---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create user instructions templates

# Create user instructions templates {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.

## Before you begin

The user instructions card template displays two different headers which provides you more information about a specific incident on the form view.  
Role required:

* sn_dlir.admin - Create, edit, and delete.
* sn_dlir.analyst and sn_dlir.analyst_read - View (read-only).
{#create-and-manage-user-instructions-template-for-dlp-incidents__ul_i4v_zgh_h5b}

## About this task

When an incident is assigned to the end user then the user might be required to know the additional instructions on how to respond to the incidents, introduce the users to the terminology and provide any additional
information about the incident. These templates can guide the users to provide the accurate response to the DLP incidents.

## Procedure

1. Navigate to AllDLP AdministrationUser Instructions Templates.
2. Click New.
3. On the form, fill in the fields.  
   {#create-and-manage-user-instructions-template-for-dlp-incidents__table_usk_rtj_g5b__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the user instruction template. |
   | Short Description | Unique description of this user instruction template. |
   | Active | Option to indicate whether the user instruction template is active. |
   | Execution Order | Priority of the incident user instruction template. This field indicates the order in which the order is executed to evaluate the user instruction template when an incident is created. The option with the lowest number has the highest priority. To set the order of operation, enter a value. For example, 100, 200, or any other number. The default is 100. |
   | Incidents matching condition | Incidents that match the defined conditions in the condition builder will be displayed. These conditions are based on the DLP incident data. To build a condition for a user instruction, select any of the incident fields. Use the lists and fields of the conditions builder to set the filters for the first row. To add more conditions, click AND or OR: If AND is selected, all conditions must be matched. If OR is selected, either condition can be matched. To set a second filter condition, click New Criteria. Note: The conditions in the condition builder are case sensitive. |
   | Applies to | Select the user or user groups that the template is applicable for. The other available options are: * All end users: Select this check box if the instructions template applies to all the users. * All reviewers of escalated incidents: Select this check box if the template applies to all the reviewers of the escalated incidents. * Specific users: Click the icon to add a particular user from the list to whom the DLP incident conditions are applicable. You can also add a user by using their email address or search option. For example, Legal Manager. To add yourself as the user to whom the DLP conditions are applicable, click the Add me icon. * Specific user groups: Click the icon to add a particular group from the list to whom the DLP incident conditions are applicable. You can also add a group by using the search option. For example, Survey creators. {#create-and-manage-user-instructions-template-for-dlp-incidents__ul_rkz_s4l_5xb} |
   | Instructions Template: Instructions | Add instructions in the rich text editor with variables available at an incident level. |
   [Table 1. DLP Incident Assessment]

   {#create-and-manage-user-instructions-template-for-dlp-incidents__table_usk_rtj_g5b}
4. Drill down to the Instructions Template section, enter the template instruction and add incident level information under this section, if required.
5. Drag-and-drop the required variables to dynamically display certain fields.
6. Click Submit.  
   The user instructions templates are now created and you can click on any user instruction header to know the additional details of a DLP incident.

   For more information, see [Data Loss Prevention Incident Response User Workspace](https://www.servicenow.com/docs/2JXewtK5EBFUic~N1MwKlQ "The Data Loss Prevention Incident Response (DLP IR) User Workspace is a workspace where end users, managers, and approvers can respond to the assigned DLP incidents. The end users, managers, and approvers can then respond to the incidents by specifying the correct actions.").
{#create-and-manage-user-instructions-template-for-dlp-incidents__steps_kgf_rxk_5xb}
* **[Configure DLP UI user instructions](https://www.servicenow.com/docs/AxEXRtVHy0C06L863zbtNQ)**   
  Configure the system UI messages to add detailed user instruction headers as required.

**Related concepts**   

* [Monitor DLP Integration Run process](https://www.servicenow.com/docs/SEN6LY_8hKz6MD8ldIGuVA "Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.")
* [DLP Incident Access Restrictions](https://www.servicenow.com/docs/9vlLhpUoXVMLbIOXaQG7AA "Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.")  
**Related tasks**   

* [DLP default configuration settings](https://www.servicenow.com/docs/byIuJ~f0un4uAmDtYahOVg "Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.")
* [Create end user lookup rules](https://www.servicenow.com/docs/3~7V6tLXfDyGR9elDsMk1g "You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.")
* [Create assignment rules](https://www.servicenow.com/docs/4Nvihko2uI_cFDRh9j~dmA "Create assignment rules and assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.")
* [Create incident consolidation rules](https://www.servicenow.com/docs/xDBI2oXVU7y3svnRnEIPdQ "Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.")
* [Create response due date rules](https://www.servicenow.com/docs/aGfuTB1~6JSqftIesOB6nQ "Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create Approval Rules](https://www.servicenow.com/docs/LZuUVX4lLn79vagW0wH76w "Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.")
* [Create email templates](https://www.servicenow.com/docs/bQ7LBfNMV59D18ohgqIwSA "Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create a Data Loss Prevention Incident Response SLA trigger](https://www.servicenow.com/docs/4wU9FTaZr9_1sv5243aREA "Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.")
* [Create a Data Loss Prevention Incident Response SLA definition](https://www.servicenow.com/docs/cvKsTbRENDm2pzvMYTabuw "Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.")
* [Create assessments](https://www.servicenow.com/docs/lUPlbqXTYbUc77Gzj_5H6w "Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.")
* [Configure response option for your DLP incidents](https://www.servicenow.com/docs/bMy63OZMfsT~evTa~gr96w "Use this feature to configure the type of response that an end user or analyst should perform.")
* [Create incident response option rules](https://www.servicenow.com/docs/Xn~YZ7ubcst6Qp3hGi3gZA "Create the incident response option rules that end user or analyst can use while responding to an incident.")
* [Create age chart configurations](https://www.servicenow.com/docs/RA_omQ4xLGPRZmVdlTKDNQ "Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.")
* [Create user delegate configurations](https://www.servicenow.com/docs/K_Vasn65TCCHVPJcNBeOfg "Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.")
* [Create repeat offender identification rules](https://www.servicenow.com/docs/74i8xF9eMAJi_vMs7dMX5Q "Create repeat offender identification rules to identify users who repeat the same issue multiple times.")
* [Create additional incident data fields](https://www.servicenow.com/docs/VqR5XYIMrGZ2_YWVpnDHug "Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.")
* [Configure advanced settings](https://www.servicenow.com/docs/66mwACGZCgPo22sR4rNoLA "Configure the advanced settings to customize the incident display and behavior. For example, enable displaying the sensitive data on an incident and its clone, or specifying fields on the incident to identify the end users. In addition, activate and customize the evidence files preview properties.")
* [DLP Incidents Archival](https://www.servicenow.com/docs/uvETPiXeLxWT6j7T3DlXmg "The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.")  
**Related reference**   

* [DLP SLA Definition form](https://www.servicenow.com/docs/vo6L6EU_uyk1GYSEqwadBw "Field descriptions for the DLP SLA Definition form used to create an SLA record.")

*[\>]: and then


