Your new workforce won't be all human. Join the
conference to learn how to manage it.
request invite

Share this article

Discovery is Solved. But Your Software Inventory is Still Wrong.

One reconciliation sweep found six things wrong with a software inventory. The most useful was the one the AI Coworker refused to fix.

TL;DR: Every CIO can list their applications. Nobody can promise the list is still correct, and once it drives purchasing, access and renewals, wrong data starts making decisions on its own. One reconciliation sweep found six things worth someone's attention, and the most useful was the one it refused to fix.

Ask a CIO to list their applications and they can. Discovery solved that. Ask when the list was last correct and the room goes quiet.

That used to be a tidiness problem. It is not any more. An inventory now feeds purchasing, access reviews, offboarding and renewal calendars. A wrong seat count triggers a purchase. A stale assignment leaves access open. A missing renewal date lets a contract roll over. The automation executes faster than anyone reviews it.

Discovery runs continuously. Cleanup runs quarterly.

Ask a software asset manager what they actually do all week. Decide whether a discovered record is a real license or a free console. Decide whether two records are the same product. Find out who owns it. Notice the contract data is missing. Notice the seat count is not believable. None of it is hard. There are hundreds of them and they never stop arriving.

That is why inventories decay. Discovery keeps running, people join and leave, vendors rename products, assignments move. The inventory starts rotting the day after someone cleans it, which makes a quarterly cleanup structurally guaranteed to lose. It is a continuous workload staffed as a periodic project.

So we pointed a License Data Steward Coworker at a reconciliation ticket in a demo tenant, against Software License and License Assignment records populated by identity discovery. It came back with six findings. Each one costs a different person something.

The count was already wrong before anyone read it

One application had two records. That splits the seat pool, so a shortage calculation watching one of them sees a pool too small to cover its assignments, fires, and procurement buys seats the company already pays for. Nobody decided to double buy. The data decided. The Coworker flagged the pair and refused to merge them, because a merge destroys the assignment history on the losing record.

And nothing in the budget cycle pushes back. An unspent line gets cut the following year, so a team that discovers it is paying twice has no reason to say so out loud. The saving does not come back to them. It comes off their number. Duplicate spend survives because reclaiming it is punished.

Then there were the records that were never licenses. Discovery faithfully returns free vendor consoles and internal utilities alongside paid products, and defaults them to per seat, because per seat is the common case. They have no purchased quantity, no cost, no renewal date. Left classified as products, they inflate every application count you report, forever.

The two it would not answer

One record could have been a licensed product or an internal sync tool. The name did not settle it, and the answer determines whether contract data applies at all. Guess one way and someone chases a contract that does not exist. Guess the other way and a paid product sits outside cost tracking. So it asked one precise question and moved on.

The second one is the part worth arguing about. A record claimed four assigned seats. The assignments underneath it showed one. The Coworker had the answer, had a write tool, and left the four alone.

That count is derived from the assignments beneath it. Changing the four to a one would make the record look right while the broken source stayed broken, and it would erase the only evidence that two systems disagree. So it documented the discrepancy and named the question a human has to answer: which system is wrong.

Traditional cleanup fails at exactly this point. Someone edits four to one, closes the task, and next sync it is four again.

The dangerous agent is not the one that cannot act. It is the one that sees something wrong and fixes it immediately, because a confident correction looks exactly like progress. The control that matters is not whether AI can write. It is whether it knows which fields it owns and which ones it must not touch.

Two answers that are not in any API

A revoke requested on 3 August during an offboarding was still pending 21 days later with no vendor confirmation. Either it completed and nobody updated the record, or it never completed and a former employee still has access. Same symptom, opposite consequences. A license marked returned is not evidence that access was removed.

A group of applications had no purchased seat count at all, because no provider API publishes what you bought. That number lives in the contract. A threshold with no denominator does not fail loudly. It reports green forever. Separately, a paid tool had its annual cost recorded at 1,176 dollars and no renewal date, which is how auto-renewals win. Discovery gives you visibility. Contract data is what turns visibility into license management.

What the admin's week becomes

The admin stops maintaining an inventory and starts resolving exceptions: one merge decision, one classification question, one revoke to verify, a short list of contracts to open. Everything determinable was determined and annotated before a person opened the ticket.

Two things decide whether a finding becomes an outcome. Every application needs a named owner, because an alert without one lands nowhere. And every judgement needs to leave evidence, because when an auditor asks who had access and what proves it, a status field is not an answer. The refusal to overwrite that seat count is itself on the record, which means the reasoning outlives the person who made it.

The Coworker classifies, annotates, reconciles, recommends, asks and escalates. It is an Atomicwork AI Coworker with write access scoped to the fields it owns, and every write it makes is reversible. Purchases, retirements, merges, migrations and anything destructive stay with people. Automate the investigation, not the accountability.

The sweep closed nothing, and said so. It cost under a dollar, which matters for exactly one reason: it can run again tomorrow, and drift caught daily never compounds.

So the question for your own estate is not whether discovery works. It is whether anyone can tell you the date your inventory was last true, and what has been bought, granted and renewed on top of it since.

This was a real run in a demo tenant, not a production estate. It is smaller than a real environment, the app mix skews to tools we use, and several records are thin because nobody ever filled them in.

Sources: A license reconciliation sweep ticket worked by a License Data Steward Coworker against Software License and License Assignment records populated by identity discovery. All values are read from that run's report. No savings, accuracy or coverage percentages are claimed. User email addresses in the run are omitted.

Meet 100+
tech-forward CIOs
Date icon for Atomicwork event
Sept 24, 2025
Venue icon for Atomicwork event
Palace Hotel, SF
Request an invite

Frequently asked questions

Chevron navigation icon on Atomicwork website
FAQ question text
Chevron navigation icon on Atomicwork website

You may also like...