HomeTraining AcademyOracle Licensing MasterySession 25
Oracle Licensing Mastery · Module 5 · Session 25 of 40 · 29:35

Building the internal Oracle SAM function

Everything module 5 won was won on records built in advance; this session makes that the permanent condition. The Oracle SAM function is three records and a cadence: the entitlement library, the deployment baseline, and the contract file, refreshed until the ten day test always passes. The annual self assessment finds what an audit would find, a year earlier, at internal prices. Tooling is bought only after there is something to reconcile, the operating model is one named owner, three allies, one sponsor, and one page of policy, and the five change gates stop tomorrow's findings from ever being created. Boring is the ambition, and this is what boring costs.

The presenter in this session is an AI generated avatar. The curriculum and guidance are real, produced by Redress Compliance analysts from our consulting engagements and market network.

What you will be able to do after this session

  • 1Scope the function. Know what an Oracle SAM function actually does, and how small it can usefully be.
  • 2Build the three records. Stand up the entitlement library, the deployment baseline, and the contract file.
  • 3Run the cadence. Operate the annual self assessment and the quarterly checks that keep the records true.
  • 4Pick tooling honestly. Know what SAM tools do well, what they miss on Oracle, and when a spreadsheet wins.
  • 5Gate the changes. Route purchases, architecture changes, and M&A through the function that prices their license consequences.

How the session works

A taught session with three knowledge checks: the tool versus records budget decision sequenced correctly, the self assessment's unlicensed Partitioning finding fixed quietly on your terms, and the next audit letter arriving to an estate where the response is routine. It closes with one year of the function priced: half an FTE, roughly $500K of findings prevented or pre fixed, and the ten day test passing every quarter.

Homework before the next session, about one hour

  • 1Name the owner. One sentence to whoever runs IT: who owns the Oracle license position from today?
  • 2Start the entitlement library. Gather the order documents into one folder. This week, just make them findable.
  • 3Schedule the cadence. Four quarterly delta passes and one annual self assessment, on the actual calendar.
  • 4Write the gate sentence. The one page policy: Oracle purchases and architecture changes get a license check before commitment.
  • 5Run the ten day test. If a letter arrived tomorrow, how long to a defensible position? Write the number down.

Session transcript

The full narration of this session, section by section, for reading and reference.

Welcome and objectives 0:02

Welcome back, session twenty five of forty, and the last session of module five. The story so far, in one breath: the letter arrived, the rulebook was read, the findings were graded, and last session the four point two million dollar claim settled for about four hundred thousand of genuinely new money. A good ending. But notice what made every step of it possible: records. The containment evidence existed before the letter. The baseline audit existed before the scripts ran. The scope minute went out because a template was ready. None of that was luck, and none of it was heroics in the moment; it was an estate that had quietly done its filing. Today's session is about making that the permanent condition, the internal Oracle SAM function: the smallest operating model that keeps the records true, finds your own gaps before Oracle does, prices every decision before it ships, and turns the next audit letter into routine correspondence. The ambition of this session, and honestly of the whole course, is a strange one: boring. An Oracle estate where renewals are calm, audits are paperwork, and nothing surprising ever happens at list price. Boring is what winning looks like, sustained. Let's build it.

Five takeaways. One, you'll scope the function: what an Oracle SAM function actually does, its five jobs, and how small it can usefully be, which is smaller than almost anyone expects. Two, you'll build the three records: the entitlement library, what you own; the deployment baseline, what you run; and the contract file, what you signed. Everything else in the discipline is process wrapped around those three. Three, you'll run the cadence: the annual self assessment and the quarterly delta passes that keep the records true, because records decay from the day they're built, and a dead record is worse than none, it's false confidence. Four, you'll pick tooling honestly: what SAM tools genuinely do well, what they structurally miss about Oracle, and the circumstances where a maintained spreadsheet beats a six figure platform. And five, you'll gate the changes: the five decision points, purchases, architecture, M&A, projects, leavers, where compliance exposure is actually created, and where one early question from the function prevents it. By the end, module five is complete, and the audit module closes on its real conclusion: the audit tests whatever estate exists when the letter arrives, and the function decides what it finds. The stakes, next.

