---
title: "How Agencies Should Inventory Plugin Licences"
date: 2026-06-22
author: "Imtiaz Rayhan"
featured_image: "https://wpblocksuite.com/wp-content/uploads/2026/08/featured-agency-plugin-licence-inventory.png"
categories:
  - name: "WordPress Plugins"
    url: "/blog/category/wordpress-plugins.md"
---

# How Agencies Should Inventory Plugin Licences

An agency plugin licence inventory links commercial entitlements to clients and sites. It also links vendors, plans, owners, renewals, and evidence.

Keep one authoritative register. Reconcile it against actual sites and vendor portals after every material change.

## What is an agency plugin licence inventory?

It records what the agency can use and where. It also identifies the client and commercial terms.

It answers ownership and capacity questions without searching inboxes. It also supports renewals, handoffs, incidents, and audits.

## Inventory entitlement, not only keys

Some vendors use keys. Others use subscriptions, account connections, site tokens, memberships, or hosting entitlements.

Model the commercial right and its controls. Treat any raw credential as a separate protected secret.

## Use two linked inventories

- A site inventory describes WordPress environments and owners.
- An entitlement inventory describes commercial products and rights.
- An assignment record links one entitlement to one site.

This separation handles one licence covering many sites. It also handles one site using many licences.

## Give every record a stable identifier

Client names, domains, products, and vendors can change. Stable internal identifiers preserve history across those changes.

Never use the current domain as the only site identity. Migrations would create duplicates.

## Define the entitlement record

- Internal entitlement identifier.
- Vendor and exact product.
- Marketplace or purchasing channel.
- Plan, tier, bundle, and term.
- Purchase date and order reference.
- Commercial owner and billing owner.
- Vendor account and recovery owner.
- Renewal, expiry, and review dates.
- Site allowance and environment treatment.
- Support, download, and update rights.
- Transfer, sharing, and cancellation rules.
- Current lifecycle status.

Link official vendor records rather than copying volatile text. Store dated evidence for unusual exceptions.

## Define the site record

- Internal site identifier.
- Client and accountable site owner.
- Canonical production URL.
- Staging and development URLs.
- Hosting provider and environment type.
- WordPress and PHP versions.
- Multisite network and subsite scope.
- Maintenance plan and service status.
- Technical owner and backup owner.
- Launch, migration, archive, or closure state.

Keep personal data proportionate. The inventory needs accountability, not a complete customer database.

## Define the assignment record

- Entitlement identifier.
- Site identifier and exact environment.
- Vendor-recorded site identity.
- Activation or connection date.
- Current local status.
- Whether paid capacity is consumed.
- Purpose and approving owner.
- Last verification date.
- Expected removal or review date.
- Final deactivation evidence.

An assignment is the operational bridge. Without it, [site limits](https://wpblocksuite.com/blog/exceed-wordpress-plugin-site-limit/) and client ownership remain guesses.

## Define controlled vocabularies

Use agreed values for lifecycle state, environment, ownership, and review outcome. Free text creates inconsistent reports.

- Active and required.
- Active but under review.
- Dormant with a named reason.
- Pending transfer or cancellation.
- Expired but installed.
- Cancelled and awaiting closure.
- Closed with retained evidence.
- Unknown and assigned for investigation.

## Separate commercial and technical states

A plugin can be installed while its subscription expired. A valid entitlement can have no current site assignment.

Store purchase, renewal, installation, WordPress activation, vendor activation, and support status separately.

## Separate ownership roles

- Commercial owner approves entitlement decisions.
- Billing owner approves and reconciles charges.
- Account owner controls vendor access.
- Technical owner manages deployment.
- Client owner confirms business need.
- Security owner handles exposure incidents.
- Backup owner preserves continuity.

One person may hold several roles. Record the roles anyway because responsibilities can later separate.

## Distinguish agency-owned and client-owned licences

Agency-owned entitlement can support a service portfolio. Client-owned entitlement should remain recoverable without agency credentials.

Label the owner explicitly. Never infer ownership from who installed the plugin.

## Record service-agreement dependency

Some client sites receive entitlement only during maintenance service. Record the contract, included products, and exit consequence. The full walkthrough is in [the paid plugin handoff checklist](https://wpblocksuite.com/blog/paid-plugin-handoff-client-sites/).

This field prevents accidental promises of permanent access. It also supports clean offboarding estimates.

## Record hosting-included entitlement

A host may bundle premium plugins or services. The right can disappear when the site migrates.

Record provider dependency, replacement cost, and portability. Do not count included access as agency-owned inventory.

## Record bundles at two levels

The commercial record describes the bundle. Component records show which included plugins each site actually uses. We wrote that up in [the block-category gap audit](https://wpblocksuite.com/blog/block-category-gap-audit/).

