---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create Approval Rules

# Create Approval Rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.

## Before you begin

Role required:

* sn_dlir.admin
* sn_dlir.analyst and sn_dlir.analyst_read
{#configure-approval-rules__ul_dht_2bq_yxb}

## About this task

An approval rule is triggered when an end user selects a response option that is marked as Advanced on a DLP incident. When the rule's conditions match the incident fields, the system initiates an approval request and
routes it to the configured approvers before the response option can be applied. If multiple rules match, the rule with the lowest Execution order value runs first.

## Procedure

1. Navigate to AllDLP AdministrationDLP Approval Rules.
2. Select New.
3. On the form, fill in the fields.  
   {#configure-approval-rules__table_ilq_qrg_zrb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the approval rule. |
   | Active | Option to indicate whether the approval rule is active. |
   | Execution order | Indicates the approval rule priority. The approval rule of the highest priority or the least order is selected. The approval rule with the lowest number has the highest priority. To set the order of operation, enter a value. For example, 100, 200, 300, and so on. The default value is 100. |
   | Description | Unique description for the approval rule. |
   | Condition | Conditions in the condition builder. These conditions are based on the DLP incident table. To build a condition for the approval rule, select any of the incident fields. Use the lists and fields of the conditions builder to set the filters for the first row. To add more conditions, select AND or OR. * If AND is selected, all conditions must be matched. * If OR is selected, either condition can be matched. {#configure-approval-rules__ul_e1n_xsg_zrb} To set a second filter condition, select New Criteria. For example, you can set the conditions for this incident consolidation rule by selecting the condition as Integration Source, contains, Microsoft. |
   | Applicable for response options | Option to select the response option of type advanced. You can select the multiple response options. |
   | Approver | Select how approvers are identified for this rule. * User Table: Selects an approver based on a field in the Users (sys_user) table, such as the incident assignee's manager. * Custom Approval List: Configures a multi-level approval chain with specific users or groups at each level. {#configure-approval-rules__ul_pyg_dcq_yxb} |
   | Approver identifier | This field will appear when User Table is selected for Approver option. Select field to identifier the approver from the Users(sys_user) table. |
   | Number of levels | This field will appear when User Table is selected for Approver option. Enter a number in this field to define the levels of approval. For example, if 3 is added in the Number of levels field and Manager is selected in the Approver identifier field then approval request will traverse to three levels of approval. |
   [Table 1. DLP Approval Rules form]

   {#configure-approval-rules__table_ilq_qrg_zrb}  
   For example, your organization requires manager approval before a DLP analyst can apply the Block response option to any Microsoft DLP incident. Configure the rule as follows:
   * Condition: Integration Source \| contains \| Microsoft
   * Applicable for response options: Block
   * Approver: User Table
   * Approver identifier: Manager
   * Number of levels: 1

   {#configure-approval-rules__ul_example_approval_rule}When an analyst selects Block on a qualifying Microsoft DLP incident, the system creates an approval request and routes it to the analyst's manager. The response option is applied only after the manager approves.
4. For the Approver option, select Custom Approval List.
5. Select Submit.
6. Verify that the Approval Levels related list appears on the form.
7. In the Approval Levels section, select New.
8. On the form, fill in the fields.  
   {#configure-approval-rules__table_obp_52q_yxb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the approval level. |
   | Active | Option to indicate whether the approval level is active. |
   | level | The level for the approval rule. This field indicates the order in which the approval levels are executed when two or more levels are configured. The approval level with the lowest number has the highest priority. To set the level of operation, enter a value. For example, 100, 200, 300, and so on. The default value is 100. |
   | Approval Rule | Approval Rule for which you want to define this configuration. This will be read-only field. |
   | Description | Unique description for the approval level. |
   | Approvals required | Select option to define whether approval from all the configured users/groups are required or only required from any one user. |
   | Approvers | Option to select the approvers. 1. Users and Groups: 1. Users: Add a particular user from the list. You can add yourself or add a user by using their email address or search option. 2. Groups: Select the \<add_icon\> icon to add a particular group from the list. You can also add a group by using the search option. {#configure-approval-rules__ol_qlw_mfq_yxb} 2. Find by using script: You can use the script editor to customize and format the field values during the approval level creation. For example, you can use the email address field to identify the approver user. {#configure-approval-rules__ol_yzy_kfq_yxb} |
   [Table 2. Approval Level form]

