top of page

Application Portfolio Management in Higher Education

  • Writer: David Holstein
    David Holstein
  • Aug 11
  • 8 min read
Application portfolio management in higher education: finding the applications with no owner

TLDR: Application portfolio management in higher education is the least glamorous work available and one of the highest-return. Decades of departmental purchasing, grant-funded tools, gifted software, and point solutions have produced a portfolio in the hundreds at most institutions, much of it invisible to central IT and some of it with no accountable owner at all. APM is the business record of that portfolio: what the institution owns, who owns it, what it costs, when it renews, and which capability it serves. This piece covers how the sprawl happened, what APM records that the CMDB does not, why the renewal calendar is the fastest payback, the four dispositions every application ends up in, and the honest dependency underneath all of it.


How the Portfolio Got This Big


Ask a central IT organization how many applications the institution runs. The answer is usually the number in the service catalog. Then someone runs a spend analysis with procurement, or an SSO report, or a review of expiring contracts, and the real number turns out to be several times larger.


None of this happened through negligence. It happened through four decades of entirely reasonable decisions.


A department bought scheduling software because central IT had a queue and the term started in three weeks. A grant funded a specialized research tool, the grant ended, and the tool stayed. An alumnus gifted a platform license to a college. A vendor sold a point solution directly to a dean who had budget authority and a real problem. A unit standardized on something during a leadership transition and the person who chose it moved on.


Every one of those decisions made sense at the time. What they add up to is an institution that cannot answer a basic question about its own operations, which is what it owns and what it is paying for.


EDUCAUSE landed on the same territory in its 2026 Top 10, framing measured approaches to new technologies as a priority and recommending institutions take stock of the existing technology ecosystem before making substantial new purchases, including removing duplicative technologies and consolidating licenses. That advice is sound and it presumes an inventory most institutions do not have.


What Application Portfolio Management in Higher Education Actually Records


The first confusion to clear up is the relationship between APM and the CMDB, because institutions with a healthy CMDB often assume they already have this covered.


Application portfolio management versus CMDB in higher education: business record and technical record

The CMDB is the technical record. It answers what is running, where it runs, how components depend on each other, what a change would break, and which service an outage touches. That is an operational view and it is essential.


APM is the business record, and it answers a different set of questions. What does the institution own. Which unit owns it and who signed the contract. What does it cost across license, support, and the staff time to keep it alive. When does it renew and what is the notice period. Which business capability does it serve, and does anything else already serve that capability.


The second set is what a provost or CFO is asking about. It is also the set most institutions cannot answer without a two-week fire drill involving procurement, three deans, and someone in accounts payable searching for recurring charges.


Start With the Renewal Calendar


The instinct with APM is to build the complete inventory first, then analyze it. That is a long project with the value at the end, which is a bad shape for anything that has to survive a budget cycle.


The renewal calendar inverts it. Pull every application contract with a renewal date in the next twelve months, and work that list first. It is a smaller set, it has a natural deadline attached to each item, and it is the only part of the portfolio where a decision can actually be executed in the near term. An application that renewed last month is a conversation for next year regardless of what the analysis says.


Two things tend to surface immediately. The first is auto-renewal with a notice window that has quietly passed, which is a straightforward money question. The second is duplication that becomes visible only when two contracts sit next to each other on the same list, which happens constantly in higher education because the buying happened in different units in different years.


Working renewals first also produces something an inventory project cannot, which is a result inside one fiscal year. That result is what funds the rest of the effort.


Four Answers for Every Application

Once applications are on a list with an owner, a cost, and a capability tag, each one needs a disposition. The four-way split will be familiar to anyone who has seen the tolerate, invest, migrate, eliminate framing, and it holds up well on a campus with one adjustment, which is that ownership is a first-class criterion rather than a data field.


Four application disposition decisions for higher education: invest, tolerate, migrate, eliminate

Invest applies to the systems that serve a capability the strategic plan actually names and that are the system of record for it. These get roadmap attention and integration investment.


Tolerate is the honest answer for a great deal of the portfolio. It works, it has an owner, it costs very little, and the political cost of removing it exceeds the savings. Tag it, set the review for its renewal date, and move on. Institutions that refuse to tolerate anything spend their credibility fighting over small applications that units care about deeply.


Migrate is the largest opportunity and the most work. The capability matters, but this particular instance of it does not need to exist, usually because a platform the institution already licenses can serve the same need. This is where the orchestration argument matters. The goal is not to force every unit onto one system for the sake of tidiness. It is to stop paying separately for capability the institution already owns, while leaving the unit in control of its own process.


Eliminate covers applications with no named owner, no measurable use, or a duplicate that is already licensed elsewhere. The category is smaller than people expect and easier to act on than they fear, because in most cases the reason the application has no owner is that it stopped being used some time ago.


