---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create assignment rules

# Create assignment rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Create assignment rules and assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.

## Before you begin

Role required:

* sn_dlir.admin
* sn_dlir.analyst and sn_dlir.analyst_read
{#create-assignment-rules__ul_i4v_zgh_h5b}

## About this task

Use assignment rules to assign DLP IR incidents to user groups, end users, or to managers. The assignment of the DLP incidents occur when the conditions in the assignment rule are met.

## Procedure

1. Navigate to AllDLP AdministrationAssignment Rules.
2. Select New.
3. On the form, fill in the fields.  
   {#create-assignment-rules__table_ilq_qrg_zrb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the assignment rule. |
   | Active | Option to indicate whether the assignment rule is active. |
   | Execution order | The assignment rule priority. This field indicates the order in which the assignment rules are executed when two or more rules share the triggering conditions. The assignment rule with the lowest number has the highest priority. To set the order of operation, enter a value. For example, 100, 200, 300, and so on. The default value is 100. |
   | Description | Unique description for this assignment rule. |
   | Condition | Conditions in the condition builder. These conditions are based on the DLP incident table. To build a condition for the assignment rule, select any of the incident fields. Use the lists and fields of the conditions builder to set the filters for the first row. To add more conditions, click AND or OR. * If AND is selected, all conditions must be matched. * If OR is selected, either condition can be matched. {#create-assignment-rules__ul_e1n_xsg_zrb} To set a second filter condition, click New Criteria. For example, assume you create a DLP assignment rule for an endpoint. You can specify that the condition scan source is an endpoint file system that must be met before assigning an incident. Note: The conditions in the condition builder are case sensitive. |
   | Assign to | Assignment to either one of the following: * User group * End user * Manager * User from incident {#create-assignment-rules__ul_nhj_121_yxb}The assignment occurs when the conditions in the condition builder are met. |
   | User group | Option to search and select a user group to assign the DLP incidents to. This field appears when User group is selected from the Assign to field. Note: You can only view and select groups that have been assigned with the sn_dlir.analyst role. |
   | End user | Option to assign the DLP incident to the end user. The assignment occurs when the conditions in the condition builder are met. |
   | Assign using Manager fields | Manager of the end user. This field appears when Manager is selected from the Assign to field. You can assign the DLP incidents to a particular manager by selecting one of the Manager fields, such as Last name, Email, City, Employee number. |
   | User Identifier | The user identifier of the incident. This field appears when User from Incident is selected from the Assign to field. You can select an user identifier from the following: * Data owner email * Destination * File created by * File modified by * File owner * FTP user name * Sender * Custom user from incident {#create-assignment-rules__ul_gk2_crv_1xb} |
   | Custom attribute | Option to specify a custom attribute from the incident that has the reference to a user. This field appears only when the Custom User from Incident is selected from the User Identifier field. |
   | Attach Assessment | Option to indicate whether you want to attach an assessment to the incident. |
   | Pre assessment response state | Option to select which state that the incident should be in before the end user responds. It can also be a custom state. The default value is Pending assessment. |
   | Post assessment response state | Option to select which state that the DLP incident should be in after the user responds. The default value is Assessment Completed. |
   | Advanced | Advanced option to identify the end user. This field appears only when the Custom User from Incident is selected from the User Identifier field. You can use the script editor to customize and format the field values during the assignment rule creation to identify the end user. Then, you pick whom you want to assign the DLP incident to, which could be an End user or the End user's Manager. For example, you can use the email address field to identify the end user. |
   [Table 1. DLP Assignment Rule form]

   {#create-assignment-rules__table_ilq_qrg_zrb}  
   The following example shows an assignment rule with the name `Assign 'Medium' Priority Incident to End User`. The condition builder requires the Scan Source to be `Endpoint File System`, and the `Assign to` field is set to `End user`. Then, you can look up the 'Email' of the End user.Figure 1. DLP Assignment rule
4. Select the Assign to field from the related list section where all the DLP incidents are assigned to.  
   Select Edit to add the user group. When you select Edit from the related list section and select an item from the Collections columns and then add that selected assignee to the Group columns in the Edit Members page, and save the list.  
   Note:  
   You can only view and select groups that have been assigned with the sn_dlir.analyst role from the related list. You can only select one group.
5. Select Submit.  
   You can select one or more assignment rules and reapply it on all existing DLP incidents.
6. To reapply an assignment rule on all existing DLP incidents, select Reapply.
**Related concepts**   

