You Budget for the True-Up Because Nothing Says No

Blog · IT Asset & Endpoint

You Budget for the True-Up Because Nothing Says No

By Mohak Soni8 min read

Short answer

Somewhere in your software budget is a line for the true-up — the annual settling-up for consumption nobody authorized but everybody expects. The category's own research calls a large share of software spend waste, and its business model is to find it after the fact. A CFO does not need a faster way to discover unauthorized consumption. A CFO needs consumption that cannot occur without authorization.

Open next year's software budget and find the line that should not exist: the true-up. It is money set aside for consumption nobody authorized, discovered after it happened, and settled at the vendor's price. Finance treats it like weather — unpredictable in size, inevitable in arrival. It is not weather. It is a confession: you budget for the true-up because nothing in your architecture can say no.

The ritual is familiar to every CFO and CIO pair. Once a year — or whenever a software vendor sends the letter — the enterprise reconciles what it deployed against what it bought. Discovery data is pulled, entitlements are gathered, an effective license position is computed, and a delta emerges: seats assigned beyond the contract, installs of editions nobody purchased, subscriptions that quietly renewed for teams that no longer exist. Then the negotiation, then the settlement, then the budget line for next year's version of the same surprise.

The tooling category that serves this ritual is candid about the stakes. By its own research — and these figures are the category's claims, worth reading directionally rather than as audited fact — a large share of enterprise software spend is waste: shelfware, unused SaaS seats, oversized suites, orphaned subscriptions. Notice what that number is doing commercially. The bigger the waste, the stronger the case for tooling that finds it. The pitch is not we will stop this from happening. The pitch is we will help you find out sooner, and negotiate better once you have.

Nobody in the buying conversation asks the stranger question: why is finding out the job at all?

Be fair first, because the expertise here is real and hard-won.

  • Discovery at estate scale is genuinely difficult. Agent and agentless scanning across data centers, endpoints, SaaS, and cloud; normalization against vast product catalogs; deduplication into a single coherent inventory. The discovery and inventory tools do this well, and doing it badly is worse than not doing it.
  • License reconciliation is real expertise. Vendor licensing models are byzantine by design — processor metrics, named-user tiers, indirect access, virtualization clauses. The license-optimization vendors have translated that complexity into defensible positions that have saved enterprises from genuine audit exposure.
  • The strongest execution stories are credible. The real-time endpoint platform genuinely sees and remediates devices in near-real time, closed-loop. The workflow-of-record platform genuinely unifies the asset record with asset workflows on one platform, and executes provisioning and license assignment for the slices of the estate it directly controls.

If your estate is ungoverned, you should want all of this. The question a CFO should sit with is why the estate is ungoverned in the first place — because every capability above shares one property. It runs after.

Walk the category's value story end to end: surface the unused licenses, prepare the audit defense, negotiate from a defensible position. Every one of those services is downstream of a single architectural fact — consumption happens outside governance, and reconciliation is how the enterprise finds out. The inventory is a snapshot kept honest by re-scanning. The license position is a report computed after the installs already happened. The reclamation is a recommendation an administrator carries into some other console to execute. The category does not merely tolerate ungoverned consumption; its economics depend on it.

The strongest counter-claim in the category deserves a direct answer, because its ambition is exactly right: the record and the action unified on one platform, the full lifecycle from procurement to retirement, automated provisioning and license assignment. That is the correct destination, and for the asset classes and integrations that platform directly controls, it is real. But look at the mechanism. Its record is a CMDB kept accurate by discovery, normalization, and reconciliation — which is an architectural admission that the estate changes outside the record and must be perpetually re-synced back into it. Its reach into cloud, SaaS, and procurement estates is a set of integration calls into consoles it does not govern. And nothing in that pattern prevents an asset state change that bypasses the workflow; the next scan simply catches it later. Accuracy by reconciliation is a treadmill. You can run it faster — better discovery, fresher scans, smarter normalization — but you can never step off, because the architecture concedes that reality moves first and the record chases it.

