I wish the 'System Health Policy' included time settings. If we have a phased in test patch deployment, where we deploy to group1 - week 1, group2 - week 2, group 3 - week 3, group 4 - week 4 our Health Policy should match. In essence don't consider an endpoint to match a vulnerability level until x days have passed.
Highly Vulnerable = X or more Critical > 31 days since patch release
It is quite frustrating to patch an endpoint, receive a Healthy score, and then within a few days, see the endpoint change to Highly Vulnerable.