Software spend does not usually leak through one big hole. It seeps: a licence nobody uses, a bill five percent over the contracted rate, an uplift with no cap. Each is small enough to miss and none is anybody's job. Here is the watchdog that finds them, and why it counts before it reasons.
The expensive problems in a software estate announce themselves. The renewal is on the calendar, the audit letter arrives, the big contract is up. It is the cheap problems that do the quiet damage, because no single one is worth a person's afternoon. A team paying for two hundred seats and using a hundred and forty. An invoice running five percent over the rate the contract set. An uplift clause with no ceiling, compounding in the background. None of it is a crisis. All of it is money, and none of it is anybody's job to catch.
The anomaly center exists to make it somebody's job, specifically a machine's. It runs every week across the estate and surfaces the leaks that are individually too small to notice and collectively large enough to fund a headcount. The design principle underneath it matters more than the feature list: it counts before it reasons.
A watchdog you cannot trust is worse than none, because a false alarm every week trains the team to ignore it. So the detection layer is deterministic. It does not ask an AI whether something looks wrong. It applies rules to your own data. Shelfware is flagged when utilisation falls below a set threshold on a licence large enough to matter. Leakage is flagged when the last three complete months of actual spend run a defined percentage and dollar amount over the contracted rate. Uncapped uplifts, misaligned co-terms, and overlapping tools are found the same way, by comparison, not by vibe.
The advantage of rules is that they are explainable and repeatable. Every alert can point at the exact numbers that produced it, the entitlement, the usage, the contracted rate, the actual bill. There is no "the model thought so." There is a threshold, and your data crossed it.
This matters most when you take a finding to a vendor. "Your AI told us we are overpaying" invites an argument about the AI. "Our last three months of invoices ran six percent over the rate this contract sets, here are the numbers" does not. Deterministic detection produces alerts that survive a challenge, because the evidence is your own data and simple arithmetic, not a black box the vendor can wave away.
Rules find candidates. Rules also produce false positives, a seat that looks idle because the team is between projects, a billing spike that is a one time true up, not a leak. This is where AI is genuinely useful, and where it is kept on a short leash. A triage pass reviews each finding against the surrounding evidence, the clauses, the caps, the billing history, and returns a verdict: confirmed, downgraded, or uncertain, with the reasoning attached.
A downgraded finding is set aside automatically, but never deleted, so you can see what was dismissed and why, and restore it if the machine got it wrong. The order of operations is the whole point. Deterministic detection keeps the watchdog honest. AI triage keeps it from crying wolf. Neither is asked to do the other's job.
Want to be updated when major licensing and pricing changes land? One analyst brief a week: the price rises, metric changes and audit campaigns that move software costs. Work email only.
The exposure figure on each alert is an estimate of annual spend at risk, grounded in your contracts and usage, not a guaranteed saving. Closing a leak still takes a decision and often a conversation with the vendor. The watchdog does not reclaim the seats or renegotiate the rate. It finds the leak, prices it, and puts it in front of a person while it is still small.
That is the entire value. The leaks it catches were always there, seeping quietly between the events everyone was watching. Turning them from invisible into a ranked, priced list is the difference between finding out at renewal and fixing it the week it started.
Fredrik has spent more than twenty years in enterprise software, with time at Oracle, IBM, SAP, and Salesforce before moving to the buy side. He structured and priced the kind of large agreements most buyers only see once or twice in a career, which taught him where the leverage sits and how far a vendor will actually move. He started VendorBenchmark to hand that knowledge to every sourcing team.
What shipped on the platform, and the pricing and licensing moves worth knowing before your next renewal. One email a week, to your work address. Unsubscribe any time.