> ## Documentation Index
> Fetch the complete documentation index at: https://openlayer.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Palantir Foundry

> Monitor Palantir Foundry AIP Agents and AIP Logic functions in Openlayer

Openlayer connects to Palantir Foundry to monitor
[AIP Chatbots](https://www.palantir.com/docs/foundry/chatbot-studio/overview) and AIP Logic query
functions. AIP Chatbots were formerly called AIP Agents.

The integration ingests production executions from Foundry log exports and writes them to the Openlayer
projects linked to your enabled agents and functions.

## How it works

Once connected, Openlayer:

1. **Registers targets** — discover or register AIP Chatbots, and register AIP Logic functions by
   function RID or Query API name.
2. **Links Openlayer projects** — enabling an agent or function links it to an Openlayer project and
   inference pipeline.
3. **Syncs executions** — polls the Chatbot Studio session-log stream for agents and the OpenTelemetry
   telemetry stream for AIP Logic functions.
4. **Builds traces** — maps each completed production execution into an Openlayer trace.

Only enabled targets are ingested. Executions from unregistered agents and functions are dropped rather
than registered automatically.

<Info>
  Cron sync uses the Chatbot Studio session-log dataset rather than AIP Agents
  v2 `listSessions`. That API only returns sessions for the calling user and
  originating client, so it does not expose Studio traffic from other users.
</Info>

***

## Prerequisites

Before connecting, you need:

* A Foundry enrollment with at least one AIP Chatbot or AIP Logic function.
* OAuth2 client credentials for a third-party application or a bearer token. The application or token
  needs `api:streams-read` to read either log stream. Monitoring AIP Agents also requires
  `api:aip-agents-read` and `api:filesystem-read`. The `api:functions-read` scope is optional and is only
  required when you register an AIP Logic function by Query API name.
* The appropriate log export created by a Foundry Org Admin:
  * For AIP Agents, a Chatbot Studio session-log export using the **Palantir JSON** schema.
  * For AIP Logic, a log export using the **OpenTelemetry** schema that covers the projects containing
    the functions you want to monitor.
* An Openlayer workspace where you are an **admin**.

Your enrollment URL must use HTTPS and contain only the hostname, such as
`https://example.palantirfoundry.com`, with no path.

### Create the log exports

In **Control Panel**, a Foundry Org Admin selects the organization and opens **Log observability
settings**. Create an export that covers the relevant projects, then copy its streaming dataset RID.

Use the **Palantir JSON** schema for the AIP Agent session-log export. Use the **OpenTelemetry** schema for
the AIP Logic telemetry export. These are separate streams; do not use the Palantir JSON schema for AIP
Logic. Allow up to five minutes for rows to appear.

<Warning>
  Markings are not inherited by the exported dataset. Prompts and user input can
  appear in the stream, so configure the export's projects and access controls
  appropriately.
</Warning>

***

## Set up the integration

### Step 1: Connect your enrollment

1. In Openlayer, go to **Settings → Integrations**.
2. Select **Palantir Foundry**.
3. Under **Connect**, enter:
   * **Enrollment URL** — your HTTPS Foundry enrollment hostname with no path.
   * **Authentication** — select **OAuth2 client credentials** or **Bearer token**.
   * For **OAuth2 client credentials**, enter your **Client ID** and **Client secret**.
   * For **Bearer token**, enter your **Bearer token**.
   * **Session-log dataset RID (optional)** — the RID from your Org Admin's log export.
   * **Stream branch** — the dataset branch, which defaults to `master`.
4. Click **Connect**.

Openlayer verifies the hostname and selected credentials before saving the connection.

<img width="700" style={{ borderRadius: "0.5rem" }} src="https://mintcdn.com/openlayer-docs/v-W69qYHgVDLUbpF/images/integrations/palantir_foundry_hero.png?fit=max&auto=format&n=v-W69qYHgVDLUbpF&q=85&s=cb76c14795a6b5ab1a09b4a536869531" alt="Palantir Foundry connect" data-path="images/integrations/palantir_foundry_hero.png" />

<Note>
  You can connect without entering a dataset RID. Ingestion for each target type
  remains inactive until you configure its corresponding stream under
  **Settings**.
</Note>

After connecting, **Overview** shows the selected **Authentication** method and, for OAuth2 client
credentials, the **Client ID**. It also shows **Telemetry dataset** when you configure the AIP Logic
stream.

The integration detail page has **General**, **AIP Agents**, and **AIP Logic** tabs.

### Step 2: Discover or register AIP Agents

On the **AIP Agents** tab, click **Discover agents** to walk the Compass folders visible to your
credentials for AIP Chatbot files. You can also click **Register agent** and provide either:

* The agent RID from the Chatbot Studio URL.
* A Foundry filesystem path, such as `/Org/Project/My Agent`.

Discovery only finds Compass files with the `AIP_AGENTS_AGENT` type.

<img width="700" style={{ borderRadius: "0.5rem" }} src="https://mintcdn.com/openlayer-docs/v-W69qYHgVDLUbpF/images/integrations/palantir_foundry_agents.png?fit=max&auto=format&n=v-W69qYHgVDLUbpF&q=85&s=475165111c234c7d70a31c9d5dc6990e" alt="Palantir Foundry agents" data-path="images/integrations/palantir_foundry_agents.png" />

### Step 3: Enable chatbots

Click **Enable** for each chatbot you want to monitor. Openlayer links a project and inference pipeline,
then starts ingesting matching executions. The **AIP Agents** tab shows each chatbot and its number of
imported sessions.

