Enable · Designed
Truffle Camp
Secrets education is fragmented across docs, detector references, sales enablement, and tribal knowledge.
Career signal: Product Adoption, Technical Enablement, Product GTM
All projects1. Problem
Secrets education is fragmented across docs, detector references, sales enablement, and tribal knowledge.
Learners confuse detection with verification, severity, ownership, and remediation — and cannot practice a responsible handoff.
Without this: Ramp depends on ride-alongs. Terminology is memorized without a workflow. Stale internal knowledge keeps circulating.
2. Users
Primary: Internal TruffleHog enablement: AE, SDR, SA, CS, partner, manager, leadership
Secondary: Later: developers, AppSec, customer education, external learners
Job: Move from discovery to a source-grounded explanation and next step — without real secrets.
3. Evidence
Darktrace industry training cut new-rep ramp 50%. At Truffle, self-serve onboarding and a sales–product loop showed the same gap. The productized version is Truffle Camp (curriculum: The Secret Life Cycle; interactive layer: Secret Expedition; repo: secretsafari). Atlas stays a separate source of truth; Camp consumes a learner-safe export.
4. Goals and non-goals
Goals
- Teach the secret lifecycle with synthetic missions: Discover → Classify → Verify → Prioritize → Route → Explain → Advance.
- Role-based paths and behavior-based badges, not a speed leaderboard.
- Keep source, freshness, uncertainty, and claim status visible.
- Measure readiness from decisions, explanations, and handoffs.
Non-goals
- Scanning real repos or storing/verifying real credentials.
- Live provider verification calls.
- Replacing TruffleHog docs or merging with the Atlas repo.
- A full LMS in v1. No public leaderboards or unsafe timers.
5. MVP
Playable core: expedition map, Trailhead, one Dig Site mission, synthetic evidence viewer, decision feedback, local progress, one Field Badge.
Question the MVP tests: Can a synthetic investigation teach the lifecycle better than a slide path?
6. Workflow
- Trailhead
- Dig Site
- Verification Lab
- Risk Room
- Handoff Desk
- Field Brief
7. System design
Plain language
- Curriculum
- Missions
- Synthetic evidence
- Decisions + feedback
- Progress
- Atlas-powered cards (later)
- Campfire Q&A (later)
Technical
- Next.js App Router
- Local JSON/MDX fixtures
- Atlas export adapter
- Zod validation
- Local storage then Supabase
- No browser-side API keys
8. Data model
- Lesson
- Mission
- Forager (learner)
- Evidence inventory
- Decision
- Audit trail
- Badge
- Claim status
9. Metrics
Operational
- Time to complete First Expedition
- Stale-content rate
Behavioral
- Mission completion
- Correct reasoning vs. speed
- Audience-specific field briefs
Business
- Measured: 50% faster ramp at Darktrace for the enablement motion. Hypothesis: Camp reduces time-to-useful-conversation without overclaiming product coverage.
10. Business impact hypothesis
If learners practice the full loop on synthetic evidence, readiness and technical conversation quality improve. Darktrace is historical proof of enablement; Camp is the product.
11. Tradeoffs
- Synthetic missions vs. scanning real repos.
- Separate Atlas and Camp repos vs. one monolith.
- Versioned Atlas exports vs. a live Atlas dependency.
- Local fixtures so Camp stays playable if Notion is down.
12. Prototype
PRD complete. Repo: heyfunwhoa/secretsafari. Independent training product — not live verification, not customer data. Atlas integration is a curated export, not a merge.
Intended value
- Faster ramp
- Better product understanding
- Stronger technical conversations
- Improved adoption
- Reduced dependence on tribal knowledge
13. What I would build next
- One Dig Site mission end to end, then Verification Lab and Handoff Desk.
- Import one curated Atlas detector record via schema.
- Six initial missions (accidental commit through executive brief).
- Notion export pipeline and Campfire only after local fixtures work.