Insights

Explore the latest news and industry insights from our team of iManage specialists.

iManage Security Policy Manager (SPM): Best Practices and Recommendations for Law Firms

With Nairn McCrudden, Principal iManage Cloud Services Consultant and iManage Security Policy Manager (iManage SPM) Specialist

 

Introduction

Adopting (and maintaining) a true Need-to-know security posture is an ambition that many law firms around the world strive towards. Often, this focus is driven by common factors, from addressing compliance risks and reducing the risk of data exposure, to more specific requirements such as client requests.

Threats to law firm data are rising, and this is leading to an increased focus on security solutions. In PWC’s 2025 Law Firm Survey, it was found that 92% of Top 100 firms are concerned about cyber risk, with figures increasing from the previous year (with 89% reported in 2024).

Moreover, the threat landscape is changing. In April, The National Cyber Security Centre has warned in a letter to the Financial Times (and shared via their website) that “AI will make it easier, faster and cheaper to discover and exploit weaknesses that previously required more time, skill or resource for attackers to identify” which is “why it is more essential than ever that organisations ensure they are following established good practices” such as “reducing unnecessary exposure to attack”.

iManage’s Security Policy Manager (SPM) product has been adopted widely within the legal sector to enhance knowledge work security. The user-friendly, comprehensive solution is used by law firms around the world who rely on iManage SPM to protect sensitive documents, emails and data through information barriers (which can be set across a client, department, or workspace).

In this free resource, Nairn McCrudden, Principal iManage Cloud Services Consultant at Tiger Eye, shares best practice guidance for firms considering SPM, or looking to improve how they use the solution. Read on to discover Nairn’s tips which cover the full lifecycle of adopting and enhancing iManage Security Policy Manager across the iManage platform.

 

What Is iManage SPM (Security Policy Manager)?

iManage Security Policy Manager (known as iManage SPM) enables organisations to govern and protect sensitive information stored within documents and emails by enforcing a Need-to-know security model. SPM does this by enabling teams to set information barriers which restrict access to content. These barriers can be set per client, department or even workspace, so that only those who really need to access your data can find, edit and use it.

“iManage Security Policy Manager is the answer to the question of how to manage security in the iManage Cloud” – Nairn McCrudden.

 

Key Features Of iManage Security Policy Manager

iManage Security Policy Manager enables organisations to:

  • Manage security at scale with confidence
  • Automate tasks, workflows and processes, to reduce manual efforts e.g., during staff onboarding
  • Grant the ability to make policy changes to appropriate users and groups such as those in Risk, Compliance or Information Management
  • Set up and manage approval workflows for changing user access needs (e.g., setting up processes to request and update access rights via email)
  • Manage content access and visibility for disputes, e.g., limiting content visibility for those on one side of the dispute so that they cannot see data from the opposing side.

 

Best Practices For iManage Security Policy Manager

 

iManage SPM Recommendation #1:
Get The Right Team Involved In The Project

SPM is not a project for IT alone; leadership teams and those in risk, compliance and information management should contribute from day one.

The iManage platform, as well as add-ons and integrations within its ecosystem, are all commonly managed by IT teams within law firms. Here, application ‘owners’ will manage updates and use administration tools to respond to user requests and make necessary changes.

However, unlike other solutions, iManage Security Policy Manager really sits at the heart of the firm’s governance and information management processes. When implemented correctly, SPM facilitates and underpins the work of those outside of IT; it supports users to access what they need to get work done, and it empowers those responsible for compliance to restrict content quickly and with confidence. Therefore, it’s vital that Risk and Compliance teams are engaged when adopting iManage SPM and actively involved in any SPM projects right from the start.

Insights from those in legal operations or in practicing teams can also be hugely beneficial for SPM projects, in providing an understanding of how work gets done across the firm. Knowing how teams collaborate, if (and how) departments work together, and how workloads are managed all help to paint a picture of how data is accessed and used across the organisation. This can then feed into the SPM project to ensure that SPM is set up correctly, but also that change management communications and training are tailored effectively.

When all teams come together to contribute to the design of SPM, the system itself can facilitate true ‘self-serve’ capabilities for access control needs. So, it is critical that the right team is brought together for the project from day one. If this advice is followed, firms can then hand over ownership of SPM entirely to those responsible for managing compliance. This reduces delays as teams don’t need to make requests to IT for changes to lists, settings or workflows.

 

iManage SPM Recommendation #2:
Use A Phased Approach

Achieving true Need-to-know security may take time – and for most firms, a phased approach to SPM adoption and usage can lead to greater results.

For most firms, true Need-to-know security will take time to perfect and with this, the adoption of SPM may be split into phases.

