By NHI Mgmt Group Editorial TeamBased on Zluri: “Key Metrics Every IT Asset Manager Should Track (ITAM KPIs)” (June 26, 2025)

TL;DR: IT asset management metrics help organisations measure utilisation, compliance, and lifecycle control across hardware and software, while highlighting how shadow IT and unused licences undermine governance, according to Zluri. The real test is whether ITAM data is wired into identity, onboarding, offboarding, and renewal decisions rather than treated as a reporting exercise.


At a glance

What this is: This is a metrics-led ITAM article that ties asset utilisation, software licence compliance, and lifecycle tracking to the governance gaps created by shadow IT and unused software.

Why it matters: IAM and IT governance teams need these metrics because SaaS control only works when lifecycle data informs access, renewal, and offboarding decisions, not when it sits in a dashboard.


Context

IT asset management is the discipline of tracking assets through their full lifecycle, from deployment and maintenance through to retirement. In this article, the governance gap is not discovery alone but whether those asset metrics are turned into decisions that reduce waste, duplicate tooling, and ungoverned software use.

For identity teams, the connection is straightforward: software access, licence entitlement, and user lifecycle are tightly linked. When ITAM data is disconnected from onboarding, offboarding, and renewal workflows, organisations can measure sprawl without actually reducing it.


Key questions

Q: How should security teams govern access across SaaS sprawl?

A: Security teams should govern SaaS sprawl with one inventory, one policy model, and one review process that covers both human and non-human access. The practical goal is to connect application approval, entitlement review, and revocation to business ownership. Without that linkage, access governance becomes a manual cleanup exercise instead of a control system.

Q: Why does licence compliance break down when usage data is missing?

A: Because compliance without usage context can only confirm what was purchased, not what is still needed. When organisations do not know which applications are actively used, they cannot distinguish legitimate entitlements from dormant ones or unauthorised installs. That creates reporting confidence without actual control, especially in SaaS estates that change quickly.

Q: What are the signs that ITAM controls are not working?

A: Common signs include duplicate applications, expired licences still assigned, high numbers of unused seats, poor asset utilisation, and hardware that stays in maintenance too long. These are not just operational inefficiencies. They indicate that lifecycle ownership is fragmented and that procurement, security, and HR workflows are not aligned.

Q: What should organisations do when software access is tied to role changes?

A: They should treat role changes as governance triggers, not administrative updates. When a person moves teams, changes seniority, or leaves, software entitlements should be reviewed and adjusted in the same workflow. That prevents access from persisting after need has changed and helps reclaim licences at the same time.


Technical breakdown

Software licence compliance and entitlement drift

Software licence compliance is not just a procurement metric. It reflects whether entitlements, renewals, and active use still align with the organisation’s approved software estate. The article points to expiring licences, unauthorized software, blacklisted applications, and out-of-compliance licenses as the main signals that software governance is breaking down. In identity terms, the issue is that access and entitlement decisions are being made without a current view of actual use. That creates both waste and control drift, especially in SaaS environments where purchase, assignment, and revocation often happen in separate systems.

Practical implication: tie licence compliance reporting to access governance so renewal, removal, and reallocation happen from the same source of truth.

Hardware utilisation and lifecycle planning

Hardware utilisation is about whether physical assets are being used efficiently enough to justify their cost and replacement cycle. The article treats utilisation, assets under maintenance, average workstation cost, and average asset age as planning indicators that help forecast demand and reduce unnecessary purchases. This matters because lifecycle governance fails when organisations treat devices as static inventory rather than managed assets with depreciation, maintenance windows, and retirement points. In practice, a low-utilisation estate is often a sign of weak assignment discipline or poor joiner-mover-leaver coordination.

Practical implication: use utilisation and age data to drive refresh planning, reassignment, and retirement instead of relying on ad hoc procurement.

SaaS sprawl as an identity governance problem

SaaS sprawl becomes an identity governance problem when application inventory, licence assignment, and employee lifecycle workflows are not connected. The article highlights duplicate applications, unused licences, hidden app spend, and automated onboarding and offboarding as core management concerns. That means the real failure mode is not just cost leakage. It is uncontrolled application access across departments and roles. Once a team cannot reliably see who has what software, the organisation loses the ability to govern access, recertify need, or reclaim licences at the right time.

Practical implication: build ITAM, IGA, and SaaS management into one operating model so software access follows role and lifecycle changes.


NHI Mgmt Group analysis

SaaS lifecycle control is now an identity governance issue, not just an ITAM issue. The article’s core value is that asset metrics only matter when they inform entitlement decisions, offboarding, and renewal governance. Unused licences and shadow IT are symptoms of disconnected operational ownership, not merely inefficient procurement. Practitioners should treat SaaS inventory as part of access governance, not a separate reporting stack.

