> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/protect/encryption-and-policies/user-policies.md).

# User Policies

User policies determine which features and actions are available in the PROTECT Client, giving administrators control over the end-user experience. These policies define the options that appear in the right-click menu and in dialogs, such as the ability to add file protection to multiple files at once, change or remove file protection, create a ZIP package, etc. Each user can only be assigned one policy at a time.

Any new user who installs GuardWare PROTECT Client and logs in successfully is automatically assigned the Default policy. The Default policy cannot be deleted, but can be edited.

{% hint style="info" %}
End users only see the right-click options that are enabled on their user policy. Any options that are not permitted on the user policy are hidden from end users.
{% endhint %}

## Add a User Policy

Administrators can create custom user policies to align with different roles or departments (e.g., granting more control to IT staff while restricting options for external contractors).

1. Go to **PROTECT > User Policies** and click **+New User Policy**.<br>

   <figure><img src="/files/mteRnMwEoBV2uE4TBRAR" alt=""><figcaption></figcaption></figure>
2. Enter **Policy Title** and **Description**.
3. If you want to duplicate a user policy, select the existing policy from the **Clone from Existing Policy** dropdown.
4. Enable **Detours** if you want to prevent protected files opened in Word, Excel, and PowerPoint from being automatically saved and synced to OneDrive or SharePoint.\
   \
   When Detours is disabled, protected files are synced and stored in SharePoint in an unprotected state when edited, allowing others to download them via a OneDrive or SharePoint link. Detours ensures that the file does not sync throughout the editing process, reducing the risk of unprotected access and distribution.<br>

   <figure><img src="/files/35065e7453c7f4e4fa959ed6258e380b12789123" alt=""><figcaption></figcaption></figure>
5. Configure the following policies and click **Save.**

<table><thead><tr><th width="69.5999755859375">SN</th><th>Policy</th></tr></thead><tbody><tr><td>1</td><td><a href="#id-1.-adding-file-protection">Adding File Protection</a></td></tr><tr><td>2</td><td><a href="#id-2.-removing-file-protection">Removing File Protection</a></td></tr><tr><td>3</td><td><a href="#id-3.-changing-file-protection">Changing File Protection</a></td></tr><tr><td>4</td><td><a href="#id-4.-create-zip-package">Create ZIP Package</a></td></tr><tr><td>5</td><td><a href="#id-5.-sharing-files-using-microsoft-information-protection-mip">Sharing Files Using Microsoft Information Protection (MIP)</a></td></tr><tr><td>6</td><td><a href="#id-6.-sharing-files-as-encrypted-html-file">Sharing Files as Encrypted HTML File</a></td></tr><tr><td>7</td><td><a href="#id-7.-adding-expiry-date">Adding Expiry Date</a></td></tr><tr><td>8</td><td><a href="#id-8.-restricting-circulation">Restricting Circulation</a></td></tr><tr><td>9</td><td><a href="#id-9.-add-protection-to-files-in-folder">Add Protection to Files in Folder</a></td></tr><tr><td>10</td><td><a href="#id-10.-change-protection-added-to-files-in-folder">Change Protection Added to Files In Folder</a></td></tr><tr><td>11</td><td><a href="#id-11.-remove-file-protection">Remove File Protection</a></td></tr><tr><td>12</td><td><a href="#id-12.-disable-folder-rules">Disable Folder Rules</a></td></tr></tbody></table>

### **1. Adding File Protection**

This setting allows users to manually protect files. Users can select a classification label and specify which Security Groups are authorised to access the file.

1. **Ability to Add Protection to Unprotected Files:** Enable this option to allow users to manually protect individual files.
2. **Ability to Add Protection to Multiple Files Simultaneously:** Enable this option to allow users to protect multiple files at once.
3. **Need to Give Reason for Adding Protection to Unprotected Files:** Enable this option if users must provide a justification for adding protection. This helps reviewers understand why the files were protected and supports security audits and compliance requirements.<br>

   <figure><img src="/files/B9CBpaFGrpaeOQnOl5tA" alt=""><figcaption></figcaption></figure>

### **2. Removing File Protection**

This setting allows users to remove protection from a file. Removing a file’s protection clears file classification, Security Group restrictions, circulation restrictions, and all other applied protection.

