RFP requirements template

Know what your IT asset management platform has to do before vendors tell you.

64 requirements in 12 sections, from discovery and license optimization to CMDB integration and audit readiness. Keep what applies and put the same questions to every vendor.

  • RFP templates
  • ITAM
  • 64 requirements
  • Updated Oct 2026
  • Published Oct 2026
Create a free account

About this template

This is the requirement set Olive uses to evaluate IT asset management (ITAM) platforms: 64 requirements in 12 sections. Five sections cover managing the assets themselves, from discovery and software licenses to SaaS, lifecycle and the service desk. Four cover security, automation, reporting and administration, and three cover the vendor, its pricing and its standing.

It is written for IT operations, asset management and procurement teams choosing an ITAM platform, from a single IT department to a multi-entity organization or a managed service provider. Each section below says why it matters.

How to use it

Start with the sections, not the requirements. Decide which sections carry the most weight for your organization, then go through the requirements in each one and drop what does not apply. A team facing a software audit will weigh license optimization and audit readiness heavily; a team with sprawling SaaS spend will care most about SaaS and cloud governance.

Put the same list to every vendor, in the same words, and ask for a score and evidence on each line. A requirement list only compares vendors fairly when every vendor answers the same questions.

Asset management

These five sections cover the assets themselves: finding every device and application, managing software entitlements, governing SaaS and cloud, running the lifecycle from purchase to disposal, and keeping the service desk and CMDB in step. They are the core of any ITAM platform and the reason to buy one.

01

Asset Discovery & Inventory Coverage

7 requirements

Every other ITAM capability depends on knowing what exists. Discovery across operating systems, networks, cloud and remote devices, with agent and agentless options, decides how complete and current the inventory is.

  1. Cross-OS endpoint discovery[Must] Agent-based and agentless discovery across Windows, macOS, and Linux endpoints, including remote/off-network devices via cloud-based reconciliation.
  2. Network infrastructure discovery[Standard] Automated discovery of network infrastructure (switches, routers, printers) via SNMP and active scanning.
  3. Shadow SaaS discovery via IdP/finance[Must] Native discovery of SaaS applications through OAuth/API connectors to identity providers (e.g., Okta, Entra ID) and financial systems to surface shadow IT.
  4. Public cloud resource discovery[Must] Discovery coverage extends to public cloud resources (AWS, Azure, GCP) including compute, storage, and managed services inventories.
  5. IoT/OT device discovery[Standard] Discovery of IoT and OT devices for organizations with converged physical/IT environments.
  6. Multi-source deduplication[Must] Reconciliation logic deduplicates assets discovered via multiple methods into a single normalized record.
  7. Configurable discovery refresh rate[Standard] Discovery refresh frequency is configurable to near-real-time for critical asset classes, not limited to periodic batch scans.
02

Software Asset Management & License Optimization

6 requirements

Software licenses are often the largest controllable IT cost and the largest audit risk. Matching entitlements to what is actually deployed and used shows where to reclaim licenses and how exposed the organization is to a vendor audit.

  1. Software recognition library depth[Must] Software recognition library normalizes installations against a database of 200,000+ titles to support accurate license position calculation.
  2. Complex publisher ELP reporting[Must] Effective License Position (ELP) reporting for complex publishers (Microsoft, Oracle, SAP, IBM) accounts for downgrade rights, virtualization, and publisher-specific bundling rules.
  3. Entitlement vs. deployment tracking[Must] Tracks license entitlements against actual deployment and usage to identify both over-licensing (cost waste) and under-licensing (audit exposure).
  4. True-up and renewal forecasting[Standard] Supports true-up and renewal forecasting tied to contract end dates and entitlement counts.
  5. Unused software detection[Standard] Detects unused or rarely-used software installations to inform harvesting and reclamation decisions.
  6. Audit-defensible history[Must] Maintains historical license audit trail defensible in a formal publisher audit.
03

SaaS & Cloud Governance

5 requirements

SaaS and cloud spend grows outside central purchasing. Finding unmanaged applications, tracking usage and owners, and controlling renewals and cloud consumption keep that spend visible and governed.

