> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/protect/protect-features/protect-features.md).

# PROTECT Features

As an end user, you interact with **GuardWare PROTECT Agent** through the Windows Explorer right-click menu. From there, you can protect sensitive files by setting classifications, restricting access to specific Security Groups, limiting file circulation, adding an expiry date, and so on.

### **Add File Protection**

Adding file protection encrypts the file and allows access only to the selected [Security Groups](/protect/users-and-devices/security-groups.md). Adding protection ensures that sensitive files remain accessible only to authorised users, supporting organisational security policies and reducing the risk of accidental or deliberate data leaks or theft. It allows you to manage how information is accessed, shared, and used across your organisation.

**To add protection to a file:**

1. Right-click the file in Windows Explorer and click **Show more options**.

<div align="left"><figure><img src="/files/rwotl4mJXt4AWoPp6klp" alt="" width="182"><figcaption></figcaption></figure></div>

2. Click **GuardWare PROTECT** > **Add Protection**.

<div align="left"><figure><img src="/files/7a4e1d147542993c8008f8783d8b23962c57b4c7" alt="" width="375"><figcaption></figcaption></figure></div>

3. Select the **File Classification**. \
   File classification defines the sensitivity level of the file and also determines whether the file is protected using only MIP or both MIP and GuardWare PROTECT. \
   Contact your administrator to find out which protection mode is assigned to each file classification.
4. Select the **Security Groups** that are authorised to access the file.
5. Provide a reason for adding protection and click **Submit**. Your reason explains why the action was taken and supports audits or incident investigations.
6. Click **Exit** to close the window.

<div align="left"><img src="/files/4f7da7aa74162bc6634c5610f7f663f343310049" alt="" width="563"></div>

When opening a protected file, GuardWare PROTECT verifies your **Security Group**. If you’re in the authorised Security Group, the file is decrypted; else, access is denied, and you will see a lock icon.

Files show an icon overlay to indicate protection. By default, the colour and classification are set as follows, but administrators can customise both according to their needs, so the overlays may differ depending on your system setup.

* **Blue**: *Internal* (default)
* **Red**: *Confidential*
* **Yellow**: *Sensitive*
* **Black**: *Not accessible* (you are not authorised to access the file.)

{% hint style="info" %}
If multiple files are selected, protection is applied only to those that are not already protected.
{% endhint %}

### **Remove File Protection**

Removing a file’s protection clears file classification, Security Group restrictions, circulation restrictions, and all other applied protection, so the file behaves like a standard, unprotected document.

Removing file protection is recommended when it no longer requires special access controls and when the content is no longer sensitive or needs to be widely shared. Once protection is removed, all users can freely access, edit, and share the file without restrictions.

**To remove protection from a file:**

1. Right-click the file in Windows Explorer and click **Show more options**.
2. Click **GuardWare PROTECT** > **Remove Protection**.

<div align="left"><figure><img src="/files/c63bb200f014ce303e1c64430168ef597ab0667c" alt="" width="375"><figcaption></figcaption></figure></div>

3. Provide a reason for removing protection and click **Submit**. Your reason explains why the action was taken and supports audits or incident investigations.
4. Click **Exit** to close the window.

<div align="left"><img src="/files/c44ebf5894e8e47739c70de5bcbb0ba48ba6dd92" alt="" width="563"></div>

### **Change File Protection**

Changing file protection allows you to update the file classification and the Security Groups that can access the file. Changing a file’s protection ensures that the file’s security and access controls remain accurate as the file’s content or context changes over time.

For example, a confidential file about a takeover bid might be initially classified as **Internal Only** because it contains a customer’s phone number. However, a user who understands the file’s true content can reclassify it as Restricted and also change the Security Groups that can access it to prevent misuse. By changing protection, files always reflect the right level of security.

**To change the protection of a file:**

1. Right-click the file in Windows Explorer and click **Show more options**.
2. Click **GuardWare PROTECT** > **Change Protection**.

