At a glance
- Challenge
- SAM capability lives in individuals rather than in defined services, so it does not survive a departure, an acquisition or a change of sponsor.
- Approach
- Assess maturity, secure an executive mandate, define a service catalogue with named ownership and SLAs, then build governance and an optimisation pipeline around it.
- Primary KPI
- % of agreed SAM services operating with named ownership, defined controls and measured SLAs.
- Impact
- A capability that survives personnel change, with audit and renewal readiness as a standing state rather than a periodic scramble.
01
Executive Summary
There is a specific failure mode this playbook addresses, and it is not a lack of tooling. An organisation has a SAM platform, competent people and a reasonable data position — and none of it is written down as a service. Publisher knowledge lives with one analyst. The renewal calendar is in someone's calendar. Audit response depends on a person who has done it before. When that person leaves, the capability leaves with them.
This playbook is deliberately distinct from the platform implementation playbook. That one builds the technical capability; this one builds the organisational one. It covers the maturity assessment and executive mandate, the service catalogue that defines what SAM actually provides, the RACI that names who does it, the policy and control set, and the governance forums where publisher, renewal and audit decisions are taken.
The measure of success is uncomfortable but useful: could the function operate to the same standard if any single individual left tomorrow? An operating model exists when the answer is yes, and it does not exist when the answer is anything else.
02
Business Challenge
Undefined SAM capability presents as unpredictability. Some publishers are well governed and others are not, with no visible reason for the difference. Renewals are handled excellently when the right person notices them and poorly when they do not. Audit responses vary in quality by an order of magnitude. Leadership cannot forecast the function's output because the function has no defined output.
The second problem is that without defined services there is nothing to resource against. A request for headcount or for a managed service cannot be justified because the work has never been enumerated. So the function stays understaffed, prioritises reactively, and the highest-value work — proactive optimisation and renewal preparation — is permanently displaced by whatever is most urgent.
03
Typical Symptoms
Organisations that need this playbook usually recognise several of the following.
- Publisher expertise lives with named individuals and is not documented anywhere.
- The renewal calendar exists in a personal calendar or spreadsheet rather than as a governed asset.
- Audit response quality depends entirely on who happens to handle it.
- There is no service catalogue, so SAM's scope is defined by whatever it is asked to do.
- No SLA exists for any SAM service, so performance cannot be assessed or resourced against.
- Optimisation work is displaced by reactive requests every quarter without exception.
- Policy either does not exist or exists in a document nobody has read since it was written.
- Nobody can state what value the SAM function delivered last year in terms finance recognises.
04
Business Risks
Business risks by domain, with the risk and its impact
| Domain | Risk | Impact if unaddressed |
| Operational |
Capability held in individuals rather than in defined, documented services |
A departure removes publisher expertise, renewal awareness and audit competence simultaneously, and the function regresses by years rather than by weeks. |
| Commercial |
Reactive work permanently displacing proactive optimisation and renewal preparation |
The highest-value activity never happens. Renewals are handled at short notice and optimisation opportunities expire against contract dates. |
| Compliance |
Inconsistent publisher governance and audit readiness across the estate |
Some publishers are well evidenced and others are not, and exposure concentrates precisely where governance attention has been thinnest. |
| Technology |
No data governance or ownership over the SAM data estate |
Data quality degrades without anyone accountable, and confidence in the platform erodes until parallel spreadsheets reappear. |
05
Operating Workflow and Reference Architecture
Operating workflow
11 stages, each producing a defined output. This workflow is specific to this
playbook; the category lifecycle on the
Software Value index is an overview of how the playbooks relate,
not how any one of them runs.
↔ Wide diagram — scroll horizontally, or use the
arrow keys once it has focus. A text description is available to screen readers.
Illustrative SAM transformation workflow. This playbook builds the organisational capability; the platform implementation is covered separately in SV-001. Outcomes are not guaranteed and depend on sponsorship, scope and organisational context.
Reference architecture
The systems, data and controls the workflow above runs on.
↔ Wide diagram — scroll horizontally, or use the
arrow keys once it has focus. A text description is available to screen readers.
Illustrative operating model. The service catalogue in layer two is the central artefact — it is what converts SAM from a set of individual competencies into something that can be resourced, measured and handed over.
06
Implementation Approach
A representative implementation sequences in 5 phases. Duration and overlap
vary with estate size, data quality and the number of source systems in scope.
Phase 1
Maturity assessment and executive mandate
Establish where the capability actually sits and secure the authority to change it. Transformation without mandate produces a document.
