ENTERPRISE IT ASSET COMMAND CENTER

IT Asset Management Overview

Executive view of inventory, compliance, lifecycle, assignments and audit readiness.

Enterprise ITAM UI UI / workflow validation build • Backend, SSO and live integrations remain deployment-phase items

ITAM Operations

End-to-end IT Asset Lifecycle Management. Freshservice remains the ITSM system of record for onboarding, offboarding and service requests; ITAM owns asset custody, lifecycle, compliance, reconciliation and disposal.

Freshservice ITSM Integration

ITSM ↔ ITAM boundary
Freshservice ownsOnboarding · Offboarding · Service Requests · ITSM Tickets
ITAM ownsAsset Master · Assignment · Lifecycle · Compliance · Reconciliation · Warranty
Inbound to ITAMApproved asset request · return request · offboarding asset list · repair request
Outbound to FreshserviceAsset allocated · assigned · returned · repaired · sanitized · retired · disposed
0Open Workflows
0Pending Approval
0Due / Attention
0Completed

Lifecycle Control Center

Every material action creates a transaction, history and audit event

Operational Queue

Requests and lifecycle transactions
IDTypeAssetRequesterCurrent StateNext ActionCreatedAction

Asset State Machine

Controlled transitions
REQUESTED→APPROVED→PROCURED→RECEIVED→REGISTERED→IN STOCK→ASSIGNED→RETURNED / REPAIR→RETIRED→SANITIZED→DISPOSED

System Configuration

Configure enterprise identity, branding and core IT Asset Register settings.

Identity & Access

Authentication
Local LoginAllow local portal authentication as a fallback.
Asset ID Prefix by Asset TypeConfigure a different prefix and independent sequence for each Asset Type.
Examples: LAP-0001, DSK-0001, MON-0001. Prefix changes apply to new assets only.

Single Sign-On (SSO) Configuration

Entra ID · OIDC · SAML 2.0
SSO EnabledEnable enterprise single sign-on on the login page.
Identity ProviderChoose the protocol. Only the selected provider's settings will be displayed below.
Microsoft Entra ID ConfigurationMicrosoft Entra ID uses OAuth 2.0 / OpenID Connect with Authorization Code + PKCE for the SPA.
Microsoft Entra ID
Login Button Display NameText displayed on the login page.
Redirect URISPA redirect URI registered in Entra ID.
Post Logout Redirect URIReturn location after Entra sign-out.
Tenant IDMicrosoft Entra Directory (tenant) ID.
SPA Client IDApplication (client) ID for the ITAM SPA.
AuthorityEntra v2 authority endpoint.
API ScopeDelegated API scope requested by the SPA.
Access & ProvisioningSigning in with Microsoft Entra ID only authenticates the identity. Portal access, Department and Role come from the Users & Departments master (Users & Departments page) — a person not already provisioned there sees Access Denied even after a successful Microsoft sign-in. Use "Azure AD Group Provisioning" on that page to bulk-provision an Azure AD group's members with a Department in one step.
SSO Configuration StatusNot configured

Freshservice Integration

Service Request source
Freshservice IntegrationEnable loading Service Requests from Freshservice into the Asset Registration dropdown.
Freshservice InstanceExample: https://yourcompany.freshservice.com
Freshservice API KeyStored in the backend (DynamoDB) only. All ticket lookups are proxied server-side by this portal's own API, so this key is never sent to any browser.
Freshservice Workspace IDOptional. Leave blank for the primary workspace.
API Proxy URL (legacy, unused)No longer needed — this portal's backend now proxies Freshservice server-side automatically. Leave blank.
Integration OwnershipFreshservice: service requests and ITSM references · ITAM: asset lifecycle and custody.
ITSM + ITAM
Freshservice SettingsSaves the whole System Configuration, including Identity & Access and SSO above.

Portal Branding

Logo & identity
Livegage
Recommended: transparent PNG or SVG. The selected logo is stored locally in this SPA prototype.
Example: EUC- generates EUC-0010, EUC-0011…; IT- generates IT-0010, IT-0011…. Prefix changes apply to newly generated Asset IDs only.

