Curriculum / Palantir Portfolio for Defense (Orientation)
Classification-preserving data: markings and CBAC end to end
Introduction
Scenario: A defense mission team is moving a notional intelligence dataset between teams and networks, and leadership needs assurance that its classification travels with it. As an orientation learner, you build the literacy to explain how Foundry's mandatory controls keep that classification intact end to end.
This unit makes you fluent in the single idea that lets a defense organization trust a shared data platform with classified information: classification is not a label a person remembers to apply, it is a mandatory control the platform enforces and preserves automatically. Foundry's security model blends role-, marking-, and purpose-driven authorization, and on top of that it offers markings and Classification-based Access Controls (CBAC) — mandatory controls used to protect sensitive government information. Because these controls are mandatory rather than discretionary, no user, and no AI agent acting on a user's behalf, can quietly route around them.
The mechanics are worth stating precisely so you can restate them with confidence. A marking is an additional access control that can be applied to files, folders, and Projects, and the rule is conjunctive: to access a resource a user must be a member of every marking applied to it. CBAC structures markings into classification categories, where a conjunctive category requires a user to hold all of its markings and a disjunctive category requires only one — the pattern that mirrors a 'REL TO' releasability list. Access to classification markings can correlate with security-clearance processes that live outside the platform, so the platform enforces the control while human clearance decisions still govern who is granted membership. This is the heart of the unit: a literacy course is not asking you to configure any of this, only to explain it accurately.
By the end you will produce two short literacy deliverables: a classification-preservation narrative tracing how a notional dataset keeps its marking as it moves and derives across the platform, and a small table distinguishing markings, conjunctive vs disjunctive CBAC categories, role-based, and purpose-based controls. A light read-only check then confirms that a platform-seeded, marking-bearing demo dataset exists, so you can see a marking attached to a real resource without ever creating, changing, or being granted access to anything classified.
Capability focus: Markings (mandatory, conjunctive); CBAC categories (conjunctive level vs disjunctive REL TO); classification preservation across the platform. · Artifact: A data-classification narrative + a conjunctive-vs-disjunctive category table.
Key concepts
- Markings: A mandatory access control that can be applied to files, folders, and Projects in Foundry. The rule is conjunctive — to access a marked resource, a user must be a member of all markings applied to that resource. Markings cannot be bypassed by discretionary (role-based) grants.
- Classification-based Access Controls (CBAC): Mandatory controls used to protect sensitive government information by organizing markings into classification categories. A conjunctive category requires a user to hold all of its markings; a disjunctive category requires the user to hold any one of them.
- Conjunctive vs disjunctive categories: 'Conjunctive' (AND / all-required) models hierarchical classification levels where every applicable marking must be satisfied; 'disjunctive' (OR / any-one) models releasability such as a REL TO list, where membership in a single marking in the category is sufficient.
- Mandatory vs discretionary controls: Foundry data security is guaranteed through a combination of mandatory controls (markings, CBAC) and discretionary controls (roles). Mandatory controls are enforced by the platform regardless of role grants, while discretionary controls govern routine collaboration.
- Classification preservation: Markings and CBAC are properties of the resource itself, so classification stays attached as data is shared, moved, or derived across the platform — rather than depending on a user remembering to re-apply a label.
- Clearance correlation (outside the platform): Access to classification markings can correlate with security-clearance processes that exist outside Foundry. The platform enforces marking membership; human clearance decisions determine who is granted that membership.
- Defense-in-depth posture: Foundry pairs these authorization controls with mandatory encryption of data in transit and at rest and robust security audit logging, so classification enforcement is layered rather than reliant on a single mechanism.
Companion video
Classification-preserving data walkthrough (placeholder) · open on YouTube
Hands-on activity
each step validates · the unit completes when all steps pass- 1
Read the Markings and CBAC concept pages
Read the official Markings and CBAC concept pages and confirm you can state the core rule in your own words: markings are mandatory controls applied to files, folders, and Projects, and access is conjunctive — a user must be a member of ALL markings applied to a resource to access it. Note that CBAC organizes markings into classification categories that protect sensitive government information, and that these are mandatory controls, distinct from the discretionary role grants that govern everyday collaboration. This is a reading deliverable: self-attest that you can restate the mandatory, conjunctive control accurately.
not startedself-attestedSelf-attested: you can state a user must satisfy all markings applied to a resource (mandatory, conjunctive).
- 2
Distinguish conjunctive vs disjunctive classification categories
Build a short table that distinguishes conjunctive from disjunctive classification categories under CBAC. Define a conjunctive category as one where a user must hold every marking in the category (the AND / all-required pattern, used for hierarchical classification levels), and a disjunctive category as one where holding any single marking suffices (the OR / any-one pattern, used for releasability such as a REL TO list). For literacy completeness, extend the table to contrast these mandatory marking/CBAC controls with role-based and purpose-based controls so the reviewer can see where each control type applies. Self-attest that your definitions are correct; conceptual accuracy here is judged by a human reviewer, not by an API.
not startedself-attestedSelf-attested: your table correctly defines conjunctive (level) vs disjunctive (REL TO) categories.
- 3
Write the classification-preservation narrative
Write a one-paragraph classification-preservation narrative that follows a notional mission dataset as it moves and derives across the platform. Explain that because markings and CBAC are properties of the resource rather than labels a user must remember to re-apply, the classification travels with the data when it is shared, copied, or transformed into a derived dataset, and that any consumer still must satisfy all applicable markings to read it. Note explicitly that access to classification markings can correlate with security-clearance processes that exist OUTSIDE the platform — the platform enforces marking membership, while human clearance decisions govern who is granted that membership. This is a free-text deliverable; self-attest that your paragraph captures markings as mandatory, propagating controls.
not startedself-attestedSelf-attested: your paragraph explains markings as mandatory controls that propagate with data.
- 4
(Enrichment) Confirm a marking-bearing demo resource exists
Enrichment (read-only, existence check): confirm that a platform-seeded, marking-bearing demo dataset exists so you can see a marking attached to an actual resource. You are inspecting a pre-seeded demo artifact in read-only fashion — you are NOT creating, editing, classifying, or being granted access to anything, and this check confirms only that the demo resource resolves, not your conceptual understanding (that was assessed in the manual steps above). The point of literacy is to recognize that classification is a real, enforced property carried by resources in the platform, not an abstraction. If the demo dataset does not resolve in your environment, flag it to your instructor; the marking-bearing demo is platform-seeded and never learner-authored.
not startedinstance checkExistence-only: confirms a platform-seeded marking-bearing demo resource resolves.

