palantir-security-basics
Installation
SKILL.md
Palantir Foundry Security Baseline
Overview
Apply least privilege across discretionary roles, mandatory controls, OAuth clients, Ontology policies, logs, and exports. Test both intended access and denial because each control plane covers a different boundary.
Prerequisites
- Identify owners, users/groups, service users, projects, organizations, markings/CBAC, datasets, Ontology resources, applications, logs, exports, and incident contacts.
- Classify the maximum data sensitivity and writeback impact for the workflow.
- Read
references/official-docs.mdand the target enrollment's policies. - Begin with a read-only inventory and approved synthetic test personas.
Current Contract
- Projects and roles govern discretionary access; organizations, markings, and CBAC remain mandatory.
- Developer Console application restrictions and OAuth scopes constrain API clients alongside user/service-user permissions.
- Ontology object/property policies support granular read controls, but mandatory controls are needed where downstream propagation matters.
- Logs and audit exports may contain sensitive values and require explicit access, marking, audience, and retention decisions.