Running it like a regulated control, and keeping the position clean in the years between audits. Three knowledge checks along the way, and 4 clips from a senior licensing analyst.
This is a taught session, not a talking head. The instructor works through analyst grade slides, and three times the video stops on a question with four options on screen. Pause, commit to an answer, and the next slide explains which option is right and why each of the others is wrong. 4 times in the session the frame splits and a senior licensing analyst gives the view from inside real IBM negotiations, and the instructor picks the clip apart when the slides return.
The full narration of this session, section by section, for reading and reference. Guest analyst clips are marked.
Welcome to session ten, which closes module two. The last three sessions were mechanism. What the obligations are, what the tool does, where the boundary sits. Today is the management layer above all of it, and I want to justify why that deserves a full session rather than a closing slide. Mechanisms decay. Every one of them. The tool drifts, the coverage slips, the archive thins, and none of that requires anybody to make a mistake. Management is simply the thing that stops decay, and in this area it is worth more than any single technical decision you will make. Three knowledge checks. Let's begin.
Five objectives. First, run a calendar rather than a project, with weekly, quarterly, annual and event driven work each carrying an owner, because a control that depends on somebody remembering is not a control. Second, watch five numbers, which are coverage, scan age, the unclassified queue, archive completeness and boundary changes, and each one of them moves before a finding does. Third, rehearse the audit you have not had, because a drill against a past quarter tells you your real response time and it is the cheapest way to discover what you cannot produce. Fourth, sequence a remediation by exposure rather than by convenience, since in one fourteen week programme the densest fifth of hosts removed more than half the modelled exposure. And fifth, know what the first ninety days look like, because prepared buyers settled at thirty five to sixty percent of the opening claim while those who treated the notice as a compliance finding settled at eighty to one hundred.
Four numbers, and they all point the same way. Thirty five to sixty percent of the opening claim, where the buyer arrived prepared, against eighty to one hundred percent for those who treated the notice as a compliance finding. Ten to thirty percent of the modelled exposure, where remediation started before any letter arrived. Two quarters, which is how long the stack takes to decay without an owner, and that is faster than most audit cycles, which is the whole problem in one number. And six to twelve, the months an audit runs from notice to settlement, during which almost nothing that decides the outcome is still available to be done. The note underneath is the framing I would give a board. Sub capacity is the largest single discount IBM gives, and the tool is the price of admission. Run it like a regulated control rather than an IT project.
Guest analyst clip. The uncomfortable truth about audit defence is that most of it is not defence at all, it is bookkeeping that happened years earlier. When I am brought into a situation after the letter has arrived, the range of outcomes available is already fixed, and I can usually tell within about a day where in that range we are going to land. Not because of anything clever anybody is about to do, but because of what does or does not exist in a folder. Eight signed quarterly reports, and we are having one conversation. Two reports and a lot of good intentions, and we are having a different one, and no amount of skill closes the distance between them. I say this partly to be honest about what advisers can and cannot do, because I think the profession sometimes oversells the drama of the negotiation. But mostly I say it because it relocates the work. If the outcome is decided before the letter, then the valuable hour is not the hour in the room with IBM. It is an ordinary Tuesday, eighteen months earlier, when somebody generated a report and put it somewhere it could be found. That hour is worth more than anything I will do afterwards, and nobody ever feels that way about it at the time.
The valuable hour is an ordinary Tuesday eighteen months earlier, and nobody ever feels that way about it at the time. So let us make those hours ordinary on purpose.
Four rhythms, each with an owner. Weekly, where coverage exceptions get reviewed, new hosts get enrolled and scan failures get chased, and the interval is weekly because new hosts enrolled inside seven days of provisioning stay inside the window. Quarterly, which is generate, review, sign, export, archive, plus the bundle map and boundary review, and the quarter is both the contractual floor for reporting and the natural close for everything else. Annually, where the eligibility lists get re checked, a drill gets run and the entitlement is reconciled end to end, because both published lists change and a year is long enough for the estate to have moved underneath you. And on event, meaning hypervisor migration, credential rotation, tool upgrade and cluster change, and those are on event rather than on a schedule because all four break something silently. Nothing on this list is difficult. What makes it work is that each row has a name against it and a date that exists before the period starts.
