Appearance
Sherlock
Sherlock is VeriPrompt's central investigation console for your AI estate: one hub where you ask questions about what your AI spend, performance, and activity are actually doing.
It bundles four independent capabilities behind a single product switcher. Each one is booked separately and permissioned separately, so you turn on (and pay for) only the lenses your team needs:
| Capability | What it answers | Best for |
|---|---|---|
| Cost | Where is the money going, and what would change it? | Finance, FinOps, budget owners |
| Operations | How fast and how reliable are our providers? | Platform and reliability teams |
| Audit | What did our people send to AI, and is anything leaking? | Compliance, security, legal |
| Research | Can I answer an ad-hoc question across all of this? | Analysts and data teams |
Core promise
Sherlock is built for one job: turning raw AI-estate telemetry into answers you can act on.
- bring spend, latency, and activity data into one investigation console
- let each team see only the lens they are entitled to and permitted for
- keep sensitive activity data (the Audit lens) behind permission-only access and a clear audit trail
The four capabilities
Cost — spend transparency and what-if
What you get: a spend dashboard at /sherlock with attribution by user, project, workflow, and org unit; budgets and findings; a value view; finance-grade export; and a what-if simulator that models a routing or pricing change before you make it. Cost keeps a real-vs-internal money axis, so you can compare what providers actually charged against your internal showback figures.
Use case: your monthly provider bill jumped 30%. Open /sherlock, attribute the spend by project, and find that a single nightly batch workflow drove the increase. Run the simulator at /sherlock/simulator to model routing that workflow to a cheaper model, then export the before/after for your finance review.
Operations — latency and reliability
What you get: latency percentiles (p50/p95/p99), success and error rates, and throughput broken down by provider and model, with a per-day trend. This runs over real telemetry, so it reflects what your users actually experienced.
Use case: users report the assistant "feels slow this week." Open /sherlock/operations, sort by p95 latency, and see that one provider's p95 doubled while its error rate climbed. You now have the evidence to fail traffic over to a healthier provider.
Audit — compliance investigation
What you get: a permission-only console at /sherlock/audit to investigate employee AI activity. You can query Compliance Oversight records (decrypted for review), the AuditLog, spending-policy audits, and data-egress / leak signals. Capture, retention, and export settings live in /admin/oversight; Sherlock links out to them.
Use case: legal asks whether any client identifiers were pasted into an external model last quarter. From /sherlock/audit, query the oversight records for the period, review the egress signals, and produce a defensible answer. Every decrypted read you perform is itself recorded as an audit event (sherlock.audit.oversight_query), so the investigation is accountable.
This capability is workforce-monitoring data — see A note on the Audit capability before you enable it.
Research — ad-hoc cross-source queries
What you get: a query builder at /sherlock/research that combines cost, telemetry, and oversight data into one ad-hoc question, plus saved queries you can re-run. Access is gated per source: any source you are not permitted to read is simply excluded from your results — never leaked.
Use case: you want to know which projects have both the highest spend and the most failed requests. Build one query across the cost and telemetry sources, save it, and re-run it each month. A teammate who only has cost permission can open the same saved query and will see the cost columns, with the telemetry columns excluded.
Getting Started with Sherlock
Setup Wizard
When you access Sherlock for the first time, VeriPrompt guides you through the Setup Sherlock wizard — a 7-step onboarding flow that configures cost tracking, waste detection, budgets, and data exports based on your organization's AI usage patterns.
The wizard walks you through:
- Selecting your AI usage model (subscription, pay-per-call, BYOK, etc.)
- Configuring cost attribution (per user, project, or workflow)
- Setting up waste detection and alerts
- Enabling automated data exports (CSV, JSON, Parquet, XLSX)
- Creating sandbox budgets for safe testing
- Integrating with monitoring tools (Slack, Datadog, etc.)
- Reviewing and applying your configuration
You can skip the wizard to explore Sherlock first — a banner will remind you to complete setup later. The wizard can also be re-run anytime to update your configuration.
Learn more: Setup Sherlock Wizard Guide
Turning Sherlock On
Each capability is a separate add-on, so a company turns them on independently. There are two ways:
- Book the add-on in Billing. Go to your billing page, open Available add-ons, and book the capability you want: Cost Intelligence, Operations Analytics, Audit Analytics, or Data Research.
- Have an admin enable it on your plan. A company admin can switch the matching flag on in
/admin/packages—allowCostIntelligence,allowOpsAnalytics,allowAuditQueries, orallowDataResearch.
Booking or enabling a capability is what grants the entitlement. Until a capability is booked, it stays hidden — entitlement is fail-closed, so a plan with no add-ons gets nothing for free.
Granting access
Booking a capability is only half of access. A person also needs permission, which you grant by assigning a built-in Access Profile in /admin/company-users:
| Profile | Grants access to |
|---|---|
| Cost Controller | Cost |
| Ops Analyst | Operations |
| Auditor | Audit |
| Data Analyst | Research, plus read-only Cost |
| Sherlock Analyst | View access across all four capabilities |
Assign the profile that matches the lens the person needs. For example, give your FinOps lead the Cost Controller profile and your compliance officer the Auditor profile.
The access rule
A capability appears for a user only when both conditions are true:
- the capability is booked (entitlement), and
- the user is permitted (an Access Profile that includes it).
So a Cost Controller in a company that has not booked Cost Intelligence sees nothing — and a company that booked every add-on still shows each lens only to the people whose profile includes it. Booking without permission, or permission without booking, both resolve to "no access."
A note on the Audit capability
Audit is different from the other three:
- It is permission-only. There is no role shortcut — an elevated role alone does not grant it. The person must hold the Auditor (or Sherlock Analyst) profile.
- It is workforce-monitoring data. The Audit lens lets a reviewer read what employees sent to AI systems. In most jurisdictions this requires a DPIA and works-council (or equivalent) sign-off before you enable it in production. Treat enabling Audit as a governance decision, not just a billing one.
Choosing where to start
Use Cost when the question is about money — where spend goes, whether a budget is at risk, or what a routing change would save.
Use Operations when the question is about experience — latency, error rates, or which provider is degrading.
Use Audit when the question is about compliance — what employees sent to AI, and whether anything sensitive left the building. Confirm your DPIA and sign-off first.
Use Research when no single lens answers the question and you need to combine sources — for example spend and reliability together — in one ad-hoc query.
