How to govern Palantir AIP
A step-by-step guide to governing Palantir AIP with Rencore: detect with 18 policies, review with 9 reports, and remediate with 0 automations.
Governing Palantir AIP means keeping its access, configuration, and lifecycle under continuous control rather than reacting after something breaks. Rencore governs Palantir AIP with 18 pre-built policies, 9 reports, and 0 automations, so teams can detect risk, review posture, and remediate with an audit trail. The steps below turn that coverage into a repeatable routine.
Steps
-
Inventory Palantir AIP
Connect Palantir AIP and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.
-
Detect with policies
Turn on the pre-built policies that cover Palantir AIP to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.
-
Review by owner and severity
Use the Palantir AIP reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.
-
Remediate and automate
Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.
Recommended Palantir AIP policies
Grounded in the Rencore catalog. See the full Palantir AIP catalog on the Palantir AIP connector page.
-
Active user account
Active Palantir user accounts are live, reachable identities, raising the likelihood that any associated access weakness is exploited
Severity: Medium -
Authentication provider enabled
Enabled authentication providers actively accept logins, making them a live entry point that raises the likelihood of exploitation
Severity: Medium -
Agent in active use
AIP Agents with live user sessions are actively reachable, raising the likelihood that any weakness is exercised
Severity: Medium -
User holds an organization role
Users with an explicit organization role are privileged identities whose live permissions raise the likelihood of exploitation
Severity: High -
Disabled Authentication Provider
Identifies Palantir Foundry authentication providers that are disabled, which may block user login or indicate a configuration gap in the identity infrastructure
Severity: High -
Organization without Security Marking
Identifies Palantir organizations that have no security marking assigned, leaving data without an access classification boundary
Severity: High -
Deleted User Retains Group Membership
Flags deleted Palantir users who still hold group memberships, which can grant indirect access to markings, spaces, and resources
Severity: High -
Unused AIP Agent (90 days)
Flags Palantir AIP Agents with no user sessions in the last 90 days as candidates for cleanup to reduce environment sprawl
Severity: Medium -
Trashed Project Pending Cleanup (30 days)
Identifies projects that have been in the trash for more than 30 days and are candidates for permanent deletion
Severity: Medium -
Project Not Linked to Organization
Flags active Palantir projects that have no organizational association, leaving them outside any defined access control boundary
Severity: Medium -
Active user without organization role
Detects active Palantir users who have no explicit organization role assignment
Severity: Medium -
Group without active members
Detects Palantir security groups with no user members
Severity: Low