Constructed on the Query Security Data Mesh, Workers operate across more than 60 integrations, display every query, and handle findings from triage to closure, complete with full transcripts.
Problems that previously demanded hours of switching between consoles are now resolved in minutes, with evidence attached and every query shown. My analysts remain the ones who decide, beginning from answers rather than a blank console.”— Rudy Ristich, CISO and CPO of Avant
Query, the company that pioneered Federated Search, today announced the general availability of Query Workers. These AI agents investigate threats the way a senior analyst would, across every connected security tool, in place, without first copying data into another platform. The agents work alongside security operators, leveraging the Query Security Data Mesh to access data anywhere through a patented federated search engine that expands reach, reasoning, and AI decision-making.
This launch arrives during a week when the entire industry echoes what Query has stated since its founding. An AI agent is only as effective as the data it can access, and in a real enterprise, data does not all reside in a single location. The distinction in the Query architecture is clear in the results. Query built the data layer first and validated it in production. The Workers operate on top of it.
That data layer is the Security Data Mesh, where the challenging engineering occurred. Reaching data where it lives is the objective. Enabling an agent to reason across dozens of disconnected sources represents years of work, broken into three components.
The first is a common language. Query translates every source into the open OCSF schema at the moment a query executes. Without a shared schema, federation becomes a collection of separate searches, each producing different data sets that require the operator or the agent to spend time and effort reconciling.
The second is search that executes in place. Query runs the query against CrowdStrike, Databricks, Splunk, Microsoft Sentinel, Cribl, Okta, cloud data lakes, and dozens of other tools, reading the data where it resides instead of copying it to another platform first. The mesh spans more than sixty integrations today, with over a thousand detection recipes behind Federated Detections, and Workers that can write a new detection when your team needs one, ready for a human to review and deploy.
The third is evidence that a human can verify. Every investigation produces a report, the complete log of every query the Worker ran, a ledger of the indicators it discovered, and, for high-severity findings, an automated nine-point senior-analyst review. Nothing is a black box. Query Workers recommend and humans decide. Workers do not take actions autonomously.
"The whole market now agrees that agents need to reach data wherever it lives. I agree with the goal," said Matt Eberhart, CEO of Query. "We spent years building the layer that makes it real, and that layer turned out to be the hard part. We built the mesh first, proved it across more than sixty sources in production, and put the Workers on top. The intelligence was never going to come from the model alone. It comes from what the model can see."
Since the preview at RSAC 2026, Query Workers have evolved from autonomous investigation into how a team operates its daily workflow, in a format analysts can use now. Trust, but verify: every run leaves a complete record, down to the questions the Worker could not answer.
Findings flow into a case workspace that manages the agents and their output, built like the ticketing tools analysts already use: triage, investigate, act, escalate, close, with fast filtering and views a teammate can open from a link, or a push straight into the enterprise ticketing platform. Workers can run on a schedule, so a team starts the morning with one briefing instead of a queue nobody watched overnight: what is new, what recurred, what resolved itself, and the things that need a human review. Pricing is credit-based, with no per-gigabyte ingest fees and no data-volume charges.
Query's Demo Center publishes real Query Worker investigations as step-by-step replays, every federated query included. The invitation is the same one Query makes to the whole category: do not take our word for it. Watch the runs.
In its own testing, Query gave AI agents raw access to a large set of security tools and watched what happened as the environment grew. The agents quietly stopped consulting sources, then reported their conclusions with full confidence, built on a fraction of the data that was there. Agents working through the mesh kept looking across the whole estate. An agent that cannot reach everything will still sound certain about the little it saw.
Work that took analysts hours now finishes in about fifteen minutes, with a single Worker running dozens of federated queries on a complex case, across tools an analyst used to open one browser tab at a time.
"Issues that used to take my team hours of pivoting between separate consoles come back in minutes, with the evidence attached and every query shown," said Rudy Ristich, CISO and Chief Privacy Officer at Avant. "My analysts still make the call. They just start from an answer instead of a blank console."
"A Query Worker runs the investigation across every connected source and hands back a recommendation with the evidence shown," said Mike Bousquet, Chief Product Officer at Query. "It recommends, your team decides, and that split is deliberate. It only works because the layer underneath can reach every source and read them all in one schema."
Query Workers are generally available now. Query will be at Black Hat USA 2026. Request a demo and see live investigation replays here.
About Query
The Query security data mesh platform makes your data operational, wherever it’s stored. No ingestion. No migration. No centralization required. Give your team and agents (yours or ours) the data foundation they need to search, investigate, hunt and detect across every source, while the data stays where it lives. Query is headquartered in Atlanta, Georgia. Learn more at query.ai.
Mike Bousquet
Query.AI, Inc.
press@query.ai
Visit us on social media:
LinkedIn