  1. Shadow SaaS identification[Must] Identifies shadow SaaS applications not provisioned through IT, using expense, SSO, and browser-extension signals.
  2. SaaS spend and seat utilization tracking[Must] Tracks SaaS subscription spend, seat utilization, and renewal dates in a unified view separate from hardware/software licensing.
  3. Cloud cost attribution (FinOps)[Standard] Cloud cost management (FinOps) capability attributes cloud spend to specific teams, applications, or cost centers.
  4. Duplicate SaaS tool detection[Standard] Flags duplicate or overlapping SaaS tools across departments to support consolidation decisions.
  5. Automated SaaS offboarding[Standard] Supports automated deprovisioning workflows for SaaS access tied to employee offboarding.
04

Lifecycle & Workflow Management

6 requirements

An asset has a life from request and purchase through deployment, maintenance and disposal. Workflows that follow it keep ownership, location and warranty data accurate and cut the manual work at each stage.

  1. End-to-end lifecycle tracking[Must] End-to-end lifecycle tracking from procurement request through deployment, redeployment, and disposal/retirement.
  2. Configurable approval workflows[Must] Configurable approval workflows for asset requests, transfers, and disposals with role-based routing.
  3. Automated refresh planning[Standard] Automated hardware refresh planning based on warranty expiration, age, and depreciation schedules.
  4. Procurement system integration[Standard] Integration with procurement systems to auto-create asset records from purchase orders.
  5. Certified disposal/e-waste tracking[Standard] Certified data destruction and e-waste disposal tracking for compliance and sustainability reporting.
  6. JML workflow automation[Must] Joiner-mover-leaver (JML) workflows automatically reassign or reclaim assets tied to HR system events.
05

ITSM & CMDB Integration

5 requirements

Asset data is most useful where incidents, changes and requests are handled. A tight link to the service desk and the CMDB means one record of each asset rather than two that drift apart.

  1. Bi-directional ITSM integration[Must] Native, bi-directional integration with the organization's ITSM platform so asset data flows into incident, change, and problem records without manual sync.
  2. CMDB relationship/dependency mapping[Must] CMDB data model supports configuration item relationships and dependency mapping, not just a flat asset list.
  3. Pre-built endpoint/RMM integrations[Standard] Pre-built integrations with major endpoint management and RMM tools to avoid custom development for common stacks.
  4. Change workflows from asset records[Standard] Change management workflows can be triggered directly from asset records for regulated environments.
  5. Documented API for custom integration[Must] API-first architecture with documented REST/GraphQL endpoints for custom integrations beyond pre-built connectors.

Intelligence and control

These four sections cover control of the platform and what it tells you: security and compliance, AI and automation, reporting and audit readiness, and administration. They decide whether the data can be trusted and acted on, and whether the platform fits how the organization is structured.

06

Security & Compliance

6 requirements

An unmanaged device or unpatched application is a security gap. Security and compliance requirements cover how the platform protects its own data and how it helps find vulnerable, unauthorized or end-of-life assets.

  1. SOC 2 / ISO 27001 certification[Must] Platform itself holds current SOC 2 Type II and/or ISO 27001 certification, with audit reports available on request.
  2. Data residency controls[Must] Supports data residency controls for organizations with regional compliance requirements (e.g., GDPR, data localization).
  3. Granular RBAC[Must] Role-based access control (RBAC) with granular permissions down to asset category or business unit level.
  4. Vulnerability/patch correlation[Standard] Correlates asset inventory with vulnerability and patch management data to flag unpatched or end-of-life assets as risk exposure.
  5. Audit-ready compliance reporting[Must] Produces audit-ready compliance reports mapped to standards such as ISO 55000, ITIL, or NIS2 incident reporting requirements.
  6. Immutable change audit trail[Must] Maintains immutable audit trail of all asset record changes, including who changed what and when.
07

AI & Automation Intelligence

5 requirements

Normalizing software titles, spotting anomalies and recommending savings by hand does not scale. Automation and AI determine how much of that work the platform does without an analyst.

  1. AI-assisted software recognition[Standard] AI-assisted software recognition automatically classifies unknown or unrecognized installations without requiring manual library updates.
  2. Predictive refresh/compliance analytics[Standard] Predictive analytics flag assets likely to fail, become non-compliant, or require refresh based on historical patterns.
  3. Anomaly detection on license/usage[Standard] Automated anomaly detection surfaces unusual license consumption spikes or unauthorized software installations.
  4. Natural-language data queries[Standard] Natural-language query or AI assistant capability allows non-technical stakeholders to ask questions of the asset data directly.
  5. No-code automation rule engine[Must] Automation rule engine allows no-code configuration of triggers and actions (e.g., auto-flag non-compliant assets) without professional services.
08

Reporting, Dashboards & Audit Readiness

5 requirements

Finance, security and auditors each need a different view of the estate. Reporting that answers those questions quickly, and produces an audit-ready license position, is where much of an ITAM platform's value shows.

