Curriculum / Platform Administration
Platform Administration & Security — Defense Edition
Stand up and secure a multi-program Foundry enrollment for a defense mission, then plan its air-gapped delivery: orgs/enrollments and Control Panel roles, Users & Groups as the unit of access, Projects as the security boundary, mandatory Markings and Classification-Based Access Control (CBAC), Restricted Views, governance (lineage/retention/Sensitive Data Scanner), resource protection/branching, and an Apollo air-gapped release.
Org/enrollment admins and security/governance owners (no coding required).
The 9-unit arc
- Unit 1: Enrollment, Organizations, and the Control Panel Role Modelfoundational
Distinguish enrollment vs organization vs Project, assign Control Panel roles, and confirm Organizations are mandatory silos backed by a Marking.
- Unit 2: Users and Groups as the Unit of Accessfoundational
Model access through Foundry Groups (nested/transitive membership) rather than individual grants — the prerequisite for every downstream grant.
- Unit 3: Projects as the Primary Security Boundaryintermediate
Carve mission programs into Projects, grant Viewer/Editor/Owner/Discoverer roles to groups, and see how Organizations + Markings override discretionary roles.
- Unit 4: Mandatory Markingsintermediate
Create and apply mandatory Markings (conjunctive AND controls), grant marking access to cleared groups, and verify who can see marked resources.
- Unit 5: Classification-Based Access Control (CBAC) for Classified Dataadvanced
Model classified access with CBAC — conjunctive (level) and disjunctive (RELEASE TO) categories — recognizing CBAC must be enabled by Palantir and is not self-service.
- Unit 6: Restricted Views and Granular Need-to-Knowadvanced
Enforce row/cell-level need-to-know below the Project boundary with Restricted Views (marking-backed or granular) and object/property security policies.
- Unit 7: Data Governance: Lineage, Retention, and Sensitive Data Scanneradvanced
Operationalize governance — Data Lineage impact analysis, Data Lifetime retention, and a Sensitive Data Scanner scan whose match action auto-applies a Marking.
- Unit 8: Resource Protection and Branching for Production Integrityintermediate
Protect production resources so changes flow through branch proposals and approvals, configuring a project approval policy in the Branch protection tab.
- Unit 9: Air-Gapped Release with Apollocapstone
Plan delivery of the secured platform into a disconnected enclave with Apollo — Products/Releases/Versions, Release Channels, hub-and-spoke, and Cross Domain Solution / physical-media transfer.
Enrollment, Organizations, and the Control Panel Role Model
Distinguish enrollment vs organization vs Project, assign Control Panel roles, and confirm Organizations are mandatory silos backed by a Marking.
Users and Groups as the Unit of Access
Model access through Foundry Groups (nested/transitive membership) rather than individual grants — the prerequisite for every downstream grant.
Projects as the Primary Security Boundary
Carve mission programs into Projects, grant Viewer/Editor/Owner/Discoverer roles to groups, and see how Organizations + Markings override discretionary roles.
Mandatory Markings
Create and apply mandatory Markings (conjunctive AND controls), grant marking access to cleared groups, and verify who can see marked resources.
Classification-Based Access Control (CBAC) for Classified Data
Model classified access with CBAC — conjunctive (level) and disjunctive (RELEASE TO) categories — recognizing CBAC must be enabled by Palantir and is not self-service.
Restricted Views and Granular Need-to-Know
Enforce row/cell-level need-to-know below the Project boundary with Restricted Views (marking-backed or granular) and object/property security policies.
Data Governance: Lineage, Retention, and Sensitive Data Scanner
Operationalize governance — Data Lineage impact analysis, Data Lifetime retention, and a Sensitive Data Scanner scan whose match action auto-applies a Marking.
Resource Protection and Branching for Production Integrity
Protect production resources so changes flow through branch proposals and approvals, configuring a project approval policy in the Branch protection tab.
Air-Gapped Release with Apollo
Plan delivery of the secured platform into a disconnected enclave with Apollo — Products/Releases/Versions, Release Channels, hub-and-spoke, and Cross Domain Solution / physical-media transfer.

