Skip to main content

Settings Overview

LangGuard settings allow you to configure your workspace, manage users, and control platform behavior. Access settings via the gear icon in the bottom of the navigation sidebar or from the user menu.

Admin Required

Most settings require the admin role. Members and viewers have read-only access to settings unless otherwise noted.

Settings Sections

General

Configure your workspace name and display settings.


API Keys

Generate and manage API keys for programmatic access and OTLP trace ingestion.


MCP Server

Connect AI agents to LangGuard's governance control plane over the Model Context Protocol.


Arbiter Management

See every machine running the Arbiter daemon, its enforcement mode and verdict traffic, and relabel, remote-control, deactivate, or forget devices.


Arbiter Deployment

Install Arbiter hooks in Claude Code, Codex, Cursor, and Google Antigravity, connect to a remote daemon, or deploy Arbiter to Google Cloud or Azure.


Webhooks

Set up outbound webhooks to receive notifications when events occur in LangGuard.


Custom Checks

Reusable Rego checks that gate workflow lifecycle stages.


Tags

Create and manage tags for organizing AI assets across Discovery and Data Catalog.


Audit Log

View all user and system actions, and configure SIEM forwarding.


Single Sign-On (SSO)

Configure SSO with Microsoft Entra ID or Google Workspace, and set up role mapping.


Session Settings

Configure session timeout and idle timeout durations.


User Management

Invite users, assign roles, and manage workspace membership.


Cost Estimates

Configure cost-per-token rates for different models to power cost metrics in Trace Explorer and Monitoring.


Enforcement Mode

Switch the gateway between observe-only Shadow mode and active Enforce mode for this tenant's inline agent and LLM traffic.