Insights · Subscription assessment · Issue I, MMXXVI.

Under entitlement, read as audit exposure.

A buyer side reading of the cost of under entitlement on a Red Hat contract and the four mechanisms by which an audit finding converts the shortfall into a settlement number. Three sources. Four conversion paths. One mitigation discipline.
By The Buyer-Side Desk, an independent advisory practice. 190+ engagements, $180M+ recovered. Published
Abstract

Under entitlement on a Red Hat contract is the population of subscription quantities the buyer consumed across the operative window without a corresponding entitlement on the order form. The cost of under entitlement is the audit exposure that the shortfall produces when the compliance team reads the deployment against the entitlement record, and the mitigation share is the portion the buyer can withdraw before a finding lands. This note frames the three sources, the four audit conversion paths, and the discipline that closes the exposure before the notice arrives.

§ 1

What under entitlement actually exposes.

Under entitlement on a Red Hat contract is the population of subscription quantities the buyer consumed across the operative window without a corresponding entitlement on the order form. The cost of under entitlement is the audit exposure that the shortfall produces once the compliance team reads the deployment against the entitlement record, and the mitigation share is the portion the buyer can withdraw, reclassify, or pre empt before a formal finding lands. The cost is dormant in the entitlement record itself, only converting into a settlement number when an audit notice arrives. A buyer side reading reads it first.1

This note frames the cost of under entitlement as a subscription assessment exercise that sits inside the broader subscription assessment practice. It walks the three sources of under entitlement that recur, the four conversion paths by which an audit finding monetises the shortfall, the mitigation discipline that closes the exposure before the notice arrives, and the failure modes that leave the cost on the deployment. For the matching reading on the recoverable opposite, see the cost of over entitlement, recoverable; for the matching audit posture, see audit defense.

The frame matters because under entitlement is the species of contract drift that operating teams have the least incentive to surface. A workload deployed without a corresponding entitlement is, from the operator's view, a workload that is running. From the buyer side view, it is a settlement figure waiting for an audit team to read it. The calibration between the two readings is the subject of the working paper this note describes.

§ 2

Three sources of under entitlement.

Three sources of under entitlement recur across the subscription assessments the practice has worked in the trailing twelve months. Each source produces a different exposure profile and a different mitigation path.2

The first source is deployment growth that ran ahead of procurement. A workload was deployed inside an operating estate where the project sponsor did not file a procurement request before the deployment ran into production, and the deployment now exists without an entitlement on the order form. The pattern is common on OpenShift worker pools that scaled with traffic, on RHEL system counts that grew through routine provisioning, and on Ansible managed node populations that absorbed new estate without a corresponding line on the contract. For the matching reading on the RHEL counting mechanics, see counting RHEL systems accurately.

The second source is a counting mismatch between the deployment topology and the entitlement model. The most common cases are virtual datacenter entitlements applied to clusters that drifted past the hypervisor capacity the entitlement assumed, OpenShift core counts that did not account for hyperthreading on the operative platform, and Ansible managed node counts that did not include hosts reached through dynamic inventory. The deployment is intentional. The counting model is misaligned with the contract structure. For the matching reading on OpenShift, see OpenShift core counting in mixed environments.

The third source is the legacy estate carried across an acquisition or across a CentOS migration without being reconciled against the operative contract. The consolidated estate runs on entitlements that the operative buyer did not sign against. For the matching readings, see shadow Red Hat usage in M and A and CentOS legacy exposure.

Fig. 2.1 · Three sources of under entitlement, exposure profile by sourceRHLA · 2026 Q2
Source Audit conversion path Exposure band
Growth ahead of procurementList price shortfall, retroactive.+8% to +22%
Counting model mismatchReclassification at list, multi year.+12% to +35%
Inherited legacy estateBackfill across the look back window.+6% to +28%
Three sources of under entitlement, observed across subscription assessments the practice closed in the trailing twelve months. The exposure bands express the share by which an unmitigated audit finding tends to inflate the relevant line on the eventual settlement, not the share of total Red Hat spend. The sources frequently compound on the same estate, and the bands compound rather than add.
§ 3

Four audit conversion paths that monetise the shortfall.

The shortfall converts to a settlement number through four audit conversion paths in 2026. Each path has its own contract surface, its own arithmetic, and its own defence posture. The cost of under entitlement is the sum of the paths that the audit team can credibly reach, not the sum of all four. The discipline of the mitigation reading is to close the paths that are reachable before the notice arrives.3

The first path is the list price shortfall on the relevant line. The audit team reads the deployment, identifies the population that is not covered by the entitlement record, multiplies the population by the list price of the relevant subscription, and presents the figure as the immediate compliance gap. The defence posture reads the deployment population carefully, contests any double counting, and produces the concession band that the line will eventually settle inside. For the matching reading, see Red Hat list price versus concession bands 2026.

The second path is the multi year backfill. The audit team reads the deployment as having been in place for a defined look back window, typically two to three years, and presents the shortfall multiplied by the look back. The arithmetic compounds quickly. The defence posture reads the deployment trajectory and contests the look back where the deployment can be shown to have entered the estate inside a narrower window. The trailing telemetry on the operative platform is the working evidence. For the matching reading, see deployment evidence in audit defense.

The third path is the cross product attachment. The audit team identifies a shortfall on the base product and converts it into a shortfall on the add on lines as well. Smart Management on RHEL hosts without entitlement; add ons on partially licensed OpenShift clusters; JBoss integration add ons on middleware tiers without the base subscription. The defence reads each add on independently and contests the attachment where the add on was not deployed. For the matching reading, see Smart Management entitlements, paying for use.

