Skip to content

LangSmith AI governance security checks

AI assistants, agents and model access inside the tenant — what they can read, who can publish them, and how autonomously they act.

On LangSmith, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the LangSmith connector needs.

Checks (4)

severity: medium LangSmith Agent Unmonitored fix difficulty: medium #

Add human feedback and monitoring

  1. Set up feedback collection for the project
  2. Configure annotation queues in LangSmith
  3. Add automated evaluation runs

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low LangSmith Agent High Run Volume fix difficulty: easy #

Review high-volume autonomous operation

  1. Assess if the run volume is expected
  2. Add rate limiting or batch processing
  3. Monitor for cost and quality implications

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium LangSmith Agent No Evaluation fix difficulty: medium #

Add evaluation dataset for quality monitoring

  1. Create an evaluation dataset in LangSmith
  2. Link it to the project
  3. Set up periodic evaluation runs

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: high LangSmith Agent High Risk Unblocked fix difficulty: easy #

Block or restrict high-risk LangSmith agents with scores above 70

  1. Navigate to AI Agent Governance in SSPM
  2. Review the agent risk factors
  3. Block the agent until risks are mitigated

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

More LangSmith checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial