A perpetual ULA never forces a reckoning, which means nothing reconciles your position unless you make it. Under a PULA, governance is not a nice to have. It is the entire discipline that keeps you safe and keeps your options open.
By Daniel Voss · Ex Oracle LMS · 4 June 2026
Governing a PULA means running continuous deployment control in place of the single certification snapshot a normal ULA produces. Keep a live inventory of where licensed products run, maintain an evidence file, control which products and environments you use, and watch scope boundaries such as the customer definition and territory. Because there is no exit event, this discipline is what protects you in an audit and preserves any future move to change structure. Govern it deliberately or it governs you.
A standard ULA has a built in moment of truth. At the term end you measure everything, certify a count, and produce a clean record of your position. That single event reconciles deployment to entitlement and gives you a documented baseline you can defend for years. A PULA has no such moment. It runs perpetually, so the reckoning never arrives on its own. Whatever clarity you want about your position, you have to create yourself, continuously, for as long as you hold the agreement.
That is why the instinct to relax under a PULA is exactly wrong. Unlimited deployment with no deadline can feel like permission to stop tracking, but the opposite is true. The unlimited right covers only the named products, only within the contractual scope, and only for the entities and territories the agreement defines. Everything outside those lines is exposure, and without a certification event nothing surfaces it until an audit does. Governance is the substitute for the reckoning a PULA removed.
You replace the one time certification snapshot with an ongoing programme that does the same work continuously: knowing what you have, proving it, controlling it, and watching the boundaries. Four disciplines carry the load.
Maintain a current record of where every licensed product is deployed, across production, test, disaster recovery, cloud, and virtualized environments. This is the equivalent of the measurement you would run at certification, except you run it continuously. A live inventory tells you whether your unlimited right is being used heavily, which informs whether the PULA still earns its cost, and it is the foundation for everything else. Without it you are guessing about your own estate, and guesses do not survive an audit.
Under a normal ULA the evidence file backs the certified count. Under a PULA it backs your position at any moment Oracle chooses to look. Keep server lists, tool output, virtualization topology, and methodology documentation current, so that at any point you can show what is deployed and demonstrate that it sits inside the licensed products and scope. Evidence assembled in advance is calm and complete. Evidence assembled during an audit is rushed and incomplete, which is the worst time for it to matter.
The unlimited right applies only to the products named in the PULA. Deploying a database option, a management pack, or a separate product not covered by the agreement creates a finite license requirement that the PULA does nothing to satisfy. Put a control in front of new deployments that checks whether the product is in scope before it goes live, so that an engineer enabling a feature does not quietly create exposure. The same applies to environments and to any feature that triggers separate licensing when switched on.
The customer definition, entity lists, and territory clauses define who and where the unlimited right covers. Corporate change is where these bite. A new acquisition deploying the licensed products may sit outside the customer definition, and a deployment in a territory the contract excludes is exposure even under unlimited rights. Because a PULA never ends, these boundaries have to be watched continuously and managed against every corporate event, not reviewed once at a term end that never comes.
Under a PULA, the absence of a deadline is not a relief, it is a risk. The discipline a normal ULA concentrates into one certification has to be spread evenly across every year you hold the agreement. Treat governance as the price of the permanence you bought, run it deliberately, and you keep both your audit safety and your freedom to change course later.
Yes. A PULA grants unlimited deployment of its named products, but it does not suspend Oracle's audit rights, and it does not cover anything outside its own scope. The audit questions simply shift. Rather than challenging your count, an audit under a PULA looks for products you are running that the agreement does not cover, features that trigger separate licensing, entities outside the customer definition, and territories outside scope. Each of those is a finding the unlimited right does not answer. The evidence file and the scope controls are the defense, and because there is no certification reconciliation, they carry the entire weight.
A workable PULA governance rhythm, indicative and adaptable to your contract, looks like this. Quarterly, refresh the deployment inventory and reconcile it against the licensed product list, flagging anything new that may sit outside scope. Twice a year, refresh the evidence file so it never goes stale. At every corporate event, a new entity, an acquisition, a divestiture, or a move into a new territory, run a scope check against the customer definition and territory clauses before the licensed products are deployed there. Annually, review whether the PULA still earns its cost given your actual deployment, because that review is the only way you will ever notice if the unlimited right has stopped paying for itself. The cadence matters less than the consistency. A PULA punishes the gaps.
A well governed PULA is also a PULA you can act on. If you later decide the permanence no longer serves you, any conversation with Oracle about changing structure starts from your documented position. The organisation that has tracked its deployment, kept its evidence, and controlled its scope can negotiate from facts. The organisation that has let governance lapse has no idea what it actually runs and negotiates blind. Governance is therefore not only audit defense, it is the thing that preserves your ability to move at all.
If you hold a PULA, treat governance as an active programme and start by understanding the structure you are in. Revisit why the missing exit matters in when a PULA is a trap, understand the routes available if you want to change structure in converting between ULA structures, and ground your programme in our PULA and capped ULA guide.
Book a ULA assessment and we will build the inventory, the evidence file, and the scope controls that keep a perpetual agreement safe and keep your options open.