The fourth path is the cooperative escalation. The audit team frames the resolution as a renewal posture that closes the shortfall through an expanded contract structure rather than through a punitive settlement. The framing reads as cooperative but converts the under entitled population into the next renewal cycle at unfavourable terms. The defence distinguishes the compliance resolution from the renewal posture and runs the two on separate calendars. For the matching reading, see settlement negotiation leverage.

§ 4

The mitigation discipline.

The mitigation discipline runs the reconciliation, identifies the under entitled share by source, classifies the share by audit conversion path, prioritises the closures the buyer can execute before the next notice, and carries the residual exposure into the audit defence posture as known surface. The discipline is preventative. It runs before the notice arrives.4

The reconciliation is not a count of installed packages on the network. It is a count of operating populations against the model the contract uses. RHEL counts against socket pairs or against virtual datacenter entitlements. OpenShift counts against cores after the contract's hyperthreading convention is applied. Ansible counts against managed nodes after the inventory convention is applied. The mismatch between the operating count and the contracted model is what produces the audit conversion. The working paper carries both counts side by side.

The discipline closes the reachable paths through an order form correction inside the next renewal cycle, through a contract amendment where the structure permits, or through a posture pre filing that documents the reconciliation as the buyer's own initiative rather than as a finding. The pre filing is the most defensible closure where the deployment cannot be retired and the entitlement cannot wait for the renewal cycle. The buyer that surfaces the shortfall first writes the settlement framing. Some shortfalls can be absorbed by a flex band on a multi year contract; some require an amendment; some close at the next true up cycle. For the matching reading, see true up mechanics on Red Hat and the Red Hat enterprise agreement when it makes sense.

"Under entitlement is dormant cost. The audit notice is the conversion event. The working paper closes the reachable paths before the notice arrives."
Practice observation · The Buyer-Side Desk · Subscription assessment engagements
§ 5

What the working paper names.

The output of the mitigation discipline is a working paper that names the under entitled quantity by line, the source, the audit conversion path the line is exposed to, the recommended closure mechanism, the closure calendar, and the residual exposure after the closures execute. The paper carries the reconciled deployment evidence and a calibrated trajectory band that distinguishes the under entitled share from legitimate operative variance.

The paper is the buyer's internal compliance record. It is not filed with Red Hat as a matter of course; it is not exported to the account team as a routine update. It is the document the buyer reads against the order form before any audit notice arrives, the basis for the closure decisions across the next renewal cycle, and the evidence that the buyer side reading was already in motion if a notice does arrive later. For the broader practice cycle, see the ninety day subscription assessment.

For each under entitled line, the paper produces four numbers. The prior quantity on the order form. The operative consumption across the window, with trailing trajectory shown alongside. The recommended closure quantity, calibrated against the trajectory and the timing of the next renewal cycle. The residual exposure after closure executes, expressed as a band rather than a point estimate. The paper carries the residual into the audit defence preparation so that the posture is built before the notice arrives.

§ 6

Four recurring failure modes.

Four failure modes recur on subscription assessments where the under entitlement reading is not run with the discipline this note describes. Each leaves dormant cost on the deployment.5

The first is treating the deployment as the entitlement. The operator reads the workload as licensed because it is running and producing operative value. The contract reads it as unlicensed because it is not on the order form. The audit team reads the second. The working paper names the second reading explicitly.

The second is closing the visible path and leaving the secondary paths open. A buyer that closes the base shortfall and leaves the cross product attachment open will absorb the attachment as an inflated finding when the notice arrives. The discipline reads all four paths together. For the matching reading, see three audit triggers.

The third is delaying closure until the notice arrives. The closure that costs less inside a routine renewal cycle costs more inside a formal compliance review. A pre filing inside a renewal cycle reads as discipline; a pre filing inside a review reads as admission. The cadence is the renewal calendar.

The fourth is filing the paper with the account team as a courtesy update. The account team is compensated on retention and growth; a surfaced shortfall without a closure mechanism reads as a procurement opportunity, not a compliance event. The paper stays internal. The closure is filed through the appropriate contract mechanism. For the matching reading, see why the account team changed and what it means, renewal negotiation, and the contact desk.

Notes & references

  1. 1. Under entitlement is the population of subscription quantities the buyer consumed across the operative window without a corresponding entitlement on the order form. The cost is the audit exposure produced when the deployment is read against the entitlement record. The mitigation share is the portion the buyer can withdraw, reclassify, or pre empt before a formal finding lands.
  2. 2. The three sources in § 2 reflect the patterns observed across subscription assessments closed in the trailing twelve months. Exposure bands express the share by which an unmitigated finding tends to inflate the relevant line on the eventual settlement, not the share of total Red Hat spend. Sources frequently compound on the same estate.
  3. 3. The four audit conversion paths in § 3 reflect the paths observed across audit defences settled in the trailing twelve months. The list price shortfall is the most direct. The cooperative escalation is the most procedurally costly because it conflates compliance and renewal on the same calendar.
  4. 4. The mitigation discipline in § 4 reflects the practice standard. The discipline reads the operative deployment against the contract counting model, prioritises closures by reachability of the audit path, and carries any residual exposure into the audit defence preparation as known surface rather than as latent risk.
  5. 5. The four failure modes in § 6 are observed across subscription assessment engagements closed in the trailing twelve months. The most common is the first, where the operating teams read the deployment as licensed and the contract record is never reconciled against the operative footprint.

Preparing a response? The practice keeps a one-page Red Hat audit response checklist — what to acknowledge, what to preserve, and what not to volunteer in the first fourteen days after the letter arrives.

§ 7 · Engagement

Engage before the audit notice converts the shortfall.

Two analyst calls. No fee. We tell you what we would do, what the under entitlement exposure on your estate is likely to look like once the reconciliation has run against the order form, and whether we are the right firm. If an audit notice is already in hand, the first call happens within twenty four hours.