Scheduled Email Reports

Dashboard summary + Asset Register
Weekly ReportEmails a dashboard KPI/compliance summary (HTML) with the full Asset Register attached as a CSV.
ScheduleFixed at deployment via an AWS EventBridge rule on the backend, not editable here.
Weekly
RecipientsComma-separated email addresses. Each must be SES-verified (or your SES account/domain must be out of sandbox) to receive the report.
Report SettingsSaves the whole System Configuration, including the sections above.

Configuration Status

Current settings
No changes pending. Freshservice settings are managed in the Freshservice Integration section above.

Approval DOA

Delegation of Authority for EUC asset issuance, lost/stolen events and retirement.

Approval Queue

Separation of Duties enforced
Approval IDAssetTypeRequesterReferenceApproverStatusAction

Portal Users & Roles

Manage IT Asset Register access using role-based access control and separation of duties.

0Portal Users
0Active Users
0Assigned Roles
0Approval Roles

Portal Users

UsernameNameEmailRoleDepartmentStatusActions

Role Matrix

Enterprise RBAC
RoleRegister / EditIssueIssue ApprovalLost/Stolen ApprovalRetirement ApprovalLifecycle ActionsAudit
Administrator
Backend admin — full access, can act on any approval step including self-approval
FullYesApprove (any step)Approve (any step)Approve (any step)FullView
Asset AdminFullYesNo self-approvalNo self-approvalNo self-approvalFullView
Asset ManagerFullYesApproveApproveApproveFullView
EUC Asset CustodianCreate / UpdateExecuteNoReportRequestOperationalView
Service DeskCreate / UpdateRequest / ExecuteNoReportRequestOperationalView
Department ManagerViewRequestApproveApproveApproveNoView
IT ManagerViewRequestApproveApproveApproveNoView
Finance Approver
Approves Disposal, Write-off, Purchase Request and Purchase Order (not shown as separate columns here)
ViewViewNoNoNoNoView
Security Approver
Approves Stolen-asset declarations and Compliance Exceptions
ViewViewNoApprove (Stolen only)NoNoView
Auditor / Read OnlyViewViewViewViewViewNoView
ENTERPRISE ASSET GOVERNANCE

IT Asset Management Dashboard

Executive visibility into EUC inventory, endpoint security posture, lifecycle control and governance risk.

AAAsset Admin
EUC Administrator
0Authoritative inventory
0Requires remediation

Security Compliance Posture

Control-level compliance across the EUC estate
Overall 0%
Encryption0%
EDR Protection0%
MDM / Intune0%
0%
Overall Control HealthAverage of core endpoint controls
0Fully compliant assets
0At-risk assets
0Partially compliant

Compliance Distribution

Asset-level security status
0Assets
Compliant0
Non-Compliant0
Partially Compliant0
Control interpretationMirrors the Assessment on the Compliance Health page. Compliant = MDM / Intune + Encryption + EDR are all compliant. Partially Compliant = one or two of them are confirmed. Non-Compliant = none of them are confirmed (failing or not yet reported).

Assets by Type

Total, issued and in-stock position for each asset type. Click a number to list those assets.
Asset TypeTotalIssuedIn StockFaulty in StockAvailableOther
No assets yet.

Governance Attention

Priority exceptions requiring operational action
Risk Queue
!
0Non-compliant devices
◷
0Warranty due within 90 days
□
0Assets pending assignment
✓
0Active managed assets

Lifecycle Portfolio

Current asset-state distribution
Assigned
0
In Stock
0
In Repair
0
Lost / Stolen
0
Retired
0

Asset Register

Authoritative EUC inventory with ownership, endpoint identity, security posture and lifecycle information.

Use the dashboard for high-level posture. This register is the detailed EUC inventory.

All EUC Assets

Use View for complete asset details or Assignment for the complete lifecycle and custody history.
Filter
Asset IDUserAsset TypeManufacturerModelSerial NoHostnameDepartmentLocationStatusComplianceAction

Device Assignment

Track custody, assigned users and departmental ownership of EUC assets.

