Agent skill

Langchain Enterprise Rbac

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Enforce tenant isolation and role-based access across LangChain 1.0 chains and LangGraph 1.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and…

MITAuto-check passedBackend & APIs

Install Langchain Enterprise Rbac

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace langchain-enterprise-rbac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/langchain-enterprise-rbac .claude/skills/langchain-enterprise-rbac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
langchain-enterprise-rbac
GitHub stars
2.8k
Token cost
~4k tokens
SKILL.md length
1,333 words
Files
7 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Enforce tenant isolation and role-based access across LangChain 1.0 chains and LangGraph 1.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and…

  • Works in 6 steps: Build the retriever per-request, never… → Pick a vector-store isolation primitive → Build the agent per-request with a… → …
  • Building multi-tenant saas
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Langchain Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Enforce tenant isolation and role-based access across LangChain 1.0 chains and LangGraph 1.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and structured audit logs. Use when building multi-tenant saas, passing soc2 review, or debugging cross-tenant leak. Trigger with "langchain multi-tenant", "langchain tenant isolation", "langchain rbac", "langchain row-level security", "langchain audit log".

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/audit-log-schema.md`, `references/multi-tenant-regression-tests.md` and `references/one-pager.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Building AI agents, Authorization and RBAC and Multi-tenancy. It works with LangChain and LangGraph. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Building multi-tenant saas
  • Passing soc2 review
  • Debugging cross-tenant leak
  • With langchain multi-tenant

Example prompts

  • “langchain multi-tenant”
  • “langchain tenant isolation”
  • “langchain rbac”
  • “/langchain-enterprise-rbac”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(python:*)

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Build the retriever per-request, never at import
  2. Pick a vector-store isolation primitive
  3. Build the agent per-request with a role-scoped tool allowlist
  4. Scope rate limits and budgets by tenant
  5. Emit a structured audit log on every invocation
  6. Two-tenant regression test for cross-tenant leak

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(python:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • python.langchain.com
    • langchain-ai.github.io
    • docs.pinecone.io
    • postgresql.org
    • aicpa-cima.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Langchain Enterprise Rbac loads about 4k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 1,333 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,333 words, ~3,978 tokens.

Download SKILL.mdSave it as .claude/skills/langchain-enterprise-rbac/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
langchain-enterprise-rbac
description
Enforce tenant isolation and role-based access across LangChain 1.0 chains and LangGraph 1.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and structured audit logs. Use when building multi-tenant saas, passing soc2 review, or debugging cross-tenant leak. Trigger with "langchain multi-tenant", "langchain tenant isolation", "langchain rbac", "langchain row-level security", "langchain audit log".
allowed-tools
Read, Write, Edit, Bash(python:*)
compatibility
Designed for Claude Code
version
2.7.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, langchain, langgraph, python, langchain-1.0, multi-tenant, rbac, enterprise, security

LangChain Enterprise RBAC (Python)

Overview

A B2B SaaS team shipped their first RAG feature for two tenants. The factory code looked innocent: build PineconeVectorStore once at module import with namespace="acme-corp" (the first tenant), convert it to a retriever, store it in a module global, reuse on every request. Six weeks later tenant "Initech" went live. Their first search returned three documents from Acme Corp.

The singleton retriever had captured the Acme namespace at process start. RunnableConfig.configurable["tenant_id"] was being passed in — but the retriever never read it, because the filter was baked in. Every request for every tenant hit the same Pinecone namespace. Security review caught it three days later and put a hold on the SOC2 renewal. This is pain-catalog entry P33, the single most common cause of cross-tenant leak in LangChain 1.0 production.

This skill fixes it with four workstreams:

  • P33 — retriever-per-request factory — build the retriever inside the chain or agent invocation, keyed by tenant_id from RunnableConfig. Never at module scope. Unit-test with two tenants and assert non-overlap.
  • Role-scoped tool allowlist — build the agent per-request with only the tools the current user's role permits. Forbidden tools are not passed to create_agent at all, so the model cannot call them even if it tries.
  • Per-tenant rate limit + budget — scope the InMemoryRateLimiter (or a Redis-backed equivalent) by tenant_id, and check a per-tenant USD budget before invoking the model.
  • Structured audit log — JSON log with user_id, tenant_id, chain_name, tools_called, cost_usd, outcome, emitted in both success and failure paths. Ships to SIEM or BigQuery.

Two failure patterns anchor this skill: import-time retriever binding (P33) and missing audit log on tool failure (the try block logs on success but the except branch re-raises without emitting, so incident response has no record of denied tool calls). Pinned: langchain-core 1.0.x, langgraph 1.0.x, langchain-anthropic 1.0.x, langchain-openai 1.0.x, langchain-postgres 0.0.15+ (for PGVector RLS), pinecone-client 5.x, chromadb 0.5.x. Pain-catalog anchors: P33 primary, P18, P24, P31, P37.

Prerequisites

  • Python 3.10+
  • langchain-core >= 1.0, < 2.0, langgraph >= 1.0, < 2.0
  • At least one vector-store backend: pinecone-client, langchain-postgres (PGVector), chromadb, or faiss-cpu (single-tenant only — see §Step 2)
  • A structured logging sink: stdout JSON for local, Cloud Logging / Datadog / Splunk HEC / BigQuery streaming insert for production
  • A tenant authorization claim in every request (JWT tid claim, session cookie, or header — the auth boundary is out of scope for this skill but assumed correct)

Instructions

Step 1 — Build the retriever per-request, never at import

Move retriever construction inside the chain or agent invocation, keyed by config["configurable"]["tenant_id"].

python
from langchain_core.runnables import RunnableConfig, RunnableLambda
from langchain_pinecone import PineconeVectorStore

# WRONG — retriever bound at import time with first tenant's namespace.
# RETRIEVER = PineconeVectorStore(index_name="rag", namespace="acme-corp",
#     embedding=emb).as_retriever(search_kwargs={"k": 4})

# RIGHT — factory called per-request, reads tenant from RunnableConfig.
def retriever_for(config: RunnableConfig):
    tenant_id = config["configurable"]["tenant_id"]  # required, no default
    if not tenant_id:
        raise PermissionError("tenant_id missing from RunnableConfig")
    store = PineconeVectorStore(
        index_name="rag",
        namespace=tenant_id,   # P33 fix — namespace per-invocation
        embedding=emb,
    )
    return store.as_retriever(search_kwargs={"k": 4})

def retrieve(inputs: dict, config: RunnableConfig):
    return retriever_for(config).invoke(inputs["query"])

chain = RunnableLambda(retrieve) | prompt | model
result = chain.invoke({"query": "..."},
    config={"configurable": {"tenant_id": "initech"}})

No default on tenant_id — a missing tenant must be a hard error, not a silent fallback. See Retriever-per-request for factory lifecycle and PGVector RLS / Chroma / FAISS adapters.

Step 2 — Pick a vector-store isolation primitive
StoreIsolation primitivePer-tenant latencyMax tenantsSafety notes
Pineconenamespace=tenant_id per query~40ms p50 (shared index)100,000+ per indexNamespace is the documented isolation boundary; still apply metadata {"tenant_id": tid} as defense in depth
PGVectorPostgres row-level security (RLS) on tenant_id column~20ms p50 (HNSW index)Bounded by Postgres row countUse SET LOCAL app.tenant_id = :tid per transaction; RLS policy USING (tenant_id = current_setting('app.tenant_id'))
ChromaCollection-per-tenant (get_or_create_collection(name=tid))~30ms p50~1,000 before metadata overheadGood isolation at small scale; collection creation is synchronous — provision lazily but cache the handle per-request
FAISSIn-process index-per-tenant~5ms p50 (in-memory)10-50 practical limitPoor fit for multi-tenant SaaS — cannot shard across processes, reloads on every deploy, no durable filter. Use for single-tenant evaluation only

Pinecone scales highest. PGVector with RLS is the strongest primitive when isolation must be auditable at the database layer (RLS is enforced by the server even if application code is bypassed). Chroma is fine for ≤1,000 tenants. FAISS is not a multi-tenant production choice — document so future engineers do not adopt it. See Vector-store isolation for the PGVector RLS DDL and Chroma lifecycle.

