This idea is similar to I-831. The scenario is as follows:
For ConfigMgr Applications, you can delay in place updates to applications by X days
It would be beneficial to allow an option to always bypass this delay if the update is flagged as a critical security update. (or update type: security release)
This would also be nice to assign on a per app basis in the same vein as idea I-831.
This would allow non-critical feature updates to arrive at a lower impact delay, but automatically escalate updates that address 0-days and other critical security scenarios.