v1.0 — 1 Jun 2026 Q3 2026 Q4 2026 Q1 2027 Q2 2027 Not planned

What PatchPilot is building next

Every major feature gap has a release window. We publish this publicly so you can plan around it — not discover it at procurement.

Honest caveat: All dates are best-current-estimates. Customer commitments move things earlier; hiring phases shift density. Tell us what you need at the waitlist.

Beta 15 Jun 2026 v1.0 — Beta opens 15th June 2026 · GA follows

Everything below is built, tested, and deployment-ready. Beta access opens 15th June 2026 — we're using the extra fortnight to polish the final round of features (expanded compliance evidence packs, deeper posture telemetry on the C# agent). General availability follows beta feedback. Windows + Linux agents proven end-to-end on live VMs.

Endpoint Management
Ring-based patch deployment + auto-ramp
Automatic rollback on failure
Software request approval workflow
Self-update flow (signed MSI + SHA-256)
Network device discovery (LAN unmanaged)
Network topology graph
Configuration profiles
Configuration backup
Drift detection (config + baseline)
VSS shadow-copy snapshot + restore
Golden-image management
Custom fields per device
Remote Access
Browser-based remote desktop
Shadow + consent mode (Mode A)
Connect-as-AD/Entra-user (Mode B)
Sterile audit user mode (Mode C)
Browser-based remote terminal (PS + SSH)
Per-connection step-up MFA
Target-side consent prompts
Session recording (tamper-evident)
File transfer (technician ↔ target)
System Management
Windows services management
Remote process management
Event log retrieval
Power management (shutdown/restart/wake)
Registry management (read/write)
Bulk actions across devices
Security & Detection
CVE + KEV vulnerability scanning
Defender management + ATP status
Attack Surface Reduction (ASR) rules
Ransomware tripwire (canary-based)
BitLocker key escrow (step-up reveal)
Compliance
6-framework compliance evidence packs
CE Plus / ISO 27001 / SOC 2 / HIPAA / PCI / CISA BOD
PDF evidence export (white-labelled)
Tamper-evident audit log + export
SIEM export (CEF / LEEF / JSON)
Cyber insurance readiness report
Identity
SSO (Azure AD / Entra ID / Okta)
Microsoft Graph integration (Intune sync + CA policy)
Entra ID disable / enable / revoke sessions
Per-org encrypted credentials store
Backup & Storage
BYO storage (B2 / S3 / Wasabi / R2 / Azure / GCS)
AES-256-GCM encryption at rest
Device file/folder backup scheduler
System backup (control plane, verified restore)
Helpdesk Integrations
Bidirectional webhook integration (Jira)
Bidirectional webhook integration (Zendesk)
Bidirectional webhook integration (HubSpot)
Outbound: alert / drift / SLA breach → ticket
Inbound: ticket update → device action
HMAC-signed webhooks, per-integration tokens
MSP-specific
Multi-tenant child-org architecture
White-label (dashboard, logo, colours, reports)
Per-org branded installer (.exe / .msi)
QBR PDF generator (branded, schedulable)
Scheduled reports (PDF/CSV)
Per-client cost tracking + roll-up
Operations
Notifications (dashboard + email + webhook)
Team invitations + role management
Enrollment tokens (rate-limited, revocable, with expiry + usage limits)
Software metering (launch / dormant tracking)
7-step onboarding wizard + delegation
Waitlist signup + invite codes
Wave-D (pulled forward from v1.1 — May 2026)
SAML 2.0 + OIDC SSO (per-org, JIT provisioning, Entra/Okta/Google)
CISA KEV overlay + "Actively Exploited" badge (1,592 entries synced)
HIPAA + PCI DSS 4.0 + CISA BOD compliance packs (4 → 7 frameworks)
Warranty tracking — Dell TechDirect / HP iSEE / Lenovo APIs
AI vulnerability triage (Bedrock + Anthropic + on-prem Ollama)
Auto-rollback on patch-deploy health-check failure (self-healing patch)
macOS Agent v1 (.NET 8 native + .pkg / .tar.gz, build-verified)
VM Host scaffold (Hyper-V / libvirt / VirtualBox / VMware tracking — agent handlers v1.1)
Post-signin MFA setup wizard + role-aware sidebar

Q3 2026 Removing the "but you don't have X" objections

First 3 months post-launch. Focus: close the macOS gap, complete mobile inventory, extend the compliance library, and add full SNMP network visibility.

macOS Agent v1 — SHIPPED (build-verified)

Shipped v1.0

Native macOS agent on the same .NET 8 codebase as Windows/Linux. .pkg + .tar.gz for x64 + arm64. Build-verified — install verification rolls into a v1.0.x patch when Apple notarization is set up. Signed/notarized .pkg is the only remaining v1.1 work.

