Operations analyst monitoring database estate dashboards
Oracle

Oracle SAM. Read what the auditor reads.

Install counts miss the liability. Oracle exposure lives in usage tables and topology, and the SAM program has to read both.

Contact Us Oracle Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Generic SAM tooling reads Oracle wrong, because the licensable events live in feature usage tables and virtualization topology, not in installation counts. Oracle SAM is its own discipline.

Key takeaways

  • Installs are not the exposure: Oracle licenses by cores, users, and option usage, so install counts miss the liability.
  • Options fire silently: Partitioning, Diagnostics, and Tuning Pack usage records itself in the database whether you bought them or not.
  • Virtualization is the multiplier: where a VM can run decides what you license, not where it does run.
  • No tool is a defense: Oracle measures from its own scripts in a review; third party SAM output is internal intelligence.
  • The practice pays for itself once: one accidental pack on a 96 processor fleet is 720,000 dollars at list, and its annual support alone exceeds a fully loaded owner.
  • Quarterly beats annual: feature usage drift happens in weeks, not budget cycles, and an undated file persuades nobody.
Try Vera AI · free trial
Entitled, deployed, active: Vera reconciles all three.
  • Entitled vs deployed vs active seats compared, priced at your actual contract terms
  • Duplicate tools and unused capacity surfaced across the portfolio
  • A ranked savings queue with dollar values, not license counts
Try Vera AI free →Free 30 day trial · decode one contract free, no signup

Why does generic SAM fail on Oracle?

Standard SAM matches installations to entitlements. Oracle licensability is decided by activated cores, the core factor, named users, option feature usage, and virtualization boundaries, none of which an install scan sees.

Oracle's own License Management Services function measures from database internals: feature usage tables, parameter settings, and topology evidence. Your SAM program has to read the same sources or it is measuring a different thing.

Where Oracle exposure actually lives

Exposure sourceWhat records itGeneric SAM sees it?
Option and pack usageDBA feature usage tables in each databaseRarely
Activated cores and core factorHardware inventory plus the factor tablePartially
Virtualization boundariesHypervisor topology and migration scopeNo
Named user minimumsPer processor minimums per editionRarely
Standby and DR usageConfiguration and failover historyNo
Usage inherited by a cloneFeature history carried in with the datafilesNo

What makes option usage the silent liability?

Features install with the database and record their own usage. A database administrator opening a performance view can trigger Diagnostics Pack usage, and a partitioned table licenses Partitioning. Intent is irrelevant; the usage table is the record.

The recording view is DBA_FEATURE_USAGE_STATISTICS, and the history in it does not expire. A program that never reads it is not measuring Oracle.

The priced management packs behave the same way and cost more per processor. The console control that stops them, and the price of leaving it at the install default, is set out on the Cloud Management Pack page.

The one number that justifies the whole practice

Put the finding and the program side by side. One accidental management pack on a 96 processor fleet lists at 720,000 dollars, with annual support at 22 percent of the net license fee.

At list that support line is 158,400 dollars a year, every year. A fully loaded Oracle asset owner costs less than that, and prevents the next four findings as well.

How do you build a defensible Oracle baseline?

Read the same evidence an auditor would: collection scripts against every instance, a hardware and hypervisor inventory with the core factor applied per Oracle's published pricing structures, and the entitlement stack reconciled line by line.

  1. Inventory every database instance, including DR, test, and the ones nobody owns.
  2. Run collection scripts per instance and capture feature usage history, not just current state.
  3. Map every host to its hypervisor cluster and apply the core factor to the licensable boundary.
  4. Reconcile against entitlements: metric, edition, options, and contractual restrictions.
  5. Document remediation decisions with dates; the paper trail is the audit defense.

Which scripts should the self check use?

Use script based collection consistent with what Oracle gathers, so your internal view and the review view cannot diverge on the facts. Interpretation is where the negotiation lives, and you want the raw data to match.

What each script touches, the privileges it needs and the sequence that avoids self inflicted findings are set out in our guide to Oracle license compliance scripts. The three way reconciliation against entitlement and support records is covered in checking your Oracle license information.

The three views that must reconcile

  • Deployed. What is installed and running, per host and per instance, with cores and cluster membership attached.
  • Used. What the databases actually executed, from feature usage history, with detections against total samples.
  • Entitled. What the ordering documents say you own, by product, metric and quantity, per legal entity.