Link components to their shared renewal. This exposes [shelfware](https://wpblocksuite.com/blog/plugin-bundle-shelfware/) and prevents accidental partial cancellation.

## Record add-on dependencies

A paid add-on may require a free or paid parent. Store the dependency and supported version relationship.

The WordPress plugin header supports a Requires Plugins field for WordPress.org dependencies. Commercial relationships may remain undocumented. The mechanics are in [how to build an annual WordPress plugin budget](https://wpblocksuite.com/blog/annual-wordpress-plugin-budget/).

## Record multisite scope explicitly

One installation can contain many subsites. Vendors may count networks, subsites, or mapped domains differently.

Store network identity, activated subsites, and vendor counting evidence. Avoid one-installation assumptions.

## Record non-production environments

Mark local, development, staging, preview, demonstration, and archived sites. State whether each consumes paid capacity.

Vendor detection can differ from your label. Save portal evidence for recognised exemptions.

## Discover installed plugins consistently

Collect plugin names, slugs, versions, states, updates, and [auto-update](https://wpblocksuite.com/blog/which-wordpress-plugins-auto-update/) settings. Include inactive and must-use components.

The official [WP-CLI plugin list command](https://developer.wordpress.org/cli/commands/plugin/list/) can return structured fields. Use authorised site access and protect exports.

## Do not treat automated discovery as commercial truth

Site scans show installed code. They may not reveal vendor account, billing, transfer rights, or actual owner.

Join technical discovery with invoices, portals, contracts, and accountable interviews. Resolve every mismatch.

## Discover purchases from approved systems

- Vendor and marketplace accounts.
- Finance and expense records.
- Organisation-controlled email archives.
- Password and secret management systems.
- Client contracts and project records.
- Hosting and maintenance plans.
- Support ticket histories.
- Previous licence inventories.

Search narrowly and lawfully. Do not copy passwords, card data, or unrelated client information.

## Reconcile from sites to entitlements

For each installed paid plugin, find its valid commercial record. Investigate missing, expired, duplicated, or unknown coverage.

Record the resolution and owner. Never mark covered based only on an accepted key message.

## Reconcile from entitlements to sites

For each purchase, map every vendor-listed site to an internal site. Investigate stale or unfamiliar identities.

This reverse check finds deleted environments and unused purchases. It also exposes unauthorised reuse.

## WooCommerce recommends independent agency records

Its [agency documentation](https://woocommerce.com/document/managing-woocommerce-com-subscriptions/managing-subscriptions-as-a-developer-or-agency/) recommends mapping subscription keys to client sites. The vendor portal alone may not capture agency context.

Apply that principle across vendors. Keep your common inventory independent from one marketplace.

## Resolve renamed and migrated sites

Preserve former domains as aliases on the stable site record. Do not create another client site blindly.

Map old portal identities to the migration event. Deactivate them only after verified retirement.

## Resolve duplicate purchases

Two teams can buy the same product for one client. Confirm ownership, refund status, and future need.

Consolidate only through vendor-supported controls. Preserve separate purchases when ownership boundaries require them.

## Resolve unknown vendor accounts

A former employee or contractor may control purchasing. Use invoices and approved recovery routes to restore ownership.

Do not create another account immediately. Duplicate account history can complicate transfers and support.

## Record uncertainty instead of inventing data

Use an unresolved state, accountable investigator, and deadline. Distinguish missing evidence from confirmed absence.

Prioritise uncertainty affecting production updates, security, billing, or client ownership. Close each finding with evidence.

## Keep raw secrets outside the inventory

Most inventory users need owner, status, and site mappings. They do not need the [licence key](https://wpblocksuite.com/blog/wordpress-plugin-licence-key-management/).

Link to controlled secret storage when necessary. Avoid secret values in exports, tickets, and dashboards.

## Control inventory permissions

- Readers see assigned clients and operational status.
- Editors maintain approved records.
- Commercial owners approve purchase changes.
- Finance users access billing evidence.
- Security owners handle exposure records.
- Administrators manage structure and access.

Review access after staffing and client changes. Keep named accounts and an independent recovery path.

## Design useful views

- Entitlements renewing soon.
- Sites lacking confirmed coverage.
- Assignments with unknown owners.
- Plans near their site allowance.
- Expired entitlement on active sites.
- Clients approaching handoff.
- Unused purchases still billing.
- Accounts lacking backup recovery.
- Bundles with low component use.
- Records overdue for verification.

Views should drive owned work. A colourful dashboard without resolution workflows becomes decoration.

## Track cost without turning inventory into accounting

Store current charge, currency, tax treatment, billing cycle, and cost allocation. Link the authoritative invoice.

Finance systems remain the accounting source. The inventory explains operational purpose and site allocation.

