SaaS Management

Software Asset Management (SAM): The Complete Guide for 2026

Deeksha Chowdhury
Product Marketing Manager, Zluri
Last Updated
January 2, 2026
8 MIn read

Ready to secure your identity surface?

About the author

Deeksha is a Product Marketing Manager at Zluri. She has five years of SaaS experience. Her work focuses on product positioning, messaging, and GTM strategy for Zluri’s Identity Governance and Administration platform. With an IT background, she understands the challenges IT and security teams face around access management and automation. That helps her bridge technical depth with clear, outcome-driven messaging for decision-makers. In her spare time, she enjoys traveling, dancing, and drawing.

Software asset management is the discipline of knowing, at any moment, what software your organization has, what it costs, whether you're compliant with its terms, and whether it's actually being used. The discipline is thirty years old and more necessary than ever. What changed is the software: the estate SAM must now manage is mostly rented, invisible to network scans, and bought by people who never told IT. This guide covers the discipline in full, including the parts the classic playbook no longer reaches.

Every organization runs on software it has partially lost track of. Not through negligence, but through arithmetic: hundreds of applications, thousands of licenses, dozens of contract terms, and purchasing that happens in more places than any one team can watch. Software asset management (SAM) exists because at that scale, "we probably know what we have" reliably means "we're overpaying, under-securing, and one audit away from finding out by how much."

This guide covers SAM end to end: what it is, why it matters financially and legally, its core components, the lifecycle every software asset moves through, how SAM relates to ITAM and ITSM, and the honest 2026 question, which parts of the classic discipline still work as designed, and which parts broke when software stopped being something you install.

What Is Software Asset Management?

Software asset management is the set of processes for managing, controlling, and optimizing every software asset an organization owns or subscribes to, across its entire lifecycle: from the decision to acquire it, through deployment, active use, and renewal, to its eventual retirement.

In operational terms, a working SAM practice answers four questions continuously:

  1. What software do we have? Every application in use, including what was never officially purchased.
  2. What does it cost? Contracts, subscriptions, and the gap between what's contracted and what's actually billed.
  3. Are we compliant? Usage within the terms of every license agreement, provable on demand.
  4. Is it being used? Actual utilization per license, because software that isn't used is spend without return, and often risk without owner.

The distance between an organization that can answer these four questions on any given Tuesday and one that reconstructs the answers once a year for an audit is, in practice, the distance between managed and unmanaged software spend.

Why SAM Matters: The Four Stakes

Cost. Software is one of the largest controllable line items in any modern budget, and the waste hides well: seats assigned to departed employees, premium tiers bought for users who need the basic one, duplicate tools solving one problem in three departments, and renewals that fire automatically at last year's counts. None of it looks like waste on an invoice. All of it is.

Compliance and legal exposure. Every license agreement is a binding contract with enforceable terms. In the enterprise software world, vendors run audit programs specifically designed to find the gap between what you deployed and what you bought, and settling that gap on the vendor's timeline is the most expensive way to buy software that exists.

Security. Untracked software is unmanaged software: unpatched versions, abandoned accounts, tools with access to company data that no one is accountable for. The software you don't know about is precisely the software nobody is securing.

Decision quality. Budgeting, vendor negotiation, and consolidation decisions are only as good as the inventory underneath them. An organization negotiating a renewal without usage data is negotiating against itself.

The Five Core Components of SAM

1. Software Inventory and Discovery

Everything in SAM depends on the inventory being complete, and completeness is now the hard part. Installed software can be found by scanning devices and networks. SaaS cannot: it leaves no installation anywhere, so discovery has to read the signals SaaS actually emits, including SSO and identity provider logins, direct app integrations, finance and expense transactions, MDMs, CASBs, HRMS data, directories, and browser activity.

An inventory built only from procurement records or network scans will reliably miss a large share of what's actually in use: the card-expensed tools, the free tiers that converted to paid, the OAuth-connected apps with no invoice at all. Discovery breadth is the single biggest quality difference between SAM implementations.

