> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/insight/getting-started/insight-partner-training-course.md).

# INSIGHT Partner Training Course

### Format

See also: [INSIGHT Partner Training Course — 90 Minutes](/insight/getting-started/insight-partner-training-course-90-minutest-to-th.md)

**Total duration:** about 3 hours

* **Session 1:** Platform overview and deployment fundamentals — 45 minutes
* **Break:** 15 minutes
* **Session 2:** Governance, policies, and risk logic — 45 minutes
* **Break:** 15 minutes
* **Session 3:** Dashboards, reporting, investigation, and Q\&A — 45 minutes

### What partners should understand by the end

* How INSIGHT is deployed across endpoints and Microsoft 365.
* How organisation settings, user policies, risk definitions, and advanced settings work together.
* How to review activity, investigate incidents, and use dashboards and reports to drive action.

### Trainer preparation and demo environment checklist

Before delivering the training, prepare and verify the following:

* A reachable GuardWare Management Console URL.
* One working admin account that can sign in and complete 2FA.
* At least one online endpoint with the INSIGHT agent installed.
* At least one visible user account in **INSIGHT > End Users**.
* One configured user policy and one configured advanced setting.
* Risk definitions configured for the main monitored categories.
* Enough activity data to demonstrate dashboards, widget drill-downs, and reports.
* Microsoft 365 integration configured, or screenshots prepared, if Exchange Online or SharePoint Online monitoring will be shown.
* One demo endpoint with **INSIGHT Status Monitor** available.
* One prepared Risk Summary or Cyber Awareness email as a backup demo.
* Backup screenshots of key workflows in case live data is limited.

### Core reference material

* [Introduction to INSIGHT](/insight/about/introduction-to-insight.md)
* [INSIGHT Quick Start Guide](/insight/getting-started/insight-quick-start-guide.md)
* [Cloud Monitor Settings](/insight/settings/cloud-monitor-settings.md)
* [Organisation Settings](/insight/settings/organisation-settings.md)
* [User Policies](/insight/policies/user-policies.md)
* [Risk Definitions](/insight/settings/risk-definitions.md)
* [INSIGHT Devices](/insight/users-and-devices/insight-devices.md)
* [INSIGHT Users](/insight/users-and-devices/insight-users.md)
* [INSIGHT Dashboard](/insight/dashboard/insight-dashboard.md)
* [Cyber Awareness](/insight/reporting/cyber-awareness-report.md)
* [INSIGHT Status Monitor](/insight/dashboard/insight-status-monitor.md)

### Terminology for the training

* **GuardWare Management Console** for the central web application.
* **INSIGHT Agent** for the endpoint software that collects and sends activity data.
* **Cloud Monitor** for Microsoft 365 monitoring across Exchange Online and SharePoint Online.
* **Organisation Settings** for global classifications and monitoring context such as websites, applications, printers, email domains, USBs, AI tools, and SharePoint libraries.
* **User Policy** for the rules applied to users to monitor, warn, or block activity.
* **Advanced Setting** for the device-level monitoring and communication configuration.
* **Data Type** for the sensitive content category INSIGHT detects and tracks.
* **Risk Definition** for the severity assigned to monitored activities.
* **Dashboard Widget** for the visual view used to summarise and drill into incidents.
* **Cyber Awareness Report** for user-facing email guidance triggered by defined risk conditions.

### Session 1: Platform overview and deployment fundamentals

**Duration:** 45 minutes

#### Session goal

Give partners a clear view of what INSIGHT monitors, how data reaches the console, and how to confirm the platform is working.

#### 1. Product overview — 10 minutes

Cover the core INSIGHT flow:

* Agents and cloud integrations collect activity.
* Policies and settings determine what is monitored.
* Risk definitions shape severity.
* Dashboards and reports surface what needs review.

Explain the three main components:

* GuardWare Management Console.
* Windows endpoint devices running the INSIGHT agent.
* Exchange Online and SharePoint Online through Cloud Monitor.

For reference, use [Introduction to INSIGHT](/insight/about/introduction-to-insight.md).

#### 2. Accessing the system — 5 minutes

Show the standard admin access flow:

* Open the GuardWare Management Console.
* Sign in with the admin account.
* Complete 2FA, EULA acceptance, and password update if prompted.

Call out the difference between console access and Microsoft 365 consent during Cloud Monitor setup.

For reference, use [INSIGHT Quick Start Guide](/insight/getting-started/insight-quick-start-guide.md).

#### 3. Microsoft 365 integration and Cloud Monitor — 10 minutes

Cover this section when Exchange Online or SharePoint Online monitoring is in scope.

Show the setup path:

* **ORGANISATION > Integrations**
* **Connect Microsoft 365**
* Consent with a Global Administrator account
* **INSIGHT > Cloud Monitoring**

Then show what the connection enables:

* Exchange monitoring.
* SharePoint monitoring.
* User assignment to the monitoring group.
* Manual sync and last synced status.

For reference, use [Cloud Monitor Settings](/insight/settings/cloud-monitor-settings.md).

#### 4. Agent download, install, and validation — 10 minutes

Walk through the deployment path:

* **Resources > Agent Download**
* Configure and download the INSIGHT agent installer.
* Whitelist the agent where needed.
* Install the agent on a demo endpoint.
* Confirm the endpoint appears in **INSIGHT > Devices**.

Show how to validate:

* **Device Name** and **User Name**.
* **Setting Assigned**.
* **Last Online Time**.
* **Agent Version**.

For reference, use [INSIGHT Quick Start Guide](/insight/getting-started/insight-quick-start-guide.md) and [INSIGHT Devices](/insight/users-and-devices/insight-devices.md).

#### 5. Devices, users, and endpoint health — 10 minutes

Introduce the operational views used after deployment:

* **INSIGHT > Devices** for endpoint visibility and commands.
* **INSIGHT > End Users** for user visibility and policy assignment.
* **INSIGHT Status Monitor** for local endpoint validation and troubleshooting.

Demonstrate:

* Opening a device record.
* Opening a user record.
* Launching Status Monitor on the endpoint.
* Confirming the endpoint has received its settings.

For reference, use [INSIGHT Devices](/insight/users-and-devices/insight-devices.md), [INSIGHT Users](/insight/users-and-devices/insight-users.md), and [INSIGHT Status Monitor](/insight/dashboard/insight-status-monitor.md).

#### Demo outcomes

By the end of Session 1, partners should have seen:

* How INSIGHT is structured.
* How cloud monitoring is connected.
* How the agent is downloaded, installed, and validated.
* Where to confirm endpoint, user, and health status.

{% hint style="info" %}
If time is tight, keep the installer walkthrough short and rely on screenshots for the full install sequence.
{% endhint %}

### Session 2: Governance, policies, and risk logic

**Duration:** 45 minutes

#### Session goal

Show how INSIGHT decides what to monitor, how it scores risk, and how settings are applied across users and devices.

#### 1. Governance model overview — 5 minutes

Start with the relationship between the four core configuration areas:

* Organisation Settings define monitoring context.
* User Policies define what users are monitored for.
* Risk Definitions assign severity.
* Advanced Settings control device-level monitoring behaviour.

Explain the relationship:

* Organisation Settings reduce noise and improve context.
* User Policies define the monitored activities and control mode.
* Risk Definitions influence dashboard severity.
* Advanced Settings affect how endpoints collect and transmit data.

#### 2. Organisation Settings — 10 minutes

Show how to tune monitoring context across the organisation.

Cover:

* **Working Days** for accurate productivity and time-based analysis.
* **Websites** and **Applications** as organisational or non-organisational.
* **Printers**, **USBs**, and **Email Domains** for trusted and risky destinations.
* **Trusted Emails** to reduce false positives.
* **AI Usages**, **OneDrive Folder**, and **SharePoint** where relevant.

Explain why this matters:

* It improves reporting accuracy.
* It helps distinguish expected from risky behaviour.
* It supports better policy decisions.

For reference, use [Organisation Settings](/insight/settings/organisation-settings.md).

#### 3. User Policies — 15 minutes

This is the main working section of Session 2.

Start with the user policy lifecycle:

* Create a new policy.
* Configure environment settings.
* Add data types.
* Choose control modes.
* Assign users.

Cover the key settings:

* Application usage and blocked applications.
* Website usage and blocked websites.
* USB or storage control.
* Archive and password-protected file handling.
* Network access and connectivity.
* OCR for images and documents.
* Office document and Outlook email classification.

Then explain data type controls:

* **Off**.
* **Block**.
* **Monitor**.
* **Warn**.

Show a simple policy example:

* Monitor AI website uploads.
* Warn on sensitive email attachments.
* Block transfer of selected data types to storage media.

For reference, use [User Policies](/insight/policies/user-policies.md) and [INSIGHT Users](/insight/users-and-devices/insight-users.md).

#### 4. Risk Definitions — 5 minutes

Show how risk is assigned across categories such as:

* SharePoint activity.
* Email and file transfers.
* Printing, USB, keystrokes, and copy paste.
* AI usage and non-corporate websites or applications.

Explain why this matters:

* Dashboards become easier to prioritise.
* Reports become more meaningful.
* Teams can align severity with real business risk.

For reference, use [Risk Definitions](/insight/settings/risk-definitions.md).

#### 5. Advanced Settings and pushing changes — 10 minutes

Finish with the device-level configuration layer.

Cover:

* Report upload and communication settings.
* Network-level monitoring.
* SSL traffic monitoring.
* Keystroke and copy or paste monitoring scope.
* File-system monitoring and file extension scope.
* Assigning advanced settings to devices.-

Then show how to push or verify changes:

* Assign an advanced setting to a device.
* Use **Assign Command** where needed.
* Verify the applied configuration in Status Monitor.

For reference, use [INSIGHT Devices](/insight/users-and-devices/insight-devices.md) and [INSIGHT Status Monitor](/insight/dashboard/insight-status-monitor.md).

#### Demo outcomes

By the end of Session 2, partners should understand:

* How INSIGHT’s configuration layers fit together.
* How to create and assign a user policy.
* How risk levels shape dashboard visibility.
* How advanced settings affect endpoint monitoring.

### Session 3: Dashboards, reporting, investigation, and Q\&A

**Duration:** 45 minutes

#### Session goal

Turn collected activity into a practical review workflow. Show partners how to read dashboards, drill into incidents, and use reporting to support follow-up.

#### 1. Dashboard overview — 15 minutes

Open **INSIGHT > Dashboard** and explain the main risk categories:

* **Risk Summary** for high-level visibility.
* **Data Type Risks** for policy hits by content type.
* **SharePoint Risks** for cloud file activity.
* **AI Usage Risks** for AI websites, apps, prompts, and uploads.
* **Behaviour Risks** for productivity and heatmap views.
* **Label Events**, **Location Risks**, **Protected Files**, and **System Risks**.

Show how to use:

* The dashboard search and filters.
* Widget drill-down.
* User, device, data type, and time-based views.

For reference, use [INSIGHT Dashboard](/insight/dashboard/insight-dashboard.md).

#### 2. Incident review and investigation flow — 10 minutes

Show how an analyst or partner reviews activity in practice.

Demonstrate drill-downs from widgets such as:

* **Incidents by Data Type**.
* **Website Uploads** or **Application Transfer**.
* **Keystrokes** or **Copy Paste** when screenshot evidence is available.
* **SharePoint** widgets for internal or external access.

Explain what to review in the details:

* User and device.
* Activity type.
* Date and time.
* Data type.
* File name, path, or destination.
* Screenshot or detected content where available.

Prepare at least one earlier captured incident path before training day in case live activity is limited.

#### 3. Reports and awareness workflows — 10 minutes

Cover the reporting options that support follow-up:

* **Risk Summary** for scheduled summaries to admins.
* **Cyber Awareness** for contextual guidance sent to end users.
* Custom dashboards for team-specific views.

Explain when each is useful:

* Risk Summary for oversight.
* Cyber Awareness for behaviour change.
* Custom dashboards for role-specific monitoring.

For reference, use [Cyber Awareness](/insight/reporting/cyber-awareness-report.md) and [INSIGHT Dashboard](/insight/dashboard/insight-dashboard.md).

#### 4. Operational wrap-up and troubleshooting — 5 minutes

Finish by showing the main operational checks:

* Device online status.
* Last cloud sync.
* Audit activity.
* Status Monitor for endpoint diagnostics.

Position this as the standard first pass when a customer says data is missing, a device looks stale, or a setting has not applied.

For reference, use [INSIGHT Dashboard](/insight/dashboard/insight-dashboard.md), [INSIGHT Devices](/insight/users-and-devices/insight-devices.md), and [INSIGHT Status Monitor](/insight/dashboard/insight-status-monitor.md).

#### 5. Question and answer — 5 minutes

#### Demo outcomes

By the end of Session 3, partners should be able to:

* Navigate the main dashboard categories.
* Drill into incidents and explain what they mean.
* Use Risk Summary and Cyber Awareness in the right scenarios.
* Perform basic health and troubleshooting checks.

{% hint style="info" %}
If live incident data is limited, use prepared screenshots or a saved report to preserve the investigation flow.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/insight/getting-started/insight-partner-training-course.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
