Hello Marj,
I believe you are talking about EDM\IDM for endpoint where there cannot be any Blocking\User cancel response rule.
For DLP using EDM\IDM is a two tier detection system. i.e the EDM\IDM policies gets loaded on the Endpoint Server instead of the agent system.
When we detect some data in motion (trying to transfer some information through Mail \ USB etc. ) or at rest (Performing Endpoint Discover Scan) a copy of the reported file gets transferred to the "Endpoint Server". As we cannot wait for the action taken by the Endpoint Server and then block the transfer at the agent level we cannot have blocking feature. Also many times the agent is not connected to the endpoint server so in that case also this is not a feasible function.
Please let me know if you need any further clerification. The provided explanation is only associated with the endpoint part of DLP . EDM\IDM should block in case of other detections .