orphaned entitlement still billing, a cloud resource nobody owns. That interval is not process waste to be optimized away. It is what the architecture produces.

The most ambitious platform in the category claims exactly the right headline — the record and the action unified on one platform, full lifecycle from procurement to retirement, automated provisioning and license assignment. Concede it: that is the correct ambition, and within the slices it directly controls, it delivers. But be precise about the mechanism, because the mechanism is what survives every roadmap. Its record is a configuration database kept accurate by discovery, normalization, and reconciliation — a structural admission that the estate changes outside the record and must be perpetually re-synced. Its actions reach the cloud, SaaS, and procurement estates as integration calls into consoles it does not govern. And nothing in the pattern prevents an asset state change that bypasses the workflow; the scan just catches it later. That is governance by reconciliation, executed superbly. It is still reconciliation.

There is a structurally different answer, and it begins by relocating the record. On a composable process fabric, an IT asset — a license, a device, a cloud resource, a SaaS entitlement — is a governed object on a semantic ontology, and its lifecycle actions are not tickets about the asset or scans of the asset. Request, provision, assign, patch, reclaim, renew, retire execute as deterministic workflows on the same fabric that holds the record: governance enforced inline before the action commits, permissions evaluated per action, human approval a first-class step wherever policy demands one, and every touch of an external system made through a governed Connector — the only primitive that reaches outside.

The consequence is architectural, not aspirational: the record updates because the action executed. There is no scan-and-reconcile loop for governed actions, because nothing changed outside the record — the state change and the record's update are the same event. Record and reality cannot diverge on those paths; not because a scanner is fast, but because there is no gap for divergence to enter. Accuracy stops being a scan cadence and becomes a property of the architecture. And because every lifecycle transition writes an immutable per-action audit entry — who requested, which gate evaluated, who approved, what the Connector did — the license position for governed entitlements is not a reconstruction of the past. It is the current state of the actions that produced it.

GOVERNANCE BY RECONCILIATION CLOUD SAAS DEVICES PROCUREMENT INVENTORY (a snapshot) NORMALIZE · DEDUPE RECONCILE LICENSE POSITION (a report, after the fact) RECLAMATION (a recommendation) ADMIN ACTS IN ANOTHER CONSOLE scan · sweep · poll drift: the estate changes outside the record — rescan, repeat GOVERNANCE BY CONSTRUCTION ASSET — A GOVERNED OBJECT ON THE FABRIC REQUEST PROVISION ASSIGN RECLAIM RETIRE inline gates: permissioned · HITL approval · audited before commit GOVERNED CONNECTORS the only primitive that touches external systems EXISTING ESTATE — CLOUD · SAAS · DEVICES · CONTRACTS RECORD = REALITY, BY CONSTRUCTION every action writes an immutable audit entry

Now the honest boundary, because over-claiming here is how vendors lose expert readers. This does not mean integration disappears — Connectors are precisely the integration surface, governed and audited rather than ad hoc. And by-construction accuracy applies to the lifecycle actions that run on the fabric. On day one, in any real enterprise, that is a subset of the estate.

So the strategic argument is not that scanning dies tomorrow. It is: narrow the ungoverned paths. Route the highest-drift, highest-cost lifecycle actions through governed workflows first — SaaS entitlement grants and reclamations, cloud provisioning, license assignment, joiner-mover-leaver flows. Every action migrated is a path on which drift can no longer originate. Discovery does not die; it demotes. It stops being the architecture of truth and becomes an exception detector on a shrinking perimeter — and on that perimeter, a scan that finds a change no governed action produced is no longer routine noise to reconcile. It is a signal: shadow IT, a bypassed path, an incident. That is a far better use of a scanner than feeding a treadmill.

Strip away the dashboards and the catalogs, and one question sorts every platform in this market: does the record update because the action executed, or because a scan noticed? Everything else follows from the answer.

  • If the license position is computed, it is a report about the past, and its accuracy starts decaying the moment it is produced.
  • If reclamation is a recommendation, the saving is hypothetical until an admin acts in another console — and unaudited when they do.
  • If an asset can change state without the governed action, the workflow is optional. Optional governance is not governance; it is drift with an approval form available on request.

A discovery-first architecture can answer only one way, no matter how fast its scanners become. Its inventory can approach reality asymptotically. By design, it cannot arrive.

A record kept accurate by perpetual re-scanning is not a source of truth. It is a well-maintained echo.

See what this looks like for your enterprise.

Not a demo. A strategic conversation about how your enterprise could operate
when every process runs on one governed fabric.

Start the Conversation