Skip to content
Academy
Marketing Academy · Field Work●Growth Marketing
MiniAudit· 30 minutes

Friction Audit: Auditing TAC Security's Trial Signup Flow

TAC Security (TAC Infosec)

Objective: Given a real 8-step free-trial signup-and-setup funnel with per-step drop-off percentages, correctly identify which steps sit before the activation event (a completed vulnerability scan) and calculate how many signups are lost to non-value fields.

You're the growth analyst at TAC Security (TAC Infosec), a vulnerability-and-risk-management SaaS platform, reviewing why free-trial signups aren't reaching their first completed scan.

Apply the lesson's Step 1 (define one activation event) and Step 3 (defer everything that is not value) to a supplied step-by-step funnel with drop-off data, then flag every pre-activation step as a friction cost.

Before you start

What you'll need

Free path (everything below is enough to finish)

FreeImport the funnel export, flag steps, compute drop-off

No account friction, handles an 8-row funnel easily

Paid upgrades (optional, faster/deeper)

Amplitude(optional)
FreemiumInstrument the real funnel with actual timestamped events instead of a static export

Turns this one-time audit into the weekly funnel review the lesson's Step 6 calls for

The process

1 step

Step 01 of 01

Defer everything that is not value

The lesson's Step 3 says every field required before the aha moment costs roughly 10% of remaining signups, and the fix is deferring billing, profile setup, and tours until after activation.

Given TAC Security's 8-step funnel below, which steps happen before the activation event (first completed vulnerability scan), and what percentage of signups are lost to those pre-activation steps combined?

Google Sheets— Import the 8-row funnel export, add a column flagging each step pre- or post-activation.

Procedure

  1. Import the funnel: signup(1,000) -> email verify(870) -> company profile(690) -> team size dropdown(610) -> integration picker(540) -> asset upload(430) -> first scan configured(410) -> first scan completed(365)
  2. Mark 'first scan completed' as the single activation event per the lesson's Step 1 rule
  3. Flag every step before it (verify, profile, team size, integration picker, asset upload, scan configured) as pre-activation
  4. Sum the drop from signup (1,000) to the first post-activation-adjacent step (asset upload, 430) to quantify pre-activation loss
  5. Separate the two required-but-not-value fields (company profile, team size dropdown) from the two setup fields the product genuinely needs (integration picker, asset upload) before a scan can run
Sample output
TAC Security trial funnel (n=1,000)
signup 1,000 -> verify 870 (-13.0%) -> profile 690 (-20.7%) -> team size 610 (-11.6%) -> integration 540 (-11.5%) -> asset upload 430 (-20.4%) -> scan configured 410 (-4.7%) -> SCAN COMPLETE 365 (-11.0%)

Pre-activation loss: 1,000 -> 365 = 63.5% never reach activation
Removable-now fields (not required to run a scan): company profile, team size dropdown -> combined loss 300 signups (30% of the starting cohort)

Healthy

Every step before the activation event is either strictly required to configure the scan, or removed.

Unhealthy

Company profile and team size dropdown sit between signup and the first scan with no technical reason to gate the scan behind them.

What this means

63.5% of signups never complete a scan, and two of the six pre-activation steps (profile, team size) don't need to exist before that scan runs at all, they're collected value the product wants, not value the user came for.

So what do I do about it?

SymptomActionEffort
Company profile and team size dropdown sit before the first scanMove both fields to a post-scan settings promptdev ticket
63.5% pre-activation drop with no per-step ownershipAssign a single owner to instrument and review this funnel weekly per Step 630 min
EitherYou or a developer can handle this, depending on your access.

Final deliverable

A funnel table with every step flagged pre- or post-activation, plus a ranked list of which pre-activation fields to remove or defer first.

See a reference example
Sample output
Yatra Online, trial signup teardown (excerpt)

Activation event: first completed itinerary saved
Pre-activation steps: 5 of 7
Removable now: travel-preference survey (no scan/save dependency) -> 18% of remaining signups lost here alone
Recommendation: move preference survey to post-first-save, matches Step 3's defer principle

Success criteria

You're done when you can:

  • Correctly identifies 'first scan completed' as the single activation event, not scan configured or asset upload
  • Correctly separates the two non-essential pre-activation fields from the two functionally required ones
  • Computes the 63.5% pre-activation loss figure from the supplied numbers