Built on the Query Security Data Mesh, Workers operate across over 60 integrations, display every query, and handle findings from triage to closure, complete with full transcripts.
Problems that previously demanded hours of switching between consoles now return in minutes, with evidence and each query visible. My analysts still make the final decision, but they begin from answers rather than a blank console.”— Rudy Ristich, CISO and CPO of Avant
Query, the company behind Federated Search, has announced the general availability of Query Workers. These AI agents investigate threats the way a seasoned analyst would, reaching every connected security tool in place, without first copying data into another platform. The agents collaborate with security operators, using the Query Security Data Mesh to access data anywhere via a patented federated search engine that enhances reach, reasoning, and AI-driven decision-making.
This launch arrives at a moment when the entire industry echoes what Query has stated from the start. An AI agent is only as capable as the data it can access, and within a real enterprise, data does not reside in a single location. The difference in Query’s architecture is apparent in the results. Query built the data layer first and validated it in production. The Workers operate on top of that foundation.
That data layer is the Security Data Mesh, where the core engineering effort was invested. Reaching data where it lives is the objective. Enabling an agent to reason across dozens of disparate sources required years of work, broken into three components.
The first is a common language. Query translates every source into the open OCSF schema at the moment a query executes. Without a shared schema, federation becomes a collection of separate searches, each producing different data sets that require extra time and effort from the operator or agent to reconcile.
The second is search that executes in place. Query runs the query against CrowdStrike, Databricks, Splunk, Microsoft Sentinel, Cribl, Okta, cloud data lakes, and dozens of other tools, reading the data where it resides rather than first copying it to another platform. The mesh now spans more than sixty integrations, with over a thousand detection recipes behind Federated Detections, and Workers that can generate a new detection when your team needs one, ready for human review and deployment.
The third is evidence that a human can verify. Every investigation produces a report, a complete log of each query the Worker ran, a ledger of the indicators it discovered, and, for high-severity findings, an automated nine-point senior-analyst review. Nothing is a black box. Query Workers recommend, and humans decide. Workers do not take any autonomous actions.
“The entire market now acknowledges that agents must reach data wherever it resides. I agree with that objective,” said Matt Eberhart, CEO of Query. “We spent years building the layer that makes it a reality, and that layer turned out to be the challenging part. We built the mesh first, validated it across more than sixty sources in production, and placed the Workers on top. The intelligence was never going to come from the model alone. It comes from what the model can see.”
Since the preview at RSAC 2026, Query Workers have evolved from autonomous investigation into how a team operates day-to-day, in a form analysts can use immediately. Trust, but verify: every run leaves a complete record, down to the questions the Worker could not answer.
Findings flow into a case workspace that manages the agents and their output, designed like the ticketing tools analysts already use: triage, investigate, act, escalate, close, with fast filtering and views that a teammate can open from a link, or a direct push into the enterprise ticketing platform. Workers can run on a schedule, so a team starts the morning with one briefing instead of a queue that nobody watched overnight: what is new, what recurred, what resolved itself, and the items needing human review. Pricing is credit-based, with no per-gigabyte ingest fees and no data-volume charges.
Query’s Demo Center publishes real Query Worker investigations as step-by-step replays, including every federated query. The invitation is the same one Query extends to the entire category: do not take our word for it. Watch the runs.
In its own testing, Query gave AI agents raw access to a large set of security tools and observed what happened as the environment expanded. The agents quietly stopped consulting sources, then reported their conclusions with full confidence, built on a fraction of the available data. Agents working through the mesh continued to look across the entire estate. An agent that cannot reach everything will still sound certain about the limited data it saw.
Work that took analysts hours now completes in about fifteen minutes, with a single Worker running dozens of federated queries on a complex case, across tools that an analyst used to open one browser tab at a time.
“Problems that previously took my team hours of pivoting between separate consoles now come back in minutes, with the evidence attached and every query visible,” said Rudy Ristich, CISO and Chief Privacy Officer at Avant. “My analysts still make the decision. They just start from an answer instead of a blank console.”
“A Query Worker runs the investigation across every connected source and returns a recommendation with the evidence shown,” said Mike Bousquet, Chief Product Officer at Query. “It recommends, your team decides, and that split is intentional. It only works because the layer underneath can reach every source and read them all in one schema.”
Query Workers are now generally available. Query will be at Black Hat USA 2026. Request a demo and see live investigation replays here.
About Query
The Query security data mesh platform makes your data operational, wherever it’s stored. No ingestion. No migration. No centralization required. Give your team and agents (yours or ours) the data foundation they need to search, investigate, hunt and detect across every source, while the data stays where it lives. Query is headquartered in Atlanta, Georgia. Learn more at query.ai.
Mike Bousquet
Query.AI, Inc.
press@query.ai
Visit us on social media:
LinkedIn



