User Guide
This is a task-oriented walkthrough of tripl, written for product managers and analysts. It follows the same four-step shape the product is built around — Plan → Observe → Govern → Connect — and takes you from an empty screen to a working, tuned alert.
It assumes the app is already running and reachable in your browser — if it isn't yet, the Quick Start gets you from zero to a running instance and a first working alert. If a term here is unfamiliar, the Concepts page explains every idea in plain language; this guide focuses on doing rather than defining.
The How-to guides cover the common jobs one page at a time, with a screenshot of every screen: connecting a warehouse, setting up an alert, investigating a signal, inviting the team.
The four steps build on each other:
| Step | What you do there |
|---|---|
| Plan | Describe the events, fields, and value lists your product should send. |
| Observe | Watch the real numbers your warehouse reports and catch anomalies. |
| Govern | Keep the plan honest against reality, and control who can change what. |
| Connect | Point tripl at the warehouse it reads from. |
Inside a project, the left sidebar groups your work into three areas — Plan,
Observe, and Govern. Connect is the odd one out: wiring up a
warehouse is done once in workspace settings rather than per project, so it
isn't a sidebar group. You will usually set things up in the order Connect →
Plan → Observe → Govern, but explore them in any order. Press ⌘K (or
Ctrl-K) anywhere to search or jump. The palette's Actions group also
starts common tasks: New event, New metric, New branch, switching branch,
Invite member (owners) and the theme toggle.
Before you start
-
Open the app and create the first account on the sign-in screen. The first person to register becomes the owner of the organization (and the instance's platform admin); everyone who registers after that joins as a member, who sees the projects they create or are added to.
Forgot your password?The sign-in screen has a Forgot your password? link. When the instance has email configured (see Email delivery / the SMTP settings), it emails a single-use reset link that expires in one hour; open it to choose a new password. If email is not configured, the same screen tells you to contact an owner, who can reset it for you. To avoid leaking who has an account, the request always shows the same confirmation regardless of whether the address is registered.
-
After signing in you land on your projects. If you already have exactly one project, tripl takes you straight into it; otherwise you see the workspace dashboard.
Everything you see belongs to an organization, and the address says which: the workspace is
/o/{org}and a project page is/o/{org}/p/{project}/…(for example/o/default/p/web/events). Older links of the form/p/{project}/…still work and open the same page in the organization that holds the project. If you belong to more than one organization, the switcher above the project switcher in the sidebar moves you between them; each has its own projects, data sources, API keys and members. Its settings are under Settings → Organization (see the Administration guide). -
From the dashboard you have two ways forward:
- Generate demo project — a complete synthetic project to explore.
- New project — an empty project for your real work.
For your first ten minutes, generate the demo project. It is fully populated and needs no warehouse, so you can learn the product before wiring up any data.
A project is one tracking plan and everything around it — its own events, scans, metrics, and alert rules. Each project also has its own members: only they (and the organization's owners and admins) can see it, and whoever creates a project is an editor member of it. Add people in Settings → Project → Access, as an editor or a viewer of that project. Organization roles (owner, admin, member) and data-source connections are workspace-wide, although API keys can be bound to one project. A company with an iOS app, an Android app, and a website that share analytics is usually one project; two unrelated products are two projects.
Tour the demo project
Generate the demo project and open it. You now have a realistic catalog with events, collected metrics, detector-produced anomalies, and schema/distribution drift — all backed by a local synthetic warehouse, and kept fresh over time.

The demo's data lives in a local synthetic warehouse — a bounded, in-memory dataset that never leaves the server and is never a real connection. But the product is not faked around it: real scans, metric collection, anomaly detection, reconciliation, and a continuous runtime clock all run over that synthetic source. Alert deliveries are recorded to a local simulated sink — nothing is ever sent to Slack, Telegram, email, a webhook, Jira, Linear, PagerDuty, or Microsoft Teams. Delete or reset it whenever you like; it never touches your real projects.
See The demo workspace for exactly what is synthetic, what is really executed, and what is intentionally unavailable.
Start with the coached chapters. The welcome panel's Start: Run the live loop opens the first of them, and Browse chapters lists them all — short hands-on lessons, one per product area: run the live loop (scan → metric → chart), edit an event, properties & value drift, review a branch, reconcile the plan, route an alert, and a closing explore chapter. A strip under the demo banner tracks which chapter and step you are on and links to the next action, and a callout rings the button that performs it. Chapters advance on your actions only: the demo's background clock is running scans and collections of its own, and those never tick a chapter forward. Dismiss or restart any chapter whenever you like. (Prefer to read first? Take the tour walks the same surfaces without asking you to do anything.)
Then a good order to look around:
- Plan → Events — browse the catalog. Open an event to see its fields, values, tags, status, and recent change history.
- Observe → Overview — the health of the whole project at a glance.
- Observe → Alerting → Rules — see which alert rules are firing and where they route. Then open an event that is showing a signal and study its monitoring detail: the volume chart, the forecast, the heatmap, and the breakdown of what moved.
- Govern → Reconciliation — see what is documented-but-dead and live-but-undocumented.
Once that makes sense, the sections below show how to build the same thing from your own data.
Connect: point tripl at your warehouse
Skip this section entirely if you are only exploring the demo project.
tripl never stores your raw analytics events. It connects to a warehouse you already run, reads from it on a schedule, and keeps only the aggregated counts it needs.