I think you are misunderstanding the concept of protection. The user does not protect or unprotect anything - the system does all the protection and unprotection behind the scenes depending on the run-time conditions. So it is your responsibility as a configurator to provide protection rules according to the requirements of your system.
You have to provide conditions under which protection will happen. Consequently the reverse of these conditions is when the protection won't happen and so records will be "unprotected". For example, you can define a rule that looks like this:
If Transaction.Status = 'Completed' Then
PROTECT Transaction.Balance FROM ALL
Whenever a status of the transaction becomes "completed", the balance attribute becomes read-only (protected). It is unprotected if the status is anything else.