<h2>Sensitive data redaction for inbound emails does not redact data in comments created by inbound actions</h2><br/><div style="overflow-x:auto"><article><div ><h3 >Issue </h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <p style="margin: 0in 0in 12pt; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">After installing the Sensitive Data Redaction for inbound emails plugin, sensitive data sent in reply emails is correctly redacted in the received email record. However, when an inbound action processes that email and creates a comment on a record (such as a Requested Item or incident), the sensitive data in that comment is not redacted.</p> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div><div ><h3 >Symptoms</h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <ul style="margin-top: 0in; margin-bottom: 6pt; list-style-position: inside;"><li style="margin: 0in 0in 6pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Sensitive data (such as Social Security Numbers) is successfully redacted in inbound email records</li><li style="margin: 0in 0in 6pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Comments created by inbound actions on records contain the unredacted sensitive data</li></ul> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div><div ><h3 >Facts</h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <ul style="margin-top: 0in; margin-bottom: 6pt; list-style-position: inside;"><li style="margin: 0in 0in 6pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Sensitive Data Redaction for inbound emails plugin (com.glide.email_inbound.redaction) is installed</li><li style="margin: 0in 0in 6pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Data Discovery application (sn_data_discovery) is installed</li><li style="margin: 0in 0in 6pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Inbound email actions are configured to create comments on records (Requested Items, incidents, tasks, etc.)</li><li style="margin: 0in 0in 12pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">By default, the system property glide.email.inbound.email_redaction.email_wrapper.enabled does not exist</li></ul> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div><div ><h3 >Release</h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <p style="margin: 0in 0in 12pt; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">All currently supported releases</p> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div><div ><h3 >Cause</h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <p style="margin: 0in 0in 12pt; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">This behavior is by design. By default, the Sensitive Data Redaction for inbound emails plugin redacts sensitive data only in the inbound email record itself. The plugin does not automatically extend redaction to comments or other records created by inbound email actions. To enable redaction in comments created by inbound actions, you must explicitly configure the system property glide.email.inbound.email_redaction.email_wrapper.enabled.</p> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div><div ><h3 >Resolution</h3><section><style type="text/css"><!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } </style> <div class="ns-kb-css-body-editor-container"> <p style="margin: 0in 0in 6pt; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">To enable sensitive data redaction in comments created by inbound actions, follow these steps:</p> <ol style="margin-bottom: 0in; margin-top: 0px; list-style-position: inside;"><li style="margin: 0in 0in 10pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Open the System Properties table.</li></ol> <p style="margin: 0in 0in 6pt 0.5in; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Navigate to System > Properties > Property [System Properties] in your ServiceNow instance.</p> <ol style="margin-bottom: 0in; margin-top: 0px; list-style-position: inside;" start="2"><li style="margin: 0in 0in 10pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Create a new property record.</li></ol> <p style="margin: 0in 0in 6pt 0.5in; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Click New to create a new record.</p> <ol style="margin-bottom: 0in; margin-top: 0px; list-style-position: inside;" start="3"><li style="margin: 0in 0in 10pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Enter the property name and type.</li></ol> <p style="margin: 0in 0in 6pt 0.5in; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">In the Name field, enter: glide.email.inbound.email_redaction.email_wrapper.enabled</p> <p style="margin: 0in 0in 6pt 0.5in; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">In the Type field, select True | False.</p> <ol style="margin-bottom: 0in; margin-top: 0px; list-style-position: inside;" start="4"><li style="margin: 0in 0in 10pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Set the property value to true.</li></ol> <p style="margin: 0in 0in 6pt 0.5in; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">In the Value field, enter: true</p> <ol style="margin-bottom: 0in; margin-top: 0px; list-style-position: inside;" start="5"><li style="margin: 0in 0in 10pt 0px; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Save the property.</li></ol> <p style="margin: 0in 0in 12pt 0.5in; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">Click Save.</p> <p style="margin: 0in 0in 12pt 0.5in; line-height: 115%; font-size: 11pt; font-family: Cambria, serif;">When this property is set to true, sensitive data in inbound emails is redacted, and an additional comment containing the redacted data (with sensitive values replaced by "xxx") is posted to the created record.</p> <span id="ns-kb-css-end-div-identifier" style="display: none; pointer-events: none;"></span></div></section></div></article></div>