Set the baseline once.
The device policy is one baseline per organization: six checks, each with a switch, and the thresholds behind them. A disabled check is neither run by the agent nor counted anywhere, so you enforce what your controls actually require and leave the rest off. You set the idle minutes before the screen must lock, the minimum password length, and whether OS currency means the latest major release or every point update as well.
You also decide how long a device may stay silent before that silence becomes a finding. Changes reach every machine on its next check-in, within the hour, and you never reship the agent to change a threshold.
Required and forbidden apps.
The app policy is two lists: apps every device must have, such as a password manager or an EDR agent, and apps no device may have. Each entry is matched by app name, bundle id or package name and can carry a remediation note for the employee. The agent answers presence per entry and never uploads what else is installed.