- Maturity assessment. Assess current capability against a recognised framework across process, data, tooling, governance and skills, with evidence rather than self-assessment.
- Risk and exposure assessment. Quantify current exposure — publishers without a validated position, renewals without preparation, audit readiness gaps — to make the case concrete.
- Executive sponsorship. Secure a named executive sponsor with the authority to assign accountability outside the SAM function, since most SAM services depend on other teams.
- Scope and mandate definition. Define formally what is in and out of scope, and where SAM's authority begins and ends.
- Target state definition. Define the target maturity level with the sponsor, since 'better' is not a target that can be resourced or assessed.
Business value
The transformation has a quantified starting point, a defined target and an executive sponsor who can assign accountability beyond the SAM team.
Phase 2
Service catalogue and operating model
Define what SAM provides as services with owners and SLAs. This is the central artefact of the whole transformation.
- Service definition. Define each SAM service with its description, inputs, outputs, consumers and SLA — licence desk, publisher management, renewal preparation, audit response, optimisation delivery, reporting, data quality.
- Process ownership. Assign a named process owner to each service, accountable for its performance rather than merely performing it.
- RACI across functions. Build the RACI across SAM, IT operations, procurement, finance and the business, since almost no SAM service is delivered by SAM alone.
- Demand and capacity model. Size the demand for each service and compare it to available capacity, which is the analysis that makes a resourcing conversation possible.
- Insource versus managed service. Decide, service by service, what is retained and what is better delivered as a managed service, on evidence rather than preference.
Business value
SAM becomes a set of defined, owned, measurable services that can be resourced, assessed and — critically — handed over.
Phase 3
Policy, control and data governance
Write down the rules and assign ownership of the data the whole capability depends on.
- Policy set. Develop the policy set — software request, deployment, reharvest, unmanaged device, entitlement change — written to be followed rather than filed.
- Control framework. Define preventive and detective controls per policy, with thresholds and a named recipient for each alert.
- Data ownership. Assign ownership for each element of the SAM data estate — inventory, entitlement, contract, ownership mapping — with quality standards per element.
- Data quality measurement. Define and report a data quality score so degradation is visible before it undermines confidence.
- Policy adoption. Measure policy adoption rather than assuming publication equals adoption, and address the gaps.
Business value
The rules exist, are measurable, and have owners — so compliance can be assessed rather than assumed.
Phase 4
Publisher, renewal and optimisation governance
Establish the governance that carries the highest-value work, and protect it from reactive displacement.
- Publisher ownership. Assign a named owner per major publisher, accountable for the position, the knowledge base entry and the renewal preparation.
- Publisher knowledge base. Document publisher-specific licensing knowledge so it survives the individual who holds it.
- Renewal governance. Establish the renewal calendar as a governed asset with lead-time triggers, named owners and a preparation standard per renewal tier.
- Audit governance. Define the audit response process, the standing evidence set and the escalation path, so response quality does not depend on who receives the letter.
- Optimisation pipeline. Establish a standing pipeline with stage gates, owners and protected capacity, so proactive work is not displaced every quarter.
Business value
Publisher expertise, renewal readiness and audit competence become organisational assets rather than personal ones.
Phase 5
Measurement, capability and continuous improvement
Report performance in terms the organisation recognises, and keep the model current.
- Service SLA reporting. Report each service against its SLA on a fixed cadence, so performance is visible and resourcing conversations are evidence-based.
- Benefits reporting. Report delivered value with finance validation, so the function's contribution is stated in terms the CFO accepts.
- Skills and capability development. Build the skills matrix, address gaps through training and cross-cover, and remove single points of dependency deliberately.
- Stakeholder feedback. Measure satisfaction among the functions SAM serves, since a technically sound service that its consumers avoid is not operating.
- Maturity reassessment. Reassess maturity on cycle and adjust the model, retiring controls that are not earning their operational cost.
Business value
The capability is measured, funded on evidence and continuously adjusted — and no single departure sets it back.
07
Technology Components
This playbook is about organisational capability rather than tooling. Platform implementation is covered separately in SV-001. Products are named as examples of the systems an operating model runs on, not as recommendations.
