Update policy
Which updates you run yourself, which get scheduled together, and why the two are separated.
Two kinds of update
Updates within the running version. Security and bug fixes. Low risk, and yours to run from the interface whenever you like. We suggest off-peak hours, but you do not need anyone’s permission.
Moving to the next major version. This replaces core parts of the system. That button is deliberately held back for customers and handled with the support team in an agreed window.
Why they are separated
Major version moves are where unexpected trouble concentrates: changed defaults, configuration adjustments, reboots. Holding it back is not about trust. It is about making sure someone is standing by when a step misses.
Audit trail
Every update run from the interface is recorded in full: who, when, and the result. That record lives on your device, not on our servers, and can be collected for audits.
Networks with no outbound internet
The device can pull updates from a local mirror inside your own network. This exists for sites with strict egress policy or expensive links. Raise it during the assessment so the mirror is part of the design.