We built Second Ring because a degrees-of-separation graphic was interesting but not yet useful. The product now accepts a person’s own LinkedIn, Facebook, and Google Contacts exports, separates direct contacts from consented second-degree paths, records the evidence behind each edge, and turns the map into a concrete next action.
This is a build-in-public record of the actual work: the original request, a relationship we classified incorrectly, the data-access constraints, what the prototype can do today, the privacy choices, the tests, and what remains unfinished. That follows Dennis Yu’s building-in-public operating principle: do the work, document it, turn the documentation into a checklist, and let the checklist become software. We publish our process and mistakes. We do not publish information that belongs to somebody else.
The request that started Second Ring
Dennis asked whether we could recreate a degrees-of-separation chart for George Paladichuk, Marko Sipilä, and other people in the Local Service Spotlight network. The useful version would show direct relationships, weaker ties, connections-of-connections, and the best person to ask for an introduction.
That framing connects to a pattern we already teach: one real podcast relationship can open many credible doors. But a static illustration does not tell you whether the relationship is direct, current, reciprocal, or merely a public co-appearance. Second Ring had to show what each line actually means.
The first map was wrong about Dan Antonelli
The first prototype put Dan Antonelli behind a second-degree hop. Dennis corrected it immediately: Dan is a direct contact. Owner-authorized metadata supported that correction, so the graph now follows a strict rule:
If someone is already direct, never manufacture a second-degree introduction path.
The same metadata audit verified current direct relationships with George Paladichuk, Marko Sipilä, and Dan Leibrandt, plus a direct but dormant relationship with Lance Bachmann. The product keeps these states separate. “Direct” answers whether the edge exists. Recency, reciprocity, thread breadth, and repeated calendar participation help answer how strong or active it is.
We used participant and attendee metadata only for this owner-authorized example. We did not publish email addresses, message subjects, message bodies, raw calendar descriptions, or private contact rows. That boundary matches our published policy on why private conversations are not automatically public content.
What a user does
- Choose a source. Start with LinkedIn, Facebook, Google Contacts, or a reviewed relationship CSV.
- Request your own export. Use the platform’s official download process. Second Ring never asks for a social password.
- Upload the