Compliance > Activity Report allows you to generate downloadable reports of user activity across iManage Work. Use these reports to review document-related actions (for example, View, Print, Checkout, Export, Create Version) for one or more users over a selected date range. The reports support targeted auditing, operational oversight, and compliance investigations.

Outputs:

  • CSV: Flat, list-style export.

  • EXCEL: Structured, multi-sheet Microsoft Excel summary workbook with built-in Pivot Tables.

NOTE: The Microsoft Excel export includes interactive PivotTables and the underlying data used to generate them. You can customize views directly in Excel by adding fields, changing groups, and applying filters. For guidance on working with Excel summary workbooks, PivotTables, field availability, refresh behavior, and performance considerations, refer to Working with Microsoft Excel PivotTables in Threat Manager exports.

In this section:

Open the User Activity Report page

From the Home screen or navigation bar, go to Compliance > Activity Report. The User Activity Report page opens.

image-20260205-170749.png

Filter and refine report results

Use the Criteria filters to narrow the report to the time period, users, and activity types you want to include.

  • Date Range: Select the start and end dates for the activity data to include.

  • Include: Choose one or more users to include in the report.

  • Activities: Select the activity types to include. By default, compliance-indicating activity types are preselected.

NOTE: The activity types available in the list depend on your organization’s configuration and the audit fields that are enabled.

Generate a User Activity report

  1. Open Compliance > Activity Report. The User Activity Report page opens.

  2. Set the Date Range.

  3. Select one or more users to Include.

  4. Choose Activities to include. All compliance-indicating activities are selected by default.

  5. Select a Format: EXCEL (Excel summary workbook) or CSV (flat).

  6. Select Generate Report.

  7. When prompted, save the file to the default Downloads or choose another location.

IMPORTANT: Stay on the User Activity Report page until the download finishes. Navigating away cancels the generation. Generation time varies based on date range, number of users, and audit volume.

image-20250917-180651.png

Where to find the generated User Activity Report

After generation, the Microsoft Excel or CSV report is saved by your browser. Filenames begin with:

  • The username (for a single user), or

  • Multiple Users Documents Activity (for multi-user reports)

image-20260205-174113.png

Understanding the report formats

CSV export (flat)

  • A single, flat file of the activity results filtered on the page at generation time.

  • Does not include summaries or PivotTables.

  • Best for quick ad hoc analysis or ingestion into external tools.

EXCEL export (Excel summary workbook)

  • A multi-sheet Microsoft Excel summary workbook.

  • Includes summary worksheets, built-in PivotTables, and the underlying data required for interactive analysis.

  • Best for investigations, sharing, and interactive analysis directly in Microsoft Excel.

NOTE: PivotTables can display only the fields included in the export. If a field does not appear in the PivotTable Fields list, it was not included when the report was generated. For details, refer to Working with Microsoft Excel PivotTables in Threat Manager exports.

What’s in the Microsoft Excel summary workbook

The Microsoft Excel summary workbook generated from Compliance > Activity Report contains the following worksheets. Each worksheet provides a different view of user actions and supports investigation, auditing, and reporting workflows.

Help

Lists each worksheet in the export and briefly describes its purpose.

User Summary Details

Provides user identity information (ID, name, title, department, manager, practice area, location, phone) along with summary metrics such as:

  • Unique clients and matters accessed

  • Unique documents accessed

  • Documents owned vs. not owned

This data is populated through the User Metadata Importer.

Activity Analysis (PivotTable)

An interactive PivotTable for analyzing user activity across clients, matters, and documents. Features include:

  • Drill-down by user, client, matter, document

  • Flexible filtering, grouping, and sorting

  • Date/time filters

  • Activity-type breakdown (for example, View, Print, Checkout, Email Filed, Export to iManage Share, Document Create)

NOTE: Client and Matter values come from Control Center metadata (custom1 and custom2). Captions may appear as Custom1/Custom2, Client/Matter, or tenant-specific labels.

User Activity

A detailed export of all document-related and workspace-related actions performed by the selected user(s) during the specified date range. This worksheet provides the raw dataset for deeper investigation or custom analysis in Excel.

Field reference

The User Activity sheet includes the following commonly used fields. These values originate from iManage Control Center and may appear with tenant-specific labels. Not all fields appear in every export.

Field

Description

DateTime

When the activity occurred. Recorded in UTC or local time, based on system settings.

User

Username that performed the action. Typically matches the user’s iManage or Active Directory ID.

User Activity

Action performed (for example, Checkout, Release, Create Version, View, Print, Export).

Count

Number of times the user performed the action on the document at the given timestamp. For details, refer to Count field (details).

Database Name

The iManage Work database (library) that contains the document.

Doc. Number

Unique document identifier in iManage.

Workspace URL

Provides a direct link to the workspace associated with a workspace-level action (such as Workspace Created or Change Security), enabling you to open and review the correct workspace, including those created under an unassigned client/matter. This is important as in the past, you could not determine the workspaces for which the change security events triggered for.

Workspace Name

The name of the workspace associated with a workspace-level action. Helps you identify and confirm the workspace affected, especially when document numbers don't uniquely identify the workspace.

Filename

Document name.

Version

Document version at the time of the activity.

File Size

Most recent file size known to Threat Manager at download time.

If File Size displays NA, the document was created before file size metadata was captured in audit logs. Once new activity occurs on that document, its size will appear in future reports.

The field label may vary based on the docsize caption configured in iManage Control Center.

Application Name

Identifies the application or integration used to perform the activity (for example, Word, Outlook, a web client, or an API). If the system can't map the value, or if the activity occurred before application-name mapping was available, a legacy internal numeric ID may appear.

Comments

Optional notes or system-generated context (for example, export method, automation tags).

Client/Client ID

Client name and identifier (caption based on your tenant’s Control Center configuration).

Matter/Matter ID

Matter name and identifier (caption based on your tenant’s Control Center configuration).

Practice Area

Practice-area classification (if configured).

Author/Author Full Name

Document author identifiers, if available.

Additional metadata fields

Depending on your organization’s configuration, the User Activity sheet may also include additional fields. These values are also sourced from iManage Control Center and may vary by tenant. Not all additional fields appear in every export.

  • Author/Author Full Name

  • Operator/Operator Full Name

  • Document classification: Doc Type, Subclass, File Type

  • Status, Status Description

  • Business/context fields: Jurisdiction, Industry

  • Email context (From, To)

  • Custom fields (for example, Custom4, Custom5, Custom15, Custom29)

Count field (details)

The Count field indicates how many times a user performed a specific activity at a given timestamp.

Each row in the report represents a unique combination of:

  • Activity time

  • User ID

  • Activity type

  • Document ID

The Count value reflects the number of occurrences of that activity on that document at that timestamp.

Examples:

  • A single export of one document results in Count = 1.

  • Multiple exports of the same document at the same timestamp result in Count > 1.
    (The Count will reflect the total occurrences).

  • Exporting five documents in one action produces five rows, each with Count = 1.

NOTE: iManage Work logs activity per document. Count is measured per document, per activity, per timestamp, not per multi-document bulk action.

Activity Glossary

Definitions of the activity types present in the workbook. The glossary includes only the activity types contained in the export. This helps readers (especially those who don’t sign in to iManage Threat Manager) interpret activity types.