Rings instead of the whole fleet at once
Every ring has a soak time and an abort threshold. The next one only starts once the previous survived that time without too many failures — otherwise the rollout stops by itself.
Distribution with the brakes built in
Software distribution is the most powerful tool in client operations and the most dangerous: without a brake, a faulty package would reach the entire fleet within a single polling cycle. The module therefore places two brakes in front of every rollout — rings with soak time and an abort threshold, plus maintenance windows — and cleanly separates what the machine collects from what a human decides. The patch scan is read-only and runs as an ordinary job; it knows three states rather than two, because a device that was never surveyed is not clean, it is unknown. Delivery runs exclusively through the signed order channel, approved under the four-eyes principle.
Every ring has a soak time and an abort threshold. The next one only starts once the previous survived that time without too many failures — otherwise the rollout stops by itself.
Patched, gap known, never surveyed. The third state has a field of its own so a device that was never asked does not quietly count as clean.
The decision about an update is kept apart from the machine-collected catalog and is logged for audit — including the reason and the name behind it.
Approvals are evaluated when each order is built, not when the rollout is planned. An update withdrawn in the morning is gone from every running rollout minutes later.
Distribution that does nothing when in doubt: no approval means no order, no window means no execution, and too many failures stop the rollout by themselves.
Schedule a no-obligation demo – we will show you the module with your own use cases.