Built on the Query Security Data Mesh, Workers operate across more than 60 integrations, display every query, and handle findings from triage through closure, complete with full transcripts.
Problems that once demanded hours of switching between consoles now return in minutes, backed by evidence and every query displayed. My analysts continue to make the decisions, but they begin with answers rather than a blank console.”— Rudy Ristich, CISO and CPO of Avant
Query, the company that pioneered Federated Search, today announced the general availability of Query Workers. These AI agents investigate threats the way an experienced analyst would, across every connected security tool, in their original location, without first copying data into another platform. The agents work alongside security operators, leveraging the Query Security Data Mesh to access data anywhere via a patented federated search engine that enhances reach, reasoning, and AI-based decision-making.
This launch arrives during a week when the entire industry echoes what Query has stated from its inception. An AI agent is only as effective as the data it can access, and in a real enterprise environment, data does not reside in a single location. The distinction in the Query architecture shows up in the results. Query built the data layer first and validated it in live production. The Workers run on top of that foundation.
That data layer is the Security Data Mesh, and it represents the core engineering effort. Reaching data where it lives is the objective. Making an agent reason across dozens of disconnected sources required years of work, broken into three components.
The first is a common language. Query translates every source into the open OCSF schema at the moment a query executes. Without a shared schema, federation becomes a series of separate searches, each producing different data sets that force the operator or agent to spend time and effort reconciling them.
The second is search that runs in place. Query executes the query against CrowdStrike, Databricks, Splunk, Microsoft Sentinel, Cribl, Okta, cloud data lakes, and dozens of other tools, reading the data where it resides instead of copying it to another platform first. The mesh covers more than 60 integrations today, with over a thousand detection recipes behind Federated Detections, and Workers that can generate a new detection when your team needs one, ready for human review and deployment.
The third is evidence a human can verify. Every investigation produces a report, a complete log of every query the Worker ran, a ledger of the indicators it discovered, and, on high-severity findings, an automated nine-point senior-analyst review. Nothing is a black box. Query Workers recommend and humans decide. Workers do not take actions on their own.
“The entire market now agrees that agents must reach data wherever it lives. I share that goal,” said Matt Eberhart, CEO of Query. “We spent years building the layer that makes it a reality, and that layer turned out to be the difficult part. We built the mesh first, proved it across more than 60 sources in production, and placed the Workers on top. The intelligence was never going to come from the model alone. It comes from what the model can see.”
Since the preview at RSAC 2026, Query Workers have evolved from autonomous investigation into how a team operates daily, in a format analysts can put to work immediately. Trust, but verify: every run leaves a complete record, down to the questions the Worker could not answer.
Findings flow into a case workspace that manages the agents and their output, designed like the ticketing tools analysts already use: triage, investigate, act, escalate, close, with fast filtering and views a teammate can open from a link, or a direct push into the enterprise ticketing system. Workers can run on a schedule, so a team starts the morning with a single briefing instead of a queue nobody monitored overnight: what is new, what recurred, what resolved itself, and the items that need human review. Pricing is credit-based, with no per-gigabyte ingest fees and no data-volume charges.
Query’s Demo Center publishes real Query Worker investigations as step-by-step replays, with every federated query included. The invitation is the same one Query extends to the entire category: do not take our word for it. Watch the runs.
In its own testing, Query gave AI agents raw access to a large set of security tools and observed what happened as the environment expanded. The agents quietly stopped consulting sources, then reported their conclusions with full confidence, built on a fraction of the available data. Agents working through the mesh kept looking across the entire estate. An agent that cannot reach everything will still sound certain about the little it saw.
Work that took analysts hours now completes in roughly fifteen minutes, with a single Worker running dozens of federated queries on a complex case, across tools an analyst previously opened one browser tab at a time.
“Issues that used to take my team hours of switching between separate consoles now come back in minutes, with the evidence attached and every query displayed,” said Rudy Ristich, CISO and Chief Privacy Officer at Avant. “My analysts still make the call. They just start from an answer instead of a blank console.”
“A Query Worker runs the investigation across every connected source and hands back a recommendation with the evidence shown,” said Mike Bousquet, Chief Product Officer at Query. “It recommends, your team decides, and that split is intentional. It only works because the layer underneath can reach every source and read them all in one schema.”
Query Workers are generally available now. Query will be at Black Hat USA 2026. Request a demo and see live investigation replays here.
About Query
The Query security data mesh platform makes your data operational, wherever it’s stored. No ingestion. No migration. No centralization required. Give your team and agents (yours or ours) the data foundation they need to search, investigate, hunt and detect across every source, while the data stays where it lives. Query is headquartered in Atlanta, Georgia. Learn more at query.ai.
Mike Bousquet
Query.AI, Inc.
press@query.ai
Visit us on social media:
LinkedIn


