Enable · Designed

Truffle Camp

Secrets education is fragmented across docs, detector references, sales enablement, and tribal knowledge.

Career signal: Product Adoption, Technical Enablement, Product GTM

All projects

1. Problem

Secrets education is fragmented across docs, detector references, sales enablement, and tribal knowledge.

Learners confuse detection with verification, severity, ownership, and remediation — and cannot practice a responsible handoff.

Without this: Ramp depends on ride-alongs. Terminology is memorized without a workflow. Stale internal knowledge keeps circulating.

2. Users

Primary: Internal TruffleHog enablement: AE, SDR, SA, CS, partner, manager, leadership

Secondary: Later: developers, AppSec, customer education, external learners

Job: Move from discovery to a source-grounded explanation and next step — without real secrets.

3. Evidence

Darktrace industry training cut new-rep ramp 50%. At Truffle, self-serve onboarding and a sales–product loop showed the same gap. The productized version is Truffle Camp (curriculum: The Secret Life Cycle; interactive layer: Secret Expedition; repo: secretsafari). Atlas stays a separate source of truth; Camp consumes a learner-safe export.

4. Goals and non-goals

Goals

  • Teach the secret lifecycle with synthetic missions: Discover → Classify → Verify → Prioritize → Route → Explain → Advance.
  • Role-based paths and behavior-based badges, not a speed leaderboard.
  • Keep source, freshness, uncertainty, and claim status visible.
  • Measure readiness from decisions, explanations, and handoffs.

Non-goals

  • Scanning real repos or storing/verifying real credentials.
  • Live provider verification calls.
  • Replacing TruffleHog docs or merging with the Atlas repo.
  • A full LMS in v1. No public leaderboards or unsafe timers.

5. MVP

Playable core: expedition map, Trailhead, one Dig Site mission, synthetic evidence viewer, decision feedback, local progress, one Field Badge.

Question the MVP tests: Can a synthetic investigation teach the lifecycle better than a slide path?

6. Workflow

  1. Trailhead
  2. Dig Site
  3. Verification Lab
  4. Risk Room
  5. Handoff Desk
  6. Field Brief

7. System design

Plain language

  1. Curriculum
  2. Missions
  3. Synthetic evidence
  4. Decisions + feedback
  5. Progress
  6. Atlas-powered cards (later)
  7. Campfire Q&A (later)

Technical

  1. Next.js App Router
  2. Local JSON/MDX fixtures
  3. Atlas export adapter
  4. Zod validation
  5. Local storage then Supabase
  6. No browser-side API keys

8. Data model

  • Lesson
  • Mission
  • Forager (learner)
  • Evidence inventory
  • Decision
  • Audit trail
  • Badge
  • Claim status

9. Metrics

Operational

  • Time to complete First Expedition
  • Stale-content rate

Behavioral

  • Mission completion
  • Correct reasoning vs. speed
  • Audience-specific field briefs

Business

  • Measured: 50% faster ramp at Darktrace for the enablement motion. Hypothesis: Camp reduces time-to-useful-conversation without overclaiming product coverage.

10. Business impact hypothesis

If learners practice the full loop on synthetic evidence, readiness and technical conversation quality improve. Darktrace is historical proof of enablement; Camp is the product.

11. Tradeoffs

  • Synthetic missions vs. scanning real repos.
  • Separate Atlas and Camp repos vs. one monolith.
  • Versioned Atlas exports vs. a live Atlas dependency.
  • Local fixtures so Camp stays playable if Notion is down.

12. Prototype

PRD complete. Repo: heyfunwhoa/secretsafari. Independent training product — not live verification, not customer data. Atlas integration is a curated export, not a merge.

Intended value

  • Faster ramp
  • Better product understanding
  • Stronger technical conversations
  • Improved adoption
  • Reduced dependence on tribal knowledge

13. What I would build next

  • One Dig Site mission end to end, then Verification Lab and Handoff Desk.
  • Import one curated Atlas detector record via schema.
  • Six initial missions (accidental commit through executive brief).
  • Notion export pipeline and Campfire only after local fixtures work.