Knowledge check one. Your coverage sits at ninety four percent and has done for two quarters. Nobody has raised it because it is stable. What is the problem? A, nothing, ninety four percent is close enough and the trend is flat. B, the missing six percent are full capacity hosts, and stability means the gap is now two quarters deep in your report history. C, only that the reports will be slightly understated. D, the tool will stop reporting once coverage drops below ninety five percent. Pause here, and ask whether coverage is an average or a set of individual hosts.
The answer is B. Coverage is not an average, it is a list of hosts, and each uncovered one is a full capacity position for the products sitting on it. Answer A is the reasoning that makes a stable gap worse than a moving one, and that is worth pausing on, because it runs against instinct. A number bouncing around gets investigated. A number sitting still gets accepted as the way things are. But two quarters of stability is two quarters of evidence you cannot produce, and the stability is precisely what stopped anybody looking. Hold the floor at ninety eight percent and treat every gap as an incident rather than as a level.
So, five measures that move before a finding does. Agent coverage, meaning eligible hosts scanned as a share of eligible hosts that exist, and measured against the hypervisor's list rather than the tool's own list, with a floor of ninety eight percent. Oldest software scan age, the worst host rather than the average, alerting past twenty one days which leaves a week of margin before the thirty day contractual minimum. The unclassified queue, which is discovered components awaiting classification and the age of the oldest one, classified within thirty days or they rot into findings. Archive completeness, the count of signed quarterly reports held out of the eight that two years requires, and this is the number an audit actually reads. And boundary changes not reviewed, meaning host additions, cluster merges and activations that passed through change control without anybody asking the licensing question.
Now the drill, which is my favourite thing in this session because of how cheap it is. Pick a quarter at random, and not the last one, something four or six quarters back, because that is the range an audit will reach into. Ask for the pack and start a clock, so the PVU summary, the entitlement reconciliation, the host list, the bundle map and the signature, and note how long each one takes to appear. Record what cannot be produced, because every gap you find in a drill is a gap you find for free, and the same gap found by an auditor is priced. Target seven days, since an estate that can assemble its evidence inside a week of a letter is in a materially different negotiation to one that cannot. And run it annually at least, because it costs a morning and it is the only exercise that tells you the truth about your position rather than about your intentions.
Guest analyst clip. Every organisation of any size runs fire drills, and nobody argues about them. You do not wait for a fire to discover that a stairwell is blocked. And yet the equivalent exercise for an audit, which is far more likely to happen to you than a fire, almost never gets run. I have suggested this to a lot of clients and the reaction is usually a slight embarrassment, as though it is obviously sensible and obviously nobody has done it. So let me make it concrete, because the vagueness is what stops it happening. One morning. You email the person who owns the tool and you say: it is the fourteenth of whatever month, we have received an audit notice covering the second quarter of the year before last, please send me the PVU summary, the entitlement reconciliation, the host list, the bundle map and the sign off. Then you note the time you sent it and the time each item arrives. That is the entire exercise. And what I find is that the first time anybody does this, the result is genuinely surprising to the people who assumed they were in good shape. Not catastrophic, usually. Just slower, and patchier, than anyone believed. Which is exactly the thing you want to learn on a morning of your choosing rather than on a morning of IBM's.
A morning of your choosing rather than a morning of IBM's. And if the drill finds a gap, the next question is where you start, which is not the obvious place.
Knowledge check two. You find a coverage gap across four hundred hosts. Where do you start? A, the data centre that is easiest to schedule, to build momentum. B, the densest hosts by PVU, because exposure is concentrated and the first wave removes most of it. C, alphabetically, so nothing is missed. D, nowhere, until IBM confirms which hosts are in scope. Pause here, and ask whether the exposure is spread evenly across those four hundred hosts.
