ProductsWindows patch management
ArcPatchCore
Inventory, planning + verification · Private product
A Windows patch-management system built around trustworthy inventory, normalized update candidates, explicit planning, and visible safety boundaries before anything is allowed to change a machine.
Private workspace · explore the interface and workflow below.
Inside the product
How it works
Scan Windows updates, installed applications, Office, execution context, and restart state.
Review each provider result. Unknown, unsupported, and blocked are distinct from eligible updates.
Build a patch plan under the operator’s policy; the pictured milestone is scan-only.
The apply architecture requires authorized execution and post-update verification before reporting success.
What it solves
Patch tools fail when detection, eligibility, execution, and verification are treated as one button. The product has to distinguish what is installed, what is applicable, what is blocked, what is unknown, and what can actually be changed safely under the current execution context.
Capabilities
- Windows, application, Microsoft 365, reboot, execution-context, and software inventory evidence
- Deterministic normalization and patch planning shared by CLI and desktop UI
- Explicit blocked, current, available, partial, and failed source states
- A verification-first execution architecture being hardened for privileged service, installer, and endpoint workflows
Where it gets hard
- Different update providers expose different truth and failure modes
- SYSTEM, interactive users, policy, WSUS, application scope, and loaded user hives change what can be seen
- A successful provider call does not prove the software ended at the intended version
- Trust, authorization, reboot policy, locking, and post-patch verification have to remain explicit
In the loop
The core planner does not need AI to decide patch state. Research and automation can accelerate provider work, but execution stays behind deterministic eligibility and verification rules.
An operator remains responsible for the plan, execution policy, exceptions, and what is allowed to run on a managed endpoint.
Actual product interfaces. Captions identify local previews and sample data. Screenshots do not expose private workspaces or production records.