Skip to content

Sherlock ​

Sherlock is VeriPrompt's central investigation console for your AI estate: one hub where you ask questions about what your AI spend, performance, and activity are actually doing.

It bundles four independent capabilities behind a single product switcher. Each one is booked separately and permissioned separately, so you turn on (and pay for) only the lenses your team needs:

CapabilityWhat it answersBest for
CostWhere is the money going, and what would change it?Finance, FinOps, budget owners
OperationsHow fast and how reliable are our providers?Platform and reliability teams
AuditWhat did our people send to AI, and is anything leaking?Compliance, security, legal
ResearchCan I answer an ad-hoc question across all of this?Analysts and data teams

Core promise ​

Sherlock is built for one job: turning raw AI-estate telemetry into answers you can act on.

  1. bring spend, latency, and activity data into one investigation console
  2. let each team see only the lens they are entitled to and permitted for
  3. keep sensitive activity data (the Audit lens) behind permission-only access and a clear audit trail

The four capabilities ​

Cost — spend transparency and what-if ​

What you get: a spend dashboard at /sherlock with attribution by user, project, workflow, and org unit; budgets and findings; a value view; finance-grade export; and a what-if simulator that models a routing or pricing change before you make it. Cost keeps a real-vs-internal money axis, so you can compare what providers actually charged against your internal showback figures.

Use case: your monthly provider bill jumped 30%. Open /sherlock, attribute the spend by project, and find that a single nightly batch workflow drove the increase. Run the simulator at /sherlock/simulator to model routing that workflow to a cheaper model, then export the before/after for your finance review.

Operations — latency and reliability ​

What you get: latency percentiles (p50/p95/p99), success and error rates, and throughput broken down by provider and model, with a per-day trend. This runs over real telemetry, so it reflects what your users actually experienced.

Use case: users report the assistant "feels slow this week." Open /sherlock/operations, sort by p95 latency, and see that one provider's p95 doubled while its error rate climbed. You now have the evidence to fail traffic over to a healthier provider.

Audit — compliance investigation ​

What you get: a permission-only console at /sherlock/audit to investigate employee AI activity. You can query Compliance Oversight records (decrypted for review), the AuditLog, spending-policy audits, and data-egress / leak signals. Capture, retention, and export settings live in /admin/oversight; Sherlock links out to them.

Use case: legal asks whether any client identifiers were pasted into an external model last quarter. From /sherlock/audit, query the oversight records for the period, review the egress signals, and produce a defensible answer. Every decrypted read you perform is itself recorded as an audit event (sherlock.audit.oversight_query), so the investigation is accountable.

This capability is workforce-monitoring data — see A note on the Audit capability before you enable it.

Research — ad-hoc cross-source queries ​

What you get: a query builder at /sherlock/research that combines cost, telemetry, and oversight data into one ad-hoc question, plus saved queries you can re-run. Access is gated per source: any source you are not permitted to read is simply excluded from your results — never leaked.

Use case: you want to know which projects have both the highest spend and the most failed requests. Build one query across the cost and telemetry sources, save it, and re-run it each month. A teammate who only has cost permission can open the same saved query and will see the cost columns, with the telemetry columns excluded.

Getting Started with Sherlock ​

Setup Wizard ​

When you access Sherlock for the first time, VeriPrompt guides you through the Setup Sherlock wizard — a 7-step onboarding flow that configures cost tracking, waste detection, budgets, and data exports based on your organization's AI usage patterns.

The wizard walks you through:

  1. Selecting your AI usage model (subscription, pay-per-call, BYOK, etc.)
  2. Configuring cost attribution (per user, project, or workflow)
  3. Setting up waste detection and alerts
  4. Enabling automated data exports (CSV, JSON, Parquet, XLSX)
  5. Creating sandbox budgets for safe testing
  6. Integrating with monitoring tools (Slack, Datadog, etc.)
  7. Reviewing and applying your configuration

You can skip the wizard to explore Sherlock first — a banner will remind you to complete setup later. The wizard can also be re-run anytime to update your configuration.

Learn more: Setup Sherlock Wizard Guide

Turning Sherlock On ​

Each capability is a separate add-on, so a company turns them on independently. There are two ways:

  1. Book the add-on in Billing. Go to your billing page, open Available add-ons, and book the capability you want: Cost Intelligence, Operations Analytics, Audit Analytics, or Data Research.
  2. Have an admin enable it on your plan. A company admin can switch the matching flag on in /admin/packages — allowCostIntelligence, allowOpsAnalytics, allowAuditQueries, or allowDataResearch.

Booking or enabling a capability is what grants the entitlement. Until a capability is booked, it stays hidden — entitlement is fail-closed, so a plan with no add-ons gets nothing for free.

Granting access ​

Booking a capability is only half of access. A person also needs permission, which you grant by assigning a built-in Access Profile in /admin/company-users:

ProfileGrants access to
Cost ControllerCost
Ops AnalystOperations
AuditorAudit
Data AnalystResearch, plus read-only Cost
Sherlock AnalystView access across all four capabilities

Assign the profile that matches the lens the person needs. For example, give your FinOps lead the Cost Controller profile and your compliance officer the Auditor profile.

The access rule ​

A capability appears for a user only when both conditions are true:

  • the capability is booked (entitlement), and
  • the user is permitted (an Access Profile that includes it).

So a Cost Controller in a company that has not booked Cost Intelligence sees nothing — and a company that booked every add-on still shows each lens only to the people whose profile includes it. Booking without permission, or permission without booking, both resolve to "no access."

A note on the Audit capability ​

Audit is different from the other three:

  • It is permission-only. There is no role shortcut — an elevated role alone does not grant it. The person must hold the Auditor (or Sherlock Analyst) profile.
  • It is workforce-monitoring data. The Audit lens lets a reviewer read what employees sent to AI systems. In most jurisdictions this requires a DPIA and works-council (or equivalent) sign-off before you enable it in production. Treat enabling Audit as a governance decision, not just a billing one.

Choosing where to start ​

Use Cost when the question is about money — where spend goes, whether a budget is at risk, or what a routing change would save.

Use Operations when the question is about experience — latency, error rates, or which provider is degrading.

Use Audit when the question is about compliance — what employees sent to AI, and whether anything sensitive left the building. Confirm your DPIA and sign-off first.

Use Research when no single lens answers the question and you need to combine sources — for example spend and reliability together — in one ad-hoc query.