The requests need to be approved in the following scenarios:
Access requests require approval by the responsible attorney or the Administrator (Security Policy: Restricted)
Access requests require approval by an administrator (Security Policy: Restricted)
Access requests require approval by any member of the matter team or the administrator (Security Policy: Restricted)
NOTE: For matters restricted by client or client group, "the administrator" refers to the client or client-group administrator, not the matter administrator. If you administer only the matter (not its parent client or client group), access requests for that matter won't route to you.
NOTE: Only Team Members can approve access requests, alongside the responsible attorney, the matter administrator, or—for client- or client-group-restricted matters—the client or client-group administrator. Basic Team Members aren't eligible approvers—including users who are Basic Team Members by virtue of group membership—even when the matter is configured for approval by any member of the team or an administrator. (Basic Team Members also don't receive access request notifications.)
NOTE: A user who submits an access request on behalf of another user or group is still the requester, and can't approve that request themselves—even if they would otherwise be an eligible approver.
TIP: Access renewal requests also appear as access requests: the difference is that when reviewing such requests, the Set Access Period field is pre-filled in accordance with the requested renewal period. For more information about renewal requests, refer to Viewing assets and their access periods.
If you are the assigned 'responsible attorney' for the matter, or the matter administrator, or a member of the matter team, you can approve the user access requests.
You can approve/reject access requests in two ways:
NOTE: When you approve a request for access to a matter that's restricted by client, iManage SPM grants access to every matter secured by that client—not just the one requested. You'll now see a clear warning wherever you are asked to approve these requests: in the approval notification email, in the approval dialog, and when using Quick Approve. The warning tells you when your approval will grant client-level access, and to which client that access is approved, so you can confirm that's what you intend before approving.
This warning only appears when the matter you're approving is restricted by client. Approvals for matters without a client-level restriction are unaffected.
Option 1: From the email notification
When a user requests for access to a matter or a case, you (approver) receive an email notification. Based on the notification mode set by your system administrator, you'll receive one of the three predefined email notifications. Based on the email notification received, you can act upon the access request from the email in one of the following ways:
You access the email through a web client or mobile client, and you are required to securely access the iManage Security Policy Manager application to act on the request. The link in the email guides you to the Manage Access Requests page in iManage Security Policy Manager. For more information on how to act upon the request from the Manage Access Requests page, see Option 2: From the iManage Security Policy Manager User Console.
You access the email through a web client or mobile client, which contains tokenized links (Approve as Team Member, Approve as Basic Team Member, Deny Access Request). Selecting any link sends your response directly to iManage Security Policy Manager. The user gets unlimited period access, if approved. To update user type and access period, select Open Security Policy Manager to set the User Type and Access Period link in the notification.
You access the email through an email client, which contains tokenized links (Approve as Team Member, Approve as Basic Team Member, Deny Access Request). This configuration mode enables you to respond to the request offline. Selecting any link creates a response email and the response is sent to iManage Security Policy Manager when the internet becomes accessible. The user gets unlimited period access, if approved. To update user type and access period, select Open Security Policy Manager to set the User Type and Access Period link in the notification.
NOTE: Your system administrator may choose not to enable email notification mode. In such a case, you don't receive email notifications and you have to access the iManage Security Policy Manager application to act upon the access requests.
Option 2: From the iManage Security Policy Manager User Console
After you are logged in to the iManage Security Policy Manager application, select the Access Requests tab > Manage Access Requests tab.
The Manage Access Requests page, with the list of pending approval requests, is displayed.
NOTE:
For all the matters that are restricted by client, the system displays the client details.
For all the matters, where the parent client is part of a client group, the system displays the client group details.
You can customize the columns to be displayed on the page. Select the ellipsis/kebab button at the top right of the pane, and then select the table columns to be displayed. The available options are: User, ID / Name, Job Title, Practice Area, Request Date, Reason. Any columns which are already selected for display are shown in bold, with a checkmark beside them.
You can sort the rows displayed by selecting the column heading (for example, Reason), which will display a small arrowhead to the right of the column heading. Select this arrowhead to sort the column by the values under that heading.
If an access request has been made on behalf of a user or group, by another user, a note "Access request submitted by <user>" appears below the reason (if that column is displayed).
Select Update to refresh the list of displayed access requests.
TIP: Access renewal requests also appear as access requests: the difference is that when reviewing such requests, the Set Access Period field is pre-filled in accordance with the requested renewal period. For more information about renewal requests, refer to Viewing assets and their access periods.
Select the request row or select the check box next to a user.
Select Quick Approve (if available) to add the user directly as a team member for an unlimited access period.
(Or)Select Approve. The Approve dialog is displayed.
In the User Type field, select one of the option to add the user as a Team Member or a Basic Team Member.
In the Set Access Period field, select one of the option to provide access for unlimited period or a defined period.
If you choose Access Period is Time Limited,
From the date picker, select the date and time up to which you want to provide access to the user. If you don't specify a time, then the system will default the time to midnight in the time zone of the server.
Select Submit. The access duration is set for the user.
Select Deny to reject the request for access from the user.
Alternatively,
Select the ellipsis/kebab button in the request row, then:
Select View Reason to see the reason entered by the requestor for placing the access request.
Select Quick Approve (if available) to add the user directly as a team member for an unlimited access period.
(Or)Select Approve. The Approve dialog is displayed.
In the User Type field, select one of the option to add the user as a Team Member or a Basic Team Member.
In the Set Access Period field, select one of the option to provide access for unlimited period or a defined period.
If you choose Access Period is Time Limited,
From the date picker, select the date and time up to which you want to provide access to the user. If you don't specify a time, then the system will default the time to midnight in the time zone of the server.
Select Submit. The access duration is set for the user.
Select Deny to reject the request for access from the user.
or
If you want to directly add the user to the client/matter team, hover the pointer over a request row, and then select the Quick Approve button which displays upon hover. This adds the user as a Team Member with access for an unlimited period.