---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create response due date rules

# Create response due date rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.

## Before you begin

Role required:

* sn_dlir.admin
* sn_dlir.analyst and sn_dlir.analyst_read
{#setup-response-due-date-rules__ul_i4v_zgh_h5b}

## About this task

You can use this module to define the response due date rules for the different types of DLP incidents and the rules to start counting the due date. After the due date has expired, the users get notified about the overdue incident. You're also provided with an option to escalate the overdue incident to one of the following:

* Manager
* Custom User from Incident
* User group
{#setup-response-due-date-rules__ul_f1d_tv5_mwb}

For example, when you escalate the overdue incident to a Manager, and you've specified a maximum of three levels of escalation. The first level of Manager gets notified first. If the incident is overdue again, then the second
level of Manager gets notified, followed by the third level if the incident is still overdue. If the Manager has a Delegate, then the Manager has the option to assign the escalation or overdue incident to the Delegate.

You're also provided with the ability to create multiple response due date rules.

## Procedure

1. Navigate to AllDLP AdministrationResponse Due Date Rules.
2. Click New.
3. On the form, fill in the fields.  
   {#setup-response-due-date-rules__table_x3v_tbh_zrb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the response due date rule. |
   | Active | Option to indicate whether the response due date rule is active. |
   | Due in (days) | Number of due days. |
   | Due date counted from | Start date that is used to calculate the due date. The due date can be calculated from either the first time that the user was notified about the incident, or from the incident assignment date. |
   | Notify before due date | Option to notify the end user about the DLP incident before the due date. |
   | Notify on (days before due date) | Number of days before the due date when the rule triggers a notification to the end user. |
   | Description | Unique description for this response due date rule. |
   | Condition | Conditions in the condition builder. These conditions are based on the DLP incident table. To build a condition for the response due date rule, select any of the incident fields. Use the lists and fields of the conditions builder to set the filters for the first row. To add more conditions, click AND or OR. * If AND is selected, all conditions must be matched. * If OR is selected, either condition can be matched. {#setup-response-due-date-rules__ul_e1n_xsg_zrb} To set a second filter condition, click New Criteria. Note: The conditions in the condition builder are case sensitive. |
   | Escalate | Option to escalate the DLP incident to someone if the response due date has been breached. For more information, see [Add multiple users to access DLP incidents](https://servicenow-prod.fluidtopics.net/9nTaLlhsE4K1sjgkkrIloA "Use the escalation chain feature to allow all the respective users who are involved in the incident to access the DLP incidents from the list view, though the incident is assigned to a different user.") |
   | Escalate overdue incident to | Option to specify if the incident should be escalated to a Manager, a Custom user, or a User group. This field appears only when the Escalate option is enabled. |
   | Assign using | Specify how a manager should be identified. This field appears only when Manager is selected from the Escalate overdue incident to field. |
   | Maximum Escalation Levels | Option to define the maximum number of escalation levels for a Manager, and a Custom user. As a Manager or Custom user, you can define any number of escalation levels. By default, three levels of escalation are provided. * As a Manager, you can define any number of escalation levels by updating the value in this field. * As a Custom user, you can use the + icon to define any number of escalation levels. {#setup-response-due-date-rules__ul_wdf_23p_3tb} |
   | Custom attribute | Option to specify a custom attribute from the incident that has the reference to a user. This field appears only when Custom User from Incident is selected from the Escalate overdue incident to field. |
   | User group | Option to search and select a user group to escalate DLP incidents to. This field appears only when User group is selected from the Escalate overdue incident to field. Note: You can only view and select groups that have been assigned with the sn_dlir.analyst role. |
   [Table 1. Response Due Date Rule form]

   {#setup-response-due-date-rules__table_x3v_tbh_zrb}  
   The following example shows the response due date rule to determine how much time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP) incidents. After the end user is first notified, the response due date is in two days. The conditions builder shows that the Scan Source must match the Endpoint File System to proceed with creating the response due date. The escalation option is selected. The incident is escalated to the manager if the response due date is breached.
4. Click Submit.
* **[Add multiple users to access DLP incidents](https://servicenow-prod.fluidtopics.net/9nTaLlhsE4K1sjgkkrIloA)**   
  Use the escalation chain feature to allow all the respective users who are involved in the incident to access the DLP incidents from the list view, though the incident is assigned to a different user.