License compliance without usage context creates false confidence. An organisation can report on compliance while still carrying unauthorized software, expired entitlements, and duplicate tools across departments. That is a governance gap, not a tooling gap. The practical implication is that compliance reporting must be tied to active use and approval status, or the metric becomes descriptive rather than controlling.

ITAM metrics expose where lifecycle processes are failing. Asset age, utilisation, maintenance state, and licence counts are all lifecycle indicators, not standalone KPIs. When those indicators are not wired into joiner-mover-leaver workflows, organisations overbuy, under-reclaim, and miss the moment when access should change. Teams should read these metrics as control signals, not finance-only outputs.

Identity programmes need a shared operating model for software access and asset ownership. The article points to onboarding and offboarding automation as the bridge between ITAM visibility and governance action. That bridge matters because software access often outlives role need, and the same gap that creates wasted spend also creates lingering access. The practitioner conclusion is simple: asset lifecycle control and access lifecycle control should not be run as separate disciplines.

Hidden app spend is a governance blind spot because it masks unmanaged access paths. Once software use fragments across business units, neither procurement nor security has a complete picture of entitlement exposure. The named concept here is SaaS lifecycle drift: the gap between what is procured, what is assigned, and what is still actively needed. Practitioners should recognise that drift as an identity problem with budget consequences, not the other way around.

What this signals

SaaS lifecycle drift: The biggest governance gap is the space between what was procured, what is assigned, and what is still actively needed. When that gap is left unmanaged, teams lose control of both licence spend and software access.

ITAM metrics are most useful when they are treated as control inputs, not retrospective reports. Utilisation, age, and compliance data should trigger reassignment, renewal, or retirement decisions inside the same operating process.

The broader signal for identity teams is that software governance now depends on joining inventory, entitlement, and lifecycle data. Without that connection, organisations can optimise cost on paper while leaving access and duplication untouched.


For practitioners

  • Link software licence data to joiner-mover-leaver workflows Use employee role, department, and status changes to trigger licence assignment, removal, and review so software access stays aligned with actual need.
  • Measure utilisation before renewing major applications Review active use, duplicate apps, and entitlement counts ahead of renewal windows so renewal decisions reflect consumption rather than contract inertia.
  • Create a central software inventory for compliance checks Maintain one inventory of approved, blacklisted, expired, and active software so compliance teams can validate entitlements against current use.
  • Use asset age and maintenance status in refresh planning Track average age and maintenance backlog for hardware so replacement and reassignment decisions are based on lifecycle condition, not guesswork.
  • Automate offboarding for SaaS licence reclamation Ensure deprovisioning workflows remove unused access and return licences as part of standard leaver handling, especially for high-cost SaaS categories.

Key takeaways

  • ITAM KPIs expose whether software and hardware are actually being governed through their lifecycle, not merely recorded in an inventory.
  • The article links shadow IT, duplicate applications, and unused licences to a larger control gap between asset reporting and identity-driven decisions.
  • The practical response is to connect ITAM data to onboarding, offboarding, renewal, and refresh workflows so governance actions happen when they should.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity and Access ManagementThe article ties software access and lifecycle control to SaaS governance.
Recommendation — Apply IAM governance to keep software access aligned with assignment and offboarding.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsLicence assignment and revocation are authorisation problems in this article.
Recommendation — Review entitlement assignments against PR.AA-05 so access stays tied to current need.
CIS Controls v8CIS-5 — Account ManagementLifecycle-driven software access and offboarding map to account management discipline.
Recommendation — Use CIS-5 to remove stale software access and reclaim unused licences during offboarding.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article’s governance gap is persistent access that outlives need.
Recommendation — Apply AC-6 to keep software access limited to the minimum current role requirement.

Key terms

  • It Asset Management: IT asset management is the discipline of tracking technology assets across their useful life so they can be procured, deployed, maintained, renewed, and retired with accountability. In security programmes, it becomes valuable when lifecycle records are tied to ownership, entitlement, and revocation decisions.
  • Software License Compliance: Software license compliance is the state in which deployed software matches contractual entitlements, usage limits, and policy requirements. It is not just a legal check. It is an operational control that shows whether renewals, removals, and exceptions are being managed with evidence.
  • SaaS Sprawl: SaaS sprawl is the uncontrolled spread of software-as-a-service applications across teams and business units. It creates fragmented ownership, duplicated functionality, and weak visibility into who can access what. For IAM and NHI teams, the main risk is not only cost but persistent entitlements that outlive business need.
  • Lifecycle Governance: Lifecycle governance is the set of controls that cover creation, assignment, review, rotation, and retirement of identities and credentials. For NHIs, it is the difference between a temporary automation asset and a persistent access risk. Strong lifecycle governance keeps ownership and expiry tied to actual business use.

Deepen your knowledge

NHI governance, identity lifecycle management, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org