Skip to main content
Openlayer connects to Palantir Foundry to monitor AIP Chatbots and AIP Logic query functions. AIP Chatbots were formerly called AIP Agents. The integration ingests production executions from Foundry log exports and writes them to the Openlayer projects linked to your enabled agents and functions.

How it works

Once connected, Openlayer:
  1. Registers targets — discover or register AIP Chatbots, and register AIP Logic functions by function RID or Query API name.
  2. Links Openlayer projects — enabling an agent or function links it to an Openlayer project and inference pipeline.
  3. Syncs executions — polls the Chatbot Studio session-log stream for agents and the OpenTelemetry telemetry stream for AIP Logic functions.
  4. Builds traces — maps each completed production execution into an Openlayer trace.
Only enabled targets are ingested. Executions from unregistered agents and functions are dropped rather than registered automatically.
Cron sync uses the Chatbot Studio session-log dataset rather than AIP Agents v2 listSessions. That API only returns sessions for the calling user and originating client, so it does not expose Studio traffic from other users.

Prerequisites

Before connecting, you need:
  • A Foundry enrollment with at least one AIP Chatbot or AIP Logic function.
  • OAuth2 client credentials for a third-party application or a bearer token. The application or token needs api:streams-read to read either log stream. Monitoring AIP Agents also requires api:aip-agents-read and api:filesystem-read. The api:functions-read scope is optional and is only required when you register an AIP Logic function by Query API name.
  • The appropriate log export created by a Foundry Org Admin:
    • For AIP Agents, a Chatbot Studio session-log export using the Palantir JSON schema.
    • For AIP Logic, a log export using the OpenTelemetry schema that covers the projects containing the functions you want to monitor.
  • An Openlayer workspace where you are an admin.
Your enrollment URL must use HTTPS and contain only the hostname, such as https://example.palantirfoundry.com, with no path.

Create the log exports

In Control Panel, a Foundry Org Admin selects the organization and opens Log observability settings. Create an export that covers the relevant projects, then copy its streaming dataset RID. Use the Palantir JSON schema for the AIP Agent session-log export. Use the OpenTelemetry schema for the AIP Logic telemetry export. These are separate streams; do not use the Palantir JSON schema for AIP Logic. Allow up to five minutes for rows to appear.
Markings are not inherited by the exported dataset. Prompts and user input can appear in the stream, so configure the export’s projects and access controls appropriately.

Set up the integration

Step 1: Connect your enrollment

  1. In Openlayer, go to Settings → Integrations.
  2. Select Palantir Foundry.
  3. Under Connect, enter:
    • Enrollment URL — your HTTPS Foundry enrollment hostname with no path.
    • Authentication — select OAuth2 client credentials or Bearer token.
    • For OAuth2 client credentials, enter your Client ID and Client secret.
    • For Bearer token, enter your Bearer token.
    • Session-log dataset RID (optional) — the RID from your Org Admin’s log export.
    • Stream branch — the dataset branch, which defaults to master.
  4. Click Connect.
Openlayer verifies the hostname and selected credentials before saving the connection. Palantir Foundry connect
You can connect without entering a dataset RID. Ingestion for each target type remains inactive until you configure its corresponding stream under Settings.
After connecting, Overview shows the selected Authentication method and, for OAuth2 client credentials, the Client ID. It also shows Telemetry dataset when you configure the AIP Logic stream. The integration detail page has General, AIP Agents, and AIP Logic tabs.

Step 2: Discover or register AIP Agents

On the AIP Agents tab, click Discover agents to walk the Compass folders visible to your credentials for AIP Chatbot files. You can also click Register agent and provide either:
  • The agent RID from the Chatbot Studio URL.
  • A Foundry filesystem path, such as /Org/Project/My Agent.
Discovery only finds Compass files with the AIP_AGENTS_AGENT type. Palantir Foundry agents

Step 3: Enable chatbots

Click Enable for each chatbot you want to monitor. Openlayer links a project and inference pipeline, then starts ingesting matching executions. The AIP Agents tab shows each chatbot and its number of imported sessions. Enabled AIP Chatbot projects display a Foundry mark in the configured integrations and projects tables. To stop ingesting future traces for a chatbot, open its Agent options menu and select Disable. Existing traces remain available.

