Operate
Patch management
Two patch surfaces, one workflow: Windows Update for the OS and winget for everyday third-party apps, both on per-client schedules with approval control.
Windows Update
Agents inventory available Windows updates continuously, so every device shows its patch debt. You can approve and install ad hoc from a device page, or, the intended mode, set a per-client schedule: pick the day and hour, and Helios auto-approves and installs on that slot. If a device is off during its window, the scheduler catches up rather than skipping the day.
Third-party patching
Windows machines also report outdated everyday software through winget (browsers, runtimes, tools). The Patches area shows OS and third-party updates side by side, and third-party updates install through the same one-click and scheduled flows.
Compliance visibility
Patch state feeds each device's health score and the client rollups, so an unpatched fleet surfaces on the dashboard without anyone running a report. Patch activity also lands in the ticket trail when installs are scheduled, so there is an audit line for what changed and when.
Reboots
Pending reboots are a monitored signal with their own alert rule. Devices that finished installing but still need a restart are visible rather than silently half-patched, and a reboot can be triggered remotely from the device page.
Linux and macOS report inventory and update state through their agents; scheduled patching is deepest on Windows today, which is stated here so you are not surprised. The roadmap reflects what is being extended next.