Asset Inventory

Software Inventory: How to Build and Automate It (2026)

juanhernandez@preyhq.com
Juan H.
Jul 20, 2026
0 minute read
Software Inventory: How to Build and Automate It (2026)

Ask most IT teams how many copies of a given app are running across their fleet right now, and you'll get a pause. Then a spreadsheet. Then a caveat. One admin put it plainly in a demo: "I track my fleet in an Excel spreadsheet, and I know it's stale." He wasn't being lazy. He was being honest about a list that stops being true the moment someone installs something on a laptop in another city.

That gap has a cost. When a vulnerability drops for a common application, the first question is "which of our machines run the affected version?" When a vendor sends a true-up notice, the question is "how many seats are we actually using?" When an employee leaves, the question is "what did they have installed, and where did the data go?" A stale spreadsheet answers all three the same way: we're not sure.

A software inventory closes that gap. Done well, it turns "we're not sure" into a report you can pull in minutes. This guide covers what a software inventory is, what it should record, how to automate it so it stays current, and how to keep it in shape for security and compliance.

TL;DR

Software inventory, in five lines

  • What it is: A software inventory is a continuously maintained record of every application installed across your endpoints, with versions, license type, and usage.
  • Why it matters: You can't patch, license, or audit what you can't see. Unknown software is unlicensed risk and unpatched attack surface at the same time.
  • The spreadsheet problem: A manual list is stale the moment someone installs an app on a laptop three time zones away.
  • The fix: Automate discovery at the endpoint so the record updates itself, and set alerts for new installs, expiring licenses, and unauthorized apps.
  • Start here: Run one full audit, define the fields every entry must have, then move off the spreadsheet to a tool that detects software on its own.

What is a software inventory?

A software inventory is a continuously maintained record of every software application installed across an organization's devices, including version numbers, license type, install and expiry dates, and how often each app is actually used. It gives IT a single, current answer to a simple question: what is running, where, and under what license.

That last part matters more than it sounds. A list of app names is trivia. An inventory that ties each install to a device, a version, and a license is an operational asset. It feeds patching, license renewals, security response, and audits without you rebuilding it each time.

Software inventory sits underneath broader IT asset management work, but it's a distinct discipline. Asset management tracks the hardware and its lifecycle. Software inventory tracks what lives on that hardware, which changes far more often. A laptop is one asset for three years. The software on it can shift a dozen times a month.

Why does an accurate software inventory matter?

An accurate software inventory matters because three high-stakes IT jobs depend on it: patching vulnerabilities, staying license-compliant, and controlling cost. Each one fails quietly when your inventory is wrong, and you usually find out at the worst possible moment, during an incident or an audit.

Take security first. You can't patch what you don't know is installed. When a CVE is published for a widely used tool, response speed depends entirely on knowing which endpoints run the vulnerable version. Teams with a current inventory scope the blast radius in minutes. Teams without one start a manual sweep across the fleet while the clock runs. Every unknown app on a device is attack surface nobody is watching.

Then there's license compliance. Software vendors audit, and the gap between what you bought and what you deployed is where penalties live. One DaaS provider managing 760 devices summed up the pain from the other direction: "we can't recover licenses for devices that never come back." Whether it's over-deployment or orphaned seats, the money leaks the same way, invisibly, until someone counts.

Cost optimization is the quieter win. An honest inventory surfaces the apps nobody uses, the duplicate tools two departments bought separately, and the subscriptions still billing for people who left. You can't cut spend you can't see.

What a software inventory should record, and why the spreadsheet breaks

The value of an inventory is in its fields, not its existence. A record that only lists app names tells you nothing when a vendor audit or a vulnerability hits. At minimum, every entry should capture enough to act on without a follow-up investigation.

A workable software inventory records:

  • Application name and publisher: so you can group and identify quickly.
  • Version number: the field that decides who's exposed when a CVE lands.
  • License type and seat count: perpetual, subscription, per-user, per-device.
  • Install date and expiry or renewal date: to catch lapses before they become penalties.
  • Assigned device and user: the link that makes response and offboarding possible.
  • Usage or last-seen data: the evidence for reclaiming unused licenses.

Here's where the spreadsheet breaks down. A manual list has no way to know when someone installs, updates, or removes an app. It reflects reality only on the day someone updates it by hand, and it drifts a little further out of date every day after. Across a distributed fleet with people installing software on their own machines, the drift is constant. The list looks authoritative and is quietly wrong. That's the worst combination: confident and inaccurate.

Quick wins to run this week:

  • Define the six fields above as your inventory standard, and reject any entry that's missing one.
  • Pull a last-seen date on every app so you can spot the installs nobody has touched in 90 days.
  • Flag any application that appears on a device but isn't on your approved-software list. That's your shadow-IT starting point.

How to build and automate a software inventory

Building a software inventory is a five-step loop: audit what exists, normalize the data, track licenses against it, set alerts for change, and review on a fixed cadence. The goal isn't a one-time list. It's a record that maintains itself so you're not rebuilding it every quarter.

Start with a full audit. Before you automate anything, get a complete picture of what's installed across the fleet today, including licenses, subscriptions, and one-off installs. This is your baseline, and it's usually where the surprises live.

Normalize what you find. The same app shows up under three names across vendors and versions. Consolidate it so "Acme Reader 11," "AcmeReader," and "Acme Reader Pro" don't count as three products in your reporting.

Track licenses against the inventory. Tie each install to its license and seat count, so you can see over-deployment and orphaned seats at a glance instead of reconstructing it during an audit.

Set alerts for change. This is the step that moves you off the spreadsheet for good. Automated discovery watches for new installs, version changes, and removals, and flags them as they happen. New unauthorized app on a device? You know that day, not next quarter.

