Operations Guide- Super Admin
This guide covers the operation of the GuardWare Partner Portal as a Super Admin. Super Admins are internal GuardWare users with the highest level of access, responsible for provisioning and managing partner accounts, users, and platform-wide configurations.
Access the Portal
The Partner Portal supports two sign-in methods: email credentials provided by GuardWare or an existing Microsoft 365 account. Two-factor authentication (2FA) applies to email-based sign-in only.

Navigate to your portal URL and sign in either with your GuardWare-provided credentials or your Microsoft 365 account.
If signing in with email credentials for the first time, set up two-factor authentication (2FA) using an authenticator app. This step is mandatory and cannot be skipped.
Accept the EULA to proceed. This appears once and must be accepted to continue.
Recover 2FA
If you lose access to your authenticator app, your OTP configuration can be reset in two ways:
On the OTP entry page, select Reset OTP.
The OTP configuration will be sent to your registered email address.
Follow the instructions in the email to reconfigure your authenticator app.
Alternatively, another user can reset OTP on your behalf by logging into the Management Console, navigating to the relevant organisation, going to Organisations > Users, and clicking on your entry.
ADMINS
The Admins section provides an overview of all Super Admin accounts and allows existing Super Admins to add new ones.
Add an Admin User
Navigate to ADMINS and click +Add Admin User.
Enter the user's name, email, and phone number.
Click Create Admin.
The new Super Admin will receive their login credentials via email. On first login, they will be prompted to set a new password and configure 2FA using an authenticator app. If signing in with a Microsoft 365 account, 2FA setup is not required.
Update Details
Navigate to ADMINS and click Actions on the desired entry.
Click Update Details, make the required changes and click Save.
Reset Password
Navigate to ADMINS and click Actions on the desired entry.
Click Reset Password, enter the new password and click Reset.
The new password must be communicated to the user manually through secure channels, as sending passwords over common channels exposes them to interception.
Delete User
Navigate to ADMINS and click Actions on the desired entry.
Click Delete User to permanently remove the account. A Super Admin cannot delete their own account.
PARTNERS
The Partners section is where all partner accounts are provisioned and managed. Each partner account represents an MSP (Managed Service Provider) / MSSP (Managed Security Service Provider), SI (Systems Integrator), or Reseller operating under GuardWare.
Add a Partner
Navigate to PARTNERS and click + Add Partner.

Step 1: Partner Details
Enter the partner's information.

Partner Name: Enter the partner’s registered or official business name.
Partner Type: Select the category that best defines the partner’s role. The partner type determines the licence duration available when assigning product licences to organisations. If multiple partner types are selected, the corresponding licence durations for each apply. To assign licences to an organisation, log in as a Partner.
Partner TypeDescriptionLicence DurationMSP/MSSP
Delivers ongoing IT management and support services to customer organisations.
Monthly
SI
Integrates GuardWare into a customer's existing technology environment.
Yearly
Reseller
Sells GuardWare products directly to end customers.
Yearly
Country: Select the country from the dropdown where the partner is legally registered or operates from.
City: Enter the city of the partner’s primary business location.
Street Address: Provide the full street address of the partner’s primary office.
Website: Enter the partner’s official website URL (if available).
Phone Number: Enter a valid contact number, including country code.
Partner Logo: Upload the partner's logo. (Recommended size is 200 x 200px with a maximum file size of 2MB. Supported formats are:
PNG,JPG,JPEG,SVG,WEBP.)Click Next.
Step 2: Contact Details
Enter the partner's contact details. Assign a primary contact as well.

Name: Enter the contact person’s full name.
Email: Enter a valid email address for communication and account-related notifications.
Phone Number: Enter a contact number, including country code.
Designation: Enter the contact person’s job title or role.
Department: Specify the department the contact belongs to (e.g., Sales, IT, Support).
Is Primary Contact Person: Designates the primary contact for the partner account. At least one primary contact is required, and only one primary contact can be set at a time.
Is System Account: Creates a portal account for the contact. Login credentials are sent automatically to the provided email address upon creation.
Click +Add Contact and click Next.
Edit Partner Details
Navigate to PARTNERS and click Manage Partner on the desired partner.
Update details by clicking :

Identification: Partner name, type, contact, and address.
Contacts: Add, remove, or edit contacts and reassign the primary contact.
Products: Add or remove assigned products. To manage licence allocation, log in as a partner user and assign licences to the desired organisation(s).
Deactivate or Restore Partner
Navigate to PARTNERS and click Actions on the desired partner.
Click Delete Partner to suspend the partner account along with all associated users and organisations.

