PlatformDelivery BoardAutomation & RunbooksOutcome ReceiptsJust-in-Time ElevationCredential VaultGoverned SessionsDevices & DiscoveryPatch ManagementReporting & ExportsRoles & Multi-Tenancy
Verified AI OperationsThe Operation LoopCommanded AutonomyCompare the operating modelThe Verified Operation Spec
SolutionsFor MSPsFor Enterprise & Internal ITHealthcareLegalFinancial servicesMunicipal & Education
ProofOperation walkthroughSecurity & architectureVerified Operation SpecFive questions for your RMM's AIChangelog
CompanyAboutFounder's noteContact
PricingBuy 1–20 technician licenses onlinePlans — from $499 per monthCustom requirementsFoundation Circle
Log in

Home/Platform/Patch & Compliance

Patch & compliance

Move your fleet forward. Verify each step of the rollout.

You declare what "current" means for enrolled machines. A small group goes first. Each target reports back and re-scans itself, and the number that moves is the one the machines produced — not the one the job wrote about itself. Then the next wave goes on your schedule, inside your window.

What a rollout is made of
baselineThe updates a machine must have to count as current. You declare it.
wave sizeHow many machines go at once. The first group is the one you can afford to lose.
delayHow long the platform waits before the next wave is eligible.
windowThe hours a machine may be touched at all. Outside it, nothing dispatches.
approvalA named person, before the first machine — not after the third one broke.
stopCancel at any point. Nothing further is dispatched.

The wave

A gate opens because machines re-scanned. Not because a job finished.

This is the difference that matters and it is easy to miss. "Sent to 40 machines" is a dispatch statistic. "40 machines re-measured themselves against your baseline and 39 now meet it" is a result. Only the second one moves a gate here.

How a rollout advancescanary first
EVERY GATE OPENS ON THE SAME THING — THE MACHINES' OWN NEXT SCAN CANARY 2 machines the ones you pick WAVE ONE 10 machines same baseline WAVE TWO 40 machines same gate again THE REST everything left inside your window MACHINES RE-SCAN compliance recomputed MACHINES RE-SCAN compliance recomputed MACHINES RE-SCAN compliance recomputed WHEN THE CANARY COMES BACK FAILED CANARY 2 of 2 failed reported by the machines WAVE ONE · WAVE TWO · THE REST the failure is counted on the rollout itself, not buried in a job log you stop it, and nothing further is dispatched NOTHING GOES OUT Today that stop is a decision you make, not an automatic halt. It belongs on the diagram, not in the small print.
The canary is not a formality. It is the group you have decided you can afford to have broken, chosen deliberately, and the first honest number in a rollout comes from it. A wave that advances on elapsed time alone is a schedule, not a gate — which is why the last line of this picture is on the picture.

Baselines, rings and windows

You define "current". We measure against your definition.

A baseline is a named list of updates a machine has to have. Every enrolled machine reports what it actually has, and the gap between those two things is the only compliance number worth putting in front of a client.

Baselines, named

One list per group of machines, and different groups can hold different lines. The server that a clinic depends on at 8am does not have to live under the same rule as a spare workstation.

Windows that hold

Set the hours a machine may be touched. Outside that window nothing dispatches to it — the wave simply waits rather than deciding on your behalf that 2pm on a Tuesday is probably fine.

Reboots, on purpose

Whether a machine may restart itself is part of the rollout, not a surprise at the end of it. A pending reboot is a state the platform tracks and reports, because "patched but waiting to restart" is not the same as patched.

  • Approval comes first. A named person signs off the rollout before the first machine, and that name is on the record.
  • Each machine reports its own result back through its own tunnel, under its own signing key.
  • Cancel is real. Stop a rollout and nothing further is dispatched — including machines that were queued for a later wave.
  • Odd behaviour is flagged, not averaged away. A machine that keeps failing the same baseline is surfaced rather than absorbed into a percentage.

