---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and configure the DLP Incident Response application

# Install and configure the DLP Incident Response application {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Manage sensitive information and automate the remediation workflows by using the Data Loss Prevention Incident Response (DLP IR) application in your ServiceNow AI Platform
instance.

## Before you begin

Before you can complete the configuration steps, you must download the application
from the ServiceNow Store and install it on your instance.

Roles required: admin and sn_dlir.admin

## Procedure

1. Follow the instructions for [downloading an
   application from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").
2. After you have downloaded the DLP Incident Response application and all of its dependency applications, navigate to AllDLP AdministrationDefault Configuration to complete the rest of the [application
   configuration](https://servicenow-prod.fluidtopics.net/2LomJFXUoWOHDb4Lc0UfQA "Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.").
**Related reference**   

* [Domain separation and DLP Incident Response](https://servicenow-prod.fluidtopics.net/WO1Tvwg8MvWCthGE3UkdyA "You can use domain separation with DLP Incident Response to separate the data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.")

*[\>]: and then


