Outlier analysis identifies users whose behavior significantly deviates from the norm. Research and empirical data show that such anomalous behavior is often linked to at-risk activity.
There are two primary use cases for Outlier analysis:
Initial setup: Run Outlier analysis immediately after data ingestion to identify legitimate outliers—accounts that are expected to behave differently from typical users. Examples include robot accounts, Walls accounts, help desk users, NRTAdmin users, and information governance accounts.
These users should be added to the Global Exclusions List, and a dedicated Behavior Analytics Rule should be created to monitor them separately. Including such accounts in ongoing analysis can skew group behavior baselines and threshold calculations, reducing the accuracy of future anomaly detection.
Common examples of legitimate outliers include system accounts, help desk users, and trainees who, by design or role, have access patterns that differ significantly from standard users. Excluding them ensures cleaner peer-group analysis and more accurate identification of true anomalies.
Ongoing monitoring: After the initial setup, run Outlier analysis regularly (for example, biweekly or monthly) to detect advanced threats. Focus the analysis within specific peer groups—such as users in the same practice area or job function—to spot individuals who are gradually but consistently accessing an unusual number of unique clients, matters, or documents. These high-activity users should be flagged for further investigation.
Examples of legitimate outliers
Accounts which may typically exhibit legitimate, outlying behavioral patterns include:
NRTAdmin group: Special administrative accounts in iManage Work with elevated privileges for managing users and system settings.
Walls accounts: Accounts used to enforce ethical walls or access restrictions, limiting who can view or edit certain sensitive information.
Robot accounts: Automated or system accounts used by software robots or scripts to perform routine, repetitive tasks such as bulk updates and automated processing without human intervention. These accounts are commonly employed for handling large volumes of data efficiently.
Trainee attorneys: Accounts belonging to junior legal staff or new lawyers in training, who may have unusual access patterns due to their learning activities.
Document processors: Accounts used by staff or automated systems responsible for bulk processing, converting, or managing documents.
Information governance/Records managers: Specialized accounts for professionals overseeing compliance, retention, and proper handling of organizational records.
Helpdesk accounts:
Support accounts used by IT or helpdesk staff to troubleshoot user issues, often requiring broad but temporary access.
How it works
Outlier analysis tracks the number of unique clients, matters, and documents each user has accessed. Alongside these counts, each user is assigned a Score that reflects how anomalous their behavior is within their peer group.
Score of 0: Indicates typical behavior.
Positive Score: Means the user’s activity is above average.
Negative Score: Means it's below average.
The farther the Score is from zero, the more anomalous the behavior. There are no fixed upper or lower limits.
In iManage Threat Manager, the Outliers report visualizes user behavior in a 3D chart, grouping users with similar patterns. Anomalous users stand out clearly as they appear far from the main cluster.
The following sections explain how to define scope and activities, and how to interpret the results: