Governance guide

How to govern Palantir AIP

A step-by-step guide to governing Palantir AIP with Rencore: detect with 18 policies, review with 9 reports, and remediate with 0 automations.

Definition

Governing Palantir AIP means keeping its access, configuration, and lifecycle under continuous control rather than reacting after something breaks. Rencore governs Palantir AIP with 18 pre-built policies, 9 reports, and 0 automations, so teams can detect risk, review posture, and remediate with an audit trail. The steps below turn that coverage into a repeatable routine.

Steps

  1. Inventory Palantir AIP

    Connect Palantir AIP and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.

  2. Detect with policies

    Turn on the pre-built policies that cover Palantir AIP to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.

  3. Review by owner and severity

    Use the Palantir AIP reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.

  4. Remediate and automate

    Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.

Recommended Palantir AIP policies

Grounded in the Rencore catalog. See the full Palantir AIP catalog on the Palantir AIP connector page.

  • Active user account

    Active Palantir user accounts are live, reachable identities, raising the likelihood that any associated access weakness is exploited

    Severity: Medium
  • Authentication provider enabled

    Enabled authentication providers actively accept logins, making them a live entry point that raises the likelihood of exploitation

    Severity: Medium
  • Agent in active use

    AIP Agents with live user sessions are actively reachable, raising the likelihood that any weakness is exercised

    Severity: Medium
  • User holds an organization role

    Users with an explicit organization role are privileged identities whose live permissions raise the likelihood of exploitation

    Severity: High
  • Disabled Authentication Provider

    Identifies Palantir Foundry authentication providers that are disabled, which may block user login or indicate a configuration gap in the identity infrastructure

    Severity: High
  • Organization without Security Marking

    Identifies Palantir organizations that have no security marking assigned, leaving data without an access classification boundary

    Severity: High
  • Deleted User Retains Group Membership

    Flags deleted Palantir users who still hold group memberships, which can grant indirect access to markings, spaces, and resources

    Severity: High
  • Unused AIP Agent (90 days)

    Flags Palantir AIP Agents with no user sessions in the last 90 days as candidates for cleanup to reduce environment sprawl

    Severity: Medium
  • Trashed Project Pending Cleanup (30 days)

    Identifies projects that have been in the trash for more than 30 days and are candidates for permanent deletion

    Severity: Medium
  • Project Not Linked to Organization

    Flags active Palantir projects that have no organizational association, leaving them outside any defined access control boundary

    Severity: Medium
  • Active user without organization role

    Detects active Palantir users who have no explicit organization role assignment

    Severity: Medium
  • Group without active members

    Detects Palantir security groups with no user members

    Severity: Low
Explore the full Palantir AIP governance catalog | All guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern