> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/training-centre/self-paced-video-training/guardware-insight-video-guide.md).

# GuardWare INSIGHT Video Guide

Learn GuardWare INSIGHT through structured video tutorials.

GuardWare INSIGHT provides visibility into how sensitive information is accessed, used and moved across Microsoft 365, endpoints, email, web applications, removable media, printing and AI tools.

The purpose of this training is to teach participants how to:

* Understand the role of INSIGHT within GuardWare’s data-centric security platform.
* Recognise the data movement activities monitored by INSIGHT.
* Navigate the INSIGHT management environment.
* Deploy and validate endpoint and Microsoft 365 monitoring.
* Review and investigate data-handling events.
* Configure monitoring rules, alerts and appropriate responses.
* Identify shadow AI and sensitive information entered into AI tools.
* Use contextual user education to improve employee behaviour.
* Establish an ongoing operational monitoring and reporting process.

INSIGHT is designed to work alongside existing security and DLP investments by addressing visibility gaps across channels including endpoints, AI tools, personal cloud services, remote-working environments and shadow IT.

### Course Information

<table data-header-hidden><thead><tr><th width="163.20001220703125">Field</th><th>Value</th></tr></thead><tbody><tr><td>Duration</td><td>1 hour</td></tr><tr><td>Format</td><td>Self-paced video tutorials</td></tr><tr><td>Skill level</td><td>Beginner to Intermediate</td></tr><tr><td>Prerequisites</td><td>Basic system administration knowledge</td></tr></tbody></table>

### Course Outline

<table><thead><tr><th width="116.800048828125">Session</th><th>Topic</th></tr></thead><tbody><tr><td>1</td><td><a href="#session-1-creating-user-policies">Creating User Policies</a></td></tr><tr><td>2</td><td><a href="#session-2-configuring-advanced-settings">Configuring Advanced Settings</a></td></tr><tr><td>3</td><td><a href="#session-3-understanding-risk-definitions">Understanding Risk Definitions</a></td></tr><tr><td>4</td><td><a href="#session-4-organisation-settings">Organisation Settings</a></td></tr><tr><td>5</td><td><a href="#session-5-setting-up-cloud-monitor">Setting up Cloud Monitor</a></td></tr><tr><td>6</td><td><a href="#session-6-insight-devices">INSIGHT Devices</a></td></tr><tr><td>7</td><td><a href="#session-7-insight-dashboard">INSIGHT Dashboard</a></td></tr><tr><td>8</td><td><a href="#session-8-configuring-insight-reports">Configuring INSIGHT Reports</a></td></tr></tbody></table>

### Session 1: Creating User Policies

User Policies define how GuardWare INSIGHT monitors, alerts on, and controls user activity involving sensitive information. They allow organisations to apply different monitoring and protection settings to different users or groups based on their roles, risk levels, and business requirements.

**This session explains:**

* What User Policies are
* Creating a User Policy and importing settings from an existing policy
* Configuring application, website, USB, and network monitoring
* Enabling archive file scanning, OCR detection, and document and email classification
* Adding Data Types with **Block**, **Monitor**, and **Warn** actions
* Assigning policies to users and Security Groups
* Viewing, editing, and deleting User Policies

{% embed url="<https://youtu.be/dB8_RXfGDXU?si=t6UxLnSRl13VZ2ni>" %}

### Session 2: Configuring Advanced Settings

Advanced Settings define the global monitoring configuration that controls how GuardWare INSIGHT captures user activity and monitors the movement of sensitive information across endpoints. They provide organisation-wide settings that complement User Policies and ensure consistent monitoring behaviour across managed devices.

**This session explains:**

* What Advanced Settings are
* Creating an Advanced Setting, including copying an existing configuration and setting a default policy
* Configuring environment, browser, USB, file system, and client responsiveness settings
* Managing monitored and excluded applications, websites, IP addresses, and file extensions
* Configuring Chromium extension monitoring, keystroke monitoring, copy and paste monitoring, and encrypted website monitoring
* Assigning Advanced Settings to devices
* Viewing, editing, and deleting Advanced Settings

{% embed url="<https://youtu.be/jBxExdxOQSM?si=txNDVuFIBAoIboB9>" %}

### Session 3: Understanding Risk Definitions

Risk Definitions determine how GuardWare INSIGHT assesses and categorises the severity of user activity across the organisation. They help organisations prioritise potentially risky activities across areas such as SharePoint, email, storage devices, printing, and AI tool usage.

GuardWare INSIGHT uses these risk levels to automatically score activities, helping organisations prioritise incidents that require attention without having to manually review every event.

**This session explains:**

* Understanding the six risk levels, from **No Risk** through **Highest**
* Reviewing the thirteen activity categories, including SharePoint External, SharePoint Internal, Email, Storage Device Risk, Printing Incidents, Keystroke Capture, Copy Paste, and Usage of AI Tools
* Navigating each category's submenu to review the specific activities and their assigned risk levels
* Changing default risk levels to match your organisation's requirements
* Saving updated Risk Definitions and understanding how the changes are reflected in the **Incident Risks** dashboard

{% embed url="<https://youtu.be/jF3PeOiZMpw?si=wmhDaDXsgxptDZ63>" %}

### Session 4: Organisation Settings

Organisation Settings define how GuardWare INSIGHT classifies and manages resources across the organisation, including websites, applications, printers, USB devices, email domains, AI tools, and SharePoint resources. These classifications help INSIGHT accurately interpret user activity and apply the appropriate monitoring and risk evaluation.