Deployed above entitled is exposure. Entitled above deployed is shelfware, and it funds the exposure in the same negotiation. Both belong in the same file, carrying the same date.

What does a defensible entitlement record look like at audit time?

It is one dated file, owned by a named person, in which every product row traces to a signed document and every usage row traces to a raw collection file. Anything less is an assertion.

The columns that survive a review conversation

Minimum defensible entitlement record

FieldSource of truthWhy a reviewer asks for it
Product, edition and optionOrdering documentDecides what ships included and what is separately priced
Metric and quantity ownedOrdering document, not the support lineSupport records show what you pay for, not what you own
Agreement and CSI referenceContract file and My Oracle SupportThe evidence link from a row back to paper
Legal entityAgreement signature blockDecides whether an inherited license is yours to deploy
Deployment mappingHost and cluster inventoryTies an entitlement to the hardware it is consumed on
Measured usage and sample ratioDated raw collection filesSeparates a one time activation from production dependence
Status and ownerYour own reconciliationCovered, gap or shelfware, with a person accountable for each

The evidence pack you should be able to produce in five working days

Response speed is a governance outcome, not a heroics outcome. If the following already exists, a data request is administration. If it does not, it is a project you will run under someone else's deadline.

  • Raw collection output per instance, named by instance and collection date, kept as files rather than pasted into slides.
  • The host and cluster inventory used for the processor math, with chip type and the core factor applied, referenced to the Oracle Processor Core Factor Table.
  • Signed ordering documents and the agreement identifiers they sit under, whose terms are published in the Oracle contract documents library.
  • The change record for every remediation: what was disabled, on what date, by whom, and the collection that confirms it.
  • Clone and refresh lineage, so usage history inherited from a source database is not counted as separate usage.
  • The reconciliation file itself, with a version history rather than one overwritten spreadsheet.

Retention matters as much as content. Keep at least three years of dated collections, because backdated claims are argued over periods and the only counter to a period claim is a period record.

What to do once a formal letter arrives, including scope and response sequencing, is covered in our Oracle audit guidance. The entitlement sources themselves are set out in our Oracle license information reference.

How should SAM handle virtualization and cloud?

Treat topology as a licensing artifact, because Oracle's partitioning policy treats most software virtualization as soft partitioning, which does not limit licensing scope. The licensable boundary becomes the cluster or every host a VM could reach.

  • Contain by design: dedicated Oracle clusters with documented migration boundaries cap the scope.
  • Record the history: where VMs could run last year matters in a review covering last year.
  • Cloud counts differently: authorized cloud environments follow their own counting rules; map them separately from the data center.
  • Freeze the evidence: keep a dated export of cluster membership, not just the live console view.

What does a clean topology file look like?

Cluster diagrams, host inventories with core counts and factors, VM placement rules, and change records. If a reviewer asks where this database could run, the file answers in one document.

The test is simple. Hand the file to someone who has never seen your estate and ask them to derive the processor count. If they cannot, neither can you defend it.

What does a working Oracle SAM operating rhythm look like?

The estates that stay clean run a quarterly rhythm owned by one accountable function, with licensing review wired into change management rather than bolted on at audit time.

The Oracle SAM calendar

CadenceActivityArtifact it must leave behind
MonthlyNew build and decommission log reviewed against the inventoryUpdated instance list with owners
QuarterlyScript run across every instance and a feature usage difference against last quarterDated collection set and a remediation queue
On changeLicensing gate on any new cluster, host, database build or hypervisor changeA signed check in the change ticket
AnnuallyEntitlement stack review against the roadmap, ahead of renewal and budgetRefreshed reconciliation and a shelfware list
On eventAcquisition, divestment, data center move or major migrationEntity mapping and a fresh baseline for the affected estate

Who should own Oracle SAM?

A named owner with access to both the database estate and the contracts, typically in ITAM with a direct line to procurement. Split ownership is how usage drifts unwatched between the cracks.

Three accountabilities have to be separated in writing, because they conflict. Whoever runs the measurement should not be the person who decides what it means, and neither should be the person who negotiates.