An Application With No Owner Is an Application With No Review


This is the part that turns APM from a cost exercise into a risk one.


An application that entered through a departmental purchase probably did not go through security review. It probably does not have an accessibility conformance report on file. It may not have completed a vendor assessment. It may hold student data in a system central IT has never seen, under a contract with terms the institution has never read, and it is very likely still authenticating against institutional identity.


EDUCAUSE maintains the Higher Education Community Vendor Assessment Toolkit for exactly this reason, and it works well for applications that come through a process. It does nothing for the ones that did not.


Accessibility is the sharper edge of this in the current environment. An application acquired outside the review process was almost certainly never evaluated for conformance, and the institution carries that exposure whether or not it knows the application exists. The inventory is the precondition for doing anything about it.


The practical move is to attach three flags to every application record as the inventory is built. Does it hold protected data. Did it go through security review. Is there an accessibility conformance record. Three yes-or-no fields turn the portfolio into a risk register at almost no additional cost, and the applications that answer no to all three are the shortlist worth reviewing first.


The Dependency Worth Naming


APM is only as good as the record underneath it.


If the CMDB is incomplete, application records will be missing their infrastructure relationships, which means the cost picture will be missing the infrastructure the application consumes and the impact analysis will be missing whatever depends on it. If Discovery coverage is partial, the inventory will reflect what happens to be visible on the institutional network rather than what the institution runs, which in higher education is a meaningful gap given departmental servers, research computing, and cloud accounts held outside central governance.


We wrote about that foundation in detail in ITOM and CMDB health in higher education, and about the tuning it takes to see the full footprint in ServiceNow Discovery for higher education.


The honest sequencing advice is that this dependency is real and it is not a reason to wait. A contract-based inventory built from procurement records, SSO logs, and expense data can be assembled without a healthy CMDB and will still answer the ownership, cost, and renewal questions. The technical relationships get added as the foundation improves. Waiting for a clean CMDB before starting APM usually means waiting years to answer questions the CFO is asking this quarter.


For the CIO reading this

The short version: an inventory framed as an audit stalls at the departments holding the most unknown applications. The same inventory framed as coverage does not.


Frequently Asked Questions


How is application portfolio management in higher education different from the CMDB?

The CMDB is the technical record of what is running and how it connects. APM is the business record of what the institution owns, who owns it, what it costs, when it renews, and which capability it serves. They overlap on the application itself and answer different questions for different audiences, and APM inherits the accuracy of whatever the CMDB provides.


Where does the initial application list come from?

Four sources cover most of it. Procurement and contract records, accounts payable for recurring charges, the identity provider for anything using institutional single sign-on, and Discovery for what is visible on the network. Each one finds applications the others miss, and the SSO list is usually the one that surprises people.


How do we handle applications a college paid for with its own budget?

Record them and leave the ownership where it is. The institutional value comes from knowing the application exists, who is accountable, what data it touches, and when it renews. Attempting to seize budget authority as part of an inventory effort is the fastest way to end the inventory effort.


What if an application has no identifiable owner?

That is a finding rather than a problem to solve quietly. Assign it to the unit that funds it, and if no unit will claim the cost, that answers the disposition question. In practice, applications with no owner and no claimant have usually stopped being used, and the review is a formality.


Does APM require ServiceNow SPM?

The capability sits within the SPM product family, and the reason to run it there rather than in a spreadsheet is that the application record connects to demand, projects, contracts, and the CMDB in one place. A spreadsheet inventory is better than no inventory. It goes stale within about a quarter, because the thing that keeps a portfolio current is being wired into the processes that change it.


The Honest Summary

Application portfolio management in higher education is a business inventory, not a technical one. It answers ownership, cost, renewal, and capability, and those answers are what the CFO and provost are asking for when they ask what technology costs.

Start with renewals rather than with completeness, because that is where a decision can actually be made this year. Give every application one of four dispositions and be willing to tolerate more of the portfolio than instinct suggests. Attach the protected data, security review, and accessibility flags while the inventory is being built, since that is the cheapest moment to capture them. And frame the whole effort as coverage rather than audit, because the departments holding the applications you most need to see are the ones deciding whether to answer.


Talk it through with us

If you are trying to get to a defensible application inventory and are not sure where to start, we are happy to walk through the source data, the renewal-first approach, and what it takes to keep the record current.



About the author. David Holstein is the founder and CEO of Bettera, a ServiceNow consulting and implementation partner built exclusively for higher education. Bettera works with colleges and universities on ITSM, ITOM, CSM, SPM, and AI governance, with an AI-native delivery model.


Read next

bottom of page