Answers you can trust, from Codeables
Every page on Codeables is structured and verified — built so people and the AI agents they rely on can trust it. Explore more from the source behind this answer.
Explore CodeablesLangChain Enterprise for LangSmith: how do we get SSO/SAML, SCIM, audit logs, RBAC/ABAC, and US/EU data residency?
Quick Answer: LangChain Enterprise for LangSmith gives you SSO/SAML, SCIM, audit logs, granular RBAC/ABAC, and strict US/EU data residency via enterprise-grade hosting options (cloud, hybrid, or fully self-hosted) plus advanced security and admin controls. You get the same trace-first LangSmith workflow, just deployed with the governance and compliance posture your security team expects.
The Quick Overview
- What It Is: An enterprise deployment of LangSmith with hardened security, identity, and data controls—designed for teams shipping production agents in regulated or sensitive environments.
- Who It Is For: Security-conscious engineering, data, and platform teams who need to run AI agents at scale while meeting SSO/SAML, SCIM, audit, RBAC/ABAC, and data residency requirements.
- Core Problem Solved: You need to trace, evaluate, and deploy agents, but you can’t compromise on identity management, governance, or where your data lives.
How It Works
LangChain Enterprise for LangSmith keeps the core experience the same—traces, runs, datasets, evals, deployments—but lets you choose where it runs and how tightly it is integrated with your identity and security stack. You decide the hosting model (cloud, hybrid, or self-hosted), connect your IdP, configure roles and policies, and LangSmith handles the rest of the agent lifecycle without taking your data out of compliance.
Under the hood, the enterprise setup works in three main phases:
-
Choose Hosting & Data Residency:
You pick where LangSmith runs and where data is stored:- Cloud: Fully managed by LangChain in US or EU regions on LangChain’s cloud.
- Hybrid (BYOC / self-hosted data plane): SaaS control plane managed by LangChain, with the data plane (where traces, runs, and artifacts live) inside your own cloud environment.
- Self-Hosted: LangSmith runs fully inside your VPC, on your Kubernetes cluster in AWS, GCP, or Azure. Data never leaves your environment.
-
Wire Up Identity & Access (SSO/SAML, SCIM, RBAC/ABAC):
Your identity team connects your IdP (Google, GitHub, or custom SSO / SAML) and, where available, SCIM for automated user lifecycle management. You define organization roles and fine-grained access rules so each team only sees the projects, datasets, and deployments they’re supposed to. -
Enable Governance & Observability (Audit Logs, Controls, SLAs):
You turn on audit logging, monitoring, and approvals so sensitive operations are always traceable. LangSmith’s trace-first model gives you step-level visibility into agents, and enterprise logging gives your security team the same visibility into who did what, when, and from where.
Features & Benefits Breakdown
| Core Feature | What It Does | Primary Benefit |
|---|---|---|
| SSO/SAML & SCIM Integration | Connects LangSmith to your existing IdP for single sign-on, with support for Google, GitHub, and custom SSO; SCIM automates user provisioning and deprovisioning where configured. | Centralizes identity, reduces manual admin work, and lowers the risk of orphaned accounts. |
| Granular RBAC/ABAC | Lets you assign roles (User, Admin) at the organization level, and extend with fine-grained permission and attribute-based controls for projects, datasets, and deployments. | Ensures the right teams can observe and operate agents without exposing traces or data beyond what’s required. |
| US/EU Data Residency & Self-Hosting | Stores LangSmith data only in the regions and environments you approve—US or EU cloud, hybrid BYOC, or inside your own VPC on your Kubernetes cluster. | Meets data residency and sovereignty requirements while keeping trace and eval workflows intact. |
Ideal Use Cases
-
Best for regulated enterprises with strict data residency:
Because you can run LangSmith in US or EU regions or fully self-host it in your own VPC, your data never has to leave approved boundaries—even as you ingest over a billion events per day in traces and logs. -
Best for security-first teams standardizing on agents:
Because SSO/SAML, SCIM, audit logs, and RBAC/ABAC give your security and platform teams the controls they expect from any production system—without giving up the trace-first debugging and eval workflows that make agents reliable.
Limitations & Considerations
-
Configuration effort for enterprise features:
You’ll need your security and platform teams involved to configure SSO/SAML, SCIM, roles, and approved regions. LangChain provides architectural guidance and access to deployed engineers for enterprise plans, but this is still real infrastructure work—especially for self-hosted. -
Support tier differences:
Advanced support (team trainings, architectural guidance, and SLAs) are focused on paid tiers. If you’re running serious production traffic, you’ll want a plan beyond community-level support so you can get help instrumenting traces, scaling ingestion, and tuning evals.