**Related concepts**   

* [Monitor DLP Integration Run process](https://servicenow-prod.fluidtopics.net/1Ov8JAQizZC7T2HLNPiOvg "Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.")
* [DLP Incident Access Restrictions](https://servicenow-prod.fluidtopics.net/RLjeozrMpG2FVpJaLmRMuQ "Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.")  
**Related tasks**   

* [DLP default configuration settings](https://servicenow-prod.fluidtopics.net/2LomJFXUoWOHDb4Lc0UfQA "Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.")
* [Create end user lookup rules](https://servicenow-prod.fluidtopics.net/ccMfdPxSgHsL9Fh1Q_~JsA "You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.")
* [Create assignment rules](https://servicenow-prod.fluidtopics.net/8vAoEijgHvURfLHuuPSmqQ "Create assignment rules and assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.")
* [Create incident consolidation rules](https://servicenow-prod.fluidtopics.net/vvKTITK9qLCsbKKkoqVL5A "Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.")
* [Create Approval Rules](https://servicenow-prod.fluidtopics.net/y~1XZvQsmLOqBjkfbVKDbw "Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.")
* [Create user instructions templates](https://servicenow-prod.fluidtopics.net/CAThP9D~817jopKRDJeJPg "Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.")
* [Create email templates](https://servicenow-prod.fluidtopics.net/wQtZqtIiLEBZdQR8aYbIiA "Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create a Data Loss Prevention Incident Response SLA trigger](https://servicenow-prod.fluidtopics.net/n4qzNvzCeD6gk9FwYIJ9Vw "Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.")
* [Create a Data Loss Prevention Incident Response SLA definition](https://servicenow-prod.fluidtopics.net/80miwPm0oR7Ix7EQ~DpIew "Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.")
* [Create assessments](https://servicenow-prod.fluidtopics.net/XzB5FSKtotEb1LiHYADPog "Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.")
* [Configure response option for your DLP incidents](https://servicenow-prod.fluidtopics.net/1QqdESchbNTpm8Sp8oXHyQ "Use this feature to configure the type of response that an end user or analyst should perform.")
* [Create incident response option rules](https://servicenow-prod.fluidtopics.net/RLu4r6VrzMF9Vaxug9KjQg "Create the incident response option rules that end user or analyst can use while responding to an incident.")
* [Create age chart configurations](https://servicenow-prod.fluidtopics.net/iocRbBQN3eOFUtEHfseXng "Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.")
* [Create user delegate configurations](https://servicenow-prod.fluidtopics.net/taEwNu9D1oCTDUG~7YRq4w "Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.")
* [Create repeat offender identification rules](https://servicenow-prod.fluidtopics.net/ya7_7zLs~83PA_eUuYF80w "Create repeat offender identification rules to identify users who repeat the same issue multiple times.")
* [Create additional incident data fields](https://servicenow-prod.fluidtopics.net/CmlVgnvum6xrhlmBr5xSOA "Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.")
* [Configure advanced settings](https://servicenow-prod.fluidtopics.net/wwOHIHO~QiPeMQlpBVMNrw "Configure the advanced settings to customize the incident display and behavior. For example, enable displaying the sensitive data on an incident and its clone, or specifying fields on the incident to identify the end users. In addition, activate and customize the evidence files preview properties.")
* [DLP Incidents Archival](https://servicenow-prod.fluidtopics.net/1Y6pdckWs2tO8~g24W_scg "The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.")  
**Related reference**   

* [DLP SLA Definition form](https://servicenow-prod.fluidtopics.net/Z4MZ3Z00jp3m79J8c5joqQ "Field descriptions for the DLP SLA Definition form used to create an SLA record.")

*[\>]: and then


