IT Systems Assessment Template
Five documents and three sheets that put real sign-in data and a cancellation deadline on every application, then sort the estate by the deadline.
Free download · No account needed
Application Register · Thurlow Industrial Group · 118 applications, $3,185,000 a year · readout 3 March
Sorted on the act-by date, not on a value score
| Application | Annual | Act-by | Days | What that means |
|---|---|---|---|---|
| Strathaven BI Reporting | $23,000 | 1 Apr | +29 | Decide now. Six saved reports, none opened in 90 days |
| Ledbury Expense Portal | $41,000 | 2 Apr | +30 | Decide now. 1,140 seats provisioned, zero sign-ins |
| Halvorsen Field Service | $54,000 | 13 Apr | +41 | Decide now. Replaced in 2025, nobody cancelled it |
| Barbon Purchase Approvals | $14,500 | 2 Mar | −1 | Locked. Window shut the day before the readout |
| Camborne Print Manager | $35,000 | 30 Jan | −32 | Locked. Day 25 of the fieldwork, next chance 2028 |
| Fieldmark Asset Suite | $61,000 | 17 Jan | −45 | Locked. Day 12 of the fieldwork, next chance 2028 |
| Norwood Labour Capture | $24,000 | 2 Jul | +121 | Blocked. Still posting the nightly batch into payroll |
| Thurlow ERP | $214,000 | 3 Oct | +214 | Largest line in the estate, and nothing to decide for seven months |
$1,123,500 of headline saving, $768,800 of it reachable inside twelve months. Sixteen rows had already passed their act-by date. Eleven of them, worth $197,200, passed during the eight weeks the assessment was running.
Search this and every result hands you the same instrument. Score each application on business value, score it on technical health, weight the two, plot the composite on a grid, then read a disposition off the quadrant it lands in. The federal playbook most of the commercial versions descend from is honest about where those scores come from, which is a questionnaire sent to the application owner. Ask an owner whether their application is valuable and the answer is yes.
So this pack refuses the questionnaire and joins three record sets instead: the licence contract, the identity provider's sign-in log keyed to the seat assignment list, and the integration configuration. That is the same order the MEGABYTE Act of 2016 puts federal agencies in, requiring an inventory built with automated discovery and software usage analysed to make cost-effective decisions, rather than an inventory built by asking. Usage then has three states rather than two, because a dormant seat and a seat nobody has ever signed into need different conversations.
Then every disposition gets an act-by date, computed as the renewal date minus the notice period, and the register sorts on that rather than on a score. At Thurlow Industrial Group the client's own list held 74 applications and the records held 118. The headline saving was $1,123,500, of which $768,800 was reachable, and eleven rows worth $197,200 passed their deadline during the fieldwork. Find where the operation loses money with the operational diagnostic, or price what the client keeps against its policies with the risk and controls assessment.
What's in the pack
Application Register
One row per application with usage in three states, the licence model, the act-by date and the disposition, plus which record set found it.
Redundancy Analysis
Every apparent duplicate tested against the share of the smaller active population that signs in to both, with the migration size where it fails.
Integration Map
One row per configured connection, what it carries, who owns it, and what breaks if the target is switched off on a contract date.
Assessment Findings
What the records found against what the client's own list held, the seat split, and the dead applications with their annual cost.
Rationalization Recommendation
Sequenced by act-by date in four waves rather than ranked by saving, each row with a named signatory and the notice that has to be served.
Risk Note
Leaver seats, applications outside single sign-on, card-bought spend with no processing terms, and the connections nobody has written down. Level the client first with the maturity model pack.
Current Architecture
A text map of the hubs and the feeds, built from the integration configuration rather than from a drawing anybody had lying around.
How the Act-by Date Is Computed
The three contract fields behind the date and the four recoverability states. Score the client against a rubric with the diagnostic assessment pack.
How to use it
- 1
Open in River, or take it blank
Open the pack in River and send the sign-in export, the contracts and the integration configuration, or download the Word documents and CSV sheets and work through them yourself.
- 2
Build the inventory from records
Join the identity provider's application list, twelve months of card statements and the client's own register. The gap between the last one and the other two is the first finding.
- 3
Read the contracts in week one
Pull the renewal date, the notice period, whether it auto-renews and whether it prices seats. Do this early, because notice windows close while an assessment runs. Eleven closed during this one.
- 4
Sort on the date, not the amount
Rank the register by act-by date and split the headline into the four recoverability states. The gap between the headline and the reachable figure is the part of the conversation nobody else has.
Frequently asked questions
Is this template free?
Yes. The zip is Word documents and CSV sheets, no account and no card. Edit with AI is the optional half: the agent joins the sign-in log to the seat list, reads the contracts and computes every act-by date. The rest sit in the template library.
What format are the downloaded files?
Five Word documents and three CSV sheets in one zip. The register carries the columns that do the work: active, dormant and never signed in as separate counts, the licence model, the act-by date and the recoverability state.
What does Edit with AI actually do?
It deduplicates the application list across the sign-in log, the card statement and the client's own register, joins seats to sign-ins, pulls the renewal and notice terms out of each contract, then returns the register sorted by act-by date.
What if the client cannot give me a sign-in log?
Most identity providers export ninety days of sign-ins in a few clicks, and that single file plus the seat list produces a usable finding before any contract is read. Where an application sits outside single sign-on, pull usage from the vendor console and record it as a current-state mapping job.
Are unused seats really worth their per-seat price?
Only where the agreement prices seats. Twenty-seven of the eighty live applications here are priced by site or tier, and their idle seats price out at $336,000 that no renewal will ever release. Those seats move to the risk note as an access finding instead.
Why do leaver seats get their own column?
Because they need no business case and no owner conversation. On the per-seat contracts here they were worth about $110,000 a year, and NIST SP 800-53 already asks for accounts no longer associated with an individual to be disabled.
Is an act-by date really worth a whole column?
Federal contracting takes the strict version of the same idea. FAR 52.217-9 makes an option to extend conditional on preliminary written notice a set number of days before expiry, sixty unless the contract says otherwise. Stopping is timetabled too.
Put a deadline on every disposition
Take the Word documents and CSV sheets blank, or send River the sign-in export and the contracts and get the register back sorted by act-by date.
Edit with AI