Scope & evidence

Copyable example for devices, servers and SaaS records. Illustrative rows contain fictional identifiers; do not place secrets or unnecessary personal data in an inventory.

Research-based; no hands-on test claim.

Choose a stable record key

Give each asset an internal ID that remains stable through renaming or reassignment. Record serial numbers, cloud resource identifiers or tenant references in separate fields. A hostname is useful for operations but may change or be reused.

Decide the unit of inventory. A physical host, its virtual machines and a SaaS subscription have different lifecycle properties. Link related records rather than squeezing all of them into a single ambiguous device row.

Capture fields that lead to action

Include asset type, service, accountable owner, location or region, lifecycle state, support end date and management source. Add last-seen and last-verified dates so stale discovery data is visible. For sensitive systems, record the classification without putting actual sensitive data in the inventory.

The example table is intentionally small enough to copy. Extend it with backup policy, patch group and supplier references when those fields have clear owners. A large catalogue of unmaintained optional fields can obscure the few facts that matter.

Asset IDType / serviceOwner roleState / verification
EX-001VM / internal file serviceInfrastructure leadIn service / example date
EX-002Laptop / staff endpointEndpoint teamAssigned / example date
EX-003SaaS / documentationService ownerActive subscription / example date

Reconcile rather than blindly import

Compare directory, endpoint-management, cloud and procurement records. Investigate duplicates, devices that have stopped checking in and billed resources with no owner. Automated discovery establishes that something was observed; it does not prove who is responsible for it or whether it should still exist.

Keep an exception list with an owner and due date. Do not automatically delete a record because a laptop was offline during a scan. Confirm retirement through the lifecycle process and retain evidence required by the organisation.

Use lifecycle gates

At onboarding, assign ownership and management before the asset enters service. During operation, update the record when role, location or support status changes. Before disposal, confirm data handling, access removal and contract consequences.

At handover, verify that another authorised person can locate the asset and its recovery or support record. Review access to the inventory itself; hostnames, software versions and network details can be sensitive operational information.

References

Next useful steps

Read our editorial and corrections policy.