The estate that is always ready 2:52

Four numbers. Forty plus: the hours of scramble in a typical unprepared audit response, and that's a kind estimate, spread across DBAs pulling deployment data from scratch, procurement hunting for order documents, and legal reading the audit clause for the first time under deadline. Against that, days of routine for the estate whose records already stand. That arbitrage, scramble versus routine, is the function's entire value proposition, and we'll price it precisely in the worked example. Three: the records that carry the whole function. What you own, what you run, what you signed. Hold onto that simplicity when the tooling vendors arrive with architecture diagrams. Everything else is process around three lists. One: the named owner, the single most predictive factor in every audit outcome this module has described, and the cheapest interventions in enterprise software. Estates with an owner respond in days; estates with a committee respond in quarters. And zero point five: roughly the full time equivalents a mid size estate needs once the records exist. The function is a discipline, not a department, and pretending it needs a department is how it never gets built. Every worked example in module five, the containment evidence, the scope minute, the challenge file, traced back to records built in advance. This session is where they come from. The function's actual job, next.

What the SAM function is 4:21

What does an Oracle SAM function actually do? Five jobs, none of them glamorous, all of them decisive. Job one, it keeps the position current: the effective license position, entitlements reconciled against deployments, refreshed on a cadence, and trusted enough that real decisions get made on it. Not a one time project, a standing answer. Job two, it prices decisions before they ship: every architecture change, every purchase, every new project gets its license consequence estimated before commitment. This is the job that prevents findings rather than discovering them, and we'll give it a whole slide under the change gates. Job three, it runs the vendor calendar: renewal dates, notice windows, Oracle's quarter ends, ULA certification dates, module four's entire calendar, owned and diarized in one place by one person. Job four, it owns the audit file: the contracts, the annotated clauses, the contact plan, the last settlement's release paper, session twenty one's folder, maintained as a living thing instead of rebuilt in a panic. And job five, the quiet one, it carries the institutional memory: what was argued in the last audit, what was conceded, what was banked, and why. In most estates that knowledge retires with whoever handled it, and every cycle starts from zero. Now notice what's not on the list: buying tools, producing dashboards nobody reads, policing developers. The function is records plus decisions. Not surveillance. The records themselves, next.

The three records 5:59

The three records, plus the two layers they generate. Record one, the entitlement library: every order document, every license with its metric and quantity, every CSI mapped to its license set, exactly as session seventeen taught. Its source is the contracts, not anyone's memory, and building it is archaeology the first time and maintenance forever after. Record two, the deployment baseline: where Oracle software actually runs. Hosts, clusters, environments, options enabled, users provisioned. This is session sixteen's baseline audit, kept alive on a cadence instead of rerun from zero every time someone gets nervous. Record three, the contract file: the agreements themselves, audit clauses annotated, notice windows diarized, settlement papers filed, session twenty two's homework, institutionalized. From those three, two derived layers. The position: entitlements minus deployments, which surfaces surpluses to harvest, gaps to fix quietly, and the instant answer to every what if question the business asks. And the evidence layer: containment configurations, failover logs, deprovisioning records, feature usage reviews, the proof that turned session twenty three's claims into withdrawals. One more thing, and it decides your first quarter: build order matters. Entitlements first. Deployments without entitlements is just an inventory, and an inventory can't defend anything. Which sets up the classic first budget decision. Knowledge check one.

Knowledge check 1 7:45

Knowledge check one. Budget allows one hire or one tool this year. The estate has no entitlement library, no deployment baseline, and a shortlist of SAM tools from three vendor demos. What comes first? A, the tool, automation will build the records. B, the records, and the owner to build them: the entitlement library from the contracts, then the deployment baseline, with tools coming after there is something to reconcile. C, neither, wait for the next audit to force the issue. Or D, outsource the whole question permanently. Pause here. What does a tool reconcile against, on day one?

The answer is B, and the reasoning starts with the question on the slide: what does a SAM tool actually do? It discovers deployments and reconciles them against entitlements. On day one, this estate has no entitlement library, which means there is nothing to reconcile against, and the expensive tool's output is an inventory wearing a dashboard: half the position, at full price. And the entitlement half cannot be automated into existence, because it lives in order documents, migration paperwork, and contract language that only a person with session three's knowledge can read. That's why B sequences the work the way it does: owner first, entitlement library second, deployment baseline third, and the tool conversation after both sides of the ledger are real, when a tool finally has a job. And per session sixteen, the first baseline is scripts, queries, and a spreadsheet, unglamorous and entirely sufficient. A is the most common failure pattern in enterprise SAM, worth describing so you recognize it: the tool arrives with fanfare, the entitlement side stays empty, the dashboards render confidently wrong numbers for eighteen months, and then the tool gets blamed for what was always a records problem. C is the default this entire module priced for you: the next audit will absolutely force the issue, at list price, on Oracle's calendar, with a findings report instead of a to do list. D deserves nuance: outside expertise for the analysis, absolutely, this module has used it throughout. But ownership, of the records, the position, and the decisions, has to live inside, or the institutional memory walks out the door at every contract renewal. Records, owner, cadence, then tooling. The cadence, next.