Click Restore Partner to restore the suspended partner account.

PARTNER USERS
Partner users are the individuals who use the Partner Portal to manage customer organisations, assign products, and handle day-to-day operations. All partner users across all partner accounts are visible in this section, regardless of their affiliated partner. A partner account must be assigned when creating a partner user. There are two partner-level user roles:
Partner Admin
Partner Admins are created by GuardWare and have the highest level of access in the partner portal. They can create and manage Partner Admins as well as Partner Users.
Partner User
Partner Users can access the Partner Portal and manage organisations, users, and settings for the customers.
Organisation Users are not partner-level users. They are end customers who access the GuardWare Management Console for their assigned organisation only and have no access to the Partner Portal. For managing organisation users, see Adding Organisation Users.
Add a Partner User
Partner users are the individuals who will use the Partner Portal to manage customer organisations, assign products, and handle day-to-day operations across managed organisations.
Navigate to PARTNER USERS and click +Add Partner User.
Select the Partner you want to add the user to from the dropdown.
Enter the user's name, email, phone number, and designation.

Select the partner role, Partner Admin or Partner User, and click Create. A login invitation will be sent to the provided email address.

Only Partner Admins can create other Partner Admins.
Edit a Partner User

Navigate to PARTNER USERS and click Actions.
Click Update Details on the desired user's entry.
Update the required details and click Save.
Resend Invitation

Navigate to Partner Users > Actions.
Click Send Invitation on the desired user's entry. A new login invitation will be sent to the user's registered email address.
Disable or Restore a Partner User

Navigate to PARTNER USERS > Actions on the desired user's entry.
Click:
Disable to suspend the account.
Restore to reactivate it.
Reset User Password

Navigate to Partner Users > Actions.
Click Reset Password on the desired user's entry.
Enter the new password and click Reset. The user can now log in using the new password.
The new password needs to be communicated to the user manually through secure channels, as sending passwords over common channels (email, logs) exposes them to interception.
ORGANISATION
Organisations represent individual customer environments managed under partner accounts. Each organisation maps to a single end customer and has its own users, products, and licences.
Partner Admins can transfer organisations between partner accounts. This may be required when a customer is moving from one partner to another. The original partner loses access to the organisation immediately upon transfer.
Transfer an Organisation

Navigate to ORGANISATION.
Select the organisations you wish to transfer by clicking the checkboxes.
Click Transfer Organisation.
Select the destination partner from the dropdown and type
Confirm.Click Submit to complete the transfer.
Organisation details can be viewed at any time by navigating to Actions > View Organisation on the desired entry. For creating and managing organisations, refer to the Partner Portal guide.
DATA TYPES
DATA TYPES define what sensitive data GuardWare scans for within an organisation's environment. Data Type Templates created are visible to all Partner Admins and Partner Users. Templates created at the partner level are not visible upward.
Create a Data Type Template
Navigate to Data Types > Data Type Template and click +New Data Type Template.

If you wish to import configuration from existing templates, select Import Settings and choose an existing template from the dropdown. Otherwise, leave it as is.
Enter a name and short description. Click Continue.

Select the datatypes from the list.
Use the search to find specific datatypes quickly.
Use the filter options to filter datatypes by category in the dropdown (sensitive words, filename expressions, or regex).
Click Save Template to create the new template.

Edit a Data Type Template
Navigate to Data Types > Data Type Templates.
Click to update the template name and description.

Select or unselect datatypes from the list and click Save Template to update changes.

