| name | windows-patch-management |
| description | Use when discovering or planning Windows updates, servicing, installed software, maintenance windows, patch rings, failure handling, or reboot readiness; use windows-health-assessment for health-only checks. |
| metadata | {"portable":true,"compatible_with":["claude-code","codex"]} |
Windows Patch Management
Use when
- Inventory update/build/pending-reboot state and ownership.
- Plan download, install, reboot, validation, rollback, or fleet rings.
- Diagnose a failed servicing or application update.
Do not use when
- The request implies an unapproved production reboot.
- An application owner or endpoint management plane is unknown.
Inputs
Target/role, update source and owner, maintenance window, approval ring,
dependencies, reboot policy, workload health oracle, rollback boundary, and SLA.
Platform and privilege boundary
Discovery is R0. Install is R2; remote-access or security-agent changes may be
R3/R4. Executable mutation is NOT_ASSESSED in 0.1.
Workflow
- Capture OS/build, source, update history/failures, servicing and reboot state.
- Classify OS, quality, security, feature, driver, firmware, and application updates.
- Detect Intune/WUfB/ConfigMgr/Arc/local/vendor ownership.
- Define canary, prechecks, install, explicit reboot, readiness, observation,
failure threshold, and rollback/escalation.
- Preserve per-host outcomes and verify the workload after reboot.
Mutation, verification, and recovery
Never reboot implicitly. Recovery distinguishes uninstall/rollback, restore,
known-issue mitigation, and roll-forward. Verify boot plus user-visible workload.