Analytics
Torno’s analytics — funnels, retention, and paths — are Loop instruments, built to raise Signals and test Hypotheses rather than to be a general business-intelligence product. Every read passes the same privacy gate, and every linked Metric equals the number the semantic layer reports.
Instruments, not dashboards
Each instrument answers a question a Loop actually asks. If you want a warehouse of exploratory dashboards, excellent products exist for that; Torno is deliberately not one of them.
| Instrument | The question it answers | Built-in honesty |
|---|---|---|
| Funnels | Where do Subjects drop off between dictionary events? | Versioned definitions, truncation markers, live readouts |
| Retention | Do Cohorts come back at D1, D7, D30? | Unreached horizons show as pending, never zero; below-k cells are suppressed |
| Paths | What routes do Subjects take from an entry, or toward an exit? | Small branches collapse to other without leaking their counts |
Funnels are built from versioned, ordered dictionary events with filters and Cohort breakdowns, and they link to the Metrics, Loops, and Changes they inform. Retention definitions are versioned the same way. Path explorations can be saved and revisited.
Autocapture controls
Autocapture — pageviews and clicks — is switched per Property. Autocaptured events are marked second-class with pinned shapes, so they never silently pollute the authored event dictionary. When one earns a place, promote it to an explicit tag. Details in Event collection.
Historical imports
Imports are on-ramps: they bring your history in so the instruments are not blind on day one. Adapters exist for PostHog (export API), Segment (S3 archives), and GA4 (BigQuery), each running a checkpointed lifecycle — credential, sample, map, approve, import — with pause, resume, cancel, and owner-only rollback. Credentials are stored encrypted and write-only, and a lawful-basis assertion is required before anything moves.
Imported events keep deterministic IDs, so reruns are safe, and they attach to import-scoped Subjects that are never stitched to your first-party Subjects. Every readout labels its sources, so a mixed funnel says which steps rest on imported data. Events older than your retention window are counted, not hidden.
Privacy on every read
Every aggregate goes through the Cohort authority described in Identity and privacy: a Workspace k-anonymity minimum defaulting to 25 with a hard floor of 10, refusal without leakage below k, and masking of additional cells so small numbers cannot be recovered by subtraction. There is deliberately no agent scope for Subject-level analytics.
From a chart to a Loop
The instruments act on what they show. Every view links to the Metrics, Loops, and Changes it concerns, and a funnel drop-off step can prefill the Hypothesis composer with the evidence already attached. Readouts attach to Loops as evidence, so a later Decision can cite the exact view that motivated it. A Metric shown in a funnel equals the same Metric read anywhere else — one number, defined once in the semantic layer. See Loops in practice for how these moves fit a working Loop.
Honest notes
The three import adapters are implemented, and each source’s verification status is visible in the product. Torno does not claim live-provider proof beyond what your Workspace’s import screens show — check them before you lean on imported history for a Decision.