What an honest IT asset inventory actually finds

Diagram of IT asset management and monitoring delivered by Stark Technology

Almost every environment we take over arrives with an asset list. Almost none of them are true. The list is usually a spreadsheet that someone maintained carefully for about four months, and then a laptop was replaced in a hurry, a server was rebuilt, a licence was renewed by finance rather than IT, and the document quietly stopped describing reality.

That matters more than it sounds. Almost every other IT decision you make — budget, security, compliance, capacity — is downstream of knowing what you own.

The three questions most companies cannot answer

When we start an asset review we ask three deliberately simple questions. If a business can answer all three without going to look, its IT function is in good shape. Most cannot answer any of them.

  1. What do we own? Not what we bought — what is currently powered on and in use.
  2. Where is it? Which office, which floor, which rack, which person.
  3. Is it still supported? Warranty, licence and end-of-life status, per item.

What the first honest count usually turns up

The first proper discovery run is rarely comfortable, but it is always useful. Across the environments we have inventoried, the same findings come up again and again:

  • Equipment nobody knew was still running. A switch in a comms cupboard, a server that was supposed to be decommissioned two years ago, a wireless controller still passing production traffic.
  • Licences being paid for machines that no longer exist. This is the one that pays for the exercise. Per-device licensing renews on a list, and the list is rarely pruned.
  • Warranty that expired quietly. Hardware out of support is not a problem until it fails, at which point it becomes the only problem.
  • Duplicate spend. Two overlapping tools doing one job, bought by different departments in different years.
  • Machines with no owner. Nobody knows whose laptop this is, and it is still joined to the domain with an active account.

Discovery, then a record that stays true

A one-off count has a short shelf life. The reason inventories rot is that they are built as a project and then maintained by goodwill. The fix is to make the record a by-product of monitoring rather than a separate chore.

In practice that means agent-based discovery on endpoints and servers, network discovery for the infrastructure that will not take an agent, and a single database that both feed. When a device appears on the network, it appears in the record. When it stops reporting for thirty days, it is flagged rather than silently forgotten.

A backup that has never been restored is an assumption. An inventory that is not fed by monitoring is the same thing — a document that describes the day it was written.

What good looks like

The target is not a beautiful spreadsheet. It is the ability to answer a question in under a minute. A useful asset record holds, for every item:

  • Make, model, serial and asset tag
  • Owner and physical location
  • Purchase date, warranty end and planned refresh date
  • Operating system and patch level, for anything that runs one
  • Licences attached to it, and their renewal dates
  • Current health — reachable, reporting, within capacity

What it is actually for

Three things, all of which save money or trouble:

Refresh planning instead of emergency replacement

When you know that eleven laptops fall out of warranty in the same quarter, you can budget for them. When you do not, you buy them one at a time at retail prices, usually urgently.

Renewals you can defend

Licence reconciliation against what is actually deployed is the single fastest way to reduce IT spend without reducing capability. You are not cutting anything — you are stopping payment for things that are not there.

Audits that do not consume a fortnight

ISO 27001, PCI DSS and SOC audits all ask for an asset register. If you keep one continuously, the evidence already exists. If you do not, someone spends two weeks reconstructing it, and the auditor can usually tell.

Where to start if the list has already rotted

Do not try to correct the old spreadsheet. Start again with discovery, accept that the first output will contain surprises, and reconcile the differences deliberately — each surprise is either something to decommission, something to bring under management, or something to stop paying for.

We run this as a fixed-scope engagement before any managed service starts. IT Asset Management →