Activities are the specific user actions iManage Threat Manager tracks through audit logs, the foundation for Behavior Analytics, Detect and Protect, Compliance, Matter Activity, and Outliers. This page explains what activities are and how they’re categorized, then provides a full reference of the activities tracked for monitoring, reporting, and investigation.

In this section:

What are activities?

Activities in iManage Threat Manager represent specific user actions performed on documents, emails, folders, or workspaces within the iManage Work system. These actions are tracked through audit logs and are used to detect anomalies, generate alerts, and support compliance reporting.

Threat Manager categorizes activities to help you:

  • Monitor user behavior

  • Investigate potential data loss

  • Identify compliance gaps

  • Analyze trends across clients, matters, and documents

How are activities used?

  • Behavior Analytics: Detects deviations from personal and peer-group baseline behaviors.

  • Compliance Reports: Identifies users not engaging with the document management system.

  • Matter Activity Reports: Tracks user actions across specific clients and matters.

  • Outlier Analysis: Flags users with unusually high access to unique documents, clients, or matters.

What are the primary activity categories used in threat detection and behavior analysis?

The three activity types of Client, Matter, and Document are the foundational units used throughout iManage Threat Manager to evaluate user behavior. They're central to:

  • Defining scope in rules and reports

  • Calculating risk scores

  • Identifying outliers

  • Visualizing user behavior across clients, matters, and documents

Table: Primary activity categories

Activity

Description

Client

Number of unique clients associated with the documents a user interacted with.

Matter

Number of unique matters associated with the documents a user interacted with.

Document

Number of unique documents a user interacted with, based on selected activities.

What activities are tracked for monitoring, reporting, and investigation?

The following list includes specific actions users may perform within iManage Work. These activities are tracked in audit logs and are used to:

  • Trigger alerts in Behavior Analytics and Detect and Protect rules

  • Populate Compliance and Matter Activity reports

  • Support forensic investigations and usage analysis

Activities are grouped into sets (for example, Threat Monitoring, Compliance Indicating, Activity Monitoring), which determine how unique document, client, and matter counts are calculated. These sets can be configured under Configuration > Settings > Activity Sets.

Table: Activities tracked for monitoring, reporting, and investigation

Activity Name

Description

Changed Profile

The profile metadata for a document, folder, or workspace was modified.

Change Security

The security permissions for a document, folder, or workspace were modified.

Checkin

The document was checked in, updating the official version in the system and making it available to others.

Checkout

The document was checked out for editing, restricting modifications by others until checked in.

Close

A document or email was closed without being checked in, indicating changes weren't saved.

Copy

A document or folder was duplicated within the system.

Create

A new document, folder, or workspace was created in the system.

NOTE: Create is a legacy activity equivalent of Document Create. It is retained for compatibility with rules and reports from earlier Threat Manager versions.

Create Version

A new version of a document was created, preserving previous versions for reference.

Declared

A document was declared as a record for compliance or retention purposes.

NOTE: Declared and Undeclared may appear separately or as a combined activity (Declared/Undeclared) depending on the report or rule context.

Document Create

A new document was added to a folder or workspace in the system.

Document Delete

A document was deleted from a folder or workspace in iManage Work.

NOTE: Document Delete replaces the older Delete activity used in previous versions.

Download to Mobile 

A document was downloaded to a mobile device for offline access.

Email filed

An email was filed into a workspace or folder in the system.

Exited

A co-authoring session on a document was ended by the user.

Export

A document, folder, or workspace was exported from the system to an external location.

NOTE: This is a legacy activity that combines several export types, including iManage Work Server exports, mobile downloads, Drive synchronizations, and Share uploads. This legacy Export activity is retained for compatibility with existing rules and reports in iManage Threat Manager. For new rules or reports, use the individual export activities to provide clearer insight into export actions: Export from DMS, Download to Mobile, Offline Download, and Export to iManage Share.

Export from DMS

A document, folder, or workspace was exported directly from iManage Work.

It doesn't include:

  • Mobile downloads (captured by Download to Mobile)

  • Drive synchronizations (captured by Offline Download)

  • Share uploads (captured by Export to iManage Share)

NOTE: In earlier versions of Threat Manager, the Export activity combined all export types: iManage Work exports, mobile downloads from iMobility for iOS, Drive synchronizations (Offline Download), and uploads to iManage Share. This legacy export activity is retained to ensure compatibility with existing rules and reports.

In current versions, the legacy Export activity includes only iManage Work exports, iMobility downloads, and iManage Share uploads. Drive synchronizations are now recorded separately as Offline Download and are no longer counted as part of the legacy Export activity.

Export to iManage Share

A document, folder, or workspace was exported to iManage Share for external collaboration.

Folder Delete

A folder and its contents were deleted from a workspace or the system.

Guest Share

A document was shared with an external guest through a collaboration link.

