Install counts miss the liability. Oracle exposure lives in usage tables and topology, and the SAM program has to read both.
Generic SAM tooling reads Oracle wrong, because the licensable events live in feature usage tables and virtualization topology, not in installation counts. Oracle SAM is its own discipline.
Standard SAM matches installations to entitlements. Oracle licensability is decided by activated cores, the core factor, named users, option feature usage, and virtualization boundaries, none of which an install scan sees.
Oracle's own License Management Services function measures from database internals: feature usage tables, parameter settings, and topology evidence. Your SAM program has to read the same sources or it is measuring a different thing.
Where Oracle exposure actually lives
| Exposure source | What records it | Generic SAM sees it? |
|---|---|---|
| Option and pack usage | DBA feature usage tables in each database | Rarely |
| Activated cores and core factor | Hardware inventory plus the factor table | Partially |
| Virtualization boundaries | Hypervisor topology and migration scope | No |
| Named user minimums | Per processor minimums per edition | Rarely |
| Standby and DR usage | Configuration and failover history | No |
| Usage inherited by a clone | Feature history carried in with the datafiles | No |
Features install with the database and record their own usage. A database administrator opening a performance view can trigger Diagnostics Pack usage, and a partitioned table licenses Partitioning. Intent is irrelevant; the usage table is the record.
The recording view is DBA_FEATURE_USAGE_STATISTICS, and the history in it does not expire. A program that never reads it is not measuring Oracle.
The priced management packs behave the same way and cost more per processor. The console control that stops them, and the price of leaving it at the install default, is set out on the Cloud Management Pack page.
Put the finding and the program side by side. One accidental management pack on a 96 processor fleet lists at 720,000 dollars, with annual support at 22 percent of the net license fee.
At list that support line is 158,400 dollars a year, every year. A fully loaded Oracle asset owner costs less than that, and prevents the next four findings as well.
Read the same evidence an auditor would: collection scripts against every instance, a hardware and hypervisor inventory with the core factor applied per Oracle's published pricing structures, and the entitlement stack reconciled line by line.
Use script based collection consistent with what Oracle gathers, so your internal view and the review view cannot diverge on the facts. Interpretation is where the negotiation lives, and you want the raw data to match.
What each script touches, the privileges it needs and the sequence that avoids self inflicted findings are set out in our guide to Oracle license compliance scripts. The three way reconciliation against entitlement and support records is covered in checking your Oracle license information.
Deployed above entitled is exposure. Entitled above deployed is shelfware, and it funds the exposure in the same negotiation. Both belong in the same file, carrying the same date.
It is one dated file, owned by a named person, in which every product row traces to a signed document and every usage row traces to a raw collection file. Anything less is an assertion.
Minimum defensible entitlement record
| Field | Source of truth | Why a reviewer asks for it |
|---|---|---|
| Product, edition and option | Ordering document | Decides what ships included and what is separately priced |
| Metric and quantity owned | Ordering document, not the support line | Support records show what you pay for, not what you own |
| Agreement and CSI reference | Contract file and My Oracle Support | The evidence link from a row back to paper |
| Legal entity | Agreement signature block | Decides whether an inherited license is yours to deploy |
| Deployment mapping | Host and cluster inventory | Ties an entitlement to the hardware it is consumed on |
| Measured usage and sample ratio | Dated raw collection files | Separates a one time activation from production dependence |
| Status and owner | Your own reconciliation | Covered, gap or shelfware, with a person accountable for each |
Response speed is a governance outcome, not a heroics outcome. If the following already exists, a data request is administration. If it does not, it is a project you will run under someone else's deadline.
Retention matters as much as content. Keep at least three years of dated collections, because backdated claims are argued over periods and the only counter to a period claim is a period record.
What to do once a formal letter arrives, including scope and response sequencing, is covered in our Oracle audit guidance. The entitlement sources themselves are set out in our Oracle license information reference.
Treat topology as a licensing artifact, because Oracle's partitioning policy treats most software virtualization as soft partitioning, which does not limit licensing scope. The licensable boundary becomes the cluster or every host a VM could reach.
Cluster diagrams, host inventories with core counts and factors, VM placement rules, and change records. If a reviewer asks where this database could run, the file answers in one document.
The test is simple. Hand the file to someone who has never seen your estate and ask them to derive the processor count. If they cannot, neither can you defend it.
The estates that stay clean run a quarterly rhythm owned by one accountable function, with licensing review wired into change management rather than bolted on at audit time.
The Oracle SAM calendar
| Cadence | Activity | Artifact it must leave behind |
|---|---|---|
| Monthly | New build and decommission log reviewed against the inventory | Updated instance list with owners |
| Quarterly | Script run across every instance and a feature usage difference against last quarter | Dated collection set and a remediation queue |
| On change | Licensing gate on any new cluster, host, database build or hypervisor change | A signed check in the change ticket |
| Annually | Entitlement stack review against the roadmap, ahead of renewal and budget | Refreshed reconciliation and a shelfware list |
| On event | Acquisition, divestment, data center move or major migration | Entity mapping and a fresh baseline for the affected estate |
A named owner with access to both the database estate and the contracts, typically in ITAM with a direct line to procurement. Split ownership is how usage drifts unwatched between the cracks.
