Snyk has turned an agent originally built for its support staff into Snyk Assist, a customer-facing feature available to paying users. The agent searches product documentation and account context, checks packages for known vulnerabilities, opens support cases and records feature requests from a conversation.
The security company spent roughly a year using the system internally before moving it into the core product in September. That staging gave Snyk traces from real support work without exposing early failures to customers. Those traces became evaluation cases used to test later changes.
Access control is central to the design. Snyk says the agent must not return anything the current user could not already see, and it tests whether the system answers correctly and refuses requests outside its permissions. LangGraph provides the workflow runtime, while LangSmith records traces and runs evaluations before releases.
One runtime supports several product surfaces rather than maintaining a separate agent for each interface. The case study is Snyk and LangChain’s account of their own deployment, not an independent accuracy audit. Its practical contribution is the rollout pattern: begin with a constrained internal workflow, convert observed failures into tests, and keep authorization checks at the data and tool boundaries.