IT Asset Lifecycle and Secure Disposal
CompleteOverview
Owned hardware asset lifecycle across US and Canadian offices for roughly three years — refresh cycles, new-hire provisioning, termination returns, secure data destruction, and certified recycling — plus the recovery work when devices went unaccounted for.
Problem
Asset management fails quietly. Every unreturned laptop from a departed employee, every device that stops checking in, every machine sitting in a closet after a refresh is a data-bearing endpoint that inventory still believes is fine. The risk is not the hardware value; it is that a corporate-managed device with cached credentials and local data exists somewhere nobody can name.
Compounding it, disposal is not deletion. Retired hardware leaving the building without verified destruction moves the problem outside the perimeter rather than solving it.
Approach
Treated the lifecycle as a closed loop with an enforcement step at the end rather than a paperwork step.
Refresh and returns ran on a tracked cycle each fiscal year, with new-hire provisioning and termination asset returns as measured throughput rather than ad-hoc requests.
Recovery used management tooling instead of email chasing. For devices that were inactive or unaccounted for, I pushed remote lock through the Jamf Pro API rather than waiting on voluntary return — turning an open inventory item into a device that is useless to whoever holds it.
Destruction used BitRaser to DoD wipe standards before anything left custody, including a set of retired systems reviewed and wiped for donation to an internal research team.
Disposal ran through certified e-waste vendors with documented pickups, coordinated across offices, including cross-border trips to reach sites that had gone years without an on-site IT visit.
Architecture
Inventory of record in ServiceNow, device truth in Jamf. Discrepancies between the two — a device in inventory not checking into management — became the recovery worklist. Remote lock via the Jamf API served as the enforcement action for anything on that list that could not be physically recovered.
Outcome
Sustained throughput across three fiscal years: 209 new-hire systems provisioned and 232 termination asset returns processed, against annual refresh cycles.
86 inactive or missing devices across Canada and the US were remote-locked in a single sweep, closing a standing inventory gap.
Certified disposal moved 500+ end-of-life assets — laptops, towers, monitors, and AV equipment — across coordinated pickups, plus 20 systems globally wiped to DoD standard and redirected to an internal threat research team instead of being destroyed.
Lessons Learned
Inventory accuracy is not an administrative metric, it is a security control. The turning point was treating the gap between “ServiceNow says we own it” and “Jamf says it checked in” as an actionable queue with a technical enforcement action attached, rather than as a reconciliation chore. A device you cannot locate is a finding; a device you have locked is not.