2. License Management

Tracking what's been purchased against what's assigned and what's used, per contract, continuously. This is a deep enough discipline to have its own dedicated coverage in our guide to SaaS license management and the accompanying best practices, so the one-line summary: a license record that only knows the purchased count is a receipt, not management. The value lives in the two gaps, seats purchased but assigned to nobody, and seats assigned to people who never use them, because those gaps are where the recoverable money sits.

3. Compliance Management

Ensuring usage stays within every agreement's terms, and being able to prove it. For installed enterprise software, this means entitlement reconciliation against complex license metrics. For SaaS, the compliance surface shifts toward the access side: demonstrating that seats and accounts belong to current, appropriate users, which is where SAM starts overlapping with identity governance and audit frameworks like SOX ITGC.

4. Usage Monitoring and Optimization

Per-license activity data, gathered continuously, is what converts an inventory from a record into a decision tool. It's how underused licenses get identified for reclamation, over-tiered users get identified for downgrade, and redundant tools get identified for consolidation. Without it, every optimization conversation is opinion versus opinion.

5. Lifecycle and Retirement Management

Software assets need a managed exit as much as a managed entrance. Retirement discipline (archiving unused apps, terminating lapsed contracts, closing the accounts attached to both) is what prevents the estate from accumulating stale entries that quietly keep billing and quietly keep access open.

The SAM Lifecycle

Every software asset moves through five stages, and most waste can be traced to a stage where nobody was watching:

  1. Plan and acquire. Need identified, overlap with existing tools checked, terms negotiated, purchase made through a defined process. Waste enters here as duplicate purchases and over-tiering.
  2. Deploy and assign. The software enters the inventory, gets an owner, and licenses get assigned, ideally by role rather than by maximal default templates.
  3. Operate and monitor. Usage, cost, and compliance tracked continuously through the asset's active life. This is the most commonly skipped stage, and skipping it is why the later stages run blind.
  4. Optimize and renew. Idle licenses reclaimed, tiers corrected, and renewals treated as staged decisions informed by the monitoring data, not calendar events that fire unexamined.
  5. Retire. Usage ends, the contract terminates, accounts close, and the record is archived. An asset that exits the environment without exiting the inventory (or worse, exits the inventory while still billing) is the signature failure of this stage.

SAM, ITAM, and ITSM: Where the Boundaries Sit

SAM is one discipline within a larger family, and the boundaries are worth keeping crisp:

  • IT asset management (ITAM) is the umbrella: hardware, infrastructure, and software together, managed as assets through their lifecycles. SAM is ITAM's software half, and in most organizations, its faster-moving and worse-inventoried half.
  • ITSM manages the services IT delivers (incidents, requests, changes), not the assets themselves. The two meet constantly: a well-run offboarding ticket (ITSM) should trigger license reclamation (SAM), and the interesting failures happen at exactly these handoffs.

What Changed: The Classic Playbook and the SaaS Estate

The classic SAM playbook was engineered for a specific kind of software: installed on machines you control, licensed through complex perpetual entitlements, purchased through procurement, and audited by vendors. For that estate, the playbook still works, and organizations with significant Oracle, IBM, SAP, or Microsoft datacenter footprints still need it in full.

But the majority of most organizations' application count no longer fits that description, and the differences aren't cosmetic. SaaS leaves nothing to scan. It bills continuously, so a stale record has a recurring price. It enters through corporate cards and OAuth grants as often as through procurement. And every SaaS license is an account, an identity with access to data, which makes license management inseparable from access management.

The result is that SAM in 2026 is really two disciplines wearing one name: classic entitlement-centric SAM for the installed estate, and identity-centric SaaS management for everything else. The full comparison, including when you genuinely need both, is covered in our breakdown of SAM vs SMP. The one-line summary: the expensive mistake is not choosing the wrong one, it's assuming either covers the other.

