Vendor and Product Reality

Gotham's center of gravity is the ontology: a customer-curated graph of object types, properties, link types, and actions that gives meaning to the heterogeneous data the platform ingests. Around the ontology, Gotham composes dynamic objects (live, workflow-bearing instances of those types), the Operations and Targeting workflows that intelligence and defense customers depend on, geospatial and temporal analytic surfaces, and, since 2023, AIP, which exposes the ontology to large language models under structured policy. Underneath, Foundry provides the data-platform substrate (pipelines, branches, datasets, permissions); Apollo provides the deployment, configuration, and update plane that lets Palantir push code into classified environments without ceding administrative control to the customer.

The customer footprint is consequential. U.S. Army (TITAN, Vantage, Maven Smart System), U.S. Special Operations Command, the intelligence community across multiple agencies, the U.K. Ministry of Defence, Ukraine's defense apparatus, and a long tail of allied ministries all run mission workloads on Gotham. The technical execution, ingest at scale, ontology authoring, low-latency operator workflows, AIP-mediated analytic loops, is mature, defensible, and very difficult to displace. None of what follows contests the platform's value within its operational envelope.

Architectural Gap

The structural property at issue is where authority lives. In the Gotham model, every access decision, every read of an object, every traversal of a link, every invocation of an action, every AIP prompt that touches ontology data, is mediated by Foundry's policy engine, evaluated against state Foundry holds, and recorded in audit substrate Foundry owns. The model is internally coherent and produces strong guarantees inside the deployment. The relevant architectural boundary is export: when an object is exported, replicated, or shared with a system that is not Foundry, the policy that governed it inside the platform is no longer the enforcing authority at the destination. Downstream consumers receive bytes; the rules those bytes were meant to be read under stay with the platform that held them. This is a general property of platform-bound access control, not a defect specific to Gotham.

In coalition and cross-authority intelligence operations this is a recurring source of operational friction. Sharing an object with a partner instance, even another Gotham instance operated by a different sovereign, proceeds through replication or export, with the receiving instance applying its own ontology mappings and its own access controls. The original authority's intent travels in side channels: cover sheets, releasability markings, bilateral memoranda, integration code that re-implements the predicates each time. AIP intensifies the problem, because model outputs derived from governed objects are not themselves governed by the source policy unless the deriving instance chooses to enforce it. The gap is not that Gotham does access control poorly; it is that the access-control authority is bound to the platform rather than to the object, so the predicate cannot follow the object out of the platform.

What the Primitive Provides

The governed spatial mesh, as disclosed in the provisional, carries the rules with the data. In the disclosed architecture each governed observation is a self-describing credentialed object whose byte layout carries an authority credential, a spatial and temporal reference, a time-to-live (freshness), a payload, and a lineage field, with a cryptographic attestation binding the stored data to the issuing authority. A receiving device reconstructs the observation and evaluates it through its own composite admissibility evaluator, against the requesting principal's credentials and the operational context, rather than deferring to a coordinator's instructions. The lineage field records that the evaluation occurred, composing with the lineage of other observations to produce cross-device, cross-authority provenance. This evaluation does not depend on the consumer being inside Foundry, on Apollo having deployed the policy engine to the consumer's environment, or on a network path back to the originating tenant.

For a Gotham deployment this means an exported object can remain governed at its destination. In the disclosed architecture, an observation produced through a derivation function carries a derivation-lineage record that links the derived observation to each input observation, to the derivation function applied, and to the governance-policy version under which the derivation ran, so that a model output derived from governed inputs remains bound to the inputs' authorities. A coalition partner receiving an object, whether they run Gotham, a different platform, or a custom analytic stack, receives a self-describing artifact whose admissibility they can evaluate without reverse-engineering the originator's policy. Revocation is disclosed as enforceable: a credentialing authority emits a revocation governed observation identifying a device, credential, or credential class as no longer authoritative, and each consuming device down-weights or invalidates previously admitted observations, with the revocation event entering the lineage.