  1. Pre-built executive dashboards[Must] Pre-built executive dashboards summarize spend, compliance posture, and utilization without custom report-building.
  2. No-code custom report builder[Standard] Custom report builder supports ad hoc queries across asset, license, and financial data without SQL expertise.
  3. Scheduled report distribution[Standard] Scheduled report distribution to stakeholders outside the platform (email, Slack, Teams).
  4. One-click drill-down to asset record[Standard] Drill-down from summary dashboards to individual asset records in a single click.
  5. Multi-currency/multi-entity rollups[Standard] Reporting supports multi-currency and multi-entity rollups for global organizations.
09

Administration, Configuration & Multi-Tenancy

5 requirements

Roles, permissions, configuration without code and support for several entities or clients decide how much effort the platform takes to run and whether it fits the organization's structure.

  1. No-code custom fields/categories[Must] Custom fields and asset categories can be configured without vendor professional services.
  2. Multi-tenant data segregation[Standard] Multi-tenant architecture supports organizations managing multiple business units, subsidiaries, or (for MSPs) multiple end-client environments with data segregation.
  3. Bulk import/export tooling[Must] Bulk edit and bulk import/export capabilities support large-scale data migration and cleanup.
  4. Configurable expiration/renewal alerts[Standard] Configurable notification rules alert asset owners and IT before warranty expiration, contract renewal, or compliance deadlines.
  5. Data retention/archival controls[Standard] Admin console provides granular control over data retention and archival policies.

Vendor and commercial

These three sections cover the company behind the product: implementation and support, the pricing and commercial model, and the vendor's standing in the market. They are easy to leave until contract stage, and they shape the total cost and the risk of the decision.

10

Implementation, Support & Vendor Viability

5 requirements

An ITAM platform only pays off once its data is complete and trusted. Time to value, migration help, support quality and the vendor's long-term health matter as much as features.

  1. Disclosed implementation timeline[Must] Vendor provides a defined implementation methodology with a typical time-to-first-baseline-inventory disclosed upfront.
  2. 24/7 Sev-1 support included[Must] 24/7 support is available for Severity 1 issues at the buyer's intended pricing tier, not gated behind a premium support add-on.
  3. Published SLA[Must] Vendor publishes an SLA with defined uptime and response-time commitments.
  4. Community/certification ecosystem[Standard] Active user community, knowledge base, or certification program exists to reduce dependency on the vendor for troubleshooting.
  5. Pilot/POC availability[Standard] Vendor offers a proof-of-concept or pilot period before full contract commitment.
11

Pricing & Commercial Model

5 requirements

ITAM pricing varies by device, user, module and connector. Understanding what is counted, what is included and how the price scales with the estate avoids surprises at renewal.

  1. Transparent, forecastable pricing model[Must] Pricing model (per-asset, per-endpoint, per-user, or tiered) is disclosed clearly enough to forecast cost as the estate grows, without requiring a sales call for a budgetary estimate.
  2. No penalty for discovery growth[Standard] No material price increase is triggered simply by crossing a discovery threshold (e.g., discovering more SaaS apps than initially scoped).
  3. Flexible scale-down terms[Standard] Contract terms support scaling down as well as up without punitive penalty clauses.
  4. TCO includes required add-on modules[Must] Total cost of ownership includes required add-on modules (e.g., SaaS management, CMDB) rather than a low headline price that excludes core functionality.
  5. Multi-year discounting without full prepay[Standard] Multi-year contract discounting is available without requiring an all-at-once upfront payment.
12

Company & Product Overview

4 requirements

This section covers the vendor and product themselves: whether the product is actively developed and sold on its own, the vendor's presence in ITAM, and its customer base. It is the context for every other answer.

  1. Active independent product[Must] Vendor demonstrates an active, independently-sold product with confirmed press activity and sales motion within the last 12 months.
  2. Public AI/automation roadmap[Standard] Vendor publishes a public product roadmap or briefing covering AI/automation investment for the next 12-24 months.
  3. No pending acquisition/sunset risk[Must] Vendor has not been the target of an acquisition, merger, or sunset announcement in the past 18 months that would affect product continuity.
  4. Disclosed customer base and references[Standard] Vendor discloses customer base size and reference customers relevant to the buyer's industry or company size.

Talk to Olive

Book a conversation with the team about what you are working on.