Competes with: NinjaOne macOS, Atera macOS, Jamf Pro

VM Host Lifecycle Control (agent handlers)

Q3 2026

Mark devices as VM hosts; manage their guests directly from the dashboard: pause, resume, shutdown, launch, snapshot, export, import. Hypervisor adapters: Hyper-V (WMI), QEMU/libvirt (virsh), VirtualBox (vboxmanage), VMware (vSphere). v1.0 ships the schema + dashboard scaffold + command queue; v1.1 ships the agent-side handlers that actually execute.

Differentiator: only NinjaOne ships Hyper-V control today; nobody covers all four hypervisors.

iOS & Android BYOD Agent

Q3 2026

Mobile device inventory, OS version tracking, and basic policy enforcement (screen lock, encryption state). Lightweight — not a full MDM. Full MDM management commands ship Q2 2027 once this foundation is in place.

Competes with: NinjaOne mobile inventory, Atera BYOD tracking

NHS DSPT Compliance Pack

Q3 2026

Pre-built control mapping and evidence template specifically for NHS Data Security & Protection Toolkit submissions. One-click PDF for your DSPT assessment officer. No other RMM vendor has a native DSPT pack — it's currently a manual spreadsheet exercise.

Gap — no RMM competitor has a native DSPT pack

SNMP Polling for Switches & Routers

Q3 2026

v1 ships network discovery and topology graph. v1.1 adds full SNMP polling: live device metrics — uptime, port utilisation, bandwidth — plus SNMP trap ingestion. Switch and router visibility alongside your endpoint data in one pane.

Competes with: Auvik, Domotz, PRTG (SMB tier)

Linux Feature Parity

Q3 2026

Compliance evidence pack generation, ransomware tripwire, and full baseline comparison ship on Linux in v1.1. The v1 Linux agent covers patching, posture, shell commands, and run_script. v1.1 closes the remaining gap with Windows.

Differentiator — most RMM vendors treat Linux as second-class

EDR Integration v1

Q3 2026

Bitdefender, CrowdStrike, and SentinelOne alert feeds surfaced in the PatchPilot dashboard. Status sync, alert triage, correlated CVE view. Surfaces your EDR data alongside patch and posture — doesn't replace it.

Competes with: NinjaOne EDR integrations, ConnectWise SentinelOne connector

Microsoft 365 SaaS Protection v1

Q3 2026

Exchange, SharePoint, and OneDrive backup with granular restore. Point-in-time recovery, configurable retention. Backups stream to customer's own BYO storage or managed Vault. Datto's flagship SaaS backup, delivered at SMB price.

Competes with: Datto SaaS Protection, Veeam M365, Acronis M365

Browser-native RDP Shadow Mode

Q3 2026

Currently Mode A shadow uses the unified PatchPilot agent. The new shadow path gives browser-native RDP — no extra install on the technician's machine, better UX, simpler network path. Completes the remote access stack.

Differentiator — browser-native shadow with zero technician-side install

Live device telemetry

Q3 2026

Real-time CPU%, top processes, network bandwidth, battery state, and onboard temperatures streamed from every agent. Sub-30-second metric refresh on the device detail page — no waiting for a polling cycle.

Planned

Metric history & trending

Q3 2026

Time-series storage for every device metric with 7-day, 30-day, and 90-day trend graphs. Spot creeping disk usage, memory leaks, or thermal drift weeks before they cause an outage.

Planned

SSE push for alerts

Q3 2026

Server-Sent Events pipeline for sub-second alert delivery to the dashboard and mobile clients — replacing today's 30-second polling loop. Technicians see incidents the moment they happen.

Planned

Domain & SSL monitoring

Q3 2026

SSL certificate expiry tracking plus HTTP/HTTPS uptime monitoring for customer URLs. Get a 30/14/7-day expiry warning and an immediate alert on first failed probe.

Planned

Microsoft Defender / EDR sync

Q3 2026

Pull Microsoft Defender and other EDR detections into device_alerts so threats appear in the same triage queue as patch and posture alerts. One pane, one workflow.

Planned

Q4 2026 AI + Native Helpdesk + Enterprise on-site — the two biggest "competitors have this" gaps, plus air-gapped deployment

Months 4–6 post-launch. AI features and a full native helpdesk UI take the product from patch manager to complete IT ops platform. New for Q4 (committed 2026-05-19): on-site / air-gapped / private-cloud deployment package for regulated enterprise and public-sector. Note: bidirectional helpdesk webhook integration with Jira, Zendesk, and HubSpot is already shipped at v1.

