This risk mitigation technique is called “rip the bandaid off”. While it’s a little more risky than your phased rollout plan, it’s also much less work
Assertion: desktop apps should preserve state across reboot where possible.
Having to wipe out multiple desktops containing intermediate work state to do a security update and reboot is no longer a rare occurrence, and the OS should handle it better. macOS restore windows is a good start but needs deeper integration.