The annual cadence 10:21

The cadence, because records decay from the day they're built, and the difference between a SAM function and a SAM project is that the function has a calendar. Quarterly, the delta pass: what's new, what's retired, what changed. New deployments, decommissioned systems, user movements, option flags. Reviewed against the baseline, differences applied. If it's actually done quarterly, it's an afternoon; if it's done annually, it's a project; if it's done at audit time, it's a scramble. Annually, the self assessment: a full internal effective license position, entitlements against deployments, run with genuine audit discipline, but on your side of the table. The findings get fixed quietly, at your prices, on your calendar, and we'll spend the next knowledge check on exactly how. Before every renewal: session twenty's season opens at T minus six with the baseline refreshed for the affected streams. The cadence calendar and the renewal calendar are the same calendar, deliberately. After every change: migrations, virtualization moves, acquisitions, major purchases, each triggers a targeted position update while the change is fresh and still reversible. And the honest test, the one line audit of your own function: could you produce a defensible license position in ten business days if a letter arrived tomorrow? When that answer drifts toward no, the cadence has quietly died, whatever the org chart says. The self assessment finds what an audit would find, one year earlier, at internal prices, with no settlement meeting. That arbitrage is the entire business case. And it raises the interesting question. Knowledge check two.

Knowledge check 2 12:08

Knowledge check two. The annual self assessment finds unlicensed Partitioning use on two production databases. Genuine, sustained use by the DBA team, not upgrade artifacts. No audit is underway, and nobody outside the building knows. What does the prepared estate do? A, nothing, if no audit is running there is no problem. B, immediately email Oracle a confession and ask to purchase licenses. C, fix it on your terms: assess whether the feature is actually needed, then either license it through a planned negotiated purchase or remove the usage, and document the remediation either way. Or D, delete the feature usage history so the finding disappears. Pause here. Who is on the other side of this finding today, and who would be next year?

The answer is C, and this finding is the self assessment doing precisely what it exists to do: surfacing a genuine gap while you still own the clock, the price, and the choice of remedy. Walk the options like the analyst you are by now. First question: is Partitioning actually needed on those two databases? If yes, the licenses join the next planned purchase, negotiated per module four, at your discount reality instead of list, ideally folded into a deal Oracle already wanted to close, and the gap resolves at a fraction of its audit price, quietly, inside ordinary procurement. If no, the feature gets disabled, the workloads adjusted, and, this is the part estates skip, the change gets documented: remediation of inadvertent use, dated, filed in the evidence layer. That paragraph is what turns a future audit claim into a one paragraph response, because session twenty three taught you exactly how historical usage flags read two years later. Now the wrong answers, each instructive. A leaves a genuine, sustained, discoverable gap standing until the audit cycle reaches it, at which point it's priced at list with back support attached, in a findings report; the entire arbitrage of self assessing, finding it first at internal prices, is thrown away. B converts a private finding into a public negotiation with zero leverage: the unprompted confession invites the compliance frame at the worst moment and prices the fix at panic rates. Even outside audits, session twenty one's rule holds: volunteer facts deliberately or not at all. And D, one final time, because the course will not stop saying it: evidence destruction converts a fixable commercial gap into misconduct, the one category of problem no negotiation can retrieve. The prepared estate's advantage was never having no findings. It's finding them first. Tooling, next.

Tooling, honestly 15:10

Tooling, honestly, because the SAM tool market is where good intentions go to become shelfware. What tools genuinely do well: discovery at scale. If you're running Oracle across thousands of hosts, automated discovery, scheduled collection, option and pack usage flagging, and keeping the deployment side of the ledger continuously fresh are real capabilities that scripts and spreadsheets eventually can't match. That's the honest case for buying one. What they structurally miss on Oracle: the entitlement side. Contract interpretation, license set boundaries, migration credits, the VMware counting position, everything module three taught about ULAs, none of it installs. Tools count; they do not judge, and Oracle licensing is mostly judgment applied to counts. On verification: Oracle formally verifies certain third party tools for data collection, which is genuinely useful in an audit, your tool's output can substitute for some script battles. But read what verification covers: gathering the data. Not interpreting it, and interpretation is where the money lives. The spreadsheet truth, said plainly: a mid size estate with clean records runs perfectly well on collection scripts plus a maintained workbook, and should buy tooling when scale actually breaks that, not before. And the buying rule: price the tool against the half FTE it replaces and the audit findings it would genuinely prevent, remembering that with an empty entitlement library it prevents none of them. The tool question is session sixteen's shelfware lesson pointed inward: software bought to manage software, unused, is a special irony to avoid. The people, next.

