The workflow outlines the responsibilities of the data security administrator and data security viewer in identifying and assessing data protection requirements, creating data-in-motion rules, investigating DLP-related issues, and protecting the organization's assets and data properties.
### Data security administrator
The data security administrator views and manages all data security information, including objects and data patterns.
They are responsible for creating and managing [data-in-motion rules](../configure-dlp-end-to-end#create-data-in-motion-rules) and identifying and investigating DLP-type threats and attacks within an organization.
**Steps**:
1. Configuring Endpoint DLP Settings: Configure the settings according to your organization's needs.
2. Configuring sensitive data definitions: Identify and classify sensitive data (Data Profiles and Data Patterns).
3. Configuring policies: Set rules to apply for sensitive data.
4. Investigate: Review and analyze DLP-related issues to gather information to reduce false positives, refine policies, and improve incident response and auditing.
5. Refine policies: Adjust DLP rules to improve accuracy, reduce false positives, and address new risks.
### Data security viewer
The data security viewer reviews and analyzes DLP-related issues to gather information that will help reduce false positives, refine policies, and improve incident response and auditing.
**Steps**:
1. Investigate and remediate: For true incidents, stop the data loss and investigate what happened and why.
2. Document and report: Create a record of the incident for legal and compliance purposes.
3. Communicate and educate: Speak to the user involved and update security training to prevent future issues.