Preparing a Fortify entitlement reconstruction
An audit finding is the vendor's account of what a buyer owes. An entitlement reconstruction is the buyer's account of what it actually holds and uses. When the two are placed side by side, the gap between them is where a Fortify finding falls. The reconstruction is not a defensive afterthought assembled once the finding arrives; it is the independent license position a buyer builds from its own records, and the single most important piece of work a buyer can do under audit. Preparing a Fortify entitlement reconstruction well is what turns a one sided measurement into a contest the buyer can win.
This article explains what a Fortify entitlement reconstruction is, what records it draws on, and how it disarms an inflated finding. It supports our Fortify and AppSec audit defense practice and links up to the complete OpenText audit defense playbook for 2026.
What an entitlement reconstruction is
An entitlement reconstruction is the buyer's effective license position, built independently against its contracts and the Additional License Authorizations before any vendor measurement script runs. It answers three questions in the buyer's own evidence: what the buyer is entitled to, how the products are actually used, and what the defensible gap between the two really is. Because the licensee carries sole responsibility for compliance under the terms, the buyer that arrives with a documented position is in a far stronger place than the buyer that waits to react to the vendor's number. The seat side of this work is set out in reconciling Fortify entitlements before an audit.
The reconstruction is built from the buyer's records, not the vendor's. Its authority comes from being verifiable against contracts, deployment data, and usage logs the buyer controls.
The records a Fortify reconstruction draws on
A complete Fortify reconstruction assembles several layers of evidence, each correcting a different inflation point in a finding:
- License entitlements and order history. Every purchase, the metric each was sold under, and whether the seats are perpetual or term, a distinction examined in Fortify perpetual versus term license positions.
- Scan history and submitter identity. The record of who actually submitted scans, which separates genuine consumers from repository readers, the core of the Fortify SCA seat overclaim between repository access and scan submitters.
- Environment mapping. Which scans ran in production versus test, staging, or CI, so non production activity is not swept into the production count.
- Service and integration accounts. The automated identities that should not be counted as human seats, drawn from CI pipeline service accounts counted as Fortify seats.
- Decommissioned projects and systems. Work that has been retired but may still appear in a finding, the subject of decommissioned Fortify projects still on the audit.
Building the reconstruction before the script runs
Timing is the difference between a reconstruction that controls the finding and one that merely responds to it. The defensible sequence is to build the position independently, before any vendor measurement tool touches the estate. A buyer that has already mapped its entitlements, scoped its environments, and identified its true scan submitters can read a vendor finding against a baseline rather than starting from the vendor's number and arguing downward. The seven day notice window makes early reconstruction urgent: the clock starts the moment the notice lands, and the buyer that uses that window to begin assembling records is the buyer that sets the terms of the measurement rather than reacting to them.
How the reconstruction reads against the finding
Once the reconstruction exists, the finding is no longer the only document in the room. Each line of the vendor's measurement can be checked against the buyer's evidence: a seat the finding counts is either matched to a documented submitter or challenged; a scan attributed to production is either confirmed against the environment map or moved to non production; an account treated as a human consumer is either a person or a service identity the buyer can name. The reconstruction converts an undifferentiated total into a line by line contest, and that is the contest the buyer wins. The method for working through it is set out in defending a Fortify developer seat finding line by line.
How the four Rs use the reconstruction
The reconstruction sits at the center of the method. In the respond stage the firm takes over first contact and the single controlled channel so that no estate data reaches the vendor before the position is built. In the reconstruct stage the firm assembles the entitlement and usage records and builds the effective license position independently. In the rebut stage the reconstruction becomes the evidence base for challenging every line of the finding on metric definition, environment, identity, and decommissioned scope. In the resolve stage the settlement is struck on the reconstructed figure and converted forward into a clean agreement with defined metrics. The reconstruction is the through line that holds all four stages together.
A representative outcome
In a recent engagement, a Fortify finding presented a developer seat count built from broad repository access and an undifferentiated scan total. Rather than argue the vendor's number down piece by piece, the buyer built an entitlement reconstruction first: it mapped its purchases, identified its actual scan submitters, scoped its environments, and listed its service accounts and retired projects. With that position in hand, the finding read as an overclaim against a documented baseline rather than as an authoritative measurement. The matter settled well below its opening figure, consistent with our E-02 case file, where a technology company brought a Fortify developer seat overclaim down by 80 percent.
The reconstruction discipline in one line
Build your own license position from your own records before the vendor builds theirs, and the finding becomes a document you check rather than a number you owe. That is what preparing a Fortify entitlement reconstruction delivers. For the evidence techniques that support it, see reducing a Fortify finding with commit and scan evidence, and to start your reconstruction with us you can open a case with our team.
Build your license position before the vendor builds theirs
We assemble entitlements, scan history, environment maps, and account records into an independent Fortify position that reads against the finding line by line. Open a case to begin.
Open a case →For the seat counting methodology at the heart of the reconstruction, read the Fortify seat counting white paper.
If an OpenText or Micro Focus audit notice has reached your desk, the first seven days carry more weight than any week that follows. OpenText Audit Defense is an independent, buyer side practice founded in 2020 by former vendor compliance leadership. We have defended more than 200 audits, brought the average finding down by 68 percent, and mitigated more than $90M in claims against vendor positions. We do not resell OpenText software and we are not affiliated with OpenText Corporation. To open a case, use the contact form on this site.