---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create email templates

# Create email templates {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 7 minutes to read

Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.

## Before you begin

Role required:

* sn_dlir.admin - Create, edit, and delete.
* sn_dlir.analyst and sn_dlir.analyst_read - View (read-only).  
  Important:  
  For Analysts to view email communications of a DLP Incident on the activity stream, you should add or append the 'sn_dlir.analyst' role in the global system property `glide.ui.activity.email_roles`.
{#create-and-manage-email-templates__ul_i4v_zgh_h5b}

## About this task

Email notifications are categorized by the incident notifications that are sent to the end users, the escalation notifications that are sent to the managers, or the due date notifications. You can send email notifications about the due dates for DLP incidents, or even coach the end users about what to do when certain conditions are met in the email conditions filter.

DLP email templates enable you to send the email
notification for end users, managers, and analysts. You can configure the templates to be sent per incident or as a digest. Your email subject and body can contain variables so that you can reuse your existing content.  
DLP provides the following preconfigured email templates based on the categories:

* DLP Email template - Per incident approval notification: Notify users about the approval for their requests.
* DLP Email template - Escalation notification: Send escalation notifications to managers in the form of digests.
* DLP Email template - Pending approval notification: Notify approvers about pending items.
* DLP Email template - Per incident approval request cancellation notification:Notify users about an approval request that has been cancelled by DLP analyst team.
* DLP Email template - User response completion notification: Notify DLP analyst team about the response submitted by users.
* DLP Email template - User incident notification:This is a default template for user digest notification. Send incident notifications to the end users in the form of digests every few days, even if there are no new incidents, to inform the users about the total number of incidents on the particular user's name. You can also send digest notifications to notify the users about the nearest upcoming due dates of DLP incidents with the severity as critical, high, medium, or low.
* DLP Email template - Per incident pending approval notification: Notify approvers about pending approvals.
* DLP Email template - rejection notification: Send reject notification to requester.
* DLP Email template - Due date notification: Send incident due date notification. If a DLP incident is assigned to the end user, and if the end user has not taken any action before the due date, then an email notification is sent to the end user. You also have an option to escalate the DLP incident to a manager, a custom user, or a user group if the response due date has been breached.  
  Note:  
  Due date notifications must be in the form of digests.
* DLP Email template - Per incident user response notification: Notify analysts about the response submitted users per incident.
* DLP Email template - Per incident escalation notification: Notify managers about escalations per incident.
* DLP Email template - Per incident user notification: Notify users about assignment per incident.
{#create-and-manage-email-templates__ul_zzb_s1f_vsb}

