Audit findings reduced by 40 to 70 percent once the sub capacity reports were rebuilt correctly, which moved more money than any argument about the entitlement did
This is a portfolio of eight families on three metrics, and almost every large finding traces to the same missing evidence rather than to the licensing itself.
Prepared by Redress Compliance · August 19, 2026 · IBM Tivoli engagements. 25 to 40 engagements covering the portfolio, 2024 to 2025.
Executive summary
Sub capacity reporting was missing or stale on 30 to 50 percent of estates claiming the rate. Without it, every deployment licenses at full capacity by default.
Processor entitlements were overstated by 15 to 30 percent against actually deployed cores. The overstatement runs in the buyer's favour and nobody reconciles it.
Audit findings reduced by 40 to 70 percent once the reports were rebuilt correctly. The evidence is the negotiation on this portfolio.
This is a portfolio, not a product. Eight product families, over forty line items, and three different metrics that behave nothing alike.
What is actually inside this portfolio?
Eight functional families, each with a distinct metric, a distinct reporting scope and a distinct modernisation path. Treating them as one product is the first error.
The four groupings that matter commercially
- Monitoring: server and application monitoring, event correlation, and the modern observability successors.
- Automation: job scheduling, high availability failover, and the modern operations consolidation point.
- Storage and endpoint: backup, endpoint patching, mobile device management.
- Service management: service desk, enterprise asset management, and the legacy ticketing tail.
Adjacent products get licensed alongside
Security and asset management products are frequently cross sold into the same agreement, which is how a portfolio of forty line items becomes a bill nobody reads line by line. The catalog sits on the software product pages.
Which metric applies to which product?
Three metrics carry the whole portfolio, and they do not convert into one another. The metric decides the exposure before the price is discussed.
| Metric | Applies to | How it counts | Where it goes wrong |
|---|---|---|---|
| Processor value unit | Server side products | Cores multiplied by a published rating | Full capacity without reporting |
| Resource value unit | Storage and endpoint products | Per terabyte or per endpoint, tiered | Tier ladder never revisited |
| Authorized user | Service desk administrators | Named per person, no concurrency | Leaver discipline on the named list |
| Stacked | Service desk end to end | Back end on processors, front end on named users | One product, two meters, one invoice |
The processor mechanic in four steps
Count the cores, apply the published rating table, multiply, then match the result against the entitlement on the contract. Sub capacity cores only count when the reporting supports them.
Named users need joiner mover leaver discipline
Each administrator is licensed by name with no concurrency, so a named list that is never reviewed is a list that only grows. An annual review is the whole control.
The IBM audit defense playbook
Sub capacity posture, the reporting obligations, and the buyer side moves across the IBM estate.
Get the brief →What 25 to 40 IBM engagements showed
Across roughly 25 to 40 IBM engagements covering Tivoli and its successor products between 2024 and 2025, sub capacity compliance was the single largest audit exposure. Three patterns recur.
- Reporting missing or stale on 30 to 50 percent of estates claiming sub capacity.
- Processor entitlements overstated 15 to 30 percent against actual deployed cores.
- Audit findings reduced 40 to 70 percent once the reports were rebuilt correctly.
Most large findings on this portfolio trace back to missing evidence rather than to genuine overuse. Rebuilding the record is cheaper than arguing about the number.
- Every risky clause flagged with the verbatim quote and page anchor
- Entitlements, caps and protections verified across your whole contract portfolio
- Paste ready replacement language and an evidence trail for the response
When is the reporting tool mandatory?
Whenever sub capacity rates are claimed, on any virtualized platform, and across mixed bare metal and virtual estates. Without it every deployment licenses at full capacity.
Four situations that trigger it
- Any virtualized platform in the estate.
- Any contract claiming sub capacity rates.
- A mixed estate with bare metal and virtual on the same product line.
- Container platform deployments.
The operational rules that make the claim hold
Deploy within ninety days of the first installation, run the report every quarter, retain reports for two years, update the release at least annually, and validate every component against the bundle mapping. The obligations are documented at the metric tool reference.
How does the agreement shape the exposure?
Through the program terms rather than through the price. The same deployment can be compliant or exposed depending on paper written years earlier.
The program agreement is the governing document
Terms sit in Passport Advantage, with the agreement text at the published agreements and the licensing terms at the software licensing page.
The modernisation path is a commercial event
The consolidation route to the modern operations platform carries a trade in credit against the existing base, which makes it a negotiation rather than an upgrade. The container platform mechanics sit in the container platform guide and the agreement shape in the enterprise agreement reference.
Where the common advice on this portfolio is wrong
The common advice is to negotiate the entitlement quantity down at renewal. We disagree.
The evidence moves more than the entitlement does
Audit findings fell 40 to 70 percent once the reports were rebuilt correctly, which is a larger movement than any entitlement negotiation produced in the same file.
The buyer side move is to fix the reporting first, reconcile the processor count against deployed cores, and only then discuss quantity. The response sequence sits in the audit defense reference and the preparation in the readiness checklist.
What the engagements measured, 2024 to 2025
Two cuts of the engagement file, and the second is what the first buys.
While claiming sub capacity rates, which means the claim itself was unsupported the moment an auditor asked for the record.
Once the reports were reconstructed correctly, before any negotiation about the entitlement quantity took place.
The exposure was evidentiary rather than substantive in most estates. That is the cheapest kind of finding to remove and the easiest to leave in place.
Your first five moves
- Confirm the reporting tool is deployed, current and running quarterly, because it was missing or stale on 30 to 50 percent of estates claiming the rate.
- Rebuild the reports before anybody asks for them, since doing so reduced audit findings by 40 to 70 percent in the reviewed file.
- Reconcile the processor entitlement against actually deployed cores, which ran 15 to 30 percent apart across the estates reviewed.
- Separate the three metrics on the order and read each on its own terms, because processors, resource units and named users do not convert into one another.
- Price the modernisation trade in as a negotiation, not an upgrade. The IBM practice rebuilds the reporting position before the renewal or the audit letter arrives.
Frequently asked questions
Is this one product or many?
A portfolio. Eight functional families and over forty line items, each with its own metric, its own reporting scope and its own modernisation path.
Which metrics apply?
Processor value units for server side products, resource value units for storage and endpoint products, and authorized users for service desk administrators.
Can the metrics be mixed on one product?
Yes. A service desk is commonly licensed with the back end on processors and the front end on named users, which is one product carrying two meters.
Why is the reporting tool mandatory?
Because sub capacity rates depend on it. Without current reports every deployment licenses at full capacity, which is the most expensive possible reading.
How often is the reporting broken?
It was missing or stale on 30 to 50 percent of the estates that were claiming sub capacity rates on their contract.
What are the operational rules?
Deploy within ninety days of first installation, report quarterly, retain reports for two years, update the release annually, and validate every component against the mapping.
How overstated are entitlements?
Processor entitlements ran 15 to 30 percent above actually deployed cores. The overstatement runs in the buyer's favour and almost nobody reconciles it.
How much does rebuilding the reports recover?
Audit findings fell 40 to 70 percent once the reports were rebuilt correctly, before any negotiation about entitlement quantity.
Is the exposure real overuse?
Usually not. In most estates it was evidentiary: the deployment was defensible and the record supporting it was not.
Is the modernisation path an upgrade?
It is a commercial event. The consolidation route carries a trade in credit against the existing base, which makes it a negotiation rather than a version change.