The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a Set Reviewer task

Prev Next

You can assign reviewers for different incidents and operational events to divide the workload in large organizations.

In ePO - On-prem User Management → Permission Sets, create a reviewer, or designate a group reviewer, with Set Reviewer permissions for DLP Incident Manager and DLP Operations.

The Set Reviewer task assigns a reviewer to incidents/events according to the rule criteria. The task only runs on incidents where a reviewer has not been assigned. You cannot use it to reassign incidents to a different reviewer.

  1. In ePO - On-prem, select Menu → Data Protection → DLP Incident Manager or Menu → Data Protection → DLP Operations.

  2. Click the Incident Tasks or Operational Event Tasks tab.

  3. Do one of the following:

    • For Trellix DLP Endpoint: Select an incident type from the drop-down list (Incident Tasks only), select Set Reviewer in the Task Type pane, then click Actions → New Rule.

    • For Trellix DLP Discover: Select Data at rest (Network) from the drop-down list.

  4. Enter a name and optional description. Select a reviewer or group, then click Next.

    Rules are enabled by default. You can change this setting to delay running the rule.

  5. Click > to add criteria, < to remove them. Set the Comparison and Value parameters. When you have finished defining criteria, click Save.

    Tip

    If there are multiple Set Reviewer rules, reorder the rules in the list.

The task runs hourly.

Note

You cannot override the reviewer through the Set Reviewer task after the reviewer is set.