@psyhackological My initial internal thing was an ansible playbook that generated a local report that I templated via jinja, but it got clumsy fast and either gave me too much data or not enough. Adjusting was annoying every time, and it was shockingly slow. Getting an aggregate report of all hosts is also one of these things ansible does clumsily.
It really isn't meant to be an either/or thing in this case, as it focuses exclusively on _reporting_, i.e. telling you what updates and patches there are on t he system, what they are, which ones are security, and letting you query this at will, with copious cache.
It doesn't apply updates for you at all, which is definitely an area where you should use better tooling. I personally absolutely use Ansible for that part.