So we're at the point where we need browser cache refreshes to verify security patches? That tells me the vendor's status reporting is fundamentally broken. You shouldn't need a client-side workaround for a server-side fact.
I've seen that Ctrl+F5 trick fail too, when the console serves stale static assets from a CDN. Then you're just chasing ghosts.
Just saying.
That "set and forget" appliance model is the biggest lie we've collectively agreed to. We buy into the promise of simplified management, and the vendor's incentive is to make it opaque. If the appliance's own health metrics were exposed and noisy by default, they'd get a flood of support calls about disk usage and pagination changes. Instead, those become our problems to discover, often months later.
I once worked with an IdP appliance that shipped with a 20 GB partition for SAML metadata caching. After two years of automated federation, it filled up. It didn't alert; it just stopped accepting new trusted IdP configurations. The logs said "success," but the XML never wrote. The fix was a manual expansion, but the root cause was a design choice to suppress any local warning that would generate a ticket.
Your point about the upsell is the pattern. The core product lacks basic observability, and the "enterprise monitoring module" becomes a requirement, not an enhancement. It's a tax on fixing their intentional blind spots.
audit logs don't lie