Connect principals to the jobs and tables they touch
Connect principals and applications to jobs, datasets, tables, and query activity. Detect behavioral changes and investigate historical activity across every project.

Native telemetry used
Trailox reads Google Cloud Audit Logs (Data Access logs) and INFORMATION_SCHEMA.JOBS, which together capture every query job run against your BigQuery datasets.
What access Trailox can see
Every query job, the datasets, tables, and columns it referenced, bytes processed, and job status.
Identity and application attribution
Trailox resolves every job to the IAM principal that ran it, a user or service account, and to the calling application where identifiable, the console, the API, a client library, or a BI tool.

Behavioral detections for BigQuery
- A principal accessing a dataset or table for the first time
- Query jobs processing an unusually large number of bytes
- New service account activity against production datasets
- Query activity outside a principal's established pattern
- Sudden expansion into new datasets or projects
Investigation capabilities
Search historical job activity by principal, dataset, or table, and reconstruct a table's complete access history over time.
How Trailox connects
A read-only IAM role with access to Cloud Audit Logs and BigQuery job metadata. No datasets or jobs are modified.
Start with proof,
not a pitch.
Scoped read-only role, 30-day lookback, results in 48 hours.