Powered by the Query Security Data Mesh, these agents operate across more than 60 integrations, display every query, and handle findings from triage to closure, complete with full transcripts.
“Problems that once demanded hours of switching between consoles now return in minutes, complete with evidence and a full log of every query. My analysts still make the final decision—they just begin with answers instead of an empty screen.”— Rudy Ristich, CISO and CPO of Avant
Query, the company that pioneered Federated Search, announced today that Query Workers are now generally available. These AI agents investigate threats the way a seasoned analyst would, reaching into every connected security tool where the data resides, without first copying information into another platform. The agents work alongside security operators, leveraging the Query Security Data Mesh to access data anywhere via a patented federated search engine that enhances reach, reasoning, and AI decision-making.
This launch arrives at a moment when the entire industry echoes what Query has stated from its inception. An AI agent is only as effective as the data it can access, and in a real enterprise, data does not all reside in one location. The difference in Query’s architecture becomes apparent in the results. Query built the data layer first and validated it in production. The Workers operate on top of that foundation.
That data layer—the Security Data Mesh—is where the significant engineering effort went. Reaching data where it lives is the objective. Enabling an agent to reason across dozens of disconnected sources required years of work, broken into three components.
The first is a common language. Query translates every source into the open OCSF schema at the moment a query runs. Without a shared schema, federation becomes a collection of separate searches, each producing different data sets that force the operator or agent to spend time and effort reconciling them.
The second is search that executes in place. Query runs the query against CrowdStrike, Databricks, Splunk, Microsoft Sentinel, Cribl, Okta, cloud data lakes, and dozens of other tools, reading the data where it lives instead of copying it to another platform first. The mesh now spans more than sixty integrations, backed by over a thousand detection recipes within Federated Detections, and Workers that can generate a new detection when your team needs one, ready for human review and deployment.
The third is evidence that a human can verify. Every investigation produces a report, a complete log of every query the Worker ran, a ledger of the indicators it discovered, and—on high-severity findings—an automated nine-point senior-analyst review. Nothing is a black box. Query Workers make recommendations; humans make the decisions. Workers do not take actions autonomously.
“The entire market now agrees that agents must reach data wherever it lives. I share that goal,” said Matt Eberhart, CEO of Query. “We spent years building the layer that makes it possible, and that layer turned out to be the hard part. We built the mesh first, proved it across more than sixty sources in production, and placed the Workers on top. The intelligence was never going to come from the model alone. It comes from what the model can see.”
Since the preview at RSAC 2026, Query Workers have evolved from autonomous investigation into how a team operates daily, in a form analysts can deploy right now. Trust, but verify: every run leaves a complete record, down to the questions the Worker could not answer.
Findings flow into a case workspace that manages the agents and their output, designed like the ticketing tools analysts already use: triage, investigate, act, escalate, close, with fast filtering and views a teammate can open from a link, or a push directly into the enterprise ticketing platform. Workers can run on a schedule, so a team starts the morning with a single briefing instead of a queue no one watched overnight: what is new, what recurred, what resolved itself, and the items that need human review. Pricing is credit-based, with no per-gigabyte ingest fees and no data-volume charges.
Query’s Demo Center publishes real Query Worker investigations as step-by-step replays, including every federated query. The invitation is the same one Query extends to the entire category: do not take our word for it. Watch the runs.
In its own testing, Query gave AI agents raw access to a large set of security tools and observed what happened as the environment grew. The agents quietly stopped consulting sources, then reported their conclusions with full confidence, built on a fraction of the data that was there. Agents working through the mesh kept looking across the entire estate. An agent that cannot reach everything will still sound certain about the little it saw.
Work that took analysts hours now completes in about fifteen minutes, with a single Worker running dozens of federated queries on a complex case, across tools an analyst used to open one browser tab at a time.
“Issues that used to take my team hours of pivoting between separate consoles come back in minutes, with the evidence attached and every query shown,” said Rudy Ristich, CISO and Chief Privacy Officer at Avant. “My analysts still make the call. They just start from an answer instead of a blank console.”
“A Query Worker runs the investigation across every connected source and hands back a recommendation with the evidence shown,” said Mike Bousquet, Chief Product Officer at Query. “It recommends, your team decides, and that split is deliberate. It only works because the layer underneath can reach every source and read them all in one schema.”
Query Workers are generally available now. Query will be at Black Hat USA 2026. Request a demo and see live investigation replays here.
About Query
The Query security data mesh platform makes your data operational, wherever it’s stored. No ingestion. No migration. No centralization required. Give your team and agents (yours or ours) the data foundation they need to search, investigate, hunt and detect across every source, while the data stays where it lives. Query is headquartered in Atlanta, Georgia. Learn more at query.ai.
Mike Bousquet
Query.AI, Inc.
press@query.ai
Visit us on social media:
LinkedIn