1. **Ability to Remove File Protection:** Choose whether users are allowed to remove protection from files:
   * **User is unable to remove protection from files**\
     Select this option if users should *never* be able to remove file protection.
   * **User is able to remove protection from all files**\
     Select this option if users are allowed to remove protection from any file.
2. **Ability to Remove Protection from Multiple Files Simultaneously**\
   Enable this option if you want users to remove protection from multiple files at once.
3. **Need to Give a Reason for Removing File Protection**\
   Specify whether a reason is required when users remove protection. This helps reviewers understand why the protection was removed and supports security audits and compliance requirements.
   * **User never has to give a reason**\
     Select this option if no justification is needed when removing protection.
   * **User always has to give a reason**\
     Select this option if users must provide a reason for removing protection.

<figure><img src="/files/a7YyVLCFzzcQjQHDjZdx" alt=""><figcaption></figcaption></figure>

### **3. Changing File Protection**

This setting allows users to change the protection of a file by modifying the classification of protected files and updating the Security Groups that are allowed to access them.

1. **Ability to Change File Protection:** Select whether users are allowed to modify protection settings:
   * **User is unable to change file protection**\
     Select this option if you don’t want to allow users to update the classification or security group settings of any file.
   * **User is able to change the file protection of all files**\
     Select this option if you want to allow users to modify protection on any protected file.
2. **Ability to Change Protection of Multiple Files Simultaneously:** Enable this option if you want users to update protection for multiple files at once.
3. **Need to Give a Reason for Changing File Protection:** Specify whether a reason is required when users change protection. This helps reviewers understand why the protection as changed and supports security audits and compliance requirements.
   * **User never has to give a reason for changing file protection**\
     Select this option if no justification is required.
   * **User always has to give a reason for changing file protection**\
     Select this option if the user must provide a reason for applying changes.

<figure><img src="/files/8k4JhtzYDIZQrClX95wB" alt=""><figcaption></figcaption></figure>

### **4. Create ZIP Package**

This setting allows users to securely share protected files to external recipients who do not have the PROTECT Client installed by creating a password-protected ZIP package.

1. **Ability to Package Files:** Select whether users are allowed to create ZIP packages:
   * **User is unable to package files**\
     Select this option if users are not allowed to share files with third parties by creating ZIP packages.
   * **User is able to package all files**\
     Select this option to allow users to share files as password-protected ZIP packages. 2.
2. **Ability to Package Multiple Files**: Enable this option if you want to allow users to include multiple files in a single ZIP package.
3. **Need to Give a Reason for Packaging Files:** Specify whether a justification is required when users create a ZIP package. This helps reviewers understand why the ZIP package was created and supports security audits and compliance requirements.
   * **User never has to give a reason for packaging files**\
     Select this option if no reason is required when creating a ZIP package.
   * **User always has to give a reason for packaging files**\
     Select this option if a reason must be entered for creating a ZIP package.

<figure><img src="/files/ZTGHz5Ysu0s142Ssx4Pb" alt=""><figcaption></figcaption></figure>

### **5. Sharing Files Using Microsoft Information Protection (MIP)**

This setting allows users to securely share protected files by using **Microsoft Information Protection (MIP)** with recipients who do not have the PROTECT Client installed. When a file is shared using this option, PROTECT’s protection is temporarily removed and replaced with Microsoft Information Protection.

1. **Ability to Share Files Using Microsoft Information Protection**: Choose whether users are allowed to share files using MIP:
   * **User is unable to share files using Microsoft Information Protection**\
     Select this if users should not be able to share files via MIP.
   * **User is able to share all files using Microsoft Information Protection**\
     Select this if users are allowed to share protected files using MIP.
2. **Ability to Share Multiple Files Using Microsoft Information Protection:** Enable this option to allow users to share multiple files at once.
3. **Need to Give a Reason for Sharing Files Using Microsoft Information Protection:** Choose whether users must provide a justification when sharing files. This helps reviewers understand why the files were shared using MIP and supports security audits and compliance requirements.
   * **User never has to give a reason**\
     Select this option if no reason is required when sharing files using MIP.
   * **User always has to give a reason**\
     Select this option if users must enter a reason when sharing files using MIP.