**This session explains:**

* Configuring **Working Days**, the setting that is configured directly rather than populated through user activity
* Understanding how **Printers, Websites, Applications, USBs, AI Usages, and SharePoint** are populated automatically as users interact with them, and how to classify these resources
* Classifying **Email Domains** as Organisational, Insecure, or Undefined
* Manually classifying **AI Websites and AI Applications**, as AI tools are not detected automatically
* Marking **SharePoint libraries** as Sensitive or Undefined
* Adding and removing **Trusted Emails and OneDrive Folders**, which are configured directly rather than populated through user activity

GuardWare INSIGHT uses these classifications to improve monitoring accuracy, reporting, and risk evaluation across the organisation.

{% embed url="<https://youtu.be/0KMlG5VPuiw?si=m6cVPKaBSx0GZjvx>" %}

#### Session 5: Setting up Cloud Monitor

Cloud Monitor enables GuardWare INSIGHT to monitor user activity and data movement across Microsoft 365 and Google Workspace environments. It provides visibility into cloud-based services such as email, file storage, and collaboration platforms, helping organisations extend monitoring beyond endpoint devices.

**This session explains:**

* Connecting **Microsoft 365** using a **Global Administrator** account, which is required for Cloud Monitor functionality
* Connecting **Google Workspace**, including the prerequisite configuration of a Google Service Account
* Enabling monitoring for **Exchange**, **SharePoint**, **Gmail**, and **Google Drive**
* Assigning users for **Exchange** and **Gmail** monitoring
* Performing manual synchronisation of Microsoft 365 data
* Assigning **Data Types** to define what Cloud Monitor monitors within SharePoint
* Understanding where Exchange, Gmail, SharePoint, and Google Drive activities are displayed within the INSIGHT dashboard

Cloud Monitor provides centralised visibility into cloud activity, helping organisations monitor sensitive information, identify risky behaviour, and investigate incidents across their Microsoft 365 and Google Workspace environments.

{% embed url="<https://youtu.be/YmFjlqtOHEk?si=VonEb-_Yqy1iwxhC>" %}

#### Session 6: INSIGHT Devices

INSIGHT Devices provides a centralised view of all endpoints running the GuardWare INSIGHT Agent. It enables administrators to monitor device status, manage endpoint configurations, and perform administrative actions directly from the Management Console.

**This session explains:**

* Viewing device status and inventory information, including hardware details, installed software, and agent versions
* Assigning **Advanced Settings** to control device monitoring behaviour and policies
* Sending endpoint commands, including **Update Client** and **Uninstall Client**
* Managing device logs through **Maintenance Mode**, including enabling logging, disabling logging, and retrieving log files
* Viewing detailed device and agent information from the Management Console
* Updating or uninstalling the INSIGHT Agent directly from the device management interface

INSIGHT Devices gives administrators complete visibility and control over monitored endpoints, helping ensure consistent policy enforcement, efficient troubleshooting, and effective device management across the organisation.

{% embed url="<https://youtu.be/0huzgLlQ7XY?si=0PK9zSg-n8yaGbAL>" %}

#### Session 7: INSIGHT Dashboard

The INSIGHT Dashboard provides a centralised view of user activity, data movement, and risk across the organisation. By bringing together endpoint, cloud, and behavioural monitoring data, it helps administrators and security teams identify unusual activity, investigate incidents, and gain actionable insights from a single interface.

**This session explains:**

* Navigating the risk category tabs: **Risk Summary**, **Data Type Risks**, **SharePoint Risks**, **AI Usage Risks**, **Behaviour Risks**, **Label Events**, **Location Risks**, **Protected Files**, and **System Risks**
* Understanding dashboard widgets, from high-level summary views to detailed incident records
* Interpreting colour-coded risk levels and their relationship to configured **Risk Definitions**
* Exporting dashboard data to **Excel** or **PDF** for reporting and analysis
* Creating **Custom Dashboards** focused on specific devices, users, data types, or risk categories
* Viewing, editing, deleting, and switching between dashboards

The INSIGHT Dashboard transforms monitoring data into meaningful insights, enabling organisations to quickly identify risks, investigate incidents, and make informed security decisions.

{% embed url="<https://youtu.be/5smUdy_ckuU?si=x4nDblwk8RuNj4Y9>" %}

#### Session 8: Configuring INSIGHT Reports

Reports in GuardWare INSIGHT deliver risk and activity information to the right stakeholders automatically, reducing the need for manual dashboard reviews. They help security teams, managers, and end users stay informed about risky behaviour through scheduled and customised reporting.

**This session explains:**

* Configuring the **Risk Summary Report**, which provides an organisation-wide overview of risky activities for security teams
* Configuring the **User-Based Risk Report**, designed to track risk trends and incident activity for specific users
* Configuring the **Cyber Awareness Report**, which is sent directly to end users with information and guidance related to their own activities
* Setting **Incident Thresholds**, **Data Type Occurrence Thresholds**, and **Duration Thresholds** to determine when reports are generated
* Customising report branding and content, including cover images, introductory messages, footers, and privacy statements
* Sending test emails to preview report content before deployment
* Enabling, editing, and deleting report configurations

INSIGHT Reports ensure that critical risk information is delivered automatically and consistently, helping organisations improve visibility, strengthen security awareness, and support proactive risk management.

{% embed url="<https://youtu.be/IZZkqrAmNYs?si=qQjlPaugGCCAVr2K>" %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/training-centre/self-paced-video-training/guardware-insight-video-guide.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
