Somewhere in your client base right now, a tool is checking in, reporting for duty, and doing nothing useful. Nobody is using it. Nobody remembers turning it on. And every month, it bills.
This is not an edge case. It is one of the most common and least discussed line items in a managed services business. The tools you stop needing rarely announce it. They just keep running, and keep charging.
How the waste gets in
Two situations create almost all of it, and both are routine.
The first is offboarding. A client leaves, or a set of users gets cut, and the accounts get closed on the front end. But the seat in the EDR, the mailbox in the email security tool, the endpoint in the backup platform, those do not always get cleaned up in the same motion. The client is gone. The license is not. It keeps checking in, and it keeps appearing on the bill, sometimes for months.
The second is tool migration. You move a client from one platform to another. The new tool goes in, everyone confirms it is working, and the project is declared done. What often does not happen is the last step: fully decommissioning the old tool on every machine. A handful of endpoints keep running the platform you thought you left behind. Two tools now cover the same job. You pay for both.
Neither of these is negligence. They are the natural residue of a busy operation where the urgent work is standing things up, not tearing them down.
Why you cannot see it from inside any one tool
The reason this spend stays hidden is the same reason coverage gaps stay hidden. Each tool only sees itself.
The old platform left running after a migration is, from its own point of view, perfectly healthy. It is installed, it is checking in, its dashboard is green. It has no idea it was supposed to be retired. It will report itself as active indefinitely, because nothing inside it knows the decision to replace it was ever made.
The only way to catch it is to look across tools at once. To line up what is still checking in against what should still be there, and flag the difference. That comparison is exactly what no single console can perform, which is why the waste survives quarter after quarter in stacks that otherwise look well run.
This is recoverable money, not a sunk cost
Here is the part that changes how you think about it. This is not spend you have to accept. It is money sitting inside a stack you already own, waiting to be found.
Cross-reference your connected tools against a time window, say 60 or 90 days, and ask a direct question. What is still checking in that has no business doing so? The seats that outlived an offboarding. The platform that survived a migration. Draw a line at, for example, day 91, and anything still reporting past it that should have been retired becomes a candidate to cut.
For a lot of MSPs the first pass alone recovers enough to pay for the effort several times over. This is not a one-time cleanup. Run the same comparison on a rhythm and the waste never gets the chance to accumulate again.
The client-facing upside
Recovered margin is the obvious win. The less obvious one is what this does for client trust.
Most QBRs are a mix of reassurance and upsell. A savings finding is neither. It is you walking into the room and handing the client money back, with a clear reason attached. You were paying for this, it was doing nothing, we turned it off. There is no spin to see through. It is the kind of moment that makes a client believe you are watching their spend as closely as their security, which is exactly the relationship that survives a budget review.
There is a security angle too. Every orphaned tool and stale license is one more thing in the environment that nobody is managing. Clearing them out does not just cut cost. It shrinks the surface area of things that can quietly break, get exploited, or muddy the picture when you are trying to see the stack clearly.
How Cork surfaces it
This is one of the places the cross-referencing approach pays off in plain dollars. Since Cork connects to the tools you already run and compares them against one another, it can surface savings opportunities directly. The licenses still checking in that map to no active need. The leftovers from offboarding and migration. The seats you are paying for and not using.
The output is not another report to interpret. It is a list of specific things you can act on, tied to specific clients, with the wasted spend attached. Some partners leveraging this today think of it less as a savings feature and more as a decommissioning tool, because that is what it does. It tells you what to turn off.
The audit worth running this quarter
You can start without any new tooling at all. Pick your three largest clients. For each, list every security tool you believe is active, then check it against what is actually checking in today. Look specifically for anything tied to a user who left or a platform you migrated away from.
Whatever you find is money you were spending for nothing, and now get back. Do it once and it is a nice recovery. Build it into how you run, and it becomes a permanent line of margin you were leaving on the table.
You cannot recover spend you cannot see. The good news is that seeing it is the hard part, and it is very findable.



