---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Execute Smart Response Rules

# Execute Smart Response Rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use this feature to execute Smart Response Rules for the Symantec DLP incidents.

## Before you begin

You need to configure the Smart Response Rules by following procedure explained here in this section, [Configure Smart Response Rules](https://servicenow-prod.fluidtopics.net/zed_b98V45sMEuKDlkkvWA "Configure the Symantec smart response rule(s) to perform response actions on the ingested Symantec DLP Incidents.").

Role required: sn_dlir.admin  
Note:  
The response options on the workspace will be available for the end user or analyst or manager based on the configuration mentioned in the section [Configure response option for your DLP incidents](https://servicenow-prod.fluidtopics.net/1QqdESchbNTpm8Sp8oXHyQ "Use this feature to configure the type of response that an end user or analyst should perform.").

## Procedure

1. Navigate to AllDLPDLP User Workspace.
2. Open any Symantec DLP incident.
3. Click Respond.
4. Select the response option from the Response drop down list.  
   The response options will be visible based on the configuration of the Incident Response Option Rule and Response Option Mappings.
5. Click Submit.  
   Note:  
   You can also configure the approval rule(s) for the Response Options by following the procedure explained in the [Create Approval Rules](https://servicenow-prod.fluidtopics.net/y~1XZvQsmLOqBjkfbVKDbw "Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.") section. When an approval rule is configured for the Smart Response Rule, the approval flow will be triggered first and after receiving all the approvals, the Smart Response Option flow will be triggered. The state of the DLP Incident will be updated as per the target state of the Response Option mapping after successful run of response option.

*[\>]: and then