The answer is B, the densest hosts by PVU. In a fourteen week remediation across roughly three thousand hosts, the first wave took the densest twenty percent of hosts and removed more than half the modelled exposure on its own. Answer A is how most programmes are actually sequenced, by data centre convenience, and I want to be fair to it because it is not irrational, since scheduling is genuinely easier that way. It is simply expensive. The same work, in a different order, leaves the largest exposure standing longest, and if a letter arrives midway through, the order you chose is the difference between most of the problem being solved and most of it still being open.
So, how to run a remediation that lands, five steps. Rank hosts by PVU density, which is cores multiplied by rating per host for hosts running eligible products, and that ranking is a spreadsheet and it decides the whole programme. Work in waves with the largest exposure first, since four waves over fourteen weeks cleared roughly three thousand hosts in one programme with the first wave carrying most of the value. Fix the intake at the same time, putting the agent into the gold image in week one, otherwise you are draining a bath with the tap still running. Report from the first wave onward rather than waiting for completion, because the clock on your two year history starts with the first retained report and there is no reason to delay it. And do it before a letter if you possibly can, because remediation started before an audit letter settled at ten to thirty percent of the modelled exposure, while afterwards it is a negotiation about how much.
Guest analyst clip. The mistake I see most often in remediation programmes is not the sequencing, it is forgetting the tap. A team gets funded to fix a coverage gap. They work hard, they enrol hundreds of hosts, and the coverage number climbs steadily, which everybody can see on a chart and everybody feels good about. And meanwhile the build process is still producing new hosts from an image that has no agent in it. So they are enrolling hosts at the front and creating uncovered ones at the back, and depending on how fast the estate is growing, they can work for months and end up roughly where they started. It is genuinely demoralising when it becomes visible, because the effort was real. So the rule I would give is: fix the intake in week one, before you enrol a single existing host. It is usually a small piece of work, it is nobody's idea of an exciting deliverable, and it is the difference between a programme that converges and one that does not. And there is a nice second effect, which is that once the intake is fixed, the coverage number becomes trustworthy. A rising number that you know is not being undermined behind you is a number you can actually manage against.
Fix the intake in week one, before enrolling a single existing host. Otherwise the programme cannot converge, however hard anybody works.
Now the first ninety days after a letter, because the shape of the outcome is set there. Hours forty eight to seventy two are triage, establishing what the tool covers today, what the archive holds, and who owns the response, with nothing conceded and nothing sent yet. Days one to thirty are emergency coverage, because buyers who begin closing the coverage gap inside the first thirty days consistently land better outcomes, for the simple reason that the uncovered period stops growing. Months zero to three are the perimeter, agreeing scope, entities and the period in writing, and an unbounded scope is the most expensive thing you can accept early. Months four to six are the exchange, where inventory goes across, and what you send is what the model gets built from, so it goes out reconciled rather than raw. And months seven to twelve are finding and settlement, where you dispute the base rather than the price, because a discount on a wrong model quietly validates the model.
So what has to be producible inside a week. Eight signed quarterly reports, two years in order with the signatures on them, and this is the exhibit that everything else supports. The entitlement position, what you own by product and part number with the source, which is the baseline from session five kept current rather than rebuilt in a panic. The host and boundary record, which hosts existed, which clusters they belonged to, and what the workloads could reach in each period. Mobility and change history, meaning migration logs and change tickets retained for two years to match the reports, because together those two bound the claim. And the anomaly log, scan failures with dated resolutions, and I would stress this last one because it feels counterintuitive. Documented problems read as a controlled estate. Undocumented ones read as an uncontrolled estate, and the difference is entirely in whether somebody wrote down what they did.
Knowledge check three. Your CIO asks what a year of this discipline is worth. What is the honest answer? A, it removes audit risk entirely. B, it moves a future settlement from eighty to one hundred percent of the opening claim toward thirty five to sixty percent, and lowers today's bill through the catalog. C, it is a compliance obligation with no financial return. D, it is only worth it if an audit is already expected. Pause here, and ask what the discipline actually changes, and when it pays.
The answer is B. The honest claim is a shift in the distribution rather than the removal of risk, which is why answer A overstates it, and I would avoid making that promise internally because it is the kind of claim that gets found out and takes your credibility with it. Answer D inverts the logic that matters most here. The work only pays if it was done before the notice arrived, since remediation before a letter settled at ten to thirty percent of the modelled exposure and after it is a negotiation about how much. An audit you are already expecting is an audit where most of the value has already gone.