Current Assignments

Custody overview
AssetAssigned UserDepartmentLocationStatus

Assignment History

Complete custody and user assignment history for EUC assets. Historical records are retained independently from the current assignment.

0Total Assignment Events
0Active Assignments
0Returned / Closed
0Reassignments

Assignment History

Custody chain
AssetPrevious UserNew UserDepartmentAssignedReturnedService RequestCustodianStatus

Selected Asset — Complete History

Select an asset from the table
Select an Assignment History record to view the complete chronological lifecycle and assignment history.

Lifecycle Management

Monitor EUC assets from procurement and stock through assignment, repair, retirement and disposal.

0In Stock
0Assigned
0In Repair
0Retired

Lifecycle Register

AssetPurchase DateCurrent StateWarranty EndLocation

Compliance Health

Endpoint security posture covering MDM/Intune, encryption and EDR compliance.

0%Encryption
0%EDR
0%MDM / Intune

Security & Compliance by Asset

Endpoint-control posture, ownership and evidence status
AssetAsset TypeUserDepartmentSerial NoEncryptionEDRMDM / IntuneAssessmentEvidence
Evidence control: When MDM / Intune is Yes, Encryption is Compliant, or EDR is Compliant, supporting evidence is required on the asset record. Use View or Edit from the Asset Register to review or update evidence.

Exceptions

Security and operational exceptions requiring remediation, approval or documented risk acceptance.

Open EUC Exceptions

Derived from non-compliant endpoint controls
ExceptionAssetOwnerPriorityStatus

Users & Departments

Central master source for Username and Department. All user assignment and department selections across ITAM consume this master.

Authoritative identity source for both SSO and Local Login users. An SSO sign-in is only granted portal access if the person already has a record here — use "Provision from Azure AD" to bulk-add an Azure AD group's members with a Department in one step. Role is always assigned here by an administrator, for SSO and local users alike.

User & Department Master

Authoritative user source
UserDisplay NameDepartmentRoleProvisioningAction

Item Master

Authoritative item catalog for PR, PO, Procurement, Receiving and Asset Registration. Create and maintain purchasable IT items here.

PR and PO line items must be selected from the active Item Master.
0Items
0Manufacturers
0Models
0Asset Types

Item Catalog

Used by PR and PO
Filter
Item CodeItem NameCategoryAsset TypeManufacturerModelUOMSerializedStatusAction

Vendor Master

Vendor registration and master list. Populates the Vendor dropdown on Purchase Orders and on Send for Repair requests.

Only Active vendors appear in the Purchase Order and Send for Repair vendor dropdowns.
0Vendors
0Active
0Inactive
0Categories

Registered Vendors

Authoritative vendor source across ITAM
Filter
Vendor CodeLegal Vendor NameCategory / TypeCriticalityStatusAction

Data Cleanup

Administrator-only. Delete individual test records from any section's own screen (a Delete button now appears there for Administrator), or wipe an entire section here in one action before go-live. Every action here is permanent and cannot be undone.

Receiving & Stock isn't listed separately — its rows are generated from Procurement's Purchase Orders, so deleting a PO here already removes its receiving rows too. Peripherals are removed one at a time via the existing "Detach" action on an asset's Attached Peripheral screen; "Clear All" below still wipes the whole peripheral list at once if needed. Assignment History and Lifecycle are historical logs, not row-editable records, so they only offer "Clear All" (never per-row delete).

Sections

Record counts refresh each time you open this page
SectionRecordsAction

Asset Issuance Approval — DOA

Delegation of Authority workflow for controlled issuance of EUC assets to employees and contractors.

