Patch management
Two patch surfaces, one workflow: Windows Update for the OS and winget for everyday third-party apps, both on per-client schedules with approval control.
Windows Update
Agents inventory available Windows updates continuously, so every device shows its patch debt. You can approve and install ad hoc from a device page, or, the intended mode, set a per-client schedule: pick the day and hour, and Helios auto-approves and installs on that slot. If a device is off during its window, the scheduler catches up rather than skipping the day.
Third-party patching
Windows machines also report outdated everyday software through winget (browsers, runtimes, tools). The Patches area shows OS and third-party updates side by side, and third-party updates install through the same one-click and scheduled flows.
Compliance visibility
Patch state feeds each device's health score and the client rollups, so an unpatched fleet surfaces on the dashboard without anyone running a report. Patch activity also lands in the ticket trail when installs are scheduled, so there is an audit line for what changed and when.
Rules and holds
Before an update goes out to twenty machines, the Patches page shows what it did on the ones that already tried it: how many installed it and how many are sitting on a failed install. That record comes from your own estate, not a vendor's rating.
Two standing rules sit above the schedule. Block an update everywhere, by KB or by a phrase in its title, from the most-missed list or from a failed install, and the schedule and the vulnerability fix leave it alone on every device until you unblock it. Hold every newly seen update for 3, 7 or 14 days after Helios first sees it, so a Tuesday release has time to go wrong somewhere else first. A technician approving a patch by hand on one device is an explicit decision and is always honoured.
Reboots
Pending reboots are a monitored signal with their own alert rule. Devices that finished installing but still need a restart are visible rather than silently half-patched, and a reboot can be triggered remotely from the device page.
Linux has a middle state Windows doesn't: upgrades can leave services running on outdated libraries without needing a full reboot. Helios shows these as a "services need restart" chip on the device, listing the affected units, and restarts just those services with one click, with no downtime and no reboot. Only services the agent itself reported can be restarted this way.
Linux and macOS report inventory and update state through their agents; scheduled patching is deepest on Windows today, which is stated here so you are not surprised. The roadmap reflects what is being extended next.