palantir-data-handling
Installation
SKILL.md
Palantir Data Governance and Handling
Overview
Map the full data path before editing a permission or transform. Foundry discretionary roles, mandatory controls, Ontology row/property policies, and downstream exports protect different boundaries and must be reviewed separately.
Prerequisites
- Identify data owner, purpose, classifications, source datasets, derived resources, Ontology objects and properties, logs, exports, and retention obligations.
- Record the projects, organizations, markings, CBAC policies, groups, and roles governing each stage.
- Read
references/official-docs.mdand involve the information-security or privacy owner for regulated data. - Use synthetic data for policy tests unless a protected test environment is approved.
Current Contract
- Projects and roles provide discretionary access, while organizations, markings, and CBAC remain mandatory and propagate according to their own rules.
- Ontology object and property policies can implement row- and column-level read controls; granular controls do not automatically protect downstream exports.
- Mandatory controls within security policies continue to protect derived data where the documented propagation rules apply.
- Logs and audit exports may contain sensitive or personal data and require explicit access, marking, retention, and audience decisions.