  • Measure. The database team runs the collection and owns its accuracy and its dates.
  • Interpret. ITAM or SAM maps measurement to entitlement and classifies every row.
  • Decide. Procurement and legal own what is disclosed, what is bought, and what is argued.

A maturity ladder you can place yourself on honestly

Where most estates actually sit

LevelWhat is trueWhat it costs you in a review
0. BlindNo instance list, no collection, entitlements scatteredThe vendor's numbers are the only numbers in the room
1. ReactiveScripts run when asked, output kept in emailWeeks lost rebuilding evidence under a deadline
2. MeasuredQuarterly collection, dated files, a reconciliation with ownersFindings are argued from your file, not discovered in theirs
3. GovernedLicensing gates in change management and a topology file kept currentMost findings never happen, because the trigger was blocked

Most estates we baseline sit at level 1 and believe they are at level 2. The distinguishing test is not whether scripts exist. It is whether last quarter's output can be produced in under an hour, with a date and an owner attached.

What tooling actually earns its place?

Four jobs need doing, and no single product does all four well. Buy against the jobs rather than against a category label.

  • Discovery. Finding every host and instance, including the ones no team admits to owning.
  • Database collection. Feature usage and configuration read from the database itself, on a schedule, kept as dated files.
  • Contract repository. Ordering documents and agreements indexed so a row in the reconciliation can be traced to paper in seconds.
  • Reconciliation. The join across deployed, used and entitled, which is usually a spreadsheet and is none the worse for it.

The job most tools do worst is the third one. A dashboard that cannot show you the signed page behind a quantity is telemetry, not evidence.

Where the common advice on Oracle SAM tooling is wrong

The standard advice says buy a verified SAM tool and the Oracle problem is handled. We disagree. In roughly 25 to 35 baselines Fredrik Filipsson built in 2024 to 2025, tool output alone missed the exposure that mattered, option usage history and virtualization scope, in most estates, and no tool output binds Oracle in a review. The tools are useful telemetry. The defense is script level evidence, a topology file, and a quarterly remediation rhythm with named owners. The buyer side move is to budget for the discipline, not just the dashboard, because the dashboard does not negotiate.

ITAM analyst reviewing database feature usage reports on two monitors
The review will be argued from feature usage tables and cluster diagrams, which is exactly where most SAM dashboards stop looking.

What the engagement data shows

Three cuts of our advisory engagement file frame the size of the opportunity.

25 to 35
Oracle baselines built 2024 to 2025
60 to 80%
First baselines showing unpurchased option usage
2x
Lower settlement exposure with quarterly self checks

Source: Redress Compliance advisory engagement file, 2024 to 2025. Stated as observed ranges across the engagement population, not as measured averages.

A dashboard tells you what a tool believes. A dated collection file tells you what the database recorded. Only one of those is evidence.

What does an Oracle SAM practice cost to run?

Less than one finding, in every estate where we have costed it. The practice has four line items and only one of them is a person.

The four line items, and what their absence costs

Line itemWhat it takesWhat happens without it
Named ownerHalf to one full time role, depending on estate sizeThe tooling keeps running and nobody reads the output
Collection and schedulingAutomation effort. The Oracle scripts themselves cost nothingStale, undated evidence that persuades nobody
Searchable contract repositoryUsually an existing document system, indexed properlyQuantities you believe but cannot trace to a signed page
Independent reviewAnnually, or ahead of a renewal or a data requestYour interpretation is first tested by the party invoicing you

Budget plans we see put a fully loaded owner in the 100,000 to 180,000 dollar range a year, depending on market and seniority. Treat that as the planning band we observe, not a benchmark we have measured.

Now set it against a single accidental pack: 720,000 dollars at list on a 96 processor fleet, and 158,400 dollars a year in support at 22 percent. One prevented finding funds the practice for several years.

What the first year actually delivers

  • Quarter one. Instance list, first full collection, and an honest reading of which maturity level you are on.
  • Quarter two. Reconciliation and the shelfware list, which in most estates pays for the program on its own.
  • Quarter three. Pack access posture set to deny, topology file built, licensing gates added to change management.
  • Quarter four. The evidence pack rehearsed once, and a dated baseline in place before the renewal window opens.

The order matters more than the speed. Shelfware surfaces early because it is easy to find and it is the part finance cares about, and it buys the political room to do the harder topology work later.

What should a buyer do next?