Enabled AIP Chatbot projects display a Foundry mark in the configured integrations and projects tables.

To stop ingesting future traces for a chatbot, open its **Agent options** menu and select **Disable**.
Existing traces remain available.

### Step 4: Configure log streams

On the **General** tab under **Settings**, enter the **Session-log dataset RID** for AIP Agents and the
**Telemetry stream dataset RID (AIP Logic)** for AIP Logic, then click **Save log streams**.

Turn on **Periodic sync** to poll the stream every 15 minutes, or click **Sync now** to queue a manual
sync. Periodic sync requires at least one dataset RID and the `api:streams-read` scope.

Under **Connection health**, click **Test connection** to check your stored credentials. Openlayer reports
invalid credentials, missing OAuth scopes, missing resource permissions, or Foundry availability
problems separately.

***

## Monitor AIP Logic query functions

Before registering a function, configure the OpenTelemetry log export in Foundry and save its RID as the
**Telemetry stream dataset RID (AIP Logic)** on the **General** tab. AIP Logic ingestion remains inactive
until this RID is set.

On the **AIP Logic** tab, select **Register function** and identify the function by **Function RID** or
**Query API name**. Registering by function RID is recommended and works for functions that are not
published as Queries. Registering by Query API name resolves the RID through the Functions API and
requires the optional `api:functions-read` scope.

Select **Enable**, then choose **Create new project** or **Map to existing project**. The table shows
**Function** and **Runs**, with no version column. Only enabled functions are ingested; executions from
unregistered functions are dropped. Select **Disable** to stop ingesting future executions for a function.
Existing traces remain available.

***

## Ingest a single session

The session-log stream is the primary sync source. If you have a gateway-originated session's three
identifiers, you can ingest that session directly:

1. Open the chatbot row's **Agent options** menu and select **Ingest**.
2. Enter the **Session RID** and **Session trace ID**. The agent RID is already known from the chatbot row.
3. Click **Ingest**.

This action uses `getSessionTrace` and only works when you have the IDs from the originating client.
Palantir documents that these sessions expire after approximately 24 hours.

***

## Trace mapping

Openlayer maps Palantir JSON session-log events as follows:

| Foundry event | Openlayer trace data |
| - | - |
| `session_metadata` | Root metadata, including agent, version, session, caller |
| `user_request` | Root input and retriever contexts |
| `system`, `user`, or `assistant_chat_message` | Chat completion spans |
| `tool_call` and `tool_call_result` | Tool spans |
| `final_response` | Root output |
| `execution_error` | Root error |

Model, token, and cost data appear only when sibling language-model usage events share the same `traceId`.
Chatbot events do not always include these usage events.

<img width="700" style={{ borderRadius: "0.5rem" }} src="https://mintcdn.com/openlayer-docs/v-W69qYHgVDLUbpF/images/integrations/palantir_foundry_trace.png?fit=max&auto=format&n=v-W69qYHgVDLUbpF&q=85&s=ef71e88d2862a6ac9d516b3845cbf05d" alt="Palantir Foundry trace" data-path="images/integrations/palantir_foundry_trace.png" />

***

## Disconnecting

To disconnect, open **Settings → Integrations → Palantir Foundry** and click **Disconnect**. Disconnecting
stops syncing and deletes registered AIP Agent and AIP Logic function records. Existing Openlayer traces
are preserved.

## Troubleshooting

**Sync fails with a missing dataset RID.**
Configure the dataset RID for the target type under **Settings**. AIP Agent session logs use the Palantir
JSON schema; AIP Logic telemetry uses the OpenTelemetry schema.

**No chatbots appear after discovery.**
Discovery only finds `AIP_AGENTS_AGENT` Compass files. Confirm that your credentials have
`api:filesystem-read` and can see the folders containing your chatbots. You can also register a chatbot by
RID or filesystem path.

**Test connection reports "Foundry rejected these credentials."**
For OAuth2 client credentials, confirm the **Client ID** and **Client secret**. For bearer token
authentication, confirm the **Bearer token**.

**Test connection reports "Missing OAuth scope."**
Add the required scope to the third-party application. Log streams require `api:streams-read`. AIP Agent
discovery requires `api:aip-agents-read` and `api:filesystem-read`; registration by Query API name
requires `api:functions-read`.

**Test connection reports "Missing resource permissions."**
Confirm that the Foundry service user can access the requested chatbot, filesystem, or session-log
resource.

**Test connection reports "Could not reach Foundry."**
Confirm that the enrollment URL is an available HTTPS hostname with no path, then try again.

**An enabled chatbot has zero traces.**
Confirm that the session-log export covers the chatbot's project, uses the Palantir JSON schema, and has
started receiving rows. The chatbot must be enabled, and executions remain pending until they include a
`final_response` or `execution_error`.

**An enabled AIP Logic function has zero runs.**
Confirm that the export uses the OpenTelemetry schema, covers the function's project, and has started
receiving rows. Confirm that you registered the function's RID; registering by RID is the recommended
path.

**A single-session ingest is not ready.**
Confirm that `getSessionTrace` reports a complete session and that you entered the correct session trace
ID. Path A sessions expire after approximately 24 hours.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.