## Procedure

1. Navigate to AllDLP AdministrationEmail Templates.
2. Click New.
3. On the form, fill in the fields.  
   {#create-and-manage-email-templates__table_r3h_shh_zrb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the email template. |
   | Active | Option to indicate whether the DLP email template is active. If this option is not enabled, then notifications are not sent for this email template. |
   | Category | Email notification category. DLP supports the following options: * Incident notification to end users: Sent when the incidents are assigned to the end users. * Escalation notification to managers: Sent when the response due date is breached or manually assigned to the manager through DLP Ops portal. * Due date notification: Sent when the response due date is breached. * User response notification to analysts: Sent when the end user takes any action on the DLP incident. * Pending approvals notification: Notify approvers about pending items. * Approval notification to the requester: Notify users about the approval for their requests. * Reject notification to the requester: Notify users about the rejection for their requests. * Cancel notification to the requester: Notify users about the cancellation for their requests. {#create-and-manage-email-templates__ul_bjy_f3h_zrb} |
   | Type | Option to indicate whether the email is sent per incident or as a digest. Note: If you selected Due date notification from the Category field, then you can use only digests. Select this option. |
   | Description | Unique description for this email template. |
   | Execution Order | Email template priority. This field indicates the order in which the email templates are executed when two or more email templates share the triggering conditions. The email template with the lowest number has the highest priority. To set the order of operation, enter a value. For example, 100, 200, or any other number. The default value is 100. |
   | Template Condition | Options in the template conditions that are based on the DLP incident table. You can select any of the incident fields for building the email template trigger condition. Use the lists and fields of the conditions builder to set the filters for the first row. To add more conditions, click AND or OR. * If AND is selected, all conditions must be matched. * If OR is selected, either condition can be matched. {#create-and-manage-email-templates__ul_fvs_kn2_tsb} To set a second filter condition, click New Criteria. Note: The conditions in the condition builder are case sensitive. |
   | Target Users | Target users for the template when the conditions are met. The target users can be one of the following: * All recipients: Send the email to target users. * Recipients in the group: Send the email only to recipients within a particular group by using the filter option. * Recipients matching the criteria: Send the email to target users who match the criteria. You can use the filter to drill down target users based on the conditions. For example, city. {#create-and-manage-email-templates__ul_l2q_p1t_vsb} |
   | Email Template | Email template that you can select. You can define the variables to reuse existing content to add to the email notification. The Category and Type fields determine the variables that are available for selection. For example, let's say that the email category is set to incident notification and that the email type is a digest, then the variables for selection are digest fields to accommodate the accumulation of multiple DLP incidents. Here is an example Email Body HTML of each email template: * Default template for Per incident approval notification: Dear ${respondent.first_name}, Your request "${end_user_response}" on the incident ${number} has been approved. - Date protection team * Per incident approval request cancellation notification Dear ${respondent.first_name}, Your request "${end_user_response}" on the DLP incident ${number} has been cancelled. No action is required from you at this point. Data protection team will contact you for any further information required. - Data protection team * Default template for Due date notification: Dear ${target_user.name}, Following incidents require your response. ${due_days_table} - Data protection team * Default template for Per Incident user notification: Dear ${assigned_to.name}, DLP Incident ${number} is assigned to you. Please review and submit your response. - Data protection team * Default template for User incident notification: Hello ${target_user.name}, You have ${total_number_of_incidents} incidents assigned to you currently that require your response. ${new_incidents_in_period} new incidents got assigned to you since the last email communication. Nearest upcoming due date for responding to a critical incident is ${nearest_due_date_for_critical_severity_incidents}. Please log in to the ${link_to_dlp_portal} and submit your response. - Data protection team * Default template for Escalation - Digest: Hi ${target_user.name}, The following data security incidents have been escalated to you due to lack of response from the assignees. Please login to the incident response workspace to review the incidents and submit your response. ${overdue_table} - Data protection team * Default template for Escalation - Per Incident: Dear ${assigned_to.name}, Data security incident ${number} has been escalated to you. Please review and submit your response or assign the incident back to the user. - Data protection team * Default template for Pending approval notification: Dear ${approver.first_name}, Your approval is required for a few requests on data security incidents. Please login to the workspace here and review the requests. - Data protection team * Default template for Per incident pending approval notification: Dear ${Approver}, Your approval is required for the incident ${number} requested by the user ${respondent.first_name} ${respondent.last_name}. Please visit this here to approve or reject the request. - Data Protection Team * Default template for Per incident rejection notification: Dear ${respondent.first_name} ${respondent.last_name}, This is to inform you that your request "${end_user_response}" for the DLP incident ${number} has been rejected. Please review the incident here. - Data protection team * Default template for Per incident user response notification: Hi ${assigned_to.name}, This is to inform you that a response has been submitted for the DLP Incident ${number}. * Default template for User response completion notification: Hello ${target_user.name}, This email is to inform you that users have submitted their response for ${new_incidents_in_period_user_response_completed} new incidents since the last email communication. Please review the response for these incidents ${link_to_incidents_in_period_user_response_completed}. {#create-and-manage-email-templates__ul_ivg_3b5_1xb} |
   [Table 1. DLP Email Template form]

   {#create-and-manage-email-templates__table_r3h_shh_zrb}  
   The following example shows the DLP Email Template with the target users defined as all recipients.Figure 1. Email template

   The following example shows an email template with the subject "User incident notification" and a variable <var class="keyword varname">new_incidents_in_period</var>. The email body contains multiple variables that are added from the
   Select variables column.
   Figure 2. Email template variables
4. Click Submit.

## Result

The end user receives a digest notification email with all the selected variable
fields in the template.
**Related concepts**   

* [Monitor DLP Integration Run process](https://servicenow-prod.fluidtopics.net/1Ov8JAQizZC7T2HLNPiOvg "Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.")
* [DLP Incident Access Restrictions](https://servicenow-prod.fluidtopics.net/RLjeozrMpG2FVpJaLmRMuQ "Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.")  
**Related tasks**   

* [DLP default configuration settings](https://servicenow-prod.fluidtopics.net/2LomJFXUoWOHDb4Lc0UfQA "Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.")
* [Create end user lookup rules](https://servicenow-prod.fluidtopics.net/ccMfdPxSgHsL9Fh1Q_~JsA "You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.")
* [Create assignment rules](https://servicenow-prod.fluidtopics.net/8vAoEijgHvURfLHuuPSmqQ "Create assignment rules and assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.")
* [Create incident consolidation rules](https://servicenow-prod.fluidtopics.net/vvKTITK9qLCsbKKkoqVL5A "Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.")
* [Create response due date rules](https://servicenow-prod.fluidtopics.net/VgO2TB6WZtrxmG4~JWv2vA "Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create Approval Rules](https://servicenow-prod.fluidtopics.net/y~1XZvQsmLOqBjkfbVKDbw "Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.")
* [Create user instructions templates](https://servicenow-prod.fluidtopics.net/CAThP9D~817jopKRDJeJPg "Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.")
* [Create a Data Loss Prevention Incident Response SLA trigger](https://servicenow-prod.fluidtopics.net/n4qzNvzCeD6gk9FwYIJ9Vw "Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.")
* [Create a Data Loss Prevention Incident Response SLA definition](https://servicenow-prod.fluidtopics.net/80miwPm0oR7Ix7EQ~DpIew "Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.")
* [Create assessments](https://servicenow-prod.fluidtopics.net/XzB5FSKtotEb1LiHYADPog "Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.")
* [Configure response option for your DLP incidents](https://servicenow-prod.fluidtopics.net/1QqdESchbNTpm8Sp8oXHyQ "Use this feature to configure the type of response that an end user or analyst should perform.")
* [Create incident response option rules](https://servicenow-prod.fluidtopics.net/RLu4r6VrzMF9Vaxug9KjQg "Create the incident response option rules that end user or analyst can use while responding to an incident.")
* [Create age chart configurations](https://servicenow-prod.fluidtopics.net/iocRbBQN3eOFUtEHfseXng "Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.")
* [Create user delegate configurations](https://servicenow-prod.fluidtopics.net/taEwNu9D1oCTDUG~7YRq4w "Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.")
* [Create repeat offender identification rules](https://servicenow-prod.fluidtopics.net/ya7_7zLs~83PA_eUuYF80w "Create repeat offender identification rules to identify users who repeat the same issue multiple times.")
* [Create additional incident data fields](https://servicenow-prod.fluidtopics.net/CmlVgnvum6xrhlmBr5xSOA "Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.")
* [Configure advanced settings](https://servicenow-prod.fluidtopics.net/wwOHIHO~QiPeMQlpBVMNrw "Configure the advanced settings to customize the incident display and behavior. For example, enable displaying the sensitive data on an incident and its clone, or specifying fields on the incident to identify the end users. In addition, activate and customize the evidence files preview properties.")
* [DLP Incidents Archival](https://servicenow-prod.fluidtopics.net/1Y6pdckWs2tO8~g24W_scg "The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.")  
**Related reference**   

* [DLP SLA Definition form](https://servicenow-prod.fluidtopics.net/Z4MZ3Z00jp3m79J8c5joqQ "Field descriptions for the DLP SLA Definition form used to create an SLA record.")

*[\>]: and then


