Fortinet's documentation is pretty good, you can have a look at it:
https://docs.fortinet.com/forticlient/admin-guides
https://docs.fortinet.com/d/forticlient-6.0.0-xml-reference
A very useful under-the-hood setting is <popup_registry_alerts>0</popup_registry_alerts>. If you set it to 1, FortiClient displays alerts if a process tries to change registry start items.
Everyone here said FortiClient shouldn't be tested alone, but at least with SysHardened (if not with OSArmor). It would be nice if
@MoriartyOW could make some tests with FC + SH (as
@Evjl's Rain usually does with Avast).
I think SH would have picked the missed samples of this test
https://malwaretips.com/threads/30-08-2018-21.86368/ and the setting I wrote above should have prevented the items set on startup (you can see them in Autoruns and Process Explorer)