Guest analyst clip. I want to say something about how you sell this internally, because I have watched people lose the argument by overclaiming and I would rather you did not. The temptation, when you are trying to get an owner appointed and a quarterly close funded, is to promise that it eliminates audit risk. Do not. It does not, it cannot, and the first time an audit finds anything at all, your credibility goes with the promise. What it does is move where you land. Instead, make the argument in two halves, because they land on different people. The first half is this quarter and it is the catalog, where you are currently overstating your own consumption and paying real support money on the difference, and that appeals to whoever owns the budget. The second half is the distribution, where a prepared estate settled at thirty five to sixty percent of an opening claim and an unprepared one at eighty to one hundred, and that appeals to whoever owns the risk. Neither half requires anybody to believe a promise. Both halves are just arithmetic. And I find that an argument nobody has to take on faith is an argument that survives the person who made it leaving, which for a control that has to run for years is the property that actually matters.
So here is a clean year, in five lines. One owner, named, with a financial mandate, because everything below that line fails without it and the stack decays within two quarters when the tool belongs to nobody. Four quarterly closes, signed and archived, generate review sign export archive, and eight of those standing behind you is what a defence is actually made of. Fifty two weekly coverage reviews, or however your week works, with new hosts enrolled inside seven days, scan failures investigated within ten business days and the resolutions documented. One drill and one eligibility check, a morning each, where the drill tells you your response time and the check catches products that quietly left the list. And a licensing line on every relevant change, so hypervisor migrations, credential rotations, tool upgrades and cluster changes, four events, one question, minutes each. That is the entire operating model, and you could write it on a postcard.
Three sentences. The tool is a mechanism and mechanisms decay, so the operating model is a calendar with owners, weekly coverage, quarterly closes, an annual drill and eligibility check, and a licensing question attached to the four events that break things silently. Five numbers move before a finding does, which are coverage measured against the hypervisor's host list, the oldest scan age, the unclassified queue, archive completeness out of eight, and boundary changes that passed without a licensing check. And prepared buyers settled at thirty five to sixty percent of the opening claim while those who treated the notice as a compliance finding settled at eighty to one hundred, with remediation before any letter settling at ten to thirty percent of the modelled exposure, so the outcome is decided in the years before an audit rather than in the months during it.
Homework, about an hour, and this is the most directly useful hour in module two. Run a one hour drill, picking a quarter from about eighteen months ago, asking for the full pack and timing it, because whatever you learn in that hour you learned for free. Measure the five numbers, coverage, oldest scan age, unclassified queue, archive completeness out of eight, and unreviewed boundary changes, and write them down as a baseline you can compare against next quarter. Rank your hosts by PVU density, cores times rating for every host running eligible products, because the top twenty percent of that list is where your exposure actually lives. Find the four event triggers, checking whether hypervisor migrations, credential rotations, tool upgrades and cluster changes each raise a licensing question in your change process today. And put the calendar in the calendar, four quarterly closes and one drill, dated, with names, for the next twelve months. Do that last one and you have implemented this session.
Five guides. The IBM audit defence playbook carries the phase map from notice to settlement, the settlement ranges by preparation, and the argument for disputing the base rather than the price. The ILMT comprehensive pillar covers running the tool as a regulated control, the sign off cadence, and the anomaly documentation that is itself evidence. And the deployment guide gives you the KPIs, the coverage floor and the scan age alert thresholds, which is where the five numbers in this session come from.
The pharmaceutical case study shows four waves over fourteen weeks across roughly three thousand hosts, sequenced by PVU density rather than by data centre convenience, and it is the practical model for the remediation section. And the audit penalties guide explains the backdated support layer that frequently exceeds the licence shortfall itself, which is the part of a finding people forget to model. That closes module two. Next time module three opens with IBM Cloud Paks: the bundles, the Virtual Processor Core metric, and the entitlement conversion ratios. See you there.