Comparison
InvGate Asset Management vs Reftab
Two tools districts shortlist for device tracking and IT operations, compared the way a buying committee actually reads them: what each is, what each does well, and what to check before signing. We build Chalk, a third option in this space — that context is worth knowing as you read, and it is why every claim below carries its basis.
InvGate Asset Management
A serious corporate ITAM platform with real discovery, a CMDB, and an on-premises option — priced per networked device, which is the worst possible meter for a 1:1 district.
Where InvGate Asset Management is strong
- Genuinely strong automated discovery — a lightweight agent, agentless network scanning, integrations, and bulk import covering hardware, servers, containers, databases, and cloud services.
- A real CMDB with automatic relationship discovery and assisted dependency mapping.
- A deep integration catalog: Intune, Jamf, SCCM, Active Directory, Entra ID, Okta, AWS, Azure, VMware, ServiceNow CMDB, Jira Service Management, Zendesk, Slack, Teams, and remote-access tools, plus a documented REST API.
- A genuine on-premises option on Windows Server or RHEL with your choice of database, including support for air-gapped operation — unusual in this category.
- Google Workspace integration that imports ChromeOS devices and users, so Chromebooks do land in the inventory automatically.
- Software asset management with license optimization, metering, deployment, and compliance.
What to check before you buy
Pricing is per networked device per year, so cost scales directly with fleet size. A district with one Chromebook per student is quoted on the single number it has most of, which is the opposite of a per-technician model.
Basis: InvGate's published pricing page prices Pro per IP device per year and defines an IP device as any asset connected to a network with an IP address.
Ticketing is a different product. InvGate Asset Management is ITAM only; a help desk means separately licensing InvGate Service Management, which is a second contract and a second bill.
Basis: InvGate sells Asset Management and Service Management as two separately licensed products and describes the ITAM platform as functioning standalone.
No SIS or rostering integration — no OneRoster, Clever, ClassLink, or PowerSchool. The identity sources in the integration catalog are corporate directories only.
Basis: InvGate's full published integration list names Active Directory, Entra ID, Okta, Google Workspace, and cloud platforms; no education system appears.
No student or guardian concepts. Asset owners are users and employees, with no enrollment, grade, guardian relationship, or reaction to a mid-year transfer.
Basis: The product's lifecycle and ownership model is employee framed; the vendor's named customers are manufacturing, utilities, aerospace, retail, and insurance.
No 1:1 device circulation loop — no due dates on a student's device, no overdue workflow, no e-signed parent agreement, no loaner pool, and no lost or stolen lifecycle. The lifecycle modelled is procurement, assignment, and disposal.
Basis: Absent from InvGate's asset lifecycle documentation, which is corporate IT framed.
No funding-source or grant tracking — no way to attribute devices to ESSER, Title, or E-Rate money for reporting.
Basis: No grant or funding-source dimension appears in the product documentation.
ChromeOS support is import only. Chromebooks and users come in from Google Workspace; nothing writes back — no OU moves, no disable, no annotated fields.
Basis: InvGate documents the Google Workspace integration as importing users, ChromeOS devices, and organizational data; no write-back is claimed.
It consumes SSO but is not an identity provider — Okta and Entra ID appear as identity sources it reads, not identity it issues.
Basis: InvGate is configured as a service provider against an external IdP; it is not listed as issuing SAML or OIDC.
Reftab
A well-designed asset tracker with a real free-forever tier, self-serve signup, and no sales call — and, like the rest of its class, no help desk, no roster, and no student.
Where Reftab is strong
- The only genuinely free-forever tier in this comparison, and a generous one — unlimited custom fields and locations, reservations with calendars, advanced reports with export, mobile apps, and barcode check-in/check-out at no cost.
- SSO and two-factor authentication at the lowest paid tier rather than gated to enterprise, which is unusual and district-friendly.
- Unlimited platform users on every tier, so the bill never grows because you added staff.
- Native iOS and Android apps with barcode scanning, plus a barcode designer and custom email templates.
- Strong MDM breadth at the top tier — Intune, Jamf Pro and Jamf School, Kandji, Mosyle, NinjaOne, FleetDM, and Apple Business Manager — plus vendor warranty sync from Dell, CDW, Lenovo, and Apple.
- A Google Workspace integration that imports Chromebooks and mobile devices daily, with configurable field mapping and optional auto-assignment to the Google-assigned user.
What to check before you buy
No native help desk or ticketing with SLAs. Jira Cloud and Zendesk connectors exist to surface assets on someone else's ticket, and they are top-tier features — so a district buys a service desk separately either way.
Basis: Reftab's integration listing offers Jira and Zendesk plugins rather than native ticketing; no SLA capability appears in any tier.
No SIS or rostering integration — no OneRoster, Clever, ClassLink, or PowerSchool — and no student, guardian, or family concepts. Nothing reacts to a transfer, a withdrawal, or grade rollover.
Basis: None appear in Reftab's integration catalog or documentation; the identity integrations are corporate directories.
Signature capture is staff-side custody acknowledgement, not a parent or guardian e-signature on a device agreement, and it sits behind a mid-tier upgrade.
Basis: Reftab lists signature capture as a Pro-tier feature; no guardian entity or agreement workflow exists in the data model.
No student fee assessment and no family balances, so damage recovered at collection time is tracked outside the system.
Basis: Absent from Reftab's documented feature set across all tiers.
No funding-source or grant tracking for ESSER, Title, or E-Rate attribution.
Basis: No funding-source dimension appears in Reftab's documentation.
ChromeOS support is import only and syncs once daily. Nothing writes back, so OU moves and disabling a stolen Chromebook remain manual work in Google Admin.
Basis: Reftab's Google Workspace integration guide documents a daily one-way import with field mapping; no write-back is described.
The MDM connectors that make the inventory self-maintaining — Intune, Jamf, Kandji, Mosyle, Apple Business Manager — are all top-tier features, which is a meaningful jump from the tier where SSO lives.
Basis: Reftab's pricing page places all MDM, vendor, and IdP integrations at the Business tier.
It consumes SSO but is not an identity provider. Okta, Entra ID, SAML 2.0, SCIM, and LDAP are identity it reads, not identity it issues — and the IdP user-provisioning integrations are top-tier only.
Basis: Reftab is configured as a service provider against an external IdP; provisioning integrations are listed at the Business tier.
The third option: Chalk
If you are weighing InvGate Asset Management against Reftab, Chalk belongs on the same shortlist. It is the open-source K-12 IT stack: device inventory that fills itself in from Google Admin, Intune, and Jamf against a roster synced from your SIS, a 1:1 circulation desk with agreements and fees, repairs with parts and costs, a help desk that already knows who is asking, and a built-in SAML/OIDC identity provider.
- Self-host it free forever under AGPL-3.0 — the entire feature set, one binary, your infrastructure — or use the hosted version, priced by fleet size with no per-seat or per-student fees and the price ladder published.
- Built only for K-12: students, buildings, custody, funding sources, and ChromeOS auto-update expiration are native concepts, not custom fields.
- Writes back to Google Admin as a reviewed diff — every OU move, disable, and deprovision previewed before it executes — and serves a OneRoster 1.1 API so other district systems can pull the roster from Chalk.
- Fees are assessed and tracked without touching payment cards, keeping the asset system out of your PCI scope.
See all three on your own roster.
Chalk installs to a populated inventory in about 30 minutes. Self-host free under AGPL-3.0, or let us run it — priced by fleet size, never per seat.