Control LLM data access with Markings

Enrollment administrators can configure which mandatory Markings are allowed for requests to AIP language models. Use this policy to prevent a model from receiving requests from Foundry sessions that can access data protected by mandatory Markings outside an approved set. The policy applies to interactive AIP use and automated workflows.

How allowed Markings work

The enrollment policy applies to every Palantir-provided model family. It is also the default for registered models that do not have a model-specific policy.

The Data access settings provide the following options:

  • Allow any data: Do not restrict requests based on mandatory Marking access.
  • Allow only the following markings: Allow a request only when every mandatory Marking available to the request token is included in the configured allowlist.

An allowlist does not require the data in a request to carry one of the selected Markings. A request token with no mandatory Markings passes this check.

When you configure an allowlist, AIP evaluates all mandatory Markings available in the user's current Foundry session, as represented on the request token. The same token-level check applies to automated workflows. AIP rejects the request if the token includes any mandatory Marking outside the allowlist, even when the data included in the request does not have that Marking.

For example, consider a policy that allows Markings A and B:

Allowed MarkingsMandatory Markings available to the request tokenResultReason
A, BNoneAllowedThe token has no mandatory Markings outside the allowlist.
A, BAAllowedA is included in the allowlist.
A, BBAllowedB is included in the allowlist.
A, BA, BAllowedEvery mandatory Marking is included in the allowlist.
A, BA, CRejectedC is not included in the allowlist.

If a user's session includes more mandatory Markings than the model policy allows, the user can select a scoped session that limits the Markings available in their session. The request passes this data access check when the scoped session contains no mandatory Markings outside the model's allowlist.

Configure the enrollment policy

To configure the default policy for Palantir-provided models and registered models without a model-specific policy:

  1. In Control Panel, open the AIP settings extension.
  2. On the AIP settings tab, find the Data access section.
  3. Select Allow any data or Allow only the following markings.
  4. If you selected Allow only the following markings, select Edit, choose at least one mandatory Marking, and select Apply.
  5. Save your changes.

The enrollment Data access settings with Allow only the following markings selected.

The Manage markings dialog with a mandatory Marking selected.

You must select at least one mandatory Marking before you can save an allowlist policy.

Configure a registered-model override

The Data access step is optional when you register or edit a model. A registered model without a model-specific policy uses the enrollment policy. If you configure a model-specific policy, it completely replaces the enrollment policy and can be more or less restrictive.

Registered-model settingEffective policy
Not configuredUse the enrollment policy.
Allow any dataAllow any data, even when the enrollment policy has an allowlist.
Allow only the following markingsAllow only the selected mandatory Markings, regardless of the enrollment allowlist.

To configure an override:

  1. In Control Panel, open the AIP settings extension and select the Registered models tab.
  2. Register a model, or select an existing model and select Edit.
  3. Go to the Data access step.
  4. Select Allow any data or Allow only the following markings.
  5. If you selected Allow only the following markings, select Edit, choose at least one mandatory Marking, and select Apply.
  6. Save your changes.

The Data access step for a registered model with a model-specific allowlist.