Using the methods already covered on this page, a sensible workflow starts with the threat you are trying to address rather than with the software name. That keeps the protection proportional to the risk and avoids adding unnecessary complexity.
Decide whether you need confidentiality or control.
If unauthorized users must not read the files, encryption is the relevant approach. If trusted users only need to be prevented from editing or deleting files, access control may be enough.
Choose the protection format.
A commercial locker is the convenience-focused choice described here, while VeraCrypt is the container-based alternative for users who prefer a more manual encrypted-volume workflow.
Protect the password as carefully as the folder.
The FAQ material on this page repeatedly points to human weaknesses—especially weak or exposed passwords—as a practical route around otherwise strong encryption.
Plan for cloud or mobile access before you move the files.
If you intend to use Dropbox, Google Drive, OneDrive, iOS, or Android, use a workflow designed to keep the protected data synchronized rather than copying unencrypted versions between devices.
Test recovery and access before relying on the setup.
Make sure you can open the protected folder, mount the volume, or use the mobile workflow successfully before deleting any original working copy that you still need.