<div align="left"><figure><img src="/files/14d32ce5a9e4be815b06b1d85e3464310a04eeb6" alt="" width="375"><figcaption></figcaption></figure></div>

3. Select a **File classification**. \
   File classification defines the sensitivity level of the file and also determines whether the file is protected using only MIP or both MIP and GuardWare PROTECT. \
   Contact your administrator to find out which protection mode is assigned to each file classification.
4. Select **Security Groups**. Security Groups determine who can access the file once protection is applied. Only members of these groups can access the file; others are restricted.
5. Provide a reason for changing protection and click **Submit**. Your reason explains why the action was taken and supports audits or incident investigations.
6. Click **Exit** to close the window.

<div align="left"><img src="/files/edfc569d761e5bb36a00de0c1a030d11b6aa4a15" alt="" width="563"></div>

### **Create Zip Package**

Creating a Zip package securely bundles selected files into a single, password-protected package. This ensures sensitive files can be shared securely, as recipients must enter the separately shared password to access the contents. This option is useful for files that are not Office documents or cannot be shared through other protection methods, and for sharing files with users who do not have GuardWare PROTECT installed. In such cases, the files’ protection can be temporarily removed and secured within the password-protected Zip package.

**To create a Zip package:**

1. Select the files you want to zip, right-click, and click **Show more options**.
2. Click **GuardWare PROTECT** > **Share Files > Create Zip Package**.

<div align="left"><figure><img src="/files/b5860c8a25de64bab17b20d213bfc0ea18d80aee" alt="" width="375"><figcaption></figcaption></figure></div>

3. Select a folder path to save the Zip package.
4. Provide a reason for creating the Zip package and click **Submit**. Your reason explains why the action was taken and supports audits or incident investigations.

<div align="left"><img src="/files/4c832bf4a2b81be4e690e9ff268756fc56f8cfab" alt="" width="563"></div>

5. You’ll see the password for the Zip package on the dialog screen. **Copy and save the password** in a secure location, as you will not be able to access it after you close the dialog. Anyone who needs to access the Zip package will require the password. Share the password separately when sharing the Zip package. For example, share the Zip package in an email and password through instant messaging apps.

<div align="left"><img src="/files/7806ac2c0e5dee03f1afae97d43b7f597a8fc859" alt="" width="563"></div>

6. Click **Exit** to close the window.

### **Share Using Microsoft IP**

PROTECT integrates with Microsoft Information Protection (MIP) to let you securely share protected MS Office documents and PDFs with chosen recipients while maintaining control over their access.

An active internet connection is required to share the files using MIP.&#x20;

{% hint style="info" %}
When users open a file shared using MIP, they’ll be prompted to sign in with a Microsoft account that has permission to access it. If they don’t have the required permissions, access will be denied.
{% endhint %}

**To share a file using MIP:**

1. Right-click the file in Windows Explorer and click **Show more options**.
2. Click **GuardWare PROTECT** > **Share Files > Share Using Microsoft IP**.

<div align="left"><figure><img src="/files/806f4c68eb8d691ded87e082c646fa5eab76d849" alt="" width="375"><figcaption></figcaption></figure></div>

3. Enter the email addresses of the users you want to share the protected file with. Only the specified recipients will receive access. You can add multiple addresses separated by commas.
4. Enable **Also send email to entered email addresses** to email a copy of the new MIP-protected file to the specified recipients. When you enable this option and submit, you’ll be prompted to choose your email service provider application, from which you can manually send the email.<br>

   <div align="left"><figure><img src="/files/67964f7e844a117d66a19131658b37eb8c81540b" alt="" width="188"><figcaption></figcaption></figure></div>
5. In the **Select protection level,** choose how recipients can use the file (e.g., *View only, Edit, Comment, and Full access*). This allows you to control the degree of access granted.
6. Set an expiry date to automatically revoke access after a specific time. Once expired, no one can view or use the file.
7. Provide a reason for sharing the file using MIP and click **Submit**. Your reason explains why the action was taken and supports audits or incident investigations.
8. Click **Exit** to close the window.