Step 3 — Build the agent per-request with a role-scoped tool allowlist

Never bind every tool to every agent and trust the model to pick the right one. Build the agent inside the request handler with only the tools the user's role permits.

python
from langgraph.prebuilt import create_agent

# Map role -> allowed tool names. Owned by IAM config, not the skill.
ROLE_TOOLS: dict[str, set[str]] = {
    "viewer": {"search_docs"},
    "editor": {"search_docs", "create_note"},
    "admin":  {"search_docs", "create_note", "delete_note", "export_audit"},
}
ALL_TOOLS = {t.name: t for t in [search_docs, create_note, delete_note, export_audit]}

def agent_for(user_role: str, tenant_id: str):
    allowed = ROLE_TOOLS.get(user_role, set())
    tools = [ALL_TOOLS[n] for n in allowed if n in ALL_TOOLS]
    # Forbidden tools are not passed in — the model never sees them.
    return create_agent(model, tools=tools)

agent = agent_for(user_role="viewer", tenant_id="initech")
# viewer has no delete_note -> the agent cannot call it.

Add a denylist for dangerous argument patterns (SQL with DROP / TRUNCATE, shell with rm -rf / sudo, URLs to internal metadata endpoints) via a pre_model_hook or tool wrapper — allowlist bounds which tools run, denylist bounds what arguments they accept. See Role-scoped tool allowlist.

Step 4 — Scope rate limits and budgets by tenant

Per-tenant limits prevent one tenant's runaway job from exhausting shared model capacity. Rate-limit detail is covered in langchain-rate-limits; cost-budget detail in langchain-cost-tuning. The only RBAC-specific requirement here: limiter key must include tenant_id — never a process-global singleton.

python
# Sketch only — see langchain-rate-limits for production implementation.
_limiters: dict[str, InMemoryRateLimiter] = {}

def limiter_for(tenant_id: str) -> InMemoryRateLimiter:
    if tenant_id not in _limiters:
        # Tier lookup — different plans get different budgets.
        rps = TENANT_TIER_LIMITS.get(tenant_id, 1.0)  # 1.0 rps = free-tier default
        _limiters[tenant_id] = InMemoryRateLimiter(requests_per_second=rps)
    return _limiters[tenant_id]

For multi-process deployments use a Redis-backed limiter — InMemoryRateLimiter is per-process only, so 1 rps × 8 workers = 8 rps aggregate.

Show full SKILL.md (560 more words)Show less
Step 5 — Emit a structured audit log on every invocation

The audit log is the record of truth during an incident. Emit on both success and failure paths. The common bug is logging in the try block only — when a tool raises, the except branch re-raises without emitting, so the incident responder has no record of the denied call.

python
import json
import time
import uuid
from contextlib import contextmanager

@contextmanager
def audit(ctx: dict):
    started = time.monotonic()
    trace_id = str(uuid.uuid4())
    record = {**ctx, "trace_id": trace_id, "outcome": "pending"}
    try:
        yield record
        record["outcome"] = record.get("outcome", "success")
    except Exception as exc:
        record["outcome"] = "error"
        record["error_class"] = type(exc).__name__
        record["error_message"] = str(exc)[:500]  # truncate — no PII leakage
        raise
    finally:
        record["latency_ms"] = int((time.monotonic() - started) * 1000)  # 1000 ms per second
        print(json.dumps(record))  # or a SIEM / BigQuery client

ctx = {
    "user_id": "u_42",
    "tenant_id": "initech",
    "chain_name": "rag-qa-v3",
    "role": "viewer",
}
with audit(ctx) as record:
    result = chain.invoke(inputs, config={"configurable": ctx})
    record["tools_called"] = [m.name for m in result.get("tool_calls", [])]
    record["input_tokens"]  = result["usage"]["input_tokens"]
    record["output_tokens"] = result["usage"]["output_tokens"]
    record["cost_usd"]      = cost_of(result["usage"])

The try / finally pattern guarantees emission even when the chain raises. Required fields: user_id, tenant_id, chain_name, outcome, latency_ms, trace_id. Recommended: tools_called, input_tokens, output_tokens, cost_usd, role. See Audit-log schema for the full catalog, JSON example, SIEM / BigQuery ingestion, and query recipes.