The procurement conversation for this category is a detection conversation: how fast is discovery, how accurate is the effective license position, how early is the warning before a vendor audit lands. Those are reasonable questions inside the paradigm. The CFO question sits outside it: can a seat be assigned beyond the entitlement at all? Can a subscription be opened outside the budget? Can an install proceed when the position is already at its ceiling? In a discovery architecture, the honest answer to each is yes — and the tool will tell you afterward.

Cloud cost management already went through this reckoning. Dashboards that told finance what engineering had spent gave way to a harder question: whether overspend could be refused upstream, before it accrued. The software-asset version of that question is the same shape but with sharper teeth, because license consumption does not just cost money — it creates contractual exposure that a vendor's audit team will price for you, at a moment of their choosing. A CFO does not need a faster way to discover unauthorized consumption. A CFO needs consumption that cannot occur without authorization.

This is what Entroid changes, and the claim is architectural — a property of how the fabric is designed, not a benchmark or a case study. On the fabric, an IT asset — a license, a seat, a SaaS entitlement, a device — is a governed object, and its lifecycle actions — request, provision, assign, reclaim, renew, retire — execute as Deterministic Workflows with governance enforced inline, before the action completes, not audited after it. Business Planning puts the budget and the entitlement on the fabric as an authority ceiling. The consuming action — assign, install, subscribe — is evaluated against that ceiling at the moment it is attempted. Within the ceiling, the action executes and the record updates, because the action is the record update. Beyond the ceiling, the workflow refuses — or routes to a human approval, with the cost attached, because human-in-the-loop judgment is a first-class primitive, not an escalation email. Either way, the approval or the refusal lands in the immutable per-action audit trail.

This is not a zero-integration fantasy. ES runs over the estate you already have — the SaaS admin consoles, the cloud accounts, the endpoint tooling — through Connectors, the only primitive on the fabric permitted to touch external systems. The difference is placement: the connector call happens downstream of the gate, inside the governed workflow. The external console executes; it no longer decides.

Consider — as an illustration, not a case study — a department head requesting twenty seats of an analytics product. The workflow checks the entitlement pool and the budget line inline: twelve seats are available and assign immediately, recorded in the same motion. The remaining eight would breach the ceiling, so they route to the budget owner with the renewal cost attached. Approval raises the ceiling deliberately, on the record; refusal costs nothing and leaves no residue. Either way, there is no surprise waiting at true-up time — because the moment of consumption was the moment of decision. The record cannot diverge from reality, not because it is reconciled quickly, but because there is no path by which reality changes without the record changing in the same governed action. Accuracy by construction, not by chase.

GOVERNANCE BY RECONCILIATIONDevicesSaaSCloudthe estate changes outside the recordInventory (snapshot)re-scanNormalize · ReconcileLicense position — a reportRecommendation → an adminacts in another consoleGOVERNANCE BY CONSTRUCTIONrequest · provision · assign · subscribe · reclaim · retireinline gate: budget · entitlement ceilingover the ceiling → refused, or routed to human approvalworkflow executes via governed ConnectorSaaS · cloud · endpointsimmutable per-action auditevery approval and refusal recordedrecord = reality, by construction

An honest note, because expert readers will raise it: vendor audits cover history. Years of deployments that predate any governance still have to be reconciled, and audit defense for that legacy territory remains genuinely valuable — the license-optimization vendors' expertise does not become worthless the day a fabric goes live. Reconciliation does not vanish. What changes is its role: it stops being the control and becomes a closing account — a diminishing audit of the shrinking share of the estate that was born before governance. Consumption born on the fabric carries its authorization with it; the immutable audit trail is not preparation for an audit defense, it is the defense.

And the number the CFO actually cares about changes character. In a reconciliation architecture, the gap between entitlement and deployment grows silently and is measured periodically — which is why you budget for it. In a construction architecture, that gap cannot grow silently: a breach is either refused or converted, at the moment of attempt, into a deliberate, priced, recorded approval. Exposure stops being something you discover and becomes something the architecture bounds. The true-up line does not need to be forecast more accurately. It needs to lose its reason to exist.

Prevented spend needs no true-up — and a record that cannot drift has nothing to settle.

See what this looks like for your enterprise.

Not a demo. A strategic conversation about how your enterprise could operate
when every process runs on one governed fabric.

Start the Conversation