<div align="left"><img src="/files/690cd58ed0af2561fad0096777a77f9efd624ad2" alt="" width="563"></div>

### **Share Using Secure HTML**

Creating secure HTML files converts MS Office documents and PDFs into password-protected HTML files, preventing unauthorised access. When this option is selected, a new HTML file is created; the original file remains unchanged. Anyone who needs to access the HTML file will require the password.&#x20;

{% hint style="info" %}
You cannot create a secure HTML file for files protected only by MIP. Secure HTML can be created only for files protected by both MIP and PROTECT.
{% endhint %}

**To create a secure HTML file:**

1. Right-click the file in Windows Explorer and click **Show more options**.
2. Click **GuardWare PROTECT** > **Share Files > Secure HTML**.<br>

   <figure><img src="/files/eMekAeYQJMdVg2oGpEXA" alt=""><figcaption></figcaption></figure>
3. Enter the email addresses of the users you want to share the protected file with. Only the specified recipients will receive access. You can add multiple addresses separated by commas.
4. Enable **Also send email to entered email addresses** to email a copy of the new secure HTML file and the password to the specified recipients. When you enable this option and submit, you’ll be prompted to choose your email service provider application, from which you can manually send the email.
5. Select the folder where the secure HTML file will be created.
6. Provide a reason for creating the secure HTML file and click **Submit**. Your reason explains why the action was taken and supports audits or incident investigations.<br>

   <figure><img src="/files/G7EyRXV5oA732dJMI42u" alt=""><figcaption></figcaption></figure>
7. You’ll see the password for the secure HTML file on the dialog screen. **Copy and save the password** in a secure location, as you will not be able to access it after you close the dialog. Share the password separately when sharing the HTML file. For example, share the HTML file via email and the password through instant messaging apps.
8. Click **Exit** to close the window.

You can also select multiple files and create secure HTML files at once. The password will be the same for all HTML files.

### **Add Expiry Date**

Adding an expiry date automatically revokes access to the file after the specified time. Once expired, no one can view or use the file. An active internet connection is required to decrypt a file before expiry.

**To add an expiry date:**

1. Right-click the file in Windows Explorer and click **Show more options**.
2. Click **GuardWare PROTECT** > **Add Expiry Date**.

<div align="left"><figure><img src="/files/b46e9a36d4e5ee884651dce799c5390c6560a85e" alt="" width="375"><figcaption></figcaption></figure></div>

3. Select an expiry date, provide a reason for adding the expiry date, and click **Submit**.\
   A new file with the extension ***.restricted*** is created, and the expiry date applies only to the new file, while the original file remains unchanged.

<div align="left"><img src="/files/23d1270f44ee11f0b4b4c464ae2ca4a3348e4dd8" alt="" width="563"></div>

4. Click **Exit** to close the window.

### **Restrict Circulation**

Restricting circulation prevents other users from changing access permissions, i.e., adding Security Groups (and therefore users) who can access the file. This makes sure that only the file owner can manage sharing and access.

A new file with the extension ***.restricted*** is created, and the restriction applies only to this new file, while the original file remains unchanged. Authorised recipients can view/decrypt the restricted file.

**To restrict circulation:**

1. Right-click the file in Windows Explorer and click **Show more options**.
2. Click **GuardWare PROTECT** > **Restrict Circulation**.

<div align="left"><figure><img src="/files/fa7ecac4f3cba86ea68819ac045080f7da3a139e" alt="" width="375"><figcaption></figcaption></figure></div>

3. Provide a reason for restricting circulation and click **Submit**.\
   A new file with the extension ***.restricted*** is created, and the restriction applies only to this new file, while the original file remains unchanged. Authorised recipients can view/decrypt the restricted file; however, they cannot change the access permissions.
4. Click **Exit** to close the window.

### **File Information**

File Information displays the protection applied to the file, including its classification, assigned Security Groups, expiry date, and all active restrictions.

To access file information: Right-click the file in Windows Explorer > **Show more options** > **GuardWare PROTECT > File Information**.

<img src="/files/899971738dbcee685514bf739485edc3d2b507b3" alt="" width="375">

### **PROTECT Usage Profile**

PROTECT Usage Profile provides information on the user’s Security Groups and usage policies that define which features are available to them. This helps users understand their access level and the permissions they have.

To access this PROTECT Usage Profile:

1. Right-click the file in Windows Explorer and click **Show more options.**
2. Click **GuardWare PROTECT > PROTECT Usage Profile**.

<div align="left"><figure><img src="/files/6d0c7ed3acd20e988d8169d6e5cbb8a14323b7b0" alt="" width="375"><figcaption></figcaption></figure></div>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/protect/protect-features/protect-features.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
