New features are continuously being added to iManage Threat Manager. Refer to the enhancements and feature changes available in each update.

In this section:

August 2026

This update to iManage Threat Manager introduces the following enhancements:

  • Tracking collaboration links (links sent to non-iManage users): iManage Threat Manager now tracks guest sharing activity across Detect and Protect, Behavior Analytics, and Compliance reporting. Three new activities—Guest Share, Modified Expiration Guest Share, and Revoked Guest Share—are available for use in rules, activity thresholds, and reports.

  • Agent-aware Detect and Protect rules: You can now define Detect and Protect rules based on the application that performed an activity, such as iManage Work Web, Microsoft Word, Microsoft Outlook, Ask iManage, Claude, or Harvey. This lets you create more precise detection criteria than activity counts alone. Because high volumes of agentic activity can obscure a user's at-risk behavior, you can exclude agentic applications from a rule to focus on a user's interactive activity.

Tracking collaboration links (links sent to non-iManage users)

iManage Threat Manager now tracks guest sharing activity generated by iManage Collaboration Links across Detect and Protect, Behavior Analytics, and Compliance reporting. Three new activities are available:

  • Guest Share: A user shares a document with an external guest through a collaboration link. When you generate a Compliance > Activity Report for the user who initiated the share, the guest’s email address is displayed in the entry’s Comments field.
    NOTE: The Comments field is available when you download an activity report (Compliance > Activity Report) for one or more users.

  • Modified Expiration Guest Share: A user changes the expiration date of an existing guest share.

  • Revoked Guest Share: A user manually revokes a guest share.

You can select these activities when you configure a Detect and Protect rule:

image-20260903-164154.png

You can also select the activities when you set activity thresholds in Behavior Analytics:

image-20260903-154414.png

The guest sharing activities are also available in the User Activity Report that you export from Compliance > Activity Report:

image-20260904-170056.png

And they appear in Compliance > Adoption reports:

image-20260903-154715.png

Currently, iManage Threat Manager doesn't track a guest share that is revoked automatically when its expiration period passes; only a manual revoke generates the Revoked Guest Share activity.

iManage Threat Manager also doesn’t yet track actions the external guest takes with the shared document, such as opening or downloading it. Support for this is planned for a future update.

Agent-aware Detect and Protect rules

AI products, agents, and assistants such as Ask iManage, Claude, and Harvey can access documents and perform actions that generate large volumes of activity, such as exports. Previously, customers could identify the application that generated a user's activity only by generating a User Activity Report and reviewing the Application Name column. They couldn't define an alerting rule based on the application that generated the activity.

iManage Threat Manager Detect and Protect rules can now use the application that performed an activity as a criterion, alongside existing activity, document, and metadata criteria. Instead of defining a Detect and Protect rule only by activity count (for example, 10 exports, 10 mails, or 10 prints), you can now define it more precisely by also specifying the application that generated the activity.

When building a rule, you can optionally select the applications you want it to apply to. To monitor a user’s at-risk interactive activity and exclude agentic activity from a rule, select all applications except the agentic ones (for example, include iManage Work Web, Microsoft Outlook, and Microsoft Word, but not Ask iManage, Harvey or Claude). Applications are listed in iManage Control Center, where you can identify agentic applications for this purpose. Conversely, to monitor AI and agentic activity specifically, select only the agentic applications you want to track.

NOTE: If you don’t specify applications for a rule, iManage Threat Manager monitors activity across all applications.

image-20260810-204156.png

iManage Threat Manager automatically detects new applications and adds them to the application list in Threat Manager. You can immediately use newly-detected applications as rule criteria without manually registering them in Threat Manager. However, you must first set up an application in iManage Control Center before Threat Manager can recognize its activity. If an expected application doesn't appear in the Detect and Protect rule criteria list, verify that it's configured and listed in Control Center, as shown in the preceding screenshot.

image-20260812-144541.png
image-20260812-162953.png

In the Detect and Protect Alert List, you can filter an alert's document activity by application to focus on activity from a specific application. You can filter only by applications that are included in the rule criteria. If the rule doesn't specify any applications, you can filter by all available applications.

image-20260806-211925.png

You can currently use applications as a criterion only in Detect and Protect rules. A future release will add support for Behavior Analytics rules. 

For more information about adding agent-aware, application-based Detect and Protect criteria, refer to Creating a Detect and Protect rule and Using the Detect and Protect Alert List.