Governance by design

Every question.
Every answer.
Full audit trail.

Business users ask in plain language. Agents query the semantic layer. Role-based access is enforced. And every step - from question to metric to warehouse - is logged, traceable, and auditable. Quaeris makes AI analytics transparent.

  • Prompt-level auditEvery question logged - exact text, user, timestamp

  • Metric-to-table lineageClick any number to see full chain of custody

  • Query-time enforcementRole policies applied at execution - not just the UI

  • Exportable for SOX & compliance workflowsCompliance-ready audit reports on demand

Core Capabilities

Every question. Every answer.
Every decision on record.

Quaeris writes a tamper-evident, compliance-ready audit trail for every governed analytics event - from the natural-language question to the certified source row.

A tamper-evident record of every analytics event

Every question, answer, access grant, and denial is written to an append-only log the moment it occurs. Nothing is retroactively altered - giving auditors a forensic-quality timeline they can trust.

  • Captures user identity, timestamp, question text, and the exact SQL executed - automatically, with no developer instrumentation
  • Append-only write path prevents silent edits; hash-chained entries surface any tampering immediately
  • Exportable as signed JSON or CSV for direct upload to GRC platforms, legal holds, or external auditors
The problem

Why audit trails matter

Most AI analytics platforms are black boxes. Compliance officers, data leaders, and auditors are left without evidence when questions arise.

Problem

AI Black Box

Most AI analytics platforms treat agents as black boxes. You see an answer - but not the reasoning, not which metrics were queried, not whether the user had access to that data.

Quaeris

Every agent step logged

Quaeris logs every agent step. The system records which business rules were applied, which semantic layer definitions were used, and whether row-level access controls permitted the result. No hidden reasoning.

Problem

Orphaned Metrics

Compliance teams need proof of which numbers came from which tables, which business rules generated them, and who approved those rules. Standard BI tools show a dashboard - not the provenance.

Quaeris

Full metric lineage per answer

Every Quaeris answer surfaces the exact metric definitions it used. Traces back to the semantic layer version, the data table, the transformation rules, and the owner approval. Click any number and see the full chain.

Problem

Access Control Theater

Role-based access on dashboards is a filter - a UI layer. Executives can screenshot restricted data or pivot on unintended dimensions. Governance theater doesn't satisfy auditors.

Quaeris

Enforced at execution, not the UI

Quaeris enforces access at query time. Role policies are applied when the agent executes - not when the user views the result. Users cannot see data their role forbids, period. And every query attempt is logged.

Problem

Who Asked What?

When a number in the boardroom turns out to be wrong, compliance needs to know: who asked? when? with what intent? which model assumptions did they use? Standard analytics tools have no answer history.

Quaeris

Complete question history, searchable

Quaeris maintains a complete audit log of every question asked - by whom, when, which data they accessed, which metrics were returned, whether they're supposed to see it. Searchable, timestamped, exportable for compliance workflows.

How it works

The audit trail architecture

Four steps. Every query. Logged automatically, with zero instrumentation required from your team.

Step 01 - Question Capture

Every question logged, exactly as asked.

When a user types "Revenue vs. plan by region," Quaeris records: the exact text, the user's identity, the timestamp, their role/team, and the warehouse they're querying. The question enters the audit log immediately - before the agent even processes it. No guessing what was asked. No reconstructing intent from logs.

Learn about prompt audit
Step 02 - Query Translation & Lineage

AI-to-SQL translation is visible and auditable.

The agent translates the plain-language question into SQL against the semantic layer. Quaeris logs: the generated SQL, which semantic layer definitions were consulted, which business rules were applied, and the query execution time. If the agent needed to make assumptions - "revenue" → the Booked Revenue metric, not Pipeline Revenue - those assumptions are logged and surfaced.

Explore the semantic layer
Step 03 - Access Control Enforcement

Role policies enforced at query execution.

Before the query runs, Quaeris evaluates the user's row-level security policies against the warehouse. The system logs: which rows the user requested, which rows their role permits, and whether the query was allowed or denied. If allowed, which row-level filters were applied. Every access decision is auditable - compliant auditors can verify that a director-level user never saw frontline-employee data.

See access control in action
Step 04 - Answer Delivery & Provenance

Results returned with full source citation.

The agent returns the answer to the user. Quaeris logs: the result set, the execution time, the user's response (did they refine the query?), and a complete chain of custody. Every number in the answer is clickable - users can trace "Revenue = $2.4M" back to the exact metric definition, the table query, the transformation rules, and the owner certification. Auditors can download the full provenance report for any answer.

View an audit report
Live audit log

What your audit log looks like

Every interaction, every access decision, every metric used - logged in real time. This is an illustrative mockup of the Quaeris audit log UI.

Live stream - 2,847 events today
TimestampUserQuestionStatusMetrics UsedData AccessTime
2026-06-12
14:32:18
A. RiveraHead of AnalyticsRevenue vs. plan by regionAllowedBooked Revenue, Plan Amount, Regional Sales OrgRegion IN ['US', 'EMEA']1.4s
2026-06-12
14:28:03
M. OkaforFinance ManagerCommission accrual forecastAllowedAccrual Rate, Headcount ForecastDepartment = 'Sales'2.1s
2026-06-12
14:15:44
T. BrandtSales RepChurn by contract valueDeniedN/AAccess denied: Strategic Contracts restricted-
2026-06-12
14:12:09
K. NguyenSales DirectorPipeline by stage and managerAllowedPipeline Weighted, Stage DurationManager IN [own team]0.9s
2026-06-12
14:09:55
P. HartmannCFOExplain why MRR dropped YoYAllowedMRR, Expansion, Churn, Discount RateWarehouse filtering per role3.2s

Illustrative live audit log - for demonstration only. Real deployments log millions of interactions per month, all queryable and exportable.

Platform capabilities

Key audit capabilities

Built into the platform. No configuration required. Every feature is logged automatically from the first query.

Role-based access control

Every query enforces the user's role policies. Access decisions are logged. Users cannot see data their role forbids - enforced at query execution, not just the UI.

Complete question history

Every question asked is logged with timestamp, user, intent, and outcome. Searchable audit log - compliance teams can answer "Who asked about customer churn?" in seconds.

Metric-to-table lineage

Every answer traces back to metric definitions, business rules, source tables, and transformations. One click: see the full chain of custody for any number.

Proof of data access

Quaeris logs which specific rows each user accessed, which rows were filtered out, and why. Row-level security is auditable - not just a dashboard filter.

Exportable audit reports

Generate timestamped, signed audit reports for compliance workflows. SOX and EU AI Act ready; HIPAA controls on our roadmap - format the report to match your audit requirements.

Access denial logs

Denied queries are logged as thoroughly as allowed ones. Compliance teams see every attempt to access restricted data - and proof it was blocked.

Use cases

Who needs audit trails

Governance requirements differ by role and regulation - but the underlying need is the same: proof that AI analytics is controlled, traceable, and compliant.

Finance & Audit

SOX Compliance & Financial Audits

Auditors need to trace every number in board materials back to source data. Quaeris gives you: question, assumption, metric, table, owner certification, access control. Satisfy auditors without blocking analytics velocity.

Read the SOX guide
Data Governance

Metric Governance & Lineage

Data leaders own the semantic layer. Quaeris audit logs show you which metrics each question used, which business rules applied, and which users accessed sensitive metrics. Governance becomes visible, not theoretical.

Learn about semantic lineage
CDO / Privacy Teams

Data Privacy & EU AI Act

EU AI Act requires audit trails for high-risk AI. GDPR requires data-access logging. Quaeris logs every query at the row level. Prove compliance with automated audit exports.

See the EU AI Act checklist
Healthcare & Insurance

HIPAA & Regulated Industry AI

Sensitive industries need to prove that AI agents respect access controls. Quaeris enforces role-based access at query time and logs every access attempt. Healthcare and insurance teams can deploy agentic AI without audit risk.

View the HIPAA readiness guide
Platform comparison

Audit trail across BI platforms

Not all audit trails are equal. Compare how Quaeris's governance-by-design approach differs from incumbent BI and competing AI analytics platforms.

CapabilityQuaerisTableauPower BILookerThoughtSpotSigmaDomo
Question logging
Per-user, full text, timestamped
Dashboard usage onlyPer-user, limitedQuery audit limitedSearch token loggingBasic activity logBasic activity log
Metric-to-table lineage
Auto-surfaced per answer
Dashboard-level onlyModel-level, not answerLookML dependenciesWorksheet-levelBasic lineageBasic lineage
Row-level access enforcement
Query-time enforcement
Filter-based (UI layer)Model & RLSLookML RLSSearch-token scopedDashboard-levelAccess model
AI reasoning logged
SQL, assumptions, rules
N/A (no AI)Copilot actions hiddenConversational logs limitedReasoning opaqueAgent steps hiddenAI opaque
Access denial audit trail
Full logging
Not loggedLogged, limitedNot clearly loggedNot transparentNot transparentNot transparent
Exportable compliance reports
SOX / EU AI Act ready; HIPAA on roadmap
Manual export onlyManual export onlyManual export onlyManual export onlyManual export onlyManual export only
Warehouse-native logging
Warehouse queries logged
Cloud-based, query-hiddenCloud-based, hiddenCloud-based, hiddenElastic-basedCloud-based, hiddenCloud-based, hidden

Comparison based on publicly available documentation as of Q2 2026. Actual capabilities vary by product version and deployment model. Consult your vendor for current feature availability.

Common questions

FAQ: Audit trail specifics

Everything compliance officers, data leaders, and auditors ask before deploying Quaeris in a regulated environment.

Every user action is logged: the exact question text, the user's identity, the timestamp down to milliseconds, their role/team context, which warehouse they queried, the generated SQL, which metrics were accessed, and the result. If access was denied, that's logged too. Logs are immutable and timestamped.
Demonstrate to your auditors

See your audit trail in action.

Book a 20-minute demo. We'll walk through a sample audit log, show you how a compliant query flows through access control, lineage, and retention - then answer your governance questions. No fluff, all answers.

Stay updated on governance

Weekly insights on governed AI analytics.

Every Thursday: practical tips on audit-ready AI, semantic governance, and compliance-first analytics architectures. No hype, no fluff - just what works.