Step 4: Configure log streams

On the General tab under Settings, enter the Session-log dataset RID for AIP Agents and the Telemetry stream dataset RID (AIP Logic) for AIP Logic, then click Save log streams. Turn on Periodic sync to poll the stream every 15 minutes, or click Sync now to queue a manual sync. Periodic sync requires at least one dataset RID and the api:streams-read scope. Under Connection health, click Test connection to check your stored credentials. Openlayer reports invalid credentials, missing OAuth scopes, missing resource permissions, or Foundry availability problems separately.

Monitor AIP Logic query functions

Before registering a function, configure the OpenTelemetry log export in Foundry and save its RID as the Telemetry stream dataset RID (AIP Logic) on the General tab. AIP Logic ingestion remains inactive until this RID is set. On the AIP Logic tab, select Register function and identify the function by Function RID or Query API name. Registering by function RID is recommended and works for functions that are not published as Queries. Registering by Query API name resolves the RID through the Functions API and requires the optional api:functions-read scope. Select Enable, then choose Create new project or Map to existing project. The table shows Function and Runs, with no version column. Only enabled functions are ingested; executions from unregistered functions are dropped. Select Disable to stop ingesting future executions for a function. Existing traces remain available.

Ingest a single session

The session-log stream is the primary sync source. If you have a gateway-originated session’s three identifiers, you can ingest that session directly:
  1. Open the chatbot row’s Agent options menu and select Ingest.
  2. Enter the Session RID and Session trace ID. The agent RID is already known from the chatbot row.
  3. Click Ingest.
This action uses getSessionTrace and only works when you have the IDs from the originating client. Palantir documents that these sessions expire after approximately 24 hours.

Trace mapping

Openlayer maps Palantir JSON session-log events as follows: Model, token, and cost data appear only when sibling language-model usage events share the same traceId. Chatbot events do not always include these usage events. Palantir Foundry trace

Disconnecting

To disconnect, open Settings → Integrations → Palantir Foundry and click Disconnect. Disconnecting stops syncing and deletes registered AIP Agent and AIP Logic function records. Existing Openlayer traces are preserved.

Troubleshooting

Sync fails with a missing dataset RID. Configure the dataset RID for the target type under Settings. AIP Agent session logs use the Palantir JSON schema; AIP Logic telemetry uses the OpenTelemetry schema. No chatbots appear after discovery. Discovery only finds AIP_AGENTS_AGENT Compass files. Confirm that your credentials have api:filesystem-read and can see the folders containing your chatbots. You can also register a chatbot by RID or filesystem path. Test connection reports “Foundry rejected these credentials.” For OAuth2 client credentials, confirm the Client ID and Client secret. For bearer token authentication, confirm the Bearer token. Test connection reports “Missing OAuth scope.” Add the required scope to the third-party application. Log streams require api:streams-read. AIP Agent discovery requires api:aip-agents-read and api:filesystem-read; registration by Query API name requires api:functions-read. Test connection reports “Missing resource permissions.” Confirm that the Foundry service user can access the requested chatbot, filesystem, or session-log resource. Test connection reports “Could not reach Foundry.” Confirm that the enrollment URL is an available HTTPS hostname with no path, then try again. An enabled chatbot has zero traces. Confirm that the session-log export covers the chatbot’s project, uses the Palantir JSON schema, and has started receiving rows. The chatbot must be enabled, and executions remain pending until they include a final_response or execution_error. An enabled AIP Logic function has zero runs. Confirm that the export uses the OpenTelemetry schema, covers the function’s project, and has started receiving rows. Confirm that you registered the function’s RID; registering by RID is the recommended path. A single-session ingest is not ready. Confirm that getSessionTrace reports a complete session and that you entered the correct session trace ID. Path A sessions expire after approximately 24 hours.