What we do · License entitlement management
See every entitlement.
Then match it to a person.
A vendor inventory the firm can see in full. Entitlements mapped to actual user behavior. Discrepancies surfaced before a vendor auditor finds them. The audit-defense file maintained current as a standing artifact, not assembled as a fire drill.
The inventory problem
Why the inventory is never quite right.
-
Provisioning outlives the person
Entitlements are added when someone joins a desk and rarely removed when they move, leave, or change role. Over a few years the licensed population and the working population diverge, and the invoice follows the licensed one.
-
Three systems of record, none complete
The vendor’s admin portal, the internal permissioning system, and the finance ledger each hold part of the picture. No one of them reconciles to the other two, and the audit questionnaire asks for all three.
-
Machine consumers nobody counted
Applications, models, and agent tools consume data under user licenses that were never written for them. They are invisible in a seat count and fully visible in a vendor’s usage logs.
-
The fire drill
Most firms rebuild the entitlement record when a letter arrives, under deadline, with the people who set it up long gone. The record that results is the one the auditor works from.
The methodology
Four steps to a standing record.
- 01
Inventory
Every entitlement, at the user, terminal, and API level, across every vendor and exchange. Not the portal export: the reconciled position.
- Vendor portal, permissioning system, and invoice reconciled to one list
- Named owner for every entitlement
- Machine and application consumers captured alongside people
- Contract terms attached to each entitlement family
- 02
Usage mapping
Each entitlement matched to what the person or system actually does with it. This is where unused and under-used licenses become visible.
- Usage logs and access patterns reviewed against provisioning
- Dormant identifiers and duplicate seats flagged
- Tier mismatches: users provisioned above the level their role needs
- Redistribution and non-display use identified
- 03
Discrepancy closure
Every gap between contract, provisioning, and use is closed one way or the other: the entitlement is removed, the license is corrected, or the exposure is documented and priced.
- Removals sequenced with the renewal calendar
- Under-licensed use corrected before an audit finds it
- Permissioning system rules tightened
- Exposure number with evidence behind it, for the CRO
- 04
Standing file
The inventory becomes a maintained artifact with a cadence, an owner, and a place in the governance framework. The next letter is answered from it.
- Joiner, mover, and leaver process wired to entitlements
- Quarterly reconciliation cadence
- Audit-defense file kept current, not rebuilt
- Reporting the market data committee can read
What the work produces
One list that everyone agrees with.
- Standing
Audit-defense file
Maintained continuously as part of the operating model, not assembled after a letter arrives.
- One
Reconciled list
Portal, permissioning system, and invoice agree on who holds what.
- Named
Owner per entitlement
Every license has a person or system accountable for it, so removals and renewals have someone to ask.
- Counted
Machine consumers
Applications, models, and agent tools entitled explicitly rather than riding on user licenses.
Who we work with
The population is different at every firm.
-
Asset managers
Terminal and feed populations that have drifted from headcount; index and benchmark entitlements reconciled to the funds and products that use them.
-
Investment banks
Real-time and non-display entitlements at scale across desks and regions, where redistribution use carries the largest audit exposure.
-
Hedge funds and family offices
A small population with a large data spend per head, where a single unrecorded machine consumer can outweigh every seat.
Questions we get asked
Six questions, answered before the questionnaire.
-
What is a market data entitlement?
The right, granted under a vendor or exchange license, for a specific user, terminal, or application to access a specific dataset in a specific way. Entitlements are what auditors count and what invoices are built from, so a record of them that matches reality is the foundation of both cost control and audit defense.
-
How is this different from what the vendor’s admin portal already shows?
The portal shows what the vendor has provisioned. It does not show whether the person still works there, whether the seat is used, whether an application is consuming under it, or what the contract says the seat may be used for. The reconciled inventory answers all four.
-
Can this be done without disrupting users?
Yes. The inventory and usage mapping are read-only exercises. Removals and corrections are sequenced with the renewal calendar and the joiner, mover, and leaver process, and communicated before they happen.
-
How often does the inventory need refreshing?
Quarterly is the cadence most firms settle on, with joiner, mover, and leaver changes flowing through continuously. The point is that the file is never more than a quarter old when a letter arrives.
-
Does Paraxis install software to do this?
No. We work with the systems the firm already has: vendor portals, the permissioning system, the finance ledger, and usage logs. Where a tool would help, we say so, but the advice is not sold on the back of software.
-
Where does the exposure number come from?
From the discrepancies the reconciliation surfaces, priced at the contract rate. It is an evidence-backed figure the CRO and CFO can act on, not an estimate. Specific figures are shared under NDA.