What "verified" means here

A patch on one machine is an operation like any other.

Patch is not a separate universe with its own weaker evidence. When one machine needs fixing now, it goes through the same six steps as a printer problem — and lands in the same kind of record.

One machine, one operationOP-000241
01 QUALIFY the outcome is "this machine meets your July baseline" — not "run this installer" 02 APPROVE policy allows the patch class, and Marcus puts his name on this particular one 03 LEASE admin on SRV-ACCT-02 for twelve minutes, revoked by the clock, not by finishing 04 RUN BLIND a signed job installs what is missing — the model never held the credential 05 PROVE the machine re-scans itself and answers the question: baseline met 06 SEAL OP-000241, locked, carrying the undo that was written down beforehand THE RECORD What lands in it is the machine's own answer to a fresh check — not the installer's exit code, and not what the job said about itself.
Step five is the one nobody else does. An installer exit code tells you a process ended; a re-scan tells you the machine now holds the updates your baseline names. Only the second answer is allowed into the record.
Inventory & baselines Compliance from the machine's own scan Approved wave rollouts Automatic halt on a failed canary A receipt for every machine in a wave

Mature today: inventory collected from every enrolled machine, compliance measured against a baseline you declare, and rollouts you approve and dispatch in sized waves with a delay and a maintenance window. Still maturing: a wave stops when you stop it, so an automatic halt on a failed canary is something we are building rather than something you can buy — and a wave's evidence today is the compliance record recomputed per machine rather than a full receipt per machine. A single-machine remediation run as an operation already produces the whole record. We are joining those two up. We are not going to describe them as already joined.

What the client sees

A compliance number they can open.

The reason to measure patching this way is not internal tidiness. It is that at the end of the quarter you can hand a client a figure and then open the thing underneath it, machine by machine, without changing your story.

  • Per machine, against your named baseline — what is missing, and when that machine last measured itself.
  • Pending reboots counted separately, because "patched, waiting to restart" is a different sentence and a client can tell.
  • The machines that keep failing surfaced by name, which is usually the conversation worth having.
  • Exported under the client's branding, unmetered, alongside the quarter's operations.

The compliance figure is a count of what the machines reported. It is not an assessment against a regulatory framework, and we do not generate one — a control-framework report that fills itself in is exactly the thing that made us build this company.

Why it survives a challenge When a client asks "how do you know these are patched?", the answer is not a dashboard. It is: each of those machines measured itself against the list you approved, and here is the record of when. That answer does not get weaker under questioning, which is the only property a compliance number really needs. Reporting & exports →

The questions a technical buyer asks about this.

Is this a replacement for our patching tool?

We will not make that claim as a sweep, and you should be suspicious of anyone who does. Name the specific capability and we will tell you whether it ships, whether it is narrower than you assume, or whether it is not there. What we claim is the governance and the evidence around a rollout — approval, sized waves, a window, a per-machine result, and a compliance number that came from the machines.

What actually counts as compliant?

The machine's own scan compared against a baseline you named. Nothing else votes. If the scan is old, the record says when it was taken rather than implying it is current — a stale answer presented as fresh is worse than no answer.

What happens to a machine that is offline?

It stays pending. It is not marked done, not marked failed, and not quietly dropped from the denominator. When it comes back and re-scans, its number moves like every other machine's.

Can the AI run a rollout on its own?

Under standing authorization for a certified class of work, yes — and every step still leases its privilege, still runs without the model touching a credential, and still ends in a target-side confirmation. Autonomy changes when the human's say-so is recorded, never whether the work is proven. Commanded Autonomy →

What about the machines with no agent?

They cannot report a patch inventory, because there is nothing on them to report it. They appear in discovery and can be worked on through a brokered connection, but they do not carry a compliance number. See Devices & Discovery for exactly where that line sits.

Bring your worst rollout story

Watch a canary come back and a gate refuse to open.

Fifteen minutes, on a live system, including the part where something fails and the record says so.