Enterprise On-Site / Air-Gapped Deployment

Q4 2026 GA — design partners welcome now

Docker Compose bundle for on-prem / private-cloud / air-gapped installs. License-file activation (no phone-home), offline CVE feed sync (USB or proxy-cached), on-prem TLS, dedicated support engineer, optional managed update channel. Unlocks public-sector, defence-adjacent, and heavily-regulated enterprise that cannot host on third-party cloud. Sales can quote against Q4 2026 GA from today; design partners get co-engineering input.

Competes with: ManageEngine on-prem, Tanium (on-prem), Kaseya VSA on-prem — at a fraction of the price.

AI Patch Advisor — SHIPPED (vuln triage)

Shipped v1.0

Shipped at v1.0 launch as AI Vulnerability Triage. Claude (via Anthropic API, AWS Bedrock, OR on-prem Ollama) scores each CVE 0–100, explains the rationale in plain English, suggests remediation. Ollama is the default so customer data never leaves your server. The full LLM patch-ordering layer (factoring patch history + business hours) ships in v1.1.

Differentiator: only patch manager with on-prem AI option — every competitor sends data to US LLM providers.

AI Ticket Triage

Q4 2026

When tickets arrive via existing helpdesk integrations, AI pre-classifies priority, suggests likely resolution steps, links to similar past tickets, and recommends the right technician. Reduces Tier 1 handle time materially.

Competes with: Atera Robin AI, Freshservice AI, Zendesk AI Assist

Native PatchPilot Helpdesk UI

Q4 2026

Full ticketing module: email-to-ticket, SLA tracking, ticket merging, time entries, internal notes, customer portal. For teams on Jira/Zendesk/HubSpot, the existing webhooks remain. For teams who want single-pane-of-glass, this replaces a separate helpdesk tool entirely.

Competes with: Freshdesk, Zendesk basic, HaloPSA ticketing

Customer Portal v1

Q4 2026

End-users can submit tickets, check their device's patch and vulnerability status, request software from an approved catalogue, and view audit data about their own machine. White-labellable per MSP child-org.

Competes with: NinjaOne end-user portal, Atera end-user widget

Cyber Essentials Plus Pre-cert Tooling

Q4 2026

Mock audit dashboard: evidence checklist, "Are you CE+ ready?" readiness score, gap report. Reduces certification anxiety and shortens the assessor engagement. Pairs with the existing CE+ evidence pack already shipped at v1.

Gap — no RMM vendor offers CE+ pre-cert tooling natively

Asset Discovery + ITAM-lite

Q4 2026

LAN scan aggregation: hardware inventory, warranty tracking, lease end dates, lifecycle alerts. "What do you actually have?" across the whole estate, surfaced in one dashboard alongside patch and vulnerability data.

Competes with: Lansweeper, Asset Panda, Snipe-IT

Documentation Module v1 (IT Glue / Hudu lite)

Q4 2026

Per-client password vault, knowledge base articles, runbooks, and basic network diagrams — all linked to devices in the estate. Removes the "we need IT Glue for this" objection at a lower cost.

Competes with: IT Glue, Hudu, Confluence (for MSPs)

Slack & Microsoft Teams Native

Q4 2026

Alerts to channels, ticket creation from messages, slash commands: "PatchPilot, show me all devices with critical CVEs." Fully operational without leaving your chat platform.

Competes with: NinjaOne Teams integration, Atera Slack bot

EDR Integration v2 (Full)

Q4 2026

Multi-vendor support beyond the v1 three, deeper telemetry pull, threat hunting view, and correlated risk scoring across endpoint + EDR data. Turns PatchPilot into your unified security operations console.

Competes with: NinjaOne security suite, ConnectWise Fortify

Q1 2027 Backup-as-a-Service + network visibility

Months 7–9 post-launch. The Datto-competitor tier: image-level backup, full network monitoring, multi-region EU failover. Note: file/folder backup to BYO storage is already shipped at v1.

Image-level Backup-as-a-Service v1

Q1 2027

Volume-level continuous backup with cloud target. Bare-metal restore tested and verified end-to-end. Configurable retention, de-duplication, compression. File/folder backup to BYO storage ships at v1; Q1 2027 is Datto-grade bare-metal image backup.

Competes with: Datto BCDR, Veeam, Acronis Cyber Protect

Network Monitoring v2 (SNMP + NetFlow)

Q1 2027

SNMP polling ships Q3 2026. v2 adds NetFlow aggregation: traffic baselines, anomaly alerts, per-application bandwidth. Live network dashboards alongside endpoint data — one pane of glass for the whole estate.

