INSIGHT Quick Start Guide
GuardWare INSIGHT is a data visibility and monitoring solution that helps your organisation understand how data is being accessed, shared, and used across both internal and external environments. It provides a unified view of user activity and file movement, allowing you to detect unusual behaviour, potential data leaks, and policy violations in real time.
Before you begin, make sure you have:
Access to the GuardWare Management Console.
Endpoints ready for INSIGHT agent deployment.
A Microsoft 365 Global Administrator account if you plan to monitor Exchange Online or SharePoint Online.
Set up Cloud Monitor
Cloud Monitor audits user activities within your organisation’s Microsoft 365 environment, including Exchange Online and SharePoint Online.
To set up Cloud Monitor:
Navigate to ORGANISATION > Integrations.
Click Connect Microsoft 365.
Sign in with a Global Administrator account.
Approve MFA if prompted.
Select Consent on behalf of your organisation.
Click Accept.
Then go to INSIGHT > Cloud Monitoring and:
Enable Exchange Monitoring if needed.
Assign users to the monitoring group.
Enable SharePoint Monitoring if needed.
Run Sync to pull the latest Microsoft 365 data.

Download the INSIGHT Agent
The GuardWare INSIGHT Agent is installed on endpoint devices to continuously monitor user activities and file interactions, including file transfers, email attachments, printing, access to non-corporate websites and applications, etc.
Navigate to Resources > Agent Download.
Go to INSIGHT Agent.
Configure the required fields and click Submit.

Once the installation settings are complete, the Download Installer link becomes available. Click it to download the agent with the configured settings.
Whitelist INSIGHT
Whitelist INSIGHT in the endpoints' AV, EDR, or XDR platforms.
Add
C:\Program Files (x86)\GuardWare\to the allowlist.Add
C:\ProgramData\Guardwareto the allowlist.
See Whitelist GuardWare INSIGHT for the full list of files, services, and network exceptions.
Install INSIGHT Agent on endpoints
Deploy the INSIGHT agent on your endpoints.
To install INSIGHT Agent:
Run the INSIGHT Agent installer on the endpoint.
Complete the setup wizard.
INSIGHT Agent can also be deployed via Active Directory, Microsoft Intune, and third-party solutions. See Installation Methods for details.
After deployment, open INSIGHT > Devices and confirm each device shows the expected:
Device Name and User Name.
Setting Assigned and Last Online Time.
Agent Version.
If a device does not look right, use INSIGHT Status Monitor to review endpoint status.
Configure Organisation Settings
Set the organisation-wide settings that INSIGHT uses for monitoring and reporting.
Navigate to INSIGHT > Organisation Settings and configure:
Working Days for accurate activity timing.
Websites, Applications, Printers, and USBs as organisational or non-organisational.
Email Domains as organisational, insecure, or undefined.
Trusted Emails to reduce false positives.
OneDrive Folder, AI Usages, and SharePoint settings where needed.

For the detailed configuration steps, see Organisation Settings.
Create a User Policy and assign users
User Policies define how user activities are monitored, governed, and controlled within the organisation.
By default, new users are assigned to INSIGHT's base policy. If a different policy is configured as the default policy, all new users are automatically assigned to that policy.
To create a user policy:
Navigate to INSIGHT > User Policies and click New User Policy.
Add the policy name and description.
Configure the environment settings.
Add and configure the data types you want to monitor.
Save the policy.

Then assign users from either:
INSIGHT > User Policies > Assign Users.
End Users > INSIGHT > Assign Policies.
See User Policies for more details.
Define risk levels
Go to INSIGHT > Risk Definition and assign the risk levels for different user activities across applications, email, file sharing, and data transfers.
Start with the categories that matter most:
SharePoint external and internal activity.
Email, website uploads, and file-sharing applications.
USB transfers, printing, keystrokes, copy/paste, and AI usage.
These risk levels drive dashboard visibility and help teams prioritise incidents.

See Risk Definitions for more details.
Configure Advanced Settings and assign to devices
Advanced Settings define the global monitoring parameters applied across audit reports and device policies in GuardWare INSIGHT.
The table below provides an overview of every Advanced Setting and what it does.
Controls the intervals, durations, timeouts, and bandwidth settings for uploading reports and downloading policies and commands.
Lists applications monitored for sensitive data uploads at the network level.
Lists IP addresses included or excluded from network-level monitoring.
Defines which applications have their SSL traffic monitored when network monitoring is used.
Defines which websites have their SSL traffic monitored using certificate common names.
Specifies applications where keystroke and copy/paste activity is monitored or excluded.
Specifies websites where keystroke and copy/paste activity is monitored or excluded.
Lists applications monitored at the network level using the LSP approach.
Lists client components and controls whether each is enabled or disabled.
Filters file upload monitoring by file extension type.
Lists applications monitored for sensitive data uploads at the file system level.
Lists applications monitored to provide full file path data for network monitoring.
Suppresses repeated incident alerts from specified applications at the file system level.
Lists browser applications monitored at the file system level to intercept file uploads on end-to-end encrypted websites.
Lists websites with end-to-end encryption where file system monitoring is required alongside network monitoring.
To configure Advanced Settings:
Navigate to INSIGHT > Advanced Settings, and click + New Advanced Setting.
Add a clear name and description.
Configure the settings you need.
Review and save the configuration.

Then assign the settings to devices from INSIGHT > Advanced Settings > Assign Devices.
See Advanced Settings for details.
Configure Reports
Set up scheduled reporting once devices and users are active.
Configure:
Risk Summary for a consolidated, high-level overview of risky activities and user behaviour of your organisation in a single email.
Cyber Awareness Report for contextual reports via email sent directly to end users when a risk associated with their activity is triggered.
Use test emails before broad distribution. Then enable the schedules you want.
To configure Risk Summary:
Navigate to INSIGHT > Risk Summary.
Click + New Risk Summary.
Set the schedule, filters, recipients, and widgets.
Send a test email, then save the report.
To configure Cyber Awareness:
Navigate to INSIGHT > Cyber Awareness.
Click Configure Cyber Awareness Report.
Choose the schedule, users, recipients, and risks.
Send a test email, then create the report.
See Risk Summary and Cyber Awareness for the full configuration steps.
Monitor user activities in the Dashboard
Once data starts flowing, monitor activities from the dashboard in INSIGHT > Dashboard. INSIGHT Dashboard provides a centralised view of your organisation’s data activity, user behaviour, and potential security risks.
The dashboard includes the following Risk Category tabs, allowing you to switch between different risk areas. Each tab contains widgets that provide insights into data usage patterns, trends, and potential threats.
Risk Summary provides an overview of key security and data protection indicators across your organisation.
Data Type Risks help you review policy hits by content type.
SharePoint Risks help you review file access, downloads, anonymous links, and external sharing activity.
AI Usage Risks help you monitor AI websites, AI applications, file uploads, and sensitive prompts.
Behaviour Risks help you spot productivity trends and unusual activity patterns across users.
Label Events help you track activity involving labelled Office documents and emails.
Location Risks help you identify where risky activity is happening across countries and regions.
Protected Files help you monitor how protected files move through applications, email, websites, and storage devices.
System Risks help you monitor device status, active users, audit activity, and cloud sync health.

You can also create a custom dashboard for your team and choose the users, devices, data types, risks, and widgets that matter most for that view.
For details, see INSIGHT Dashboard.
With these steps complete, INSIGHT is ready to monitor activities and detect risks across your organisation.
Last updated