Step 6 — Two-tenant regression test for cross-tenant leak

The test that would have caught P33 on day one. Seed two tenants with distinct documents, run a golden query as each, assert non-overlap on retrieved IDs.

python
import pytest

@pytest.fixture
def two_tenant_store():
    seed("acme",    ["acme-doc-1",    "acme-doc-2"])
    seed("initech", ["initech-doc-1", "initech-doc-2"])
    yield
    cleanup(["acme", "initech"])

def test_tenant_isolation(two_tenant_store):
    acme_hits    = chain.invoke({"query": "q"}, config={"configurable": {"tenant_id": "acme"}})
    initech_hits = chain.invoke({"query": "q"}, config={"configurable": {"tenant_id": "initech"}})
    acme_ids    = {d.id for d in acme_hits["documents"]}
    initech_ids = {d.id for d in initech_hits["documents"]}
    assert acme_ids.isdisjoint(initech_ids), \
        f"CROSS-TENANT LEAK: overlap={acme_ids & initech_ids}"
    assert all("acme"    in doc_id for doc_id in acme_ids)
    assert all("initech" in doc_id for doc_id in initech_ids)

Run in CI on every PR. A regression to import-time retriever binding fails immediately. See Multi-tenant regression tests for fixtures covering tool-allowlist violation, audit-log completeness, and rate-limiter scoping.

Output

  • Retriever factory keyed by RunnableConfig.configurable["tenant_id"]
  • Vector-store choice made against the 4-row isolation table, not by defaults
  • Agent constructed per-request with a role-scoped tool allowlist (not a deny-all at tool-call time)
  • Rate limiter and cost budget keyed by tenant_id, never a process global
  • Structured audit log emitted on both success and failure paths with required fields (user_id, tenant_id, chain_name, outcome, latency_ms, trace_id)
  • Two-tenant pytest fixture in CI that asserts cross-tenant non-overlap

Error Handling

Error / symptomCauseFix
Tenant A's docs returned to Tenant B after deploySingleton retriever bound at import (P33)Move to per-request factory keyed by config["configurable"]["tenant_id"] (Step 1)
KeyError: 'tenant_id' in retriever factoryCaller forgot to pass configurableFail fast with PermissionError; never default to a tenant
permission denied for relation documents on PGVectorRLS policy enabled but session variable not setSET LOCAL app.tenant_id = :tid inside the transaction
Agent calls a tool the user's role should not haveEvery tool bound at agent constructionBuild agent per-request with only role-permitted tools (Step 3)
Audit log missing entries for errored invocationsLog emitted inside try only, not finallyMove emit to finally block (Step 5)
Shared rate limit trips all tenants when one misbehavesProcess-global InMemoryRateLimiterKey limiter by tenant_id; use Redis-backed for multi-process (Step 4)
Cross-tenant leak regression ships to prodNo two-tenant CI testAdd the Step 6 fixture; run on every PR
Audit log contains raw PII from promptsLogging inputs verbatimLog field names / token counts / IDs only; never log raw message content

Examples

Full multi-tenant RAG agent, end-to-end

Combines all six steps: retriever-per-request, Pinecone namespace isolation, role-scoped tools, per-tenant rate limit, audit-log context manager, regression test. Assembly is ~80 lines. See Retriever-per-request.

Migrating from a shared singleton to per-request

Wrap the old singleton, add the factory alongside, route by feature flag, ship the regression test first, flip the flag, delete the singleton. Typical migration window: 1-2 sprints. See Multi-tenant regression tests.

Exporting audit log to BigQuery for compliance queries

Stream each record to BigQuery per the Audit-log schema. Recipes: "tool calls by user X in last 24h", "tenants with >1% error rate", "highest-spend tenants".

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/.curated/langchain-enterprise-rbac of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/audit-log-schema.md
  • references/multi-tenant-regression-tests.md
  • references/one-pager.md
  • references/retriever-per-request.md
  • references/role-scoped-tool-allowlist.md
  • references/vector-store-isolation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Langchain Enterprise Rbac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Langchain Enterprise Rbac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Langchain Enterprise Rbac this skilljeremylongshore/tons-of-skills-marketplace2.8k—~4kAutomated safety check: PassMIT
Agentsop Streaming Outputagentsope/SkillAlchemy436—~5.3kAutomated safety check: PassMIT
Mem0 Platform SDKmem0ai/mem067k1 repos~2.2kAutomated safety check: PassApache-2.0
LangSmith Trace DebuggingComposioHQ/awesome-claude-skills77k8 repos~2.7kAutomated safety check: PassNone
Add Example AgentGetBindu/Bindu10k—~1.1kAutomated safety check: NotesCustom licence
Failproof AI SDK IntegrationFailproofAI/failproofai5.3k—~6kAutomated safety check: PassCustom licence

Similar skills

  • Agentsop Streaming Output

    agentsope/SkillAlchemy

    Enhancement-overlay decision protocol for STREAMING the output of long-running LLM / agent runs from the backend, not just wiring a typing animation in the UI.