Three accountabilities have to be separated in writing, because they conflict. Whoever runs the measurement should not be the person who decides what it means, and neither should be the person who negotiates.
Where most estates actually sit
| Level | What is true | What it costs you in a review |
|---|---|---|
| 0. Blind | No instance list, no collection, entitlements scattered | The vendor's numbers are the only numbers in the room |
| 1. Reactive | Scripts run when asked, output kept in email | Weeks lost rebuilding evidence under a deadline |
| 2. Measured | Quarterly collection, dated files, a reconciliation with owners | Findings are argued from your file, not discovered in theirs |
| 3. Governed | Licensing gates in change management and a topology file kept current | Most findings never happen, because the trigger was blocked |
Most estates we baseline sit at level 1 and believe they are at level 2. The distinguishing test is not whether scripts exist. It is whether last quarter's output can be produced in under an hour, with a date and an owner attached.
Four jobs need doing, and no single product does all four well. Buy against the jobs rather than against a category label.
The job most tools do worst is the third one. A dashboard that cannot show you the signed page behind a quantity is telemetry, not evidence.
The standard advice says buy a verified SAM tool and the Oracle problem is handled. We disagree. In roughly 25 to 35 baselines Fredrik Filipsson built in 2024 to 2025, tool output alone missed the exposure that mattered, option usage history and virtualization scope, in most estates, and no tool output binds Oracle in a review. The tools are useful telemetry. The defense is script level evidence, a topology file, and a quarterly remediation rhythm with named owners. The buyer side move is to budget for the discipline, not just the dashboard, because the dashboard does not negotiate.
Three cuts of our advisory engagement file frame the size of the opportunity.
Source: Redress Compliance advisory engagement file, 2024 to 2025. Stated as observed ranges across the engagement population, not as measured averages.
A dashboard tells you what a tool believes. A dated collection file tells you what the database recorded. Only one of those is evidence.
Less than one finding, in every estate where we have costed it. The practice has four line items and only one of them is a person.
The four line items, and what their absence costs
| Line item | What it takes | What happens without it |
|---|---|---|
| Named owner | Half to one full time role, depending on estate size | The tooling keeps running and nobody reads the output |
| Collection and scheduling | Automation effort. The Oracle scripts themselves cost nothing | Stale, undated evidence that persuades nobody |
| Searchable contract repository | Usually an existing document system, indexed properly | Quantities you believe but cannot trace to a signed page |
| Independent review | Annually, or ahead of a renewal or a data request | Your interpretation is first tested by the party invoicing you |
Budget plans we see put a fully loaded owner in the 100,000 to 180,000 dollar range a year, depending on market and seniority. Treat that as the planning band we observe, not a benchmark we have measured.
Now set it against a single accidental pack: 720,000 dollars at list on a 96 processor fleet, and 158,400 dollars a year in support at 22 percent. One prevented finding funds the practice for several years.
The order matters more than the speed. Shelfware surfaces early because it is easy to find and it is the part finance cares about, and it buys the political room to do the harder topology work later.
Five moves turn this analysis into a lower invoice on the next renewal.
The discipline of measuring Oracle deployment, core counts, option usage, and virtualization scope against entitlements, using the same evidence sources an Oracle review would: collection scripts, feature usage tables, and topology records.
Because Oracle exposure lives in feature usage history, core factors, named user minimums, and where VMs can run. Install based discovery misses most of it, and no third party tool output is binding in an Oracle review.
Diagnostics Pack, Tuning Pack, and Partitioning. They ship installed, record their own usage, and appeared unpurchased in 60 to 80 percent of the first baselines in our 2024 to 2025 file.
Quarterly. Feature usage and topology drift in weeks, and estates on a quarterly script rhythm carried roughly half the audit settlement exposure of annual checkers in our file.
Oracle measures from its own collection scripts and data. Tool reports are useful internally but do not replace script evidence, which is why your baseline should be built from the same sources.
One row per owned product and metric, with quantity taken from the ordering document, plus agreement and CSI reference, legal entity, deployment mapping, measured usage with its sample ratio, and a named owner. Every row must trace to either a signed page or a dated collection file.
At least three years of dated collections, kept as files with the instance name and date in the file name. Backdated claims are argued over periods, and a period claim can only be answered with a period record. A screenshot in a slide deck is not a record.
One named owner, usually in ITAM, with access to the database teams and to the contract file and a direct line to procurement. Keep measuring, interpreting and deciding in separate hands, because those three jobs pull in different directions.
Not to start. The four jobs are discovery, database collection, a searchable contract repository, and the reconciliation join. Most estates can run the first credible baseline with scripts, an inventory export and a spreadsheet, then buy tooling against whichever job proved hardest.
The governance, renewal and negotiation moves that hold Oracle cost across a five year horizon.
Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.
Oracle audits are argued from usage tables and cluster maps. A SAM program that cannot produce both is a subscription to surprise.
500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.
One buyer side briefing a week. Pricing moves, audit signals, and the levers that work. No vendor spin.