The operating model 16:58

The operating model, and here's the good news this session has been building toward: the smallest organization that works is genuinely small. One named owner. A role, not a committee: owns the three records, the vendor calendar, and the audit file. In most mid size estates this is half a person's time once the records are built, and the building itself is a one time project with an end date. What matters is the name; when everyone owns the license position, nobody does, and module five's entire history is written by estates that discovered that during an audit. Three standing allies, named in advance: a DBA lead for collection and the technical evidence, procurement for the vendor motion and the discount history, legal for the clauses and the settlement paper. Hours per quarter each, not headcount, but named, so the audit response team from session twenty one exists before any letter does. One executive sponsor: where escalations land and walk aways get authorized, per module four's ladder. Briefed twice a year on the position and the calendar. Never surprised, because surprised executives make expensive decisions. One page of policy, and it really is one page: Oracle deployments route through the owner; purchases and architecture changes get a license check before commitment. That sentence, ratified by whoever runs IT, is the entire operating model. Everything else is execution. And one binder, always current: the three records plus the evidence layer, kept so the ten day test always passes. That binder is what every session since twenty one has been assembling, one homework at a time. Where the binder earns its keep daily, next: the gates.

The change gates 18:43

The change gates, and this is the deepest idea in the session: compliance exposure is created at decision time, not at discovery time. The audit finds gaps; it doesn't make them. They're made in meetings, months or years earlier, where nobody asked the license question. The function sits at five of those meetings. The purchase gate: every Oracle order checked before signature for set architecture, one order or two, per session seventeen, terms quality per session eight, and future termination freedom. Thirty minutes of review against a decade of consequences. The architecture gate: virtualization changes, cluster redesigns, cloud moves, priced for license consequences while the design can still change. This is where session four's containment happens by default instead of by luck, and where session twenty three's biggest finding family simply never gets created. The M&A gate: every acquisition and divestiture gets a license due diligence pass. Whose agreements govern, which entities hold what, what actually transfers. The audit trigger from session twenty one, defused before the deal closes. The project gate: new systems declare their Oracle dependencies at design time, options, packs, Java, when the alternative is still a choice rather than a migration. And the leaver gate: deprovisioning tied to HR events, continuously, so the user counts session twenty three audited stay true all year instead of one day a year. Each gate is a single question asked early: what does this do to the license position? The function's answer costs minutes. The audit's answer, years later, costs the difference. Final check: the payoff, tested.

Knowledge check 3 20:34

Knowledge check three. Two years after the settlement, a new audit letter arrives. The function has run its cadence the whole time: quarterly deltas, annual self assessments, gates in place, binder current. What does the response look like? A, the same six month scramble as last time, audits are audits. B, routine: the letter routes to the named owner, the current position and evidence already exist, the scope minute goes out at kickoff, and the response runs in days on standing records. C, no response is needed, because a good SAM function prevents audits entirely. Or D, hand everything to the tool vendor. Pause here. What changed since the last letter, and what did not?

The answer is B, and the way to see it is to walk the first week and watch every module five lesson fire in sequence, quietly. The letter arrives and routes, per the standing instruction everyone has already received, to the named owner. No forwarding chaos, no helpful DBA answering questions on a support call. The audit file already contains the annotated clause, the contact plan, and, crucially, the last settlement's release and remediation record, which instantly bounds what this audit can even reach. The species test and the scope reading take an hour. The scope minute template goes out at kickoff, session twenty two executing from a drawer. The current position, no older than one quarter, already answers most of what the measurement phase will eventually claim, and the evidence layer, containment configs, deprovisioning records, the filed Partitioning remediation from knowledge check two, already holds the rebuttals session twenty three would otherwise have you building under deadline. The response is not effortless; there are still meetings, still scripts, still a settlement conversation eventually. But it is routine: days of assembly on standing records instead of months of archaeology. That is the forty hours to days arbitrage from the opening slide, collected. A misses the point of the entire module: audits are indeed inevitable, but scrambles are optional, and the scramble was never caused by the audit; it was caused by the missing records. C overpromises in the opposite direction: nothing prevents the cycle, session twenty one's machine runs on schedule regardless of your virtue. Boring, not invisible, was always the ambition. And D confuses collection with defense: tools gather data; positions, arguments, and negotiations belong to people. Yours. One year of the function, priced, next.