Competes with: Auvik, Domotz, PRTG (SMB tier)

Multi-region Failover (UK + EU)

Q1 2027

Active-active control plane in UK and EU data centres. Customers pin their data to a region. Supports EU-only data residency requirements — particularly relevant for regulated continental European buyers.

Differentiator — most RMM vendors offer US-only or shared EU without data pinning

AI Runbook Execution v1

Q1 2027

Script library with AI-recommended remediation steps. "AI detected this issue and suggests this script — run it?" One-click execution with full audit trail. Builds on the existing script + step-up MFA infrastructure shipped at v1.

Competes with: NinjaOne automation, Atera remediation scripts, Datto RMM scripting

Time Tracking + Billing for MSPs

Q1 2027

Per-tech hours logged against tickets, billable rate cards, monthly invoice generation, client-facing time reports. Closes the "we need Autotask for billing" objection for smaller MSPs who don't want a full PSA.

Competes with: Autotask billing, HaloPSA billing, ConnectWise Manage

Predictive Maintenance / AIOps-lite

Q1 2027

SMART disk health forecasting, patch conflict prediction before deployment, anomalous behaviour alerts. Surface problems 2–4 weeks before they become incidents — move from reactive to genuinely predictive IT.

Competes with: NinjaOne predictive alerts, Atera AIOps (early stage)

Q2 2027 MDM + scripting marketplace — the sticky tier

Months 10–12 post-launch. Deep features that make customers stay: full MDM management, community scripting, AI auto-resolution, resold managed storage.

MDM Module v1

Q2 2027

Full mobile device management: iOS and Android enrolment, MDM commands (lock, wipe, enforce passcode, app push), BYOD separation policies. Builds on the Q3 2026 iOS/Android agent foundation. Replaces Jamf Now and Intune mobile for SMB.

Competes with: Jamf Now, Kandji, Microsoft Intune (SMB tier)

Custom Scripting Marketplace

Q2 2027

Community-contributed scripts with reputation scoring, vetting, version history, and one-click deployment. Browse, fork, and publish PowerShell and Bash automations. Revenue share for top contributors. Discover, not just run.

Competes with: NinjaOne Marketplace, PDQ Library

Customer Portal v2

Q2 2027

Power-user self-service: hardware order requests, software approval workflows, password reset flows, status tracking. Full approval gates for IT admin. Reduces Tier 0 ticket volume without adding technician workload.

Competes with: NinjaOne end-user portal v2, ServiceNow (enterprise tier)

AI Auto-resolution (Tier 1 Closure)

Q2 2027

AI autonomously handles common Tier 1 tickets: password resets, approved software installs, basic connectivity troubleshooting. Closes tickets without technician touch. Full audit trail retained for every autonomous action.

Competes with: Atera Robin AI (auto-resolution), Freshservice AI

PatchPilot Vault (Resold Managed Storage)

Q2 2027

High-margin upsell for customers who prefer not to configure their own BYO storage destination. Managed, geo-redundant, GDPR-compliant. BYO remains the default and always free — Vault is the convenience tier.

Differentiator — our model is BYO-first; Vault is opt-in convenience

IT Asset Chat (Natural Language)

Q2 2027

"Show me every Win11 device with BitLocker disabled and a CVE score above 9.0." Natural-language queries against the full device estate — no SQL, no filter menus. Powered by the knowledge graph built across v1.x releases.

Differentiator — no RMM competitor offers natural-language fleet queries at this fidelity

Expanded alert types

Q2 2027

15+ new built-in alert templates: sustained CPU, event-log keyword match, repeated login failures, certificate expiry, BSOD, network packet loss, sustained disk IO, scheduled task failed, app crash count, login from new IP, and more.

Planned

User-defined alert rules

Q2 2027

Compose your own alerts: any metric + operator + threshold + time window. Save, share, and version control alert rules across the org. No need to wait for us to add the alert you want.

Planned

Notification channels (Slack / Teams / SMS / Webhook)

Q2 2027

Email and in-app notifications already ship at v1. Q2 2027 adds Slack, Microsoft Teams, SMS, and generic webhook destinations with per-channel routing rules and quiet-hours support.

Planned

Inbound helpdesk sync (auto-close)

Q2 2027

Tickets auto-close inside PatchPilot the moment they're resolved in Jira, Zendesk, or HubSpot. Completes the bidirectional sync — no more stale device alerts waiting on a technician to tidy up.

