The output
One row per tool. One decision per row.
A software audit is not a hunt for the smallest bill. It is a short inventory of jobs, owners, access, data, dependencies, renewal dates, and exit options. Thirty focused minutes can expose problems that a feature comparison never sees.
Begin with software that can charge money, receive client information, send messages, publish content, or unlock another account. Include “free” products: a zero-dollar service can still hold the only copy of a list, domain setting, or recovery email.
Minute 0–8: build the inventory
Create a sheet with these columns:
| Field | Question it answers |
|---|---|
| Tool and job | What observable task would fail if this disappeared? |
| Owner and backup | Who decides, and who can recover access if that person is unavailable? |
| Data held | Does it contain leads, clients, credentials, files, analytics, or billing records? |
| Access | Which people, service accounts, API keys, and integrations can enter? |
| True cost | Subscription, seats, usage, connector, tax, bank fees, and admin time. |
| Renewal | Monthly or annual, exact date, notice period, and responsible person. |
| Exit | What can be exported, in which format, and how long would migration take? |
Use invoices, card statements, password-manager entries, browser-installed apps, and integration lists to jog your memory. Do not paste secrets into the inventory. Record the vault item name or owner instead.
Minute 8–15: find overlap and invisible dependencies
Group tools by the job they perform: capture, schedule, communicate, sell, deliver, bill, analyze, or secure. Two products in one group are not automatically waste. The test is whether each has a distinct job and owner.
- Duplicate entry: the same contact is manually copied between tools.
- Ownerless sync: an automation runs, but nobody checks failed records.
- Connector tax: a “cheap” app requires another paid service to complete the promised path.
- Identity chain: losing one personal inbox would lock the domain, hosting, and payment stack.
- Shadow archive: an old tool remains the only place containing approved files or consent history.
Minute 15–22: review access before price
Apply least privilege: give people and integrations only the access needed for their current work. Remove departed users, disable unused API tokens, separate personal and business recovery routes, and enable multi-factor authentication where supported. Never share a one-time code or recovery code with a contractor.
Check whether the owner account is a named business-controlled identity rather than a former freelancer's personal address. A $12 subscription with uncontrolled domain access is not a small issue.
Minute 22–27: test the exit
Open the export documentation for every system of record. Confirm which objects, fields, attachments, consent states, and activity history are included. Export one safe sample when possible and inspect it. “Export available” is not useful if the result omits the context required to continue work.
Document retention and deletion separately. Keeping everything forever is not an exit plan; deleting a tool without preserving records you lawfully need is not cost control.
Minute 27–30: assign one of four decisions
- Keep: the job, owner, access, cost, and exit remain defensible.
- Consolidate: another owned tool completes the job without a harmful migration.
- Repair: retain the product but fix access, recovery, sync monitoring, or documentation.
- Retire: export what is required, revoke connections, confirm billing ends, and record the date.
Do not cancel inside the audit if the data and recovery consequences are unclear. The audit creates the task; a verified retirement completes it.
Frequently asked questions
How often should a small business audit its software stack?
Run a short review monthly and a deeper review before annual renewals, team changes, or a material client-data change. The useful cadence is the one that catches ownerless access and auto-renewals before they become incidents or sunk costs.
Should I cancel every tool I did not use this month?
No. Some tools are seasonal, compliance-related, or retained for a documented recovery need. Ask whether the job, owner, data, renewal date, and exit plan are still valid before cancelling.
What is the biggest warning sign in a software stack?
A critical account with no named owner, no second recovery route, shared credentials, or no tested export is a larger risk than a small duplicate subscription.
Can a spreadsheet be the software inventory?
Yes. A controlled spreadsheet is enough when it has one owner, restricted access, validated fields, and a recurring review date. Do not buy an asset-management tool merely to inventory a small stack.
Primary sources checked
Pricing changes. Recheck the vendor’s checkout before buying.