Settings Overview
LangGuard settings allow you to configure your workspace, manage users, and control platform behavior. Access settings via the gear icon in the bottom of the navigation sidebar or from the user menu.
Most settings require the admin role. Members and viewers have read-only access to settings unless otherwise noted.
Settings Sections
General
Configure your workspace name and display settings.
API Keys
Generate and manage API keys for programmatic access and OTLP trace ingestion.
MCP Server
Connect AI agents to LangGuard's governance control plane over the Model Context Protocol.
Arbiter Management
See every machine running the Arbiter daemon, its enforcement mode and verdict traffic, and relabel, remote-control, deactivate, or forget devices.
Arbiter Deployment
Install Arbiter hooks in Claude Code, Codex, Cursor, and Google Antigravity, connect to a remote daemon, or deploy Arbiter to Google Cloud or Azure.
Webhooks
Set up outbound webhooks to receive notifications when events occur in LangGuard.
Custom Checks
Reusable Rego checks that gate workflow lifecycle stages.
Tags
Create and manage tags for organizing AI assets across Discovery and Data Catalog.
Audit Log
View all user and system actions, and configure SIEM forwarding.
Single Sign-On (SSO)
Configure SSO with Microsoft Entra ID or Google Workspace, and set up role mapping.
Session Settings
Configure session timeout and idle timeout durations.
User Management
Invite users, assign roles, and manage workspace membership.
Cost Estimates
Configure cost-per-token rates for different models to power cost metrics in Trace Explorer and Monitoring.
Enforcement Mode
Switch the gateway between observe-only Shadow mode and active Enforce mode for this tenant's inline agent and LLM traffic.