As a user with the required permissions, you can create, edit, or remove user-related or incident-related custom attributes. Some examples of custom attributes are user's Manager information, Employee ID, City, Country, information related to remediation, the status of remediation, notes.
To create or update the properties of a custom attribute:
In ePO - On-prem, go to Menu → Data Protection → DLP Incident Manager → Custom Attributes.
Click Actions → New Item, to create a custom attribute. In the Custom Attributes page, enter the custom attribute name. Select the category of the custom attribute as Incident or User.
You can also update an existing custom attribute. Click the Edit or Delete link to modify the existing custom attribute. Deleting a custom attribute deletes the assigned values from all incidents, instead, you can turn off the attribute for a particular incident.
Click Save.
Use these attributes to assign custom attributes to all incidents. The priority of the custom attributes is shown in the top-down order. Click the up arrow and down arrow to change the priority. The custom attribute IDs aren't shown in the Custom Attributes table, but are available when you execute the customAttribute/list call.