palantir-enterprise-rbac

Installation
SKILL.md

Palantir Foundry Access-Control Design

Overview

Treat access as the intersection of several control planes. Project roles govern discretionary capabilities, mandatory controls continue to apply, and OAuth application restrictions constrain API clients independently.

Prerequisites

  • Identify the resources, projects, spaces, organizations, markings or CBAC requirements, groups, users, service users, and Developer Console applications in scope.
  • Name the data owner, project owner, application owner, information-security owner, and access-review cadence.
  • Read references/official-docs.md and use the Check access panel for concrete principals and resources.
  • Begin with a read-only entitlement inventory; do not grant access while discovering it.

Current Contract

  • Default project roles are Owner, Editor, Viewer, and Discoverer, and deployments may also define custom roles.
  • Palantir recommends group role grants at the project level to reduce individual-grant sprawl.
  • Organizations, markings, and CBAC can deny access even when a project role is present.
  • Developer Console token authority is limited by the user/service-user permissions, application restrictions, and requested OAuth scope.
Installs
2
GitHub Stars
2.8K
First Seen
12 days ago
palantir-enterprise-rbac — jeremylongshore/tons-of-skills-marketplace