Beyond iManage: Why security and governance need a wider view
For many legal firms iManage has become the centre of the information estate. Documents are stored, organised and managed all within the same platform.
The problem is that information doesn’t always behave in the simplistic way that we want it to, and is rarely contained within a single platform. A document might be created in iManage, discussed in Teams, shared through Outlook, referenced in a matter update, surfaced through analytics tools like Fabric or accessed through Copilot. By the end of the day, it has passed through several different systems, each with their own permissions, policies and most importantly, risk.
This is why iManage shouldn’t be viewed in isolation – the security and governance of information is influenced by far more than the platform where a document happens to reside.
The relationship between documents, identities, devices and data
It’s easy to think of document security as a storage problem. Store the document in a secure repository like iManage and the job is done.
But the challenge isn’t simply protecting documents – it’s maintaining control as information travels across the wider ecosystem. Every document is connected to an identity – someone creates it, accesses it, edits it or shares it. Every identity is connected to a device. Every interaction generates activity data, permissions, ownership records and access trails.
Understanding these relationships matters because information doesn’t move in neat, predictable ways anymore. Many of the controls that govern access to sensitive information actually sit outside iManage itself. Those in Microsoft Entra ID, Conditional Access policies, device compliance settings and authentication requirements all influence who can access information and under what circumstances.
Good governance starts with visibility and control
Governance problems usually show up before security problems. Users struggle to find the information they need because content has been duplicated across multiple locations. Access requests take longer than they should because ownership isn’t clear. Permissions accumulate over time and become increasingly difficult to review. Information sits around for years because nobody is certain whether it should be retained or removed.
Over time, small governance gaps create operational friction. Data volumes grow and ownership becomes harder to establish. Teams lose confidence in the quality and reliability of the information available to them.
Technology controls can only take an organisation so far. If nobody understands what information exists, who owns it and how it is being used, those controls become far harder to manage effectively.
Most firms already have security controls in place. The challenge is often understanding whether those controls are working as intended. That means being able to answer questions such as:
- Where is sensitive information located?
- Who currently has access to it?
- Has access changed over time?
- Is information being shared appropriately?
- Are existing policies being applied consistently?
Without that visibility, governance becomes reactive. Issues are often only discovered after something has gone wrong. With it, organisations can understand how information is actually being used rather than relying on assumptions, helping them make better decisions before those decisions become urgent.
Good governance turns that visibility into consistent action. Retention policies help ensure information is kept for the appropriate period and disposed of when it is no longer needed. Information lifecycle controls support data from creation through to archival or deletion, while audit trails provide evidence of who accessed information and when.
For legal firms in particular, that evidence matters. Client audits, regulatory reviews and internal governance processes require organisations to demonstrate that information is being managed appropriately. Having controls in place is important, but being able to show that they’re working as intended matters too.
Why data readiness matters
The rise of AI has also changed the conversation around information governance.
In the past, organisations often focused on what needed to be protected. Today, they’re also asking a different question: what information are we prepared to expose to intelligent systems?
Organisations are quickly realising that technology is only as effective as the information underpinning it. If information is poorly organised, duplicated, outdated or governed inconsistently, those issues don’t disappear when AI is introduced. In many cases, they’re only amplified.
The same principle applies to analytics initiatives. Platforms like Microsoft Fabric make it easier than ever to connect and analyse information from multiple different sources to generate genuinely valuable insight, but they don’t automatically solve governance challenges.
These foundations are becoming increasingly important for firms looking to make practical use of AI, analytics and emerging technologies. Firms need confidence in their data and a clear understanding of how information is governed and owned across different systems.
The encouraging part is that many of the activities that improve data readiness also strengthen security and governance.
The case for a joined-up view
Platforms, and thus security, governance and data management are becoming increasingly interconnected. This is where many organisations face a challenge. Different teams often manage different platforms. Security, data, infrastructure and business systems can all operate independently.
As we have seen, information doesn’t necessarily respect platform boundaries, and risks emerge as a result of gaps between the systems.
Taking a joined-up view helps organisations understand how information moves across the wider estate. It can reduce duplicated effort, improve consistency and make it easier to identify gaps in governance and control, while creating stronger foundations for future initiatives.
The question is no longer whether iManage is secure. The bigger challenge is understanding how information flows between iManage, Microsoft 365 and the wider SaaS environment, and putting the governance, visibility and controls in place to manage that information consistently wherever it exists.
As firms continue to expand their technology estates and explore AI-driven opportunities, those with the clearest view of their information are likely to be the best positioned to manage risk and create value from it.
Bringing it all together
Taking a joined-up approach to information is increasingly important. At Quorum, we help firms understand how information moves across iManage, Microsoft 365 and the wider technology estate, then put the right governance, security and controls around it. The aim is simple: greater visibility, more consistent control and a stronger foundation for what comes next.
Interested in learning more?
Join our webinar ‘Securing iManage in a SaaS world’ to understand where firms are most exposed and what modern iManage security looks like in practice.
📅 23 September 2026
⏰ 11:00am to 12:00pm BST
🎟️ Free to attend
AWARDS & RECOGNITION
FOLLOW US
CONTACT INFO
CONTACT INFO
Quorum
18 Greenside Lane Edinburgh
UK EH1 3AH
Phone: +44 131 652 3954
Email: marketing@quorum.co.uk
FOLLOW US
AWARDS & RECOGNITION