In Draft

A knowledge document was moved to In Draft for further edits.

Inbox Filer

An email was automatically filed into a workspace or folder when a recipient replied to a sender who has inbox filing enabled in the configuration.

Interactive Filing

A document or email was manually filed into a workspace or folder by a user.

Linked Folders

An email was automatically filed into a workspace or folder when it was moved into an Outlook folder that is linked to the corresponding iManage workspace or folder.

Mail

An audit generated when documents are attached to an email.

Mailbox Assistant

A document or email was filed into a workspace or folder that was processed by the Mailbox assistant.

Modified Expiration Guest Share

The expiration date of an existing guest share was changed.

Modify

The content or properties of a document, folder, or workspace were modified.

Offline Download

A document was downloaded for offline access on a device.

Open

A document, folder, or workspace was opened for viewing or editing.

Print

A document was printed from the system.

Published

A knowledge document was published and is accessible for reference.

Purge

A document, folder, or workspace was permanently deleted from the system, making it unrecoverable.

NOTE: This activity only applies to cloudimanage.com. In on-premises environments, purge actions are recorded as delete events with the comment “Removed from trash bin.”

Reconcile

Changes or versions of a document, folder, or workspace were reconciled to ensure consistency.

Rejected

A submitted knowledge document wasn't accepted as a knowledge document.

Release

The document was released (unlocked) or closed without changes, making it available for others.

Remove from Folder

A document or subfolder was removed from a folder or workspace.

Restore

A deleted document, folder, or workspace was restored to the system.

Retired

A published knowledge document was marked as retired, indicating it is no longer treated as a reference document.

Revoked Guest Share

A guest share was manually revoked by a user.

NOTE: Automatic revocation when a share’s expiration period passes isn’t tracked as a Revoked Guest Share activity.

Send and File

An email was sent and simultaneously filed into a workspace or folder in the system.

Submitted

A document was submitted as a knowledge document for review.

Synchronize

A document, folder, or workspace was synchronized with the system to update changes or ensure consistency.

Undeclared

The record status of a document was reverted, allowing it to be managed as a regular document.

NOTE: Declared and Undeclared may appear separately or as a combined activity (Declared/Undeclared) depending on the report or rule context.

Unpublished

A published knowledge document was taken offline for further review and editing.

View

A document, folder, or workspace was viewed by a user in read-only mode.

Workspace Create

A new workspace was created in the system for organizing documents, emails, and folders.

Workspace Delete

A workspace and all its contents were deleted from the system.

NOTE: Workspace Create and Workspace Delete are tracked as a single activity in some views, but may be split in audit logs or rule criteria depending on configuration.

Activity set definitions are available in the Activity Sets tab, accessed by selecting Configuration > Settings on the left navigation bar. For more information about activity set definitions, refer to the Configuration > Settings section of iManage Threat Manager Administration Help.

Client, Matter, and Document activity counts are calculated from the unique Client, Matters, and Documents recorded during the period being assessed. For example, if a user created two documents for Client A and 3 documents for Client B, the Client count would be two.

Other (non-client/matter/document) activity counts are determined based on the type of analysis, as outlined below.

Area

Explanation

Behavior Analytics Alerts

Client: Count of unique clients which had any of the specified activities during the period of analysis.

Matter: Count of unique matters which had any of the specified activities during the period of analysis.

Document: Count of unique documents which had any of the specified activities during the period of analysis.

[Other]: Count of unique documents which had the specified activity performed during the period of analysis.

Matter Activity Reports

Matter: Count of unique matters which had any of the specified activities during the period of analysis.

Document: Count of unique documents which had any of the specified activities during the period of analysis.

[Other]: Count of unique documents which had the specified activity performed during the period of analysis.

Compliance

Activities: A total count of selected compliance activities performed by a user during the analysis period.

Clients: The total number of clients upon which the user performed any of the selected activities, during the time frame analyzed.

Matters: The total number of matters upon which the user performed any of the selected activities, during the time frame analyzed.

Documents: The total number of unique documents upon which the user performed any of the selected activities, during the time frame analyzed.

[Other]: Count of unique documents which had the specified activities performed during the period of analysis.

Outliers

Client: Count of unique clients which had any of the specified activities during the period of analysis.

Matter: Count of unique matters which had any of the specified activities during the period of analysis.

Document: Count of unique documents which had any of the specified activities during the period of analysis.

Behavior Analytics > Analyze

Client: Count of unique clients which had any of the specified activities during the period of analysis.

Matter: Count of unique matters which had any of the specified activities during the period of analysis.

Document: Count of unique documents which had any of the specified activities during the period of analysis.

[Other]: Count of unique documents which had the specified activity performed during the period of analysis.

Behavior Analytics > Statistics

[Other]: Population threshold statistics calculated from the counts of unique documents which had the specified activities performed during the period of analysis.