Review on a cadence. Even automated inventories need a human pass. Schedule a monthly review to catch expiring licenses, retire unused software, and confirm the approved-software list still matches reality.

Consider the license-audit scenario this prevents. A vendor sends a true-up notice with 30 days to respond. With an automated inventory, you export current deployment against entitlements and answer with evidence. Without one, the same request turns into a fire drill across every department, and you negotiate from a position of "we think." Automating asset discovery is what turns the second story into the first.

Quick wins to run this week:

  • Replace one manual tracking process with automated discovery on a single device group, and compare the results to your spreadsheet. The gap is your business case.
  • Set a renewal alert on your three most expensive licenses so nothing lapses silently.

Software inventory for compliance and security

For compliance, a software inventory is your evidence layer. Frameworks like SOC 2 and ISO 27001 expect a maintained asset inventory as a baseline control, and license compliance depends on being able to prove what you deployed matches what you licensed. An inventory you can export on demand is the difference between passing an audit and scrambling through one.

Auditors don't want a promise that you manage software. They want the record. A current inventory, with install dates and license data, is documentary proof that the control exists and runs, not just that it's written in a policy somewhere. When the request comes, you're producing a report, not assembling one under pressure.

Security response leans on the same record. Beyond patching, an inventory exposes shadow IT, the unauthorized apps employees install on their own that never went through review. Each one is a potential data path outside your controls. And at offboarding, the inventory tells you exactly what a departing employee had installed and where corporate data might live, so the asset visibility that protects you during employment carries through the exit process.

Quick wins to run this week:

  • Export your current inventory as if an auditor asked today. If you can't do it in under an hour, that's the gap to close first.
  • Cross-reference installed apps against your approved list and investigate the top five you don't recognize.

Automating software inventory at the endpoint with Prey

Everything above depends on one thing: seeing software at the source, on the endpoint, continuously. A record that lives in a spreadsheet is only as current as the last person who edited it. A record that reads directly from the device stays true on its own. This is where endpoint management tools close the gap, and it's the ask we hear most: across demos, "see my whole fleet" is the single most common request, cited by 58% of teams, and 24% name the stale spreadsheet by name as the thing they're trying to replace.

Prey approaches software inventory through its Management capabilities, which include hardware and software inventory across the fleet. Because AI and automation are increasingly part of how IT teams keep this current, the record reflects what's actually installed, not what someone remembered to log. You get a centralized view across Windows, macOS, Linux, Android, iOS, and Chromebook, with custom fields to tag software by department or function and mass actions to work across many devices at once.

The practical payoff is the one the spreadsheet never delivered: an honest, current answer to what's installed and where. How many devices run the app with the new CVE? Which machines have software that isn't on your approved list? What did the offboarded employee have installed? You pull it instead of reconstructing it.

One IT lead in government administration put the combination this way in a G2 review: "In terms of inventory management and security, it meets all the necessary requirements without complications. But what really makes the difference is the human team behind it." Inventory that maintains itself, backed by people who answer when you ask, is the version of this that actually gets used day to day.

Conclusion

A software inventory isn't a document you produce once and file. It's the visibility layer under patching, licensing, audits, and incident response, and it's only useful if it's current. The spreadsheet fails not because it's the wrong format, but because it can't keep up with a fleet that changes every day.

The move is to stop maintaining the list by hand and let the endpoints report themselves. Automate discovery, define the fields that make each entry actionable, set alerts for change, and review on a cadence. Do that, and the next time someone asks what's running across your fleet, the answer is a report, not a pause. The most dangerous software on your network is the software you don't know is there. An automated inventory is how you make sure that set stays empty.

Frequently Asked Questions

What is a software inventory?

A software inventory is a continuously maintained record of every application installed across an organization's devices, including version numbers, license type, install and expiry dates, and usage. It gives IT one current answer to what's running, where, and under what license, and it feeds patching, renewals, and audits.

How do you maintain a hardware and software inventory?

Maintain it with automated discovery rather than manual updates. An agent on each device continuously reports installed software and hardware details, updates records as things change, and flags new installs or removals. Pair that with a scheduled monthly review to catch expiring licenses and retire unused software, so the record stays accurate without constant hand-editing.

How do you automate software inventory management?

Automate it with tools that detect software directly on each endpoint and update the inventory in real time. Automated discovery continuously tracks installs, version changes, and removals, generates reports, and sends alerts for expirations or unauthorized apps. This removes the manual data entry where errors and staleness come from, and keeps the inventory current across a distributed fleet.

How do you track software licenses across the organization?

Tie every install to its license and seat count in a centralized inventory, then run scheduled audits against your entitlements. Track usage so you can reclaim unused or expired seats, and set renewal alerts so nothing lapses silently. A centralized record turns license true-ups from a fire drill into an export.

What's the difference between software inventory and software asset management?

A software inventory is the record of what's installed. Software asset management (SAM) is the broader discipline that uses that record to manage licenses, contracts, costs, and the full software lifecycle from purchase to retirement. The inventory is the foundation. SAM is what you build on top of it once the data is accurate.

Why keep a software inventory up to date?

An outdated inventory fails exactly when you need it: during a vulnerability response, a vendor audit, or an offboarding. Keeping it current means you can scope security exposure in minutes, prove license compliance on demand, and reclaim wasted spend. A stale inventory looks authoritative while giving you wrong answers, which is worse than having none.

See every app on every device

Prey gives IT teams an always-on inventory of hardware and software across the whole fleet, so "what's running out there?" stops being a guess. Request a demo and see your fleet the way it actually is.