Skip to content

Track software and licences

Applies to
  • All users
  • Managers
  • Admins
Before you start
  • The assets that software runs on already exist
  • You know which titles are approved for your organisation

Software & License Management keeps one authorised-software catalogue, records where each title is installed across your assets, and tracks the seat position, renewals and compliance state of every title. It produces the SOC 2 CC6.1 evidence auditors ask for — the authorised-software inventory, seat position and prohibited-software detection in one place.

Find it under GovernanceSoftware. The desk has three tabs: Catalogue, Installations and Compliance.

The catalogue is your register of software titles. A handful of starter titles seed automatically on a new account; add your own from CatalogueAdd title.

  1. Enter the Name and Publisher — both are required.
  2. Add a Version if it matters (optional).
  3. Choose the Licence model — Per seat, Per device, Concurrent, Subscription, Perpetual, Open source or Freeware.
  4. Set the Authorisation status (see below).
  5. Enter Purchased seats if the title is licensed by seat.
  6. Add an Owner, a Contract, Linked assets, an Expires at date, a Renewal reminder and Labels as needed.
  7. Save the title.

Only Per seat, Per device and Subscription titles are seat-bounded — the others show Not seat-limited for this model and never render a seat bar.

The catalogue list shows each title with its model, authorisation, seat position, compliance state and expiry. An expiry date turns amber inside its renewal window and red once it has passed.

The Software catalogue tab listing three titles — Microsoft 365 marked Compliant at 42 of 50 seats, Adobe Creative Cloud marked Over-licensed at 13 of 10 seats with a +3 over badge, and a Prohibited uTorrent entry — with columns for model, authorisation, seats, compliance and expiry.

Every title carries an Authorisation status:

  • Approved — cleared for use.
  • Approved (restricted) — allowed under conditions.
  • Pending review — not yet decided. This is the default for a new title.
  • Prohibited — must not be installed.

Approving, restricting or prohibiting a title is a privileged action — only an owner or admin can set those. Anyone who can create or edit a title can leave it Pending review.

Each title shows its seats as used / purchased — for example 42 / 50. A seat-bounded title with more installs than seats is flagged Over-licensed and shows a +N over badge; a title with no seat cap reads N / unlimited and shows no bar. The count carries a reconciled … · recomputed nightly stamp so you know how fresh it is.

The Installations tab is the inventory of where software actually runs. Nothing is seeded here — add installs one at a time, or import them.

  1. Go to InstallationsAdd installation.
  2. Pick the Host asset — this is required.
  3. Link the Catalogue title. Leave it blank if the software isn’t in the catalogue — it will be flagged Unlicensed.
  4. Record the Raw name as reported by MDM, a Version, and the Installed at date.
  5. Choose the Discovery source — Manual, MDM sync, CSV import or API webhook.
  6. Save.

An installation’s Status — Compliant, Over-licensed, Unlicensed, Prohibited or Pending review — is normally recomputed nightly from the catalogue link. When editing an install you can set a manual status override, but the nightly job will recompute it. The discovery source can’t be changed after an install is created.

To load an MDM or CSV export, use Import CSV on either tab. The wizard runs in four steps — Upload, Map columns, Preview and Result.

  • Files are parsed in your browser; CSV and XLSX are accepted, up to 5,000 rows per import.
  • Every row needs a host asset id; the other columns are optional.
  • The discovery source is set to CSV import automatically.
  • The server validates each row: unknown host assets fail and duplicates are skipped, so an import can finish partly done. The result screen breaks the run down into total, created, skipped and failed.

The Compliance tab is the CC6.1 authorised-software evidence artefact. It lists every catalogue title with its publisher, seat position, compliance state, expiry and contract, sorted by name. It is generated on read and reflects the last nightly reconciliation, and it carries a Generated timestamp.

Four roll-up chips summarise the position: Compliant, Over-licensed, Prohibited / unlicensed and Pending review. Filter by a compliance state to narrow the table — a filter bypasses the five-minute server cache and returns the live position. Use Print / Export to produce a copy for an auditor.

Open a title and choose Archive to hide it from the catalogue while keeping it for audit.

An owner can Delete permanently instead. This can’t be undone — it removes the title and sets every installation linked to it to Unlicensed by clearing the catalogue link.

Compliance state on a title is one of Compliant, Over-licensed, Unlicensed present, Prohibited present or Pending review. An installation reads Compliant, Over-licensed, Unlicensed, Prohibited or Pending review. Both are set by the nightly job unless you override an installation by hand.

Everyone with access can read the catalogue, installations and the compliance evidence. Managers can add and edit titles, edit installations and run imports. Archiving, authorising a title and permanent deletion are reserved for owners and admins — and only an owner can delete a title permanently.