One estate, one year on 23:24

One estate, one year of the function running, the whole session in six rows. Quarter one: the entitlement library built from sixty order documents, and the owner named. For the first time, the position exists, and simply building it surfaced two forgotten surpluses, licenses bought years ago for a project that shrank. Quarter two, the first full self assessment: three genuine gaps and two harvestable surpluses found. The gaps fixed quietly for eighty five thousand dollars inside a planned order, against roughly four hundred thousand at audit prices with back support. That single row funds the function for years. Also quarter two: Partitioning removed from two databases that never needed it, remediation documented and filed, a future two hundred fifty thousand dollar finding converted into a one paragraph response, in advance. Quarter three: the renewal season run on the refreshed baseline, per module four, recovering a hundred twenty thousand a year, and notice the compounding, the uplift cap ask carried extra credibility because the self assessment's numbers were plainly real. Quarter four: the architecture gate caught a cluster redesign that would have dissolved the VMware containment; one meeting preserved it, and the finding family that fills session twenty three's reports was simply never created. The year's total: roughly half an FTE plus a few allied hours, one binder always current, about five hundred thousand dollars of findings prevented or pre fixed, and the ten day test passing every quarter. Nothing on this page is heroic. It's the same afternoon of discipline, repeated on a calendar. That's what boring costs, and that's what boring buys. Recap, and module five closes.

Recap and module 5 complete 25:13

Session twenty five in three sentences, and with it, module five. One, the function is three records and a cadence: what you own, what you run, what you signed, refreshed until the ten day test always passes, with a named owner, three allies, one sponsor, one page of policy, and tools bought only after there's something for them to reconcile. Two, the self assessment finds what the audit would find, a year earlier, at your prices, with the fix chosen on your terms, and the five change gates go one better by stopping tomorrow's findings from ever being created, because exposure is born in design meetings, not discovered in audits. Three, module five is complete: the machine and its triggers, the one paragraph rulebook, the five finding families, the settlement arc, and now the operating model that makes all of it routine, and the audit that once meant a four point two million dollar claim and months of scramble is, for the estate that keeps the binder, a correspondence file with a calendar. Next session, the course changes continent: module six, Oracle Cloud Infrastructure. Universal credits, pay as you go versus annual commitments, consumption mechanics, and how OCI deals are actually structured, the commercial fundamentals of Oracle's cloud, where the licensing rules you've mastered meet a different economic machine. Homework first.

Homework 26:45

Homework, about an hour, and this week it starts the function for real. One, name the owner: one sentence to whoever runs IT, who owns the Oracle license position from today? If the answer is nobody, propose yourself; you have twenty five sessions of qualification. Two, start the entitlement library: gather the order documents into one folder. Don't analyze anything yet; this week the job is findability, because the analysis has a whole methodology and the documents scattered across inboxes have none. Three, schedule the cadence: four quarterly delta passes and one annual self assessment, placed on the actual calendar, with session twenty's renewal season aligned to them. Recurring invites, real dates. A cadence that isn't scheduled is a wish. Four, write the gate sentence: the one page policy, Oracle purchases and architecture changes get a license check before commitment, drafted and sent for ratification. One page, one signature, operating model complete. And five, run the ten day test, honestly: if an audit letter arrived tomorrow morning, how many days to a defensible position? Write the number down, date it, and put it in the front of the binder. The function's entire job, from here on, is making that number smaller every quarter. That's the hour, and that's module five. See you in the cloud.

Further reading 28:13

Five reads, all free on redress compliance dot com. First, conducting internal Oracle license audits: the self assessment worked as a complete methodology, today's cadence slide at chapter length. Second, Oracle audit risk assessment: scoring your exposure systematically, before anyone else scores it for you. Third, how to check your Oracle license position: the practical guide to building the entitlement side of the ledger, the hardest of the three records. Fourth, Oracle vendor management, the buyer side guide: the operating model as a standing procurement discipline, the organizational chapter of today's session. And fifth, hidden Oracle audit risks: the exposure patterns the change gates exist to catch, several of which you'll now recognize by name. That's session twenty five, and that's module five: an audit machine mapped, a rulebook read, five findings graded, a claim settled for a tenth of its opening number, and an operating model that makes the whole cycle boring. Twenty five sessions down, fifteen to go. Module six opens next session in Oracle's cloud, where the meters run by the hour and the contracts still deserve reading. Bring the discipline. See you there.

Learning the playbook and want it applied to your numbers? We work on contingency: 25% of what we save you. Nothing saved, nothing paid.
Review my deal