Skip to content

FAQ & Troubleshooting

FAQ & Troubleshooting — AskSenseOps

Below are answers to common questions about AskSenseOps.


Does AskSenseOps have its own AI Model?

General: Does AskSenseOps have its own AI Model?

Answer:

No. The Agent leverages your existing cloud or offline models and acts as an intelligent orchestrator to give you the best results.


How is it different from other conversational AI products?

General: How is it different from other conversational AI products?

Answer:

AskSenseOps was designed to unlock the flexibility every data user needs with respect to:

  • Choice of models
  • Variety of sources
  • Quality of AI conversations
  • Economics of consumption
  • The last-mile experience that makes the impact

Unlike conventional AI products, it does not enforce any model or source lock-ins, nor push you towards unfettered use of credits.


Where does AskSenseOps reside?

General: Where does AskSenseOps reside?

Answer:

It is installed on the server where your sources are available. It acts as a bridge between your sources and the LLMs you use or configure.


How can I access it?

General: How can I access it?

Answer:

AskSenseOps can be accessed via:

  • A web browser
  • An extension on your data source
  • An existing LLM chat interface or channel (by adding it as an MCP connector)

Access method depends on the use case.


Will the AI see data my users shouldn't?

Security: Will the AI see data my users shouldn't?

Answer:

No. Every query runs as the authenticated human user through Qlik's spaces / section access / RLS. The DLP layer additionally redacts PII / PHI / PCI before results leave the broker.


Can the AI delete or publish without our approval?

Security: Can the AI delete or publish without our approval?

Answer:

No. Destructive and publish operations require a signed, single-use approval token via your channel (Slack / ServiceNow / SenseOps UI). The AI cannot self-issue this token.


How fast is revocation?

Security: How fast is revocation?

Answer:

CAEP push from your IdP terminates sessions and refresh tokens within seconds. Worst case (no CAEP) = access-token TTL minus 60s safety margin (≤30 min for write/delete).


Where do credentials live?

Security: Where do credentials live?

Answer:

Encrypted at rest under envelope encryption with the master key in your KMS (or ours, your choice). Operators cannot decrypt without KMS authorization. Never sent to the LLM.


Can we audit AI activity?

Security: Can we audit AI activity?

Answer:

Every authz decision, policy decision, token mint, tool call, approval-token issuance, and DLP redaction emits a hash-chained CEF / OCSF event to your SIEM + WORM. Chain verifiable offline.


Where does our data live?

Security: Where does our data live?

Answer:

In the region you select (US / EU / UK / APAC) or in your own cloud / on-prem if self-hosted. KMS keys, audit logs, and operational data never leave the region without explicit opt-in.


Is it locked to one AI vendor?

Security: Is it locked to one AI vendor?

Answer:

No. MCP is an open standard; any compliant client works. Tool manifests are signed at build time, so the trust model is uniform across Anthropic, Azure OpenAI, AWS Bedrock, or private endpoints.


🛠 Still Stuck?

Reach out to the SenseOps support team with your query and relevant details if your question isn't answered above.