Within minutes, an organization can be attacked and lose large amounts of information. To reduce this risk, it’s important not only to detect a threat, but also to act before data is lost. iManage Threat Manager Detect and Protect rules help by automatically responding to risky behavior before it causes harm.

Here’s how Detect and Protect works, from creating a rule to investigating an alert:

  1. Create a rule:

    • Define the criteria that should trigger an alert—activity, document, metadata, library, or application, including which application performed an activity, so you can account for AI agents and assistants (such as Claude or Harvey) alongside human users.

    • Set the automatic action to take, if any, and who should be notified.

  2. Once activated, the rule runs continuously, monitoring activity against those criteria and giving you near real-time protection.

  3. When a match occurs, Detect and Protect generates an alert, sends the configured notifications, and, if enabled, immediately takes action, such as warning the user or disabling their account.

  4. Review and investigate the alert in the Detect and Protect Alert List, drilling into the underlying documents, activity trends, and rule configuration as needed.

  5. If a user’s account was disabled as part of that response, review and re-enable it from Detect and Protect > Disabled Users.

  6. As your organization's risk patterns change, return to the Rules dashboard at any time to edit, disable, or delete existing rules.

This section explains how to: