---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure response option for your DLP incidents

# Configure response option for your DLP incidents {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Use this feature to configure the type of response that an end user or analyst should perform.

## Before you begin

The base system DLP Incident Response application provides the following response options:

1. Assessment Complete
2. Deleted Content
3. Deleted File
4. Encrypted File
5. Masked Content
6. Report false positive
7. Report wrong owner
8. Request email release from quarantine  
   Note:  
   This option is available for the DLP Microsoft Exchange records.
9. Required for Business Process
10. Reviewed Entitlements

{#configure-response-option-mapping__ol_vwx_lxd_cyb}Role required:

* sn_dlir.admin
* sn_dlir.analyst and sn_dlir.analyst_read
{#configure-response-option-mapping__ul_i4v_zgh_h5b}

## Procedure

1. Navigate to AllDLP AdministrationResponse Options.  
   By default, the base system provides two types of response option:
   1. Basic: A manual response option submitted by the user.
   2. Advanced: An automated response option triggers a flow designer sub flow when the user submits the response option.
   {#configure-response-option-mapping__ol_qnq_zwd_cyb}
2. Click New.
3. On the form, fill in the fields.  
   {#configure-response-option-mapping__table_wrk_qyk_zrb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Enter the name of the incident response option. |
   | Type | Option to select the response option type. |
   [Table 1. Response Option form of Type: Basic]

   {#configure-response-option-mapping__table_wrk_qyk_zrb} {#configure-response-option-mapping__table_jnq_3wd_cyb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Enter the name of the incident response option. |
   | Type | Option to select the response option. By default, this field displays the following two types of options: * Basic: When you select this option while creating a new response option, you may have to add a response option name and the type. * Advanced: When you select this option, the following fields will be available for you to select: * Flow: Select the flow designer sub flow. * Requires MID Server: Select this check box if the selected flow uses the MID Server. {#configure-response-option-mapping__ul_cgx_gzd_cyb} {#configure-response-option-mapping__ul_bgx_gzd_cyb} |
   | Flow | Select the required flow designer flow to activate the MID Application and MID Capability. When you are creating a sub flow for the response option, add the following sub flow inputs: 1. Name: * dlp_incident * mid_server_capability * mid_server_application {#configure-response-option-mapping__ul_ajk_3b2_cyb} 2. Type: * Reference (to DLP incident table) * Sys ID for both MID Server application and MID Server Capability {#configure-response-option-mapping__ul_tcj_kb2_cyb} {#configure-response-option-mapping__ol_gkh_fb2_cyb} |
   | Requires MID Server | Option to determine that MID server configuration. By enabling the Requires MID Server checkbox MID Server Application and MID Server Capability fields you can configure the MID Application and MID Capability. Note: Based on the MID Server Application and MID Server Capability configuration and if any MID is up and running then only the Response Option will be visible in the workspace. |
   | MID Server Application | Select the required MID Server Application from the drop down list. |
   | MID Server Capability | Select the required MID Server Capability from the drop down list. |
   [Table 2. Response Option form of Type: Advanced]

   {#configure-response-option-mapping__table_jnq_3wd_cyb}  
   Note:  
   If there is no MID server available for the selected MID Server Capability, the response option will not be visible. If you want a specific MID server from the list then you have to configure the MID app and make it visible in the list, and then at least one MID server which is configured should be up and running from the selected mid applications and should have the selected MID Server Capability.
4. Click Submit.  
   Note:  
   If you are creating an Advanced type of response option, then the Approval Rules related list will be populated for you to configure the approval rule for that new response option. For more information, see [Create Approval Rules](https://servicenow-prod.fluidtopics.net/y~1XZvQsmLOqBjkfbVKDbw "Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.").
   Figure 1. Configure Response Option of Type: Advanced
**Related concepts**   

* [Monitor DLP Integration Run process](https://servicenow-prod.fluidtopics.net/1Ov8JAQizZC7T2HLNPiOvg "Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.")
* [DLP Incident Access Restrictions](https://servicenow-prod.fluidtopics.net/RLjeozrMpG2FVpJaLmRMuQ "Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.")  
**Related tasks**   

* [DLP default configuration settings](https://servicenow-prod.fluidtopics.net/2LomJFXUoWOHDb4Lc0UfQA "Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.")
* [Create end user lookup rules](https://servicenow-prod.fluidtopics.net/ccMfdPxSgHsL9Fh1Q_~JsA "You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.")
* [Create assignment rules](https://servicenow-prod.fluidtopics.net/8vAoEijgHvURfLHuuPSmqQ "Create assignment rules and assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.")
* [Create incident consolidation rules](https://servicenow-prod.fluidtopics.net/vvKTITK9qLCsbKKkoqVL5A "Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.")
* [Create response due date rules](https://servicenow-prod.fluidtopics.net/VgO2TB6WZtrxmG4~JWv2vA "Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create Approval Rules](https://servicenow-prod.fluidtopics.net/y~1XZvQsmLOqBjkfbVKDbw "Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.")
* [Create user instructions templates](https://servicenow-prod.fluidtopics.net/CAThP9D~817jopKRDJeJPg "Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.")
* [Create email templates](https://servicenow-prod.fluidtopics.net/wQtZqtIiLEBZdQR8aYbIiA "Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create a Data Loss Prevention Incident Response SLA trigger](https://servicenow-prod.fluidtopics.net/n4qzNvzCeD6gk9FwYIJ9Vw "Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.")
* [Create a Data Loss Prevention Incident Response SLA definition](https://servicenow-prod.fluidtopics.net/80miwPm0oR7Ix7EQ~DpIew "Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.")
* [Create assessments](https://servicenow-prod.fluidtopics.net/XzB5FSKtotEb1LiHYADPog "Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.")
* [Create incident response option rules](https://servicenow-prod.fluidtopics.net/RLu4r6VrzMF9Vaxug9KjQg "Create the incident response option rules that end user or analyst can use while responding to an incident.")
* [Create age chart configurations](https://servicenow-prod.fluidtopics.net/iocRbBQN3eOFUtEHfseXng "Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.")
* [Create user delegate configurations](https://servicenow-prod.fluidtopics.net/taEwNu9D1oCTDUG~7YRq4w "Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.")
* [Create repeat offender identification rules](https://servicenow-prod.fluidtopics.net/ya7_7zLs~83PA_eUuYF80w "Create repeat offender identification rules to identify users who repeat the same issue multiple times.")
* [Create additional incident data fields](https://servicenow-prod.fluidtopics.net/CmlVgnvum6xrhlmBr5xSOA "Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.")
* [Configure advanced settings](https://servicenow-prod.fluidtopics.net/wwOHIHO~QiPeMQlpBVMNrw "Configure the advanced settings to customize the incident display and behavior. For example, enable displaying the sensitive data on an incident and its clone, or specifying fields on the incident to identify the end users. In addition, activate and customize the evidence files preview properties.")
* [DLP Incidents Archival](https://servicenow-prod.fluidtopics.net/1Y6pdckWs2tO8~g24W_scg "The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.")  
**Related reference**   

* [DLP SLA Definition form](https://servicenow-prod.fluidtopics.net/Z4MZ3Z00jp3m79J8c5joqQ "Field descriptions for the DLP SLA Definition form used to create an SLA record.")

*[\>]: and then