A note on standards: ISO/IEC 19770 remains the formal standards family for SAM processes and software identification tags, and it retains genuine relevance for entitlement-heavy on-premises estates and audit-driven programs. For a SaaS-majority estate, its tagging mechanics matter far less than discovery breadth and identity-connected license data, which the standard was never designed to address.

Getting Started: A Practical Sequence

For an organization building or rebuilding a SAM practice, sequence matters more than tooling brand (the full sequencing argument lives in our software asset management best practices):

  1. Establish the complete inventory first, from every signal source available, not just procurement records. Every subsequent step inherits this step's blind spots.
  2. Attach the three numbers to your largest contracts: purchased, assigned, used. Start where the money is concentrated; ten contracts usually cover the majority of spend.
  3. Assign ownership. Every application needs an accountable owner for administration, cost, and risk. Unowned assets are where problems age quietly.
  4. Put every renewal on a calendar with staged alerts, far enough ahead to decide something. Auto-renewal is the tax on organizations without this.
  5. Automate the lifecycle events. Wire license assignment and reclamation into onboarding, role changes, and offboarding, because those events, not audits, are where waste and risk are created.
  6. Then audit and measure, as verification that the continuous machinery works, not as the primary way anything gets discovered. The metrics worth tracking are covered in our guide to ITAM KPIs.

The tooling that runs this at scale is its own evaluation, covered in our guide to software asset management tools.

Where Zluri Fits

We built Zluri for the SaaS and identity half of the SAM problem, and we're specific about that scope: we don't do hardware inventory or on-prem entitlement math, and estates heavy in enterprise datacenter licensing still need classic SAM tooling for that layer.

For the SaaS estate, our SaaS management platform runs the discipline described in this guide as continuous machinery: discovery across eight methods against a 240,000+ application catalog, a complete asset record per application (users, licenses, contracts, spend, and risk on one profile with accountable owners), purchased-assigned-used reconciliation per contract, staged renewal management routed to named owners, consent-first reclamation of flagged waste, and license lifecycle automation tied to joiner-mover-leaver events. The license machinery specifically is documented in how Zluri handles software license management.

Frequently Asked Questions

What is software asset management in simple terms?

It's the practice of continuously knowing four things about every piece of software in your organization: that it exists, what it costs, that you're using it within its license terms, and whether it's actually being used. Everything else in SAM (tools, audits, processes, standards) exists to keep those four answers accurate at scale.

What's the difference between SAM and ITAM?

ITAM is the umbrella discipline covering all IT assets: hardware, infrastructure, and software. SAM is the software-specific half of it. In practice the two halves need different instruments: hardware is tracked through physical and network inventory, while modern software, being mostly SaaS, is tracked through identity, financial, and usage signals that hardware-era tools can't see.

Is SAM still relevant if almost all our software is SaaS?

The discipline is more relevant, because SaaS multiplies the number of applications, moves purchasing outside IT, and attaches a recurring monthly price to every stale record. What changes is the method: discovery from identity and finance signals instead of network scans, continuous license reconciliation instead of periodic audits, and lifecycle automation tied to HR events. The goals of SAM survive intact; the classic instruments mostly don't.

How is SAM different from license management?

License management is one component of SAM, focused specifically on entitlements, seats, usage, and renewals. SAM wraps that in the fuller asset picture: inventory and discovery, ownership and accountability, compliance posture, and lifecycle management from acquisition to retirement. Strong license management on top of an incomplete inventory optimizes the software you know about while the rest leaks unmanaged.

What does a vendor software audit look for?

Primarily the gap between deployment and entitlement: instances installed or users provisioned beyond what your agreements cover, mislicensed virtualization, and lapsed terms still in use. For SaaS, audit pressure runs the other direction more often: your own compliance auditors asking for proof that seats and accounts belong to current, appropriate users. A working SAM practice produces evidence for both without a scramble, and for high-stakes enterprise audits, specialist SAM service providers exist precisely for the defense work.

Ready to secure your identity surface?