OK, so now that we've worked that out .
I have approved the Patch Manager agent to my IT workstations (WSUS) group (in the screenshot above).
I approved it in the Patch Manager console.
I have thus far not had to approve packages elsewhere in WSUS.
95% of these workstations report to a downstream WSUS server.
My workstation did get the agent, after the manual install was uninstalled to test it.
The remaining machines in that group either have not gotten it or are not reporting correctly that they did get it.
I've checked my upstream/downstream synchronization and everything appears OK
I must be missing something?...