Assign Datatypes to Template

Navigate to Data Types > Data Type Templates.
Click Add Data Type to open the side panel.
Click All and select to assign or unselect to unassign datatypes by clicking the checkbox.
Click Update Template to apply changes.
Click Add Data Type and select Assigned to view datatypes currently assigned, or click Unassigned to view datatypes not assigned to the selected template.
Delete a Data Type Template

Navigate to Data Types > Data Type Templates.
Click to delete the selected template.
Click OK in the new window to confirm.
Data Type
Data types define the specific categories of sensitive information GuardWare scans for within an organisation. Each data type uses one of three detection methods:
Sensitive Words
Sensitive content can be identified by specific words or phrases.
Regular Expressions (regex)
Sensitive content follows a structured format or pattern, such as ID numbers or codes.
Filename Expressions
Sensitivity is indicated by the file's name or naming convention rather than its contents.
Create a New Data Type
Only create a new datatype if the predefined data types in the library don't cover the sensitive data required for your organisation.
Navigate to Data Types > Data Type and click +New Data Type.

Follow the procedures here to create a custom datatype.
Edit a Datatype
Navigate to Data Types > Data Type and click .

Rename the datatype, refine parameters and assign or remove its subtypes the same way as when creating a datatype.
Delete a Datatype
Navigate to Data Types > Data Type and click .

Click Delete to remove the datatype or Cancel to call off the operation.
Data Subtype
Data Subtypes are more specific detection rules that refine parent data types. They help narrow scan results and minimise false positives by adding another layer to data type detection.
Create a New Data Subtype
Only create a new data subtype if the predefined data types in the library don't cover the sensitive data subtype required for your organisation.
Navigate to Data Types > Data Subtype and click +New Data Subtype.
Follow the procedures here to create a custom data subtype.
Edit a Data Subtype
Navigate to Data Types > Data Subtype and click .
Rename the datatype, refine parameters and assign or remove its subtypes the same way as when creating a data subtype.
Delete a Data Subtype
Navigate to Data Types > Data Subtype and click .
Click Delete to remove the datatype.
PROTECT
PROTECT templates define the protection policies applied to an organisation. A PROTECT template is made up of three components: User Policies, Application Settings, and Avoid Folders. Each component is configured independently and combined into a template that can be assigned to one or more organisations.
For detailed guidance, follow the links in each heading to explore the topics.
User policies determine which features and actions are available in the PROTECT Agent, giving administrators control over the end-user experience.
Add a User Policy Template
Navigate to PROTECT > User Policies and click +New User Policy.

Enter Policy Title and Description.
If you want to duplicate a user policy, select the existing policy from the Clone from Existing Policy dropdown.
Enable Detours if you want to prevent protected files opened in Word, Excel, and PowerPoint from being automatically saved and synced to OneDrive or SharePoint.

Configure the user policies by expanding the options

Click Save to apply the configurations.
Edit User Policy
Navigate to PROTECT > User Policies.
Search for the policy and click under ACTIONS.

Update the policy and click Save.
Delete User Policy
Navigate to PROTECT > User Policies.
Search for the policy and click .

Click Delete to remove the policy.
The Application section defines which applications can open, edit, and save protected files. These applications ensure PROTECT can encrypt files when users save or export them in different formats. This ensures only approved applications can access or modify protected content.
Add an Application
Applications are first added to the Application List, which serves as the pool of available application policies.
The Application List contains a set of predefined application policies. Before creating a new one, check whether the application you need is already in the list.
Navigate to PROTECT > Application > Application List.
If the application you need is not in the list, click +New Application.

Enter the executable name, application suite, and folder path.
Define which file extensions the application can encrypt or decrypt.
Enable Network Drive Support if the application needs to access encrypted files on network drives.

Click Save. The application will appear in the Application List.
Edit an Application
Navigate to PROTECT > Application > Application List.
Click on the desired entry to update its details.

Click Save to apply changes.
Delete an Application
Navigate to PROTECT > Application > Application List.
Click to delete the application from the list.

Confirm deletion by clicking Delete.
Create Application Template
Applications can be grouped into a template that can be assigned across organisations.
Navigate to PROTECT > Application > Application Template.
Click +New Application Template.

Enter a Template Name, Description, and click Next.

Select the applications to assign to the template from the list.
Click Save Template.
Edit an Application Template
Navigate to PROTECT > Application Template
Click on the desired entry to update its details.

Click Save to apply changes.
Delete an Application Template
Navigate to PROTECT > Application > Application Template.
Click to remove the application template from the list.

Confirm deletion by clicking Delete.
The Avoid Folders section lets you define directories that can be excluded from encryption. Files stored in these folders will not be encrypted by PROTECT, even if they include sensitive words or match any pre-defined datatype.
The following entries are system-defined and must not be modified or removed:
C:\Users*\AppData
Mandatory App Data
C:\Program Files
Program Files
C:\Program Files (x86)
Program Files (x86)
C:\Windows
Windows
Add an Avoid Folder Directory
If the directory you need is not already in the list, you can add it manually.
Navigate to PROTECT > Avoid Folders > Avoid Folder List.
Click +New Avoid Folder.

Enter a title and the full directory path to exclude from encryption.
In Sub Folders, click + and add a complete path of subfolders within the directory that must continue to be encrypted. These subfolders override the exclusion rule of the folder. Use the + button to add multiple subfolders. While the main directory is excluded from encryption, any subfolder added here will continue to follow normal encryption rules. This allows you to exclude a directory for operational needs while still protecting specific subfolders that contain sensitive or regulated information.
Click Save.
Edit Avoid Folder Directory
Navigate to PROTECT > Avoid Folders > Avoid Folder List.
Click to make changes.
Click Save to apply configurations.
Delete Avoid Folder Directory
Do not delete folders marked 'DO NOT DELETE'. These folders contain files actively used by one or more applications. If deleted, PROTECT will encrypt the folder's contents, causing a significant slowdown. For system folders, encryption may prevent Windows from booting entirely, requiring an external boot drive and manual file restoration to recover.
Navigate to PROTECT > PROTECT Application > Avoid Folder List.
Click to delete the Avoid folder.
Confirm deletion by clicking Delete.
Create Avoid Folder Template
Navigate to PROTECT > Avoid Folders > Avoid Folder Template.
Click +New Avoid Folder Template.
Enter a Template Name, give a short Description and click Next.
Select the avoid folder directories by clicking the checkboxes.
Click Save Template to confirm the assignment.
Edit Avoid Folder Template
Navigate to PROTECT > Avoid Folders > Avoid Folder Template.
Click to make any required changes.
Click Save Template to save changes.
Assign Directories to Avoid Folder Template
Navigate to PROTECT > Avoid Folders > Avoid Folder Template.
Click +Assign to open the side panel.
Click All and select to assign or unselect to unassign directories by clicking the checkbox.
Click Assign to update changes.
Click +Assign and select Assigned to view datatypes currently assigned to the selected template.
Delete Avoid Folder Template
Navigate to PROTECT > Avoid Folders > Avoid Folder Template.
Click to delete the Avoid folder.
Confirm deletion by clicking Delete.
BILLING
The Billing section provides visibility into subscription activity across partners and organisations. It is divided into two areas: Upcoming Alerts and Alert History, allowing you to monitor future billing events as well as review past notifications.
Alert History
The Alert History view provides a record of previously triggered billing alerts. It allows you to audit notifications that have already been sent and verify that alerting is functioning as expected.
Upcoming Alerts
The Upcoming Alerts view lists all subscriptions with approaching billing or expiry dates. This helps you anticipate renewals, track active plans, and take action before deadlines.
You can refine the results using search and filtering options. Filtering is available across two key dimensions:
Partner – to view billing data associated with a specific partner.
Organisation – to narrow down results to a particular organisation.
This enables targeted tracking, especially in environments managing multiple tenants or clients.
LICENCE STATUS
The Licence Status section provides a view of licence allocation and lifecycle state across partners and organisations. It allows Partners and Super Admins to track whether licences are activated, in use, or expired.
This view lists licences for GuardWare products (INSIGHT, DISCOVER, and PROTECT) along with key details such as partner, organisation, product, licence type, status, agent usage, and relevant dates (assigned, activated, and expiry).
Records can be searched directly or filtered by partner, organisation, or licence expiry date to refine results. The status indicates whether a licence is not activated, active, or expired, helping identify unused or expired allocations.
Last updated



