Normal Windows users work with business files. A separately authenticated RivoShield administrator controls protected scope, protection state, Archive/Unarchive, license import and audit clearing after export.

1. Add a protected location

Authenticate, open Protected Locations and select Add Folder for a business folder or Add Drive for a non-system data drive. Critical operating-system locations and the Windows system-drive root are rejected.

2. Verify with disposable data

Create, save and reopen a test file. Attempt deletion and confirm the file physically remains. Protection should not replace the customer's normal permissions with SYSTEM/Administrators-only access.

3. Archive completed work

Close applications using the folder, authenticate and choose Archive. Confirm the ARCHIVED state, then verify view and copy-out work while create, edit, overwrite, rename, move and delete are blocked.

4. Unarchive when editing resumes

Authenticate and select Unarchive. Normal create/edit/save behaviour returns while delete protection remains enabled.

5. Review and preserve audit evidence

Search relevant activity, export CSV for readable reporting or JSONL for complete machine-readable evidence, and keep it in an approved location. Clear only after export and administrator authentication.

6. Verify after change or restart

Check service and filesystem protection health, protected-location visibility, archive state, a disposable delete attempt, normal edit/save/reopen and a current audit event.