Planned

Alert escalation chains

Q2 2027

L1 -> L2 -> L3 rotations with configurable acknowledgement timeouts. Page the on-call engineer when the first responder doesn't ack within N minutes. Built for MSP NOC workflows.

Planned

Agent auto-update (macOS / Linux)

Q2 2027

Windows already has signed SelfUpdate at v1. Q2 2027 brings the same signed, staged auto-update flow to the macOS and Linux agents — no more manual fleet upgrades.

Planned

Tighter offline alerting

Q2 2027

Drops the device_offline_hours default from 24h to 15min so customers learn about offline devices within a coffee break, not a working day. Per-org override remains available.

Ready

Fix 6 sidebar nav routes returning 404 Internal

Q2 2027

/tasks, /defender, /entra, /intune, /alerts, /managed-devices, /updates currently 404 from the sidebar. Backend handlers needed.

Planned

/billing leaks STRIPE_SECRET_KEY name Internal

Q2 2027

/billing surface exposes the env-var name STRIPE_SECRET_KEY to customers. Sanitise the error path.

Planned

/dev-console tab deep links broken Internal

Q2 2027

Direct links to dev-console tabs don't restore the correct active tab on load.

Planned

/about + /for-msps Tailwind CDN blocked by CSP Internal

Q2 2027

Both pages load Tailwind from a CDN; CSP blocks the script. Inline build or self-host Tailwind.

Planned

4 /settings/* subroutes show "Not Found" Internal

Q2 2027

Settings subroutes render the 404 body inside the Settings chrome rather than wiring real handlers.

Planned

/alerts returns 503 Internal

Q2 2027

Top-level /alerts page currently 503s for signed-in users. Wire the alerts handler + view.

Planned

Audit log shows raw UUIDs + raw event codes Internal

Q2 2027

Audit log UI renders user_id UUIDs and machine event codes. Resolve to friendly names and human-readable events.

Planned

/dev-console/watchdogs backend 502 Internal

Q2 2027

Watchdogs panel 502s — backend route or upstream worker not responding.

Planned

/education soft-404 Internal

Q2 2027

/education returns HTTP 200 but body says 404. Redirect to /for/education or render real content.

Ready

Marketing nav .html suffix inconsistency Internal

Q2 2027

Some marketing pages use .html-suffixed nav links, others use extension-less. Normalise to extension-less.

Ready

Top-nav mega-nav button type=submit Internal

Q2 2027

Mega-nav trigger renders without an explicit type and defaults to submit; should be type="button" to avoid stray form submits.

Ready

Contract: public-readiness-endpoint Internal

Q2 2027

Failing contract test. Public /readiness endpoint shape mismatch — repair backend response to match spec.

Planned

Contract: marketing-honesty-sweep Internal

Q2 2027

Failing contract test. Marketing copy claims drift from shipped capability — sweep and reconcile.

Planned

Contract: marketing-cross-links Internal

Q2 2027

Failing contract test. Internal marketing cross-links broken or stale.

Planned

Contract: customer-readiness-wizard-bedrock-error-handling Internal

Q2 2027

Failing contract test. Readiness wizard mis-handles AWS Bedrock error paths.

Planned

Contract: white-label-remote-control Internal

Q2 2027

Failing contract test. Remote-control UI leaks underlying vendor branding instead of full white-label.

Planned

Contract: visual-regression Internal

Q2 2027

Failing contract test. Visual regression suite reporting drift — review baselines and re-snapshot the intentional changes.

Planned

What we are not building

Honesty matters. These are features some competitors have that we have deliberately decided not to pursue — either they're out of scope or better served by integration.

Full SIEM

Splunk / Elastic / Microsoft Sentinel territory. We export to yours (CEF / LEEF / JSON at v1) — we won't replace it.

Email security gateway

Mimecast / Proofpoint / Barracuda territory. Different buyer, different product. Partnership integrations only.

Cloud cost management (FinOps)

Apptio / CloudHealth territory. Different ROI model, different buyer. Not the problem PatchPilot solves.

Container / Kubernetes management

DevOps audience, not IT Ops. We stick to the endpoint estate — servers, desktops, laptops, mobile.

HR / payroll integrations

Off-mission. Not the buyer we serve. We integrate with identity providers (Entra, Okta) — HR data stays in HR systems.

Custom OS imaging / golden image management

SCCM / Intune / WDS territory. Their job is to deploy the image. Ours is to manage and secure what they deployed.

A feature you need isn't on here?

Tell us. Customer commitments move items earlier by 2–4 quarters. Join the waitlist and tell us what matters most.

Test confidence
· loading
Launch readiness
verified · regressions
build 02:21:46