Choose the right test mode
For a normal profile containing an active rule, save your settings and choose Test monitoring (no actions) from the tray. It starts a test cycle using simulated responses. Stop it with Stop dry run when finished.
For a locked-only setup, or to test automatic enabling over an entire launch, exit the regular app first and use the supplied Test monitoring.cmd. It starts the whole application in dry-run mode. Starting that command while another copy is already running does not convert the existing process into a dry run. Confirm the test indication before proceeding.
Record one clear experiment
- Under General, enable Record event history. Choose how many recent entries to keep, from 100 to 5,000.
- Configure one target event and set unrelated actions to Do nothing.
- Save, start the appropriate dry run and reproduce the event once.
- For a locked rule, lock Windows normally, perform the harmless test and sign back in.
- Open Event history from the tray or General → View history. Check the event, profile, chosen action and dry-run result.
Read the result accurately
A dock can create USB and display events together. A locked Do nothing can suppress a normal action. A sign-in can end normal monitoring. History helps separate these cases; it records events and response requests, not the keys you type or screenshots.
An accepted real Windows request does not prove the action completed. History writes run in the background, so crashes, power loss or disk problems can lose recent entries. It is local diagnostic history, not a tamper-proof audit record.
Move from simulation to a real check
End the dry run, review the saved profile and save your work before a controlled real-action test in an activated release. Preview builds always simulate actions. Start with input locking before evaluating USB shutdown or other disruptive responses.