Data Loss Prevention Incident Response Analyst Workspace
- UpdatedJul 31, 2025
- 13 minutes to read
- Zurich
- Security Operations
Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
The DLP workspace consists of a home page with dashboards, list views, and form views that let you monitor DLP incidents.
Review and assign your DLP incidents
Access the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace so that you can review the DLP incidents and assign or resolve them. You can track trends on incidents by severity, top offenders, incidents by scan source, and incidents by policy.
Before you begin
- sn_dlir.analyst - Edit and view DLP incidents.
- sn_dlir.analyst_read and sn_dlir.read - View DLP Incidents.
Procedure
Preview evidence files
Preview Data Loss Prevention Incident Response evidence files in the DLP IR Analyst workspace.
Before you begin
Role required: sn_dlir.analyst
Procedure
Playbook for Data Loss Prevention Incident Response
A Data Loss Prevention Incident Response Playbook is a step-by-step guide for addressing and mitigating data loss incidents, which can include unauthorized exposures, leaks, or breaches of sensitive information that can compromise your organization’s security.
The following image shows the sample Playbooks available for DLP IR.
The following table lists the activities and stages available for creating a DLP Playbook. For more information, see Add a DLP Playbook:
| Activity | Description |
|---|---|
| Detection | Identify and confirm unauthorized access or exposure of sensitive data. |
| Containment | Isolate affected systems or users to prevent further data leakage or unauthorized access. |
| Investigation | Investigate the breach to understand how it occurred, what data was affected, and the potential impact. |
| Notification | Notify internal teams, external stakeholders, and regulatory bodies as required by law or policy. |
| Remediation | Apply corrective measures to address vulnerabilities, update policies, and prevent future breaches. |
| Recovery | Restore systems from secure backups and validate the integrity of data post-incident. |
| Post-Incident Review | Analyze the incident to identify root causes, improve security controls, and strengthen policies. |
The following figure shows the workflow of activities and stages involved in the creation of the Sensitive Data Breach Playbook. Playbook steps vary depending on the workflow.
Add a DLP Playbook
Add a Playbook in the Data Loss Prevention Incident Response Analyst workspace that can act as a guide for addressing and mitigating data loss incidents that can compromise your organization’s security.
Before you begin
Role required: sn_dlir.analyst - Add or view Playbooks in the DLP workspace.
Procedure
Cancel a DLP Playbook
Cancel a Data Loss Prevention Incident Response Playbook to stop a business flow when it is no longer valid.
Before you begin
Role required: sn_dlir.admin.
Procedure
- Navigate to .
- Open any DLP incident.
- Navigate to the Playbooks tab.
-
In the header of the Playbook that you want to cancel, select the Playbook actions icon (
) and then select Cancel Playbook.
- Provide a reason for canceling the Playbook.
- Select Cancel Playbook.
Result
A banner appears below the Playbook header confirming that the Playbook has been canceled.
View archived DLP incidents
Use DLP Analyst workspace to view the archived DLP incidents
Before you begin
- sn_dlir.analyst - Edit and view DLP incidents.
- sn_dlir.analyst_read and sn_dlir.read - View DLP Incidents.
Procedure
Related Content
- Data Loss Prevention Incident Response User Workspace
The Data Loss Prevention Incident Response (DLP IR) User Workspace is a workspace where end users, managers, and approvers can respond to the assigned DLP incidents. The end users, managers, and approvers can then respond to the incidents by specifying the correct actions.
- Data Loss Prevention Incident Response Dashboard
The Data Loss Prevention Incident Response (DLP IR) Dashboard provides a high-level overview of your DLP incidents and daily incidents trends in your instance in the form of graphical charts. These charts help you effectively view, manage, and remediate the DLP incidents.
- Add a DLP Playbook
Add a Playbook in the Data Loss Prevention Incident Response Analyst workspace that can act as a guide for addressing and mitigating data loss incidents that can compromise your organization’s security.