Five moves turn this analysis into a lower invoice on the next renewal.

A sequence you can run this quarter

  1. Name one owner for Oracle SAM with access to the database teams and to the contracts.
  2. Set Enterprise Manager pack access to deny before anyone starts investigating, and record the date.
  3. Run collection scripts across every instance, including DR and test, after forcing a fresh sample.
  4. Build the topology file: clusters, cores, factors, and placement rules, exported and dated.
  5. Reconcile deployed against used against entitled, and classify every row as covered, gap or shelfware.
  6. Diff feature usage quarterly and work the remediation queue with named owners.
  7. Gate new builds and cluster changes through a licensing check before go live.
  8. Rehearse the five day evidence pack once, before anyone asks for it in anger.
Need help? Try our AI agents. Ask the Oracle licensing AI agent → Scoped to one vendor and one problem. Runs in your browser.

Frequently asked questions

What is Oracle software asset management?

The discipline of measuring Oracle deployment, core counts, option usage, and virtualization scope against entitlements, using the same evidence sources an Oracle review would: collection scripts, feature usage tables, and topology records.

Why do generic SAM tools struggle with Oracle?

Because Oracle exposure lives in feature usage history, core factors, named user minimums, and where VMs can run. Install based discovery misses most of it, and no third party tool output is binding in an Oracle review.

What Oracle options trigger accidental usage most often?

Diagnostics Pack, Tuning Pack, and Partitioning. They ship installed, record their own usage, and appeared unpurchased in 60 to 80 percent of the first baselines in our 2024 to 2025 file.

How often should an Oracle self assessment run?

Quarterly. Feature usage and topology drift in weeks, and estates on a quarterly script rhythm carried roughly half the audit settlement exposure of annual checkers in our file.

Does Oracle accept third party SAM tool reports in audits?

Oracle measures from its own collection scripts and data. Tool reports are useful internally but do not replace script evidence, which is why your baseline should be built from the same sources.

What does a defensible entitlement record contain?

One row per owned product and metric, with quantity taken from the ordering document, plus agreement and CSI reference, legal entity, deployment mapping, measured usage with its sample ratio, and a named owner. Every row must trace to either a signed page or a dated collection file.

How long should we keep Oracle collection output?

At least three years of dated collections, kept as files with the instance name and date in the file name. Backdated claims are argued over periods, and a period claim can only be answered with a period record. A screenshot in a slide deck is not a record.

Who should own Oracle SAM inside the business?

One named owner, usually in ITAM, with access to the database teams and to the contract file and a direct line to procurement. Keep measuring, interpreting and deciding in separate hands, because those three jobs pull in different directions.

Do we need a SAM tool to do this properly?

Not to start. The four jobs are discovery, database collection, a searchable contract repository, and the reconciliation join. Most estates can run the first credible baseline with scripts, an inventory export and a spreadsheet, then buy tooling against whichever job proved hardest.

White Paper · Oracle

Control Oracle spend: the 5-year CIO playbook.

The governance, renewal and negotiation moves that hold Oracle cost across a five year horizon.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.

Get the white paper →
Opens the white paper landing page. We only email you about this download.
Run a software spend health check against your Oracle estate in under five minutes.
Open the Tool →
25 to 35
Oracle baselines built 2024 to 2025
60 to 80%
First baselines showing unpurchased option usage
2x
Lower settlement exposure with quarterly self checks

Oracle audits are argued from usage tables and cluster maps. A SAM program that cannot produce both is a subscription to surprise.

Fredrik Filipsson
Co Founder and Group CEO. Ex Oracle, IBM, SAP.
Deep Library

More on this topic.

Oracle Practice →
Script output review session
Oracle
Oracle Compliance Scripts
The collection scripts and what they show.
9 min read
LMS output interpretation
Oracle
Reading LMS Script Output
From raw output to a defensible position.
10 min read
Audit defense meeting
Oracle
Oracle Audit Guide
The audit process and the defense sequence.
11 min read
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of Oracle licensing changes.

One buyer side briefing a week. Pricing moves, audit signals, and the levers that work. No vendor spin.

Pass it on

Know someone facing this exact decision?

Send this to whoever owns the renewal, the audit response, or the budget. It takes two clicks and it saves them a quarter of guessing.

Share on LinkedInShare by email