Bitweb
Guide · Asset inventory

What an IT asset inventory needs to track (and what it can skip)

"Do you maintain an inventory of hardware, software and user accounts?" is a yes/no question on every insurance form and vendor audit. The spreadsheet that earns the yes has specific columns. Here they are.

By a working IT technician supporting 400+ users · Updated September 2026 · 7 min read

An asset inventory has one job: to let you answer, from a document rather than memory, three questions an insurer or auditor will ask. What devices do you have and are they protected? What software and cloud services hold your data? Who can log in to what, and when did you last check? Everything else is optional.

Tab 1: Hardware

One row per device, including phones, printers, network gear, cameras and the NAS in the cupboard. Columns that matter:

Skip: CPU model, RAM, MAC addresses. Useful for IT, irrelevant to the question being asked, and they go stale.

Tab 2: Software and SaaS

Every application or cloud service that holds company data, including the free ones somebody signed up for with their work email. This tab doubles as your vendor register for the third-party policy. Columns: application, vendor, category, business owner, data classification held (public / internal / confidential / regulated), MFA enforced?, seats, monthly cost, renewal date. The MFA column here is the one people forget; the accounting platform and the CRM matter as much as email.

Tab 3: Users and access

One row per person with a login: staff, contractors, and any vendor with standing access. Columns: name, role, manager, start date, end date, status (active / on leave / offboarded), admin rights?, systems and apps they can access, MFA on?, and last access review date. A formula that flags any row not reviewed within your cadence (90 or 180 days) turns this from a list into a control, because now "are access rights reviewed periodically?" has an answer with dates.

Tab 4: Onboarding and offboarding checklist

Not strictly inventory, but auditors ask "how do you know access is removed when someone leaves?" and the honest answer is a ticked checklist per leaver. Nine joiner tasks (account, MFA on day one, device recorded, policies signed, least-privilege access) and ten leaver tasks (accounts disabled on the last day, sessions revoked, removed from shared vaults and group chats, mailbox handled, device returned and wiped, shared passwords the person knew rotated). Date and tick each one.

The dashboard: why it matters more than the tabs

The tabs are evidence. The dashboard is what you actually look at. Six numbers, all calculated: devices in use, devices not encrypted, devices without EDR, active users without MFA, admin accounts, and access reviews overdue. When the red-flag counts read zero, you are ready for the questionnaire. When they don't, you have a to-do list. Print it before a renewal or a customer audit; it answers three questions on one page.

Excel or something else?

Under about 100 devices, a well-built workbook is the right tool: no licence, no onboarding, editable by the office manager, and readable by the auditor. Beyond that, or if you have an MSP with an RMM tool, export from the RMM into the same columns; the structure is what matters, not the software.

The free version of this is the column list above; build it in an afternoon. If you'd rather start from the finished workbook with dropdowns, formulas and the dashboard already wired, it's part of the kit.

Want the documents done for you?The IT Asset & Access Register is the written policy set, incident response plan and asset register described here, as editable Word and Excel files: CA$12 on its own, or CA$39 in the full kit, instant download. Get the asset register
The cyber-insurance questionnaire, question by question12 questions, what "yes" needs, which document proves itAn incident response plan a small business will actually useRoles, severity levels, first-hour checklist, three playbooksThe eight security policies a small business needs, and why not twentyThe minimum viable policy set, mapped to CIS v8 IG1