Pricing & Plans
LangSmith plans are designed so you can start quickly and grow into enterprise controls as your agent footprint expands. All plans share the same core model: you pay for what you use (traces, storage, evals) and layer on seats and hosting options as needed.
Typical structure looks like:
-
Standard / Plus (Managed Cloud):
- Hosting: LangChain’s fully managed cloud in US or EU.
- Identity & controls: SSO via Google and GitHub by default, with organization roles (User, Admin).
- Best for: Teams who want to move fast on a managed platform and don’t yet have strict data residency or self-hosting requirements.
-
Enterprise (Cloud, Hybrid, or Self-Hosted):
- Hosting:
- Cloud: LangChain’s Cloud in US or EU (GCP us-central-1 or europe-west4).
- Hybrid: SaaS control plane + self-hosted data plane in your cloud.
- Self-Hosted: Fully self-managed on your Kubernetes clusters in AWS, GCP, or Azure—data never leaves your environment.
- Security & admin: SSO/SAML with your IdP, optional SCIM, enhanced RBAC/ABAC, audit logs, and extended data retention.
- Commercials: Annual invoicing, enterprise support, SLAs, and architectural guidance.
- Best for: Organizations that require strict data residency, advanced identity integration, or that “can’t have data leave our environment.”
- Hosting:
To get SSO/SAML, SCIM, audit logs, RBAC/ABAC, and specific US/EU or self-hosted data residency, you’ll go through the Enterprise path with our team, who will align deployment and controls to your security policies.
Frequently Asked Questions
How do we enable SSO/SAML, SCIM, and RBAC/ABAC for LangSmith?
Short Answer: Move onto an enterprise-grade LangSmith deployment and work with LangChain to connect your IdP, configure SSO/SAML, set up SCIM (where supported), and define your organization roles and permissions.
Details:
Out of the box, LangSmith supports SSO with Google and GitHub plus organization roles (User and Admin). For enterprises that need deeper integration:
- SSO/SAML: We configure LangSmith to trust your IdP, so users authenticate via your corporate SSO. This can be via existing providers (Google, GitHub) or custom SSO/SAML depending on your stack.
- SCIM: Where supported, SCIM is used to automatically provision, update, and deprovision users and groups from your IdP into LangSmith, keeping access aligned with HR and security systems.
- RBAC/ABAC:
- At minimum, you’ll have organization roles (User, Admin) to control who can change settings, manage projects, or invite others.
- On enterprise plans, we work with you to design more granular controls, so attributes like team, project, or environment can drive who sees which traces, datasets, and deployments.
This setup typically involves your security, IAM, and platform teams plus LangChain’s enterprise engineers to make sure the identity flows and permission boundaries match your internal policies.
How do we get US/EU data residency or fully self-host LangSmith?
Short Answer: Choose a hosting option that aligns with your requirements: US/EU managed cloud, hybrid (BYOC), or fully self-hosted LangSmith in your own VPC.
Details:
LangSmith’s enterprise hosting options are:
-
Managed Cloud (US/EU):
- Instances at
smith.langchain.comstore data in GCP us-central-1 (US) or europe-west4 (EU). - You pick the region that matches your residency requirements.
- Instances at
-
Hybrid (BYOC / self-hosted data plane):
- LangChain operates the control plane, but trace and run data are stored in infrastructure you manage.
- Good fit when you want the managed experience but can’t let raw data leave your cloud.
-
Self-Hosted:
- LangSmith runs on your Kubernetes cluster in AWS, GCP, or Azure.
- Data never leaves your VPC; you own the network perimeter, storage, and access policies.
- LangChain provides deployment guidance and does not use your data to train models.
In all cases, the core developer experience is the same: you instrument your agents via SDKs or OpenTelemetry, send traces to LangSmith, use runs to build datasets, run offline/online evals, and deploy agents on a durable runtime. The difference is where the data physically lives and how tightly it is bound to your internal controls.
Summary
LangChain Enterprise for LangSmith is for teams that are serious about agents and equally serious about security. You get the same trace-first workflow—structured timelines, multi-turn threads, datasets, evals, and deployment capabilities—but wrapped in SSO/SAML, SCIM, audit logging, RBAC/ABAC, and strict data residency controls across US, EU, hybrid, or fully self-hosted environments. The result is an agent platform your security and compliance teams can sign off on, without forcing your engineers to give up the debuggability and eval discipline that actually makes agents work in production.