0Pending Approval
0Approved
0Rejected
0Elevated Approval

Issuance Approval Queue

DOA-controlled requests
Recommended EUC Issuance DOA
1. RequesterEmployee / Service Desk raises issuance request.
2. Asset CustodianValidates asset, stock, user and business need.
3. ApproverDepartment Manager / authorized DOA approver approves issuance.
4. HandoverService Desk records custody acceptance and issue date.
Request IDAssetRequesterBusiness UnitDOA TierStatusAction

DOA Rules

Example policy configuration
TierTriggerRequired ApproverControl
Tier 1Standard EUC assetDepartment ManagerBusiness need + user eligibility
Tier 2Privileged / restricted-use deviceDepartment Head + Information SecuritySecurity justification + additional controls
ExceptionOutside standard entitlementAuthorized exception approverDocumented exception / risk acceptance

Reconciliation

Compare the EUC register with endpoint-management or discovery sources. This prototype provides the control surface for reconciliation.

0Register Assets
0Unique Serials
0Hostnames
0Duplicate Serials
Production integration point: connect this module to Intune, Jamf, AD, SCCM or another endpoint source through an API and reconcile by immutable device/serial identifier.

Audit Trail

Record-level governance history for EUC asset changes and administrative actions.

Recent Activity

Prototype activity log
TimestampActionRecordActorResult

Reports

Export a point-in-time PDF snapshot of any register below. Each report opens your browser's print dialog with a clean, print-formatted layout — choose "Save as PDF" as the destination.

Available Reports

Page Access

Control which sidebar pages each role can see. A role left unchecked for a page simply doesn't see that page in its sidebar (or by direct link) — this only controls visibility, not what a role can save once on a page it can see. A page with no boxes unchecked at all is left visible to everyone, including any role added later. Administrator always sees every page and can't be restricted here, so nobody can lock every admin out of this screen.

Role × Page Visibility

Changes apply immediately in this browser and sync to every other user on save

Administration

Configuration areas for EUC asset governance. Production controls should be enforced server-side.

Entra IDRecommended authentication
RBACRole-based access
APIBackend integration ready
AuditImmutable server log recommended
Recommended roles: EUC Administrator, EUC Asset Manager, Service Desk, Department Asset Custodian, Auditor, Read Only.
ADMINISTRATION & MANAGEMENT

Password Reset

Securely reset local portal credentials for authorized users with a documented business justification.

Administrative Control

Local Account Password Reset

Use for local portal accounts only. SSO credentials remain managed by Microsoft Entra ID.
🔒 Controlled Action
Username is the primary authentication key.
Temporary passwords should be changed at next sign-in.
A valid business justification is required for every administrative reset.
Audit ControlReset activity is recorded in the Audit Trail.
Separation of DutiesOnly authorized administrative roles may perform this action.
Credential SafetyPasswords are never written to audit records.

Procurement Management

Enterprise procurement workflow: PR → Approval → PO → Receiving → Stock → Asset Registration.
Open PRs
0
Open POs
0
Ordered Units
0
Received Units
0
Pending Receipt
0
Manufacturers
0

Purchase Request Register

Business requirement before a PO is created. PR line items capture requested quantity and expected delivery.

Requirement Source
PR NumberRequesterDepartmentRequired DateItemsQtyPriorityStatusActions

Purchase Order Register

PO header plus line-item quantities. Receiving records actual accepted quantities and serial numbers.

Vendor & PO Source
PO NumberPR NumberVendorQty OrderedQty ReceivedPendingStatusManufacturerInvoice No.Invoice DateWarranty StartWarranty EndRegistered AssetsActions

Receiving & Stock Control

Receive procured serial-numbered assets, validate physical condition, record stock location and control availability before Asset Registration.

0Procured Units
0Accepted / Received
0Available Stock
0Allocated
0Rejected / Quarantined

Receiving Register

One row per procured serial number
Filter
PO NumberProcurement IDVendorAsset TypeManufacturerModelSerial NumberReceipt StatusConditionStock StateLocationReceived DateInvoice No.Invoice DateWarranty StartWarranty EndAsset IDAction

Stock Control Rules

Controlled availability
Availability rule: A serial becomes available for Asset Registration only after it is physically received and marked Received / Good. Rejected, Quarantined, or Pending items cannot be registered.
Allocation rule: Once a serial is registered to an Asset ID, its stock state becomes Allocated and it is removed from the available-stock pool.