Home/Platform/Patch & Compliance
Patch & compliance
Move your fleet forward. Verify each step of the rollout.
You declare what "current" means for enrolled machines. A small group goes first. Each target reports back and re-scans itself, and the number that moves is the one the machines produced — not the one the job wrote about itself. Then the next wave goes on your schedule, inside your window.
The wave
A gate opens because machines re-scanned. Not because a job finished.
This is the difference that matters and it is easy to miss. "Sent to 40 machines" is a dispatch statistic. "40 machines re-measured themselves against your baseline and 39 now meet it" is a result. Only the second one moves a gate here.
Baselines, rings and windows
You define "current". We measure against your definition.
A baseline is a named list of updates a machine has to have. Every enrolled machine reports what it actually has, and the gap between those two things is the only compliance number worth putting in front of a client.
Baselines, named
One list per group of machines, and different groups can hold different lines. The server that a clinic depends on at 8am does not have to live under the same rule as a spare workstation.
Windows that hold
Set the hours a machine may be touched. Outside that window nothing dispatches to it — the wave simply waits rather than deciding on your behalf that 2pm on a Tuesday is probably fine.
Reboots, on purpose
Whether a machine may restart itself is part of the rollout, not a surprise at the end of it. A pending reboot is a state the platform tracks and reports, because "patched but waiting to restart" is not the same as patched.
- Approval comes first. A named person signs off the rollout before the first machine, and that name is on the record.
- Each machine reports its own result back through its own tunnel, under its own signing key.
- Cancel is real. Stop a rollout and nothing further is dispatched — including machines that were queued for a later wave.
- Odd behaviour is flagged, not averaged away. A machine that keeps failing the same baseline is surfaced rather than absorbed into a percentage.
What "verified" means here
A patch on one machine is an operation like any other.
Patch is not a separate universe with its own weaker evidence. When one machine needs fixing now, it goes through the same six steps as a printer problem — and lands in the same kind of record.
Mature today: inventory collected from every enrolled machine, compliance measured against a baseline you declare, and rollouts you approve and dispatch in sized waves with a delay and a maintenance window. Still maturing: a wave stops when you stop it, so an automatic halt on a failed canary is something we are building rather than something you can buy — and a wave's evidence today is the compliance record recomputed per machine rather than a full receipt per machine. A single-machine remediation run as an operation already produces the whole record. We are joining those two up. We are not going to describe them as already joined.
What the client sees
A compliance number they can open.
The reason to measure patching this way is not internal tidiness. It is that at the end of the quarter you can hand a client a figure and then open the thing underneath it, machine by machine, without changing your story.
- Per machine, against your named baseline — what is missing, and when that machine last measured itself.
- Pending reboots counted separately, because "patched, waiting to restart" is a different sentence and a client can tell.
- The machines that keep failing surfaced by name, which is usually the conversation worth having.
- Exported under the client's branding, unmetered, alongside the quarter's operations.
The compliance figure is a count of what the machines reported. It is not an assessment against a regulatory framework, and we do not generate one — a control-framework report that fills itself in is exactly the thing that made us build this company.
The questions a technical buyer asks about this.
Is this a replacement for our patching tool?
We will not make that claim as a sweep, and you should be suspicious of anyone who does. Name the specific capability and we will tell you whether it ships, whether it is narrower than you assume, or whether it is not there. What we claim is the governance and the evidence around a rollout — approval, sized waves, a window, a per-machine result, and a compliance number that came from the machines.
What actually counts as compliant?
The machine's own scan compared against a baseline you named. Nothing else votes. If the scan is old, the record says when it was taken rather than implying it is current — a stale answer presented as fresh is worse than no answer.
What happens to a machine that is offline?
It stays pending. It is not marked done, not marked failed, and not quietly dropped from the denominator. When it comes back and re-scans, its number moves like every other machine's.
Can the AI run a rollout on its own?
Under standing authorization for a certified class of work, yes — and every step still leases its privilege, still runs without the model touching a credential, and still ends in a target-side confirmation. Autonomy changes when the human's say-so is recorded, never whether the work is proven. Commanded Autonomy →
What about the machines with no agent?
They cannot report a patch inventory, because there is nothing on them to report it. They appear in discovery and can be worked on through a brokered connection, but they do not carry a compliance number. See Devices & Discovery for exactly where that line sits.
Bring your worst rollout story
Watch a canary come back and a gate refuse to open.
Fifteen minutes, on a live system, including the part where something fails and the record says so.