## Allocate shared costs transparently

Agency bundles can cover several clients. Record the approved allocation method and excluded internal use.

Do not imply that allocation creates client ownership. Commercial ownership remains its own field.

## Use event-driven updates

- A plugin is purchased or refunded.
- A site launches or closes.
- A domain or host changes.
- An entitlement renews or expires.
- A plan upgrades or downgrades.
- A client service begins or ends.
- An account owner changes.
- A transfer or sharing event completes.
- A plugin is installed or removed.
- A vendor changes its licensing model.

Calendar reviews cannot repair delayed event capture. Make inventory updates part of each operational workflow.

## Set a reconciliation cadence

Review high-risk and high-value entitlements more often. Review stable low-risk records proportionately.

Always reconcile after migrations, acquisitions, staff departures, client exits, and account incidents.

## Measure inventory quality

- Entitlements with named commercial owners.
- Assignments mapped to known sites.
- Sites with confirmed commercial coverage.
- Renewals with recorded decisions.
- Unknown portal identities.
- Overdue verification records.
- Former staff retaining account access.
- Active sites using expired entitlement.
- Time required to recover vendor access.
- Age of the oldest unresolved mismatch.

Use measures to target work, not punish reporting. Hidden problems grow when teams fear recording uncertainty.

## Keep the tool proportional

A controlled spreadsheet can serve a small portfolio. A larger agency may need relational data and automation.

Tool complexity does not create truth. Ownership, evidence, access control, and reconciliation create useful inventory.

## Plan export and continuity

The inventory must survive one platform or administrator becoming unavailable. Test protected export and restoration.

Document field definitions and relationships. Avoid proprietary structures nobody can interpret outside the tool.

## Validate bulk imports before trusting them

Imported vendor and finance data can contain duplicates, old names, and incomplete identifiers. Test mappings on a small sample.

Quarantine rejected rows for review. Never overwrite verified ownership with weaker imported data automatically.

## Keep a record-level change history

Important ownership, allowance, renewal, and assignment changes need accountable timestamps. Preserve the previous value and approved reason.

Exclude secrets from history. Correct errors through traceable amendments instead of silent deletion.

## Review vendor mergers and product renaming

Acquisitions can move accounts, support routes, and product names. Keep former identifiers as searchable aliases.

Verify entitlement continuity before replacing links. Record any changed terms, migration deadlines, or required owner action.

## Document the inventory data owner

Assign responsibility for definitions, access, backups, integrations, and quality review. A shared register still needs one accountable steward.

## Close records without deleting history

A cancelled entitlement needs final billing, assignment, access, and evidence states. Keep required historical records.

Remove secrets and unnecessary client data. Apply approved retention and deletion schedules.

## Know the honest weak case

A spreadsheet can remain sufficient for a small controlled portfolio. Database software is not an automatic improvement.

Move tools when relationships, permissions, or reporting exceed the spreadsheet. Preserve the same evidence model.

## Use the agency licence inventory checklist

1. Create stable site and entitlement identifiers.
2. Define controlled states and ownership roles.
3. Build entitlement, site, and assignment records.
4. Inventory agency, client, and hosting ownership.
5. Capture plans, terms, allowances, and renewals.
6. Map bundles, add-ons, and dependencies.
7. Discover installed plugins from every site.
8. Discover purchases from approved systems.
9. Reconcile sites to commercial entitlements.
10. Reconcile vendor portals to known sites.
11. Investigate unknown and duplicate records.
12. Keep raw secrets in controlled storage.
13. Limit inventory access by role.
14. Create actionable portfolio views.
15. Update records during lifecycle events.
16. Review high-risk records proportionately.
17. Measure completeness and unresolved drift.
18. Test export and recovery.
19. Close records with retained evidence.

## Frequently asked questions

What should an agency plugin licence inventory contain?



 

Track products, owners, accounts, plans, sites, assignments, renewals, dependencies, costs, status, and evidence.



 

Should the inventory contain raw licence keys?



 

Usually not. Keep secrets in controlled storage and inventory only approved references.



 

Can a spreadsheet manage plugin licences?



 

Yes, when access, ownership, relationships, reviews, and recovery remain manageable.



 

How should agencies find installed plugin versions?



 

Use authorised site management or structured WP-CLI discovery, then reconcile commercial records.



 

How often should the licence inventory be reconciled?



 

Review proportionately and after purchases, migrations, renewals, staff changes, or client exits.



 



## The verdict

Verdict

**Model the relationships:** connect entitlements, sites, clients, owners, plans, costs, and dependencies. **Keep it true:** reconcile actual installations and vendor portals after every material lifecycle event.

A trustworthy inventory makes every commercial plugin explainable. [Review WP Block Suite’s $299 lifetime licence](https://wpblocksuite.com/#pricing).