   {#configure-approval-rules__table_obp_52q_yxb}
9. Select Submit.
**Related concepts**   

* [Monitor DLP Integration Run process](https://servicenow-prod.fluidtopics.net/1Ov8JAQizZC7T2HLNPiOvg "Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.")
* [DLP Incident Access Restrictions](https://servicenow-prod.fluidtopics.net/RLjeozrMpG2FVpJaLmRMuQ "Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.")  
**Related tasks**   

* [DLP default configuration settings](https://servicenow-prod.fluidtopics.net/2LomJFXUoWOHDb4Lc0UfQA "Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.")
* [Create end user lookup rules](https://servicenow-prod.fluidtopics.net/ccMfdPxSgHsL9Fh1Q_~JsA "You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.")
* [Create assignment rules](https://servicenow-prod.fluidtopics.net/8vAoEijgHvURfLHuuPSmqQ "Create assignment rules and assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.")
* [Create incident consolidation rules](https://servicenow-prod.fluidtopics.net/vvKTITK9qLCsbKKkoqVL5A "Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.")
* [Create response due date rules](https://servicenow-prod.fluidtopics.net/VgO2TB6WZtrxmG4~JWv2vA "Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create user instructions templates](https://servicenow-prod.fluidtopics.net/CAThP9D~817jopKRDJeJPg "Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.")
* [Create email templates](https://servicenow-prod.fluidtopics.net/wQtZqtIiLEBZdQR8aYbIiA "Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create a Data Loss Prevention Incident Response SLA trigger](https://servicenow-prod.fluidtopics.net/n4qzNvzCeD6gk9FwYIJ9Vw "Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.")
* [Create a Data Loss Prevention Incident Response SLA definition](https://servicenow-prod.fluidtopics.net/80miwPm0oR7Ix7EQ~DpIew "Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.")
* [Create assessments](https://servicenow-prod.fluidtopics.net/XzB5FSKtotEb1LiHYADPog "Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.")
* [Configure response option for your DLP incidents](https://servicenow-prod.fluidtopics.net/1QqdESchbNTpm8Sp8oXHyQ "Use this feature to configure the type of response that an end user or analyst should perform.")
* [Create incident response option rules](https://servicenow-prod.fluidtopics.net/RLu4r6VrzMF9Vaxug9KjQg "Create the incident response option rules that end user or analyst can use while responding to an incident.")
* [Create age chart configurations](https://servicenow-prod.fluidtopics.net/iocRbBQN3eOFUtEHfseXng "Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.")
* [Create user delegate configurations](https://servicenow-prod.fluidtopics.net/taEwNu9D1oCTDUG~7YRq4w "Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.")
* [Create repeat offender identification rules](https://servicenow-prod.fluidtopics.net/ya7_7zLs~83PA_eUuYF80w "Create repeat offender identification rules to identify users who repeat the same issue multiple times.")
* [Create additional incident data fields](https://servicenow-prod.fluidtopics.net/CmlVgnvum6xrhlmBr5xSOA "Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.")
* [Configure advanced settings](https://servicenow-prod.fluidtopics.net/wwOHIHO~QiPeMQlpBVMNrw "Configure the advanced settings to customize the incident display and behavior. For example, enable displaying the sensitive data on an incident and its clone, or specifying fields on the incident to identify the end users. In addition, activate and customize the evidence files preview properties.")
* [DLP Incidents Archival](https://servicenow-prod.fluidtopics.net/1Y6pdckWs2tO8~g24W_scg "The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.")  
**Related reference**   

* [DLP SLA Definition form](https://servicenow-prod.fluidtopics.net/Z4MZ3Z00jp3m79J8c5joqQ "Field descriptions for the DLP SLA Definition form used to create an SLA record.")

*[\>]: and then