Composition Pathway

The primitive is designed to compose with Gotham rather than replace any of its layers. The ontology continues to be the customer's curated semantic surface; Foundry continues to be the data platform; Apollo continues to handle deployment. The mesh layer attaches at the object boundary: an ontology action that today produces an exportable artifact instead produces a mesh-bound artifact carrying its predicate; an AIP-mediated derivation produces a derivation-aware mesh object whose policy composes the inputs' policies; a Gotham-to-Gotham coalition share becomes a federation-agreement workflow in which the receiving instance is a mesh peer rather than a destination tenant. Existing audit feeds continue to receive Gotham-side events; mesh-side events flow into the same pipelines through a defined adapter.

For Palantir, the integration is incremental and protective: it preserves the platform's primacy inside the deployment while removing the structural reason customers cite for keeping non-Palantir systems out of the workflow. For customers, it converts cross-instance sharing from a per-program integration project into a declared federation. For coalition partners and non-Palantir analytics, it provides a first-class participation path that does not require platform adoption.

Commercial and Licensing

The primitive is patent-protected and available for license under terms suitable for platform vendors operating in defense and intelligence markets. For Palantir, the natural posture is an inbound license that adds the mesh layer to Gotham's roadmap as an interoperability and coalition feature, positioned alongside the existing ontology and AIP narratives. Defense and intelligence procurement is moving, across U.S., U.K., and NATO programs: toward explicit requirements for vendor-neutral data sharing, rules-with-data semantics, and AI output governance that survives export. Adopting the substrate ahead of those requirements converts a defensive position into a contracting advantage. The alternative, competitors offering rules-with-data semantics natively while Gotham continues to bind authority to the platform, is the displacement vector the licensing terms are structured to foreclose.

Implementation and Embodiments

A skilled implementer can build the disclosed approach from primitives already common in the field. The self-describing observation is a signed record whose fields, an authority credential, a spatial reference, a temporal reference, a time-to-live, a payload, and a lineage field, are laid out in a defined byte format and bound to the issuing authority by a cryptographic attestation over the record. The credential can be issued through an enrollment, rotation, and revocation lifecycle managed by one or more credentialing authorities, and an authority taxonomy differentiates behavioral response by the issuer's governance class rather than treating all authenticated messages homogeneously. Admissibility is evaluated at each receiving unit by a composite evaluator that combines the bound policy with the requesting principal's credentials and operational context and emits a decision plus a rejection reason.

The disclosed embodiments span a range of deployments: fixed infrastructure devices that self-reference a coordinate frame through mutual ranging without dependence on satellite navigation; passive stored-data markers whose two-row payload and governance-chain layout carries the same credential semantics without an active radio; progressive-density rollouts where non-privileged issuers contribute observations that receiving units evaluate against published policy; derivation functions that produce derivation-lineage records so that outputs of composed inference remain bound to their inputs' authorities; federation mechanisms that align two or more independently maintained mesh coordinate or temporal frames; and fail-safe state transitions that preserve the governance chain. The variations are enumerated so that the approach reads on more than a single implementation, and so that the credentialed-observation, admissibility-evaluation, and lineage mechanisms can be realized across the physical-world, geospatial, and coalition contexts described above.

Disclosure Scope

The technology described here, the governed spatial mesh, its self-describing credentialed observations, cross-authority admissibility evaluation, derivation-lineage, and revocation mechanisms, is disclosed in U.S. Provisional Application No. 64/049,409. This article is a public technical disclosure tied to that filing.

References to Palantir Gotham, Foundry, Apollo, AIP, and to specific programs, agencies, and procurement trends are provided as external market and architectural context to situate the disclosed invention. They are not claims of the filing, and no affiliation with or endorsement by Palantir Technologies is implied. Characterizations of Gotham's architecture reflect publicly reported design at the level of where access-control authority resides; they are not assertions about non-public implementation details, contract terms, or capabilities. The only inventive subject matter claimed is that disclosed in U.S. Provisional Application No. 64/049,409.