Commonly, we see projects split into three distinct phases or evolutions:

  • Phase 1: Replacing ‘Like for Like’
    Often the first step in adopting SPM will be to replace existing workflows or processes with SPM itself. This will not involve any usage of SPM’s automations, or rules-based enhancements to practices. In this first phase, the focus is simple: firms are aiming to replace Access Control Lists, scripted or scheduled automations, the refiling of workspaces, or manual processes with SPM itself.
  • Phase 2: Evolution
    We generally see that then after a period of around six months of using SPM, teams are ready to take advantage of the system’s advanced features to evolve processes. Often in the second phase of an SPM adoption, the focus shifts from consolidating processes into one system (SPM), to driving automations with the system. Commonly, this phase involves significant input from risk, compliance and information management teams, who, having used SPM for a period of time, will then aim to use core features such as collections and self-maintaining rules to drive automations and truly reduce manual efforts.
  • Phase 3: Scaling
    Lastly, once the system is designed and delivering optimal results, firms will aim to expand SPM’s territory: connecting SPM to other systems and databases to provide comprehensive Need to Know governance. Learn more about this third and final phase later on in iManage SPM Recommendation #4.

 

iManage SPM Recommendation #3:
Self Maintaining Rules Can Reduce Manual Efforts Significantly – But Only If They’re Set Up Correctly

SPM’s self-maintaining rules and collections must be configured correctly to deliver impactful, reliable automations.

For many organisations, iManage SPM’s abilities for self-maintaining rules are a key driver in selecting the product. This valuable capability enables firms to automate the maintenance of access rights and the rules around these, feeding into (and governing) key processes and workflows such as employee onboarding, or staff changes.

However, there are key aspects of the set-up of SPM that must be considered, actioned and monitored to ensure self-maintaining rules can operate effectively.

For example, we recommend that all matters are tagged appropriately as they’re added to the system with the relevant department, as this tag is vital for triggering departmental-based access rights. Equally, if matters are labelled with the correct location as well as the relevant department, more sophisticated workflows can be initiated to limit access to content based on a user’s department and working location.

We also recommend that those adopting iManage SPM consider (and maintain) a groups-based approach to managing access to collections within iManage. In doing so, only relevant groups can access collections of content, providing a flexible approach to governance which can be easily updated when needed. The ongoing management of groups can then be tied into key processes (such as staff leaving or joining the firm); once an individual leaves a group, their access is instantly removed across all relevant matters.

SPM’s workflows can be tailored to a wide range of use cases, and custom properties can also be used (instead of metadata fields) to drive specific workflows or act as triggers in self-maintaining rules. Your iManage Partner should be able to help you to explore the ‘art of the possible’ of iManage SPM’s self-maintaining rules, but you can also contact our team for more information.

 

 

iManage SPM Recommendation #4:
Don’t Limit SPM to iManage: Scale Security Policies Across The Technology Stack

Use SPM at scale to protect the wider technology stack

We have previously covered how organisations using SPM can use software agents to integrate the system with third-party applications, so that protections delivered via SPM could be spread to cover other core systems. Yet this is a significant benefit of SPM that truly isn’t used to its full potential by many organisations.

For example, SPM can be connected to other core solutions such as Practice Management Systems to provide a foundation of governance across the wider technology stack, with the same rules protecting content – and the firm.

Additionally, an integrated technology stack can provide more information to trigger and drive SPM’s self-maintaining rules. For example, information about clients and matter teams can be fed from a system such as a Case Management System into iManage automatically through an integration, and SPM can then lock down integrated content based on these details.

Through integrations, time and billing systems can be linked to matters, clients and iManage. Then, using SPM, information regarding billable time or invoices attributed to a client or matter can also be hidden – visible only to those delivering the work. Communication and collaboration systems such as Microsoft Teams can be protected using SPM, with client and matter specific Teams channels governed in the same way that documents and emails in iManage are – using SPM’s enhanced protections to reduce risk and drive Need to Know security.

With the right integrations in place, secrets can remain secrets across your entire technology stack — at any scale.. Contact Tiger Eye for more information about SPM integrations.

 

Summary

In summary, our best practice guidance for firms using SPM is to:

  1. Ensure the right team is brought together to implement, adopt and manage iManage SPM from the start. In doing so, your content restrictions are much less likely to negatively impact users’ everyday workflows, and you can make the most of the system’s automations right away.
  2. Use a phased approach to continue progress towards true Need to Know security, while managing change management and communications across the organisation.
  3. Give SPM the data it needs so it can deliver optimal results – from tags to departments, locations and data fed from integrations.
  4. Don’t restrict SPM to iManage alone. Use software agents to integrate the system with third-party applications, so that protections delivered via SPM could be spread to cover other core systems
  5. Explore the art of the possible with your iManage Partner to minimise time waste across a broad range of workflows or processes (such as employee onboarding, or staff changes).

 

 

Interested in iManage SPM?
At Tiger Eye, we have helped law firms around the world to adopt, implement and optimise iManage SPM – delivering consultancy, phased adoption projects, training, enablement and much more.

How could Tiger Eye help you to protect data at scale and automate processes using iManage SPM? Contact our specialist team for more information.

Category:
Article, Blog
Author
Tiger Eye Team
Date
10th August 2026
Share This Post