<figure><img src="/files/qy4HbhLj3Iq2OpfuQXzT" alt=""><figcaption></figcaption></figure>

### **6. Sharing Files as Encrypted HTML File**

This setting allows users to convert protected MS Office files and PDFs into **password-protected HTML files** for secure external sharing. This keeps the original file unchanged while applying password-based access control for secure external sharing.

1. **Ability to Share Files as Password-Protected HTML File**: Choose whether users are allowed to export protected files as secure HTML:
   * **User is unable to share files as password-protected HTML file**\
     Select this option if HTML export should be disabled for all users.
   * **User is able to share all files as password-protected HTML file**\
     Select this option to allow users to create secure HTML exports.
2. **Ability to Share Multiple Files as Password-Protected HTML File**: Enable this option to allow users to export multiple files at once.
3. **Need to Give a Reason for Sharing Files as Encrypted HTML File**: Choose whether users must provide a justification. This helps reviewers understand why the HTML file was created and supports security audits and compliance requirements.
   * **User never has to give a reason**\
     Select this option if no reason is required when sharing files using secure HTML.
   * **User always has to give a reason**\
     Select this option if a reason must be entered for generating secure HTML.

<figure><img src="/files/KTwVBigcbiJVHfRijuSr" alt=""><figcaption></figcaption></figure>

### **7. Adding Expiry Date**

This setting allows users to restrict access to a protected file after a specific expiry date. After the expiry date, no users, including the one who set the expiry, can access the file.

{% hint style="info" %}
The device must be able to connect to the PROTECT server for the expiry policy to take effect.
{% endhint %}

1. **Ability to Add an Expiry Date to Files**: Decide whether users are allowed to set expiry dates:
   * **User is unable to add an expiry date to files**\
     Choose this option if expiry control should not be available.
   * **User is able to add an expiry date to all files**\
     Choose this option to allow users to set expiry dates on any protected file.
2. **Need to Give a Reason for Adding an Expiry Date**: Choose whether users must provide a justification when applying an expiry date. This helps reviewers understand why the expiry date was added and supports security audits and compliance requirements.
   * **User never has to give a reason**\
     Select this option if no explanation is required for adding an expiry date.
   * **User always has to give a reason**\
     Select this option if a reason must be entered for adding an expiry date.

<figure><img src="/files/Hm5pTR8RJXCWhAv9gQZS" alt=""><figcaption></figcaption></figure>

### **8. Restricting Circulation**

This setting allows users to prevent other users from expanding access by adding Security Groups. Once circulation is restricted, no one, including users with access, can add new Security Groups or expand who can open the file. This ensures that only the original file owner retains full control over sharing and access.

1. **Ability to Restrict the Circulation of Files**: Choose whether users can apply circulation restrictions:
   * **User is unable to restrict the circulation of files**\
     Select this option if users should not be allowed to restrict access permissions.
   * **User is able to restrict the circulation of all files**\
     Select this option if users are allowed to prevent others from modifying file access
2. **Need to Give a Reason for Restricting the Circulation of Files**: Choose whether users must provide a justification when applying a circulation restriction. This helps reviewers understand why the circulation was restricted and supports security audits and compliance requirements.
   * **User never has to give a reason**\
     Select this option if no explanation is required for restricting circulation.
   * **User always has to give a reason**\
     Select this option if a reason must be entered for restricting circulation.

<figure><img src="/files/SEunkKOZOJfsiXilGvdT" alt=""><figcaption></figcaption></figure>

### **9. Add Protection to Files in Folder**

This setting enables automatic protection to be applied to any unprotected files that are moved or copied into a specific folder. Once enabled, users do not need to manually apply protection to files; the system will do it automatically when a file enters the folder.

1. **Ability to Add Protection to Unprotected Files in the Folder**: Enable this option if you want automatic protection enforcement. When enabled, any unprotected file moved or copied into the folder will automatically have protection applied. This option is useful when a folder is designated as a secure storage area for confidential files.
2. **Need to Give a Reason for Adding Protection to Unprotected Files in Folder:** Enable this option if users must provide a justification when this setting is applied. This helps reviewers understand why the files were protected and supports security audits and compliance requirements.

<figure><img src="/files/eMy6l6G37lzNqTroQjUC" alt=""><figcaption></figcaption></figure>

### **10. Change Protection Added to Files In Folder**

This setting enables automatic protection changes to be applied to files when they are moved or copied into a specific folder. It ensures that any file placed in the folder automatically inherits the folder’s defined protection rules, such as updated classification or security group settings, without requiring manual action from the user.

1. **Ability to Change Protection to Protected Files in the Folder:** Enable this option if you want PROTECT to automatically apply the folder’s protection settings to any files moved or copied into the folder.
2. **Need to Give a Reason for Changing Protection to Added Files in Folder:** Enable this option if users must provide a justification when this setting is applied. This helps reviewers understand why the protection settings were altered and supports security audits and compliance requirements.

<figure><img src="/files/ovdQNp4AhzVG7yyYKLwV" alt=""><figcaption></figcaption></figure>

### **11. Remove File Protection**

This setting enables automatic removal of protection from files when they are moved or copied into a specific folder. It is useful in scenarios where a designated folder is intended for storing or processing files in an unprotected state, for example, for internal reviews, temporary editing, or reclassification.

1. **Ability to Remove Protection to Protected Files in the Folder:** Enable this option to allow automatic removal of protection from files moved or copied into the folder.
2. **Need to Give a Reason for Removing Protection from Files in Folder:** Enable this option if users must provide a justification when applying this setting. This helps reviewers understand why the protection settings were altered and supports security audits and compliance requirements.

<figure><img src="/files/nGJZ8MxbYXQSMz1yOoco" alt=""><figcaption></figcaption></figure>

### **12. Disable Applied Folder Operation**

This setting allows users to remove all automated protection rules and actions previously applied to a specific folder. When this option is enabled, all existing folder-level operations, such as automatic Add Protection, Change Protection, or Remove Protection, will be deleted. However, the existing files in the folder remain unchanged. **This will remove protection from the folder only, not from the files it contains.**

1. **Ability to disable applied folder operation:** Enable this option to remove all folder-level protection and automation rules.
2. **Need to Give a Reason for Removing Folder Operation:** Enable this option if users must provide a justification when this setting is applied. This helps reviewers understand why the protection settings were altered and supports security audits and compliance requirements.

<figure><img src="/files/FxCrOq1NpwctW7PpjLJl" alt=""><figcaption></figcaption></figure>

## Edit User Policy

1. Go to **PROTECT > User Policies**.
2. Search for the policy to edit and click the **Edit** icon under **ACTIONS**.<br>

   <figure><img src="/files/hGR7gJZIZjKyWslBAPBp" alt=""><figcaption></figcaption></figure>
3. Update the policy and click **Save**.

## Assign Users to User Policy

1. Go to **PROTECT > User Policies**.
2. Search for the policy to assign and click **Assign User** under **ACTIONS**.<br>

   <figure><img src="/files/3vSAxfgEt7v1pin7Biwt" alt=""><figcaption></figcaption></figure>
3. Search and select the users you want to assign the policy to, and click **Assign Users**. If the user already has a policy, it is replaced with the new one.<br>

   <figure><img src="/files/dfdc8da3f2a604dad580975fbc28246b64a1f8c8" alt=""><figcaption></figcaption></figure>
4. Click **Ok** in the Alert.

## Change User’s Policy

1. Go to **PROTECT > User Policies**.
2. Click **Users**.
3. Search and select the user whose policy you want to change, and click **Change Policy**.<br>

   <figure><img src="/files/K7mm22h1mZOVMYo1Q5mN" alt=""><figcaption></figcaption></figure>
4. Select the new policy and click **Assign**.<br>

   <figure><img src="/files/29b6bc81d9be395305f873b9a2ff582bb59bc9d3" alt="" width="563"><figcaption></figcaption></figure>

## Delete User Policy

1. Go to **PROTECT > User Policies**.
2. Search for the policy to edit and click the **Delete** icon under **ACTIONS**.

   <figure><img src="/files/UK2fe1Kiihxv4j31OwRd" alt=""><figcaption></figcaption></figure>
3. Click **Delete** in the confirmation alert.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/protect/encryption-and-policies/user-policies.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