    436 GitHub stars~5.3k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed
  • Adds persistent memory to AI apps with the Mem0 Python and TypeScript SDKs: store, search, update and delete user memories, with framework integrations.

    67k GitHub starsUsed in 1 repo~2.2k tokens
    AI & LLM EngineeringAuto-check passed
  • LangSmith Trace Debugging

    ComposioHQ/awesome-claude-skills

    Debugs LangChain and LangGraph agents by pulling recent execution traces with the langsmith-fetch CLI and reporting errors, tool calls, timings and token use.

    77k GitHub starsUsed in 8 repos~2.7k tokens
    AI & LLM EngineeringAuto-check passed
  • Add Example Agent

    GetBindu/Bindu

    Add a new self-contained example agent under examples/. An agent skill from GetBindu/Bindu.

    10k GitHub stars~1.1k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check: notes
  • Failproof AI SDK Integration

    FailproofAI/failproofai

    Helps instrument a custom Python or TypeScript agent to record events for Failproof AI, verify what gets written, and run an evaluator worker that scores the runs.

    5.3k GitHub stars~6k tokensUpdated 4 days ago
    AI & LLM EngineeringAuto-check passed
  • Edgeone Makers Migration

    TencentEdgeOne/edgeone-makers-tools

    Migrate existing AI agent projects (LangChain, LangGraph, OpenAI Agents SDK, Claude Agent SDK, CrewAI) to EdgeOne Makers platform conventions.

    1.9k GitHub starsUsed in 1 repo~4.1k tokens
    AI & LLM EngineeringAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Langchain Enterprise Rbac

What does Langchain Enterprise Rbac do?

Enforce tenant isolation and role-based access across LangChain 1.0 chains and LangGraph 1.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and…. Langchain Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and structured audit logs.

When should I use Langchain Enterprise Rbac?

Langchain Enterprise Rbac fits situations like: building multi-tenant saas; passing soc2 review; debugging cross-tenant leak; with langchain multi-tenant.

How do I install Langchain Enterprise Rbac in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a claude-code`. Or copy the skill folder (skills/.curated/langchain-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/langchain-enterprise-rbac in your project. Claude Code loads it when a task matches its description.

How do I install Langchain Enterprise Rbac in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a codex`. Or copy the skill folder (skills/.curated/langchain-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/langchain-enterprise-rbac in your project. Codex loads it when a task matches its description.

Can I use Langchain Enterprise Rbac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/langchain-enterprise-rbac, .gemini/skills/langchain-enterprise-rbac, .github/skills/langchain-enterprise-rbac and .opencode/skills/langchain-enterprise-rbac in your project.

What does Langchain Enterprise Rbac need to run?

SKILL.md names no scripts, command-line tools or credentials: Langchain Enterprise Rbac is instructions for the agent only. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(python:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Langchain Enterprise Rbac access the network?

SKILL.md names 5 domains. As links in the text: python.langchain.com, langchain-ai.github.io, docs.pinecone.io, postgresql.org and aicpa-cima.com. This is read from the text; nothing was executed.

Is Langchain Enterprise Rbac safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Langchain Enterprise Rbac use?

Langchain Enterprise Rbac is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Langchain Enterprise Rbac use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.4k tokens, read only when the agent opens those files.

What are the alternatives to Langchain Enterprise Rbac?

Skills that share tags, products or a category with Langchain Enterprise Rbac: Agentsop Streaming Output (agentsope/SkillAlchemy, 436 stars), Mem0 Platform SDK (mem0ai/mem0, 67k stars), LangSmith Trace Debugging (ComposioHQ/awesome-claude-skills, 77k stars) and Add Example Agent (GetBindu/Bindu, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Langchain Enterprise Rbac?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.