* [Monitor DLP Integration Run process](https://servicenow-prod.fluidtopics.net/1Ov8JAQizZC7T2HLNPiOvg "Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.")
* [DLP Incident Access Restrictions](https://servicenow-prod.fluidtopics.net/RLjeozrMpG2FVpJaLmRMuQ "Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.")  
**Related tasks**   

* [DLP default configuration settings](https://servicenow-prod.fluidtopics.net/2LomJFXUoWOHDb4Lc0UfQA "Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.")
* [Create end user lookup rules](https://servicenow-prod.fluidtopics.net/ccMfdPxSgHsL9Fh1Q_~JsA "You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.")
* [Create incident consolidation rules](https://servicenow-prod.fluidtopics.net/vvKTITK9qLCsbKKkoqVL5A "Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.")
* [Create response due date rules](https://servicenow-prod.fluidtopics.net/VgO2TB6WZtrxmG4~JWv2vA "Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create Approval Rules](https://servicenow-prod.fluidtopics.net/y~1XZvQsmLOqBjkfbVKDbw "Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.")
* [Create user instructions templates](https://servicenow-prod.fluidtopics.net/CAThP9D~817jopKRDJeJPg "Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.")
* [Create email templates](https://servicenow-prod.fluidtopics.net/wQtZqtIiLEBZdQR8aYbIiA "Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create a Data Loss Prevention Incident Response SLA trigger](https://servicenow-prod.fluidtopics.net/n4qzNvzCeD6gk9FwYIJ9Vw "Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.")
* [Create a Data Loss Prevention Incident Response SLA definition](https://servicenow-prod.fluidtopics.net/80miwPm0oR7Ix7EQ~DpIew "Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.")
* [Create assessments](https://servicenow-prod.fluidtopics.net/XzB5FSKtotEb1LiHYADPog "Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.")
* [Configure response option for your DLP incidents](https://servicenow-prod.fluidtopics.net/1QqdESchbNTpm8Sp8oXHyQ "Use this feature to configure the type of response that an end user or analyst should perform.")
* [Create incident response option rules](https://servicenow-prod.fluidtopics.net/RLu4r6VrzMF9Vaxug9KjQg "Create the incident response option rules that end user or analyst can use while responding to an incident.")
* [Create age chart configurations](https://servicenow-prod.fluidtopics.net/iocRbBQN3eOFUtEHfseXng "Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.")
* [Create user delegate configurations](https://servicenow-prod.fluidtopics.net/taEwNu9D1oCTDUG~7YRq4w "Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.")
* [Create repeat offender identification rules](https://servicenow-prod.fluidtopics.net/ya7_7zLs~83PA_eUuYF80w "Create repeat offender identification rules to identify users who repeat the same issue multiple times.")
* [Create additional incident data fields](https://servicenow-prod.fluidtopics.net/CmlVgnvum6xrhlmBr5xSOA "Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.")
* [Configure advanced settings](https://servicenow-prod.fluidtopics.net/wwOHIHO~QiPeMQlpBVMNrw "Configure the advanced settings to customize the incident display and behavior. For example, enable displaying the sensitive data on an incident and its clone, or specifying fields on the incident to identify the end users. In addition, activate and customize the evidence files preview properties.")
* [DLP Incidents Archival](https://servicenow-prod.fluidtopics.net/1Y6pdckWs2tO8~g24W_scg "The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.")  
**Related reference**   

* [DLP SLA Definition form](https://servicenow-prod.fluidtopics.net/Z4MZ3Z00jp3m79J8c5joqQ "Field descriptions for the DLP SLA Definition form used to create an SLA record.")

*[\>]: and then