Operating model artefacts
- Service catalogue
- RACI matrix
- Policy and control set
- Publisher knowledge base
- Skills matrix
Platform and data
- SAM platform
- Entitlement and contract repository
- ServiceNow ITSM and CMDB
- Data quality scoring
Governance
- Software governance forum
- Renewal calendar
- Audit response runbook
- Optimisation pipeline register
Measurement
- Service SLA dashboard
- Benefits register with finance validation
- Maturity assessment framework
- Stakeholder satisfaction survey
08
Governance Considerations
Governance should be proportionate. The six areas below are the minimum set that has to be
explicit for this capability to hold up under internal review.
Ownership
An executive sponsor with authority beyond the SAM function; a SAM capability owner; a named process owner per service; a named publisher owner per major publisher.
Decision rights
The governance forum sets priority and approves policy; process owners decide within their service; the sponsor arbitrates cross-functional accountability disputes.
Policies
The full software policy set, a data governance policy covering the SAM data estate, a renewal preparation policy with minimum lead times, and an audit response policy.
Approvals
Service catalogue and SLA changes approved by the governance forum; policy changes approved by the sponsor; insource versus managed service decisions approved on documented evidence.
Evidence
Maturity assessments with supporting evidence, service performance history, benefits validated by finance, and a publisher knowledge base maintained as a controlled asset.
Controls
Service SLA monitoring, data quality score thresholds, protected capacity for optimisation work, renewal lead-time triggers, and single-point-of-dependency tracking in the skills matrix.
09
Success Metrics
Primary KPI
SAM services fully operating
Agreed SAM services operating with a named process owner, a defined control set and a measured SLA — the working definition of a capability that survives a departure.
100% of agreed catalogue
Operational KPIs
Service coverage
100% of catalogue defined
Services with description, inputs, outputs and SLA.
Process ownership completeness
100%
Services with a named, accountable process owner.
SLA attainment
≥ 95% across services
Services meeting their defined SLA.
Data-quality score
≥ 90%
Composite score across the SAM data estate.
Governance KPIs
Policy adoption
≥ 90% measured compliance
Adoption measured rather than assumed from publication.
Publisher governance coverage
100% of major publishers
Publishers with a named owner and knowledge base entry.
Renewals reviewed on time
100% within lead-time trigger
Renewals prepared before the notice deadline.
Audit readiness
Evidence set current for all major publishers
Standing evidence available on demand.
Control exceptions
Trending down
Exceptions raised against the control framework.
Single points of dependency
Trending to zero
Services with only one competent individual.
Value KPIs
Optimisation pipeline value
Tracked as a range
Pipeline value with stated assumptions.
Realised value
Finance-validated
Benefit delivered and confirmed by finance.
Stakeholder satisfaction
Measured per cycle
Satisfaction among the functions SAM serves.
Training completion
100% of skills matrix targets
Capability development against the plan.
Maturity improvement
Against target state
Reassessed maturity against the agreed target.
Indicative targets
Every target above is an indicative KPI for a typical enterprise, intended to support
planning discussions. Baselines should be measured in the first operating cycle and targets
set from them. These are not benchmarks, commitments or achieved client results.
10
Positive Business Impact
A capability that survives a departure
Services, process ownership and a publisher knowledge base mean expertise sits in the organisation rather than in individuals — the working test of an operating model.
Resourcing conversations based on evidence
Defined services with measured demand and SLA performance make headcount and managed-service cases arguable, where an undefined function cannot justify anything.
Proactive work protected from displacement
Protected capacity and a gated optimisation pipeline stop the highest-value work being postponed by whatever is most urgent this week.
Consistent publisher and audit governance
Every major publisher has a named owner and a current evidence set, so exposure no longer concentrates wherever attention happened to be thinnest.
Renewal readiness as a standing state
The renewal calendar is a governed asset with lead-time triggers, so preparation begins on schedule rather than when someone notices.
Value stated in terms finance accepts
Benefits are validated by finance against stated baselines, so the function's contribution is recognised rather than discounted.
Outcomes depend on estate, contracts, data quality and organisational context, and are not guaranteed.
11
Related Playbooks
Playbooks commonly delivered alongside, before or after this one.
Important — please read
This playbook describes a typical implementation approach and a representative operating
model. It is illustrative guidance, not a statement of results. Any figures, targets or
ranges shown are illustrative and are intended to support planning discussions rather than
to predict or promise an outcome. Outcomes are not guaranteed and depend on the estate,
contracts, data quality and organisational context of each engagement.
No client names, client data, engagement detail or confidential delivery material is
disclosed anywhere in this library. Technology named in these pages appears only as an
illustrative example of a capability category and does not imply a partnership,
certification or recommendation.