No organization is immune to security threats—data loss can happen quickly and at a large scale. That’s why it’s important not just to detect threats, but also to take proactive steps to stop them before damage occurs.

Detect and Protect rules help you do just that. They automatically act when certain risk patterns are detected, reducing the chance of data loss. These rules work in the background 24/7 to help safeguard your information.

When your iManage Threat Manager application is set up, it comes with a default Detect and Protect rule named Sample already in place. This rule sends a notification to all members of the NRTADMIN group whenever a user exports, emails, or prints 25 or more unique documents.

Confirm the setup of the Detect and Protect rule “Sample”

  1. On the iManage Threat Manager Home page, select Detect and Protect, then select Rules.

  2. On the Detect and Protect Rules page, confirm that a rule named Sample is present. Select the row of the rule.
    The Sample rule page opens on the Rule Details tab. This provides a summary of the rule, including its criteria, included and excluded users, and notification recipients.

  3. Verify the following:

    • Included Users is set to All Users.

    • Included Groups is set to None.

    • Excluded Users is set to None.

    • Excluded Groups is set to None.

    • Criteria values are:

      • Mail 0

      • Export 0

      • Print 0

      • Documents 25

  4. Review the Notification List. To make changes, select Edit Rule.

You can send alert notifications to primary (To), CC, and BCC recipients, including both iManage Work users and non-iManage Work users.

For more information about Detect and Protect rules and how to use them, refer to iManage Threat Manager Best Practices Guide and iManage Threat Manager Help.

TIP: In Detect and Protect > Alerts > Alert Details, apply any filters and select Download EXCEL to export a multi-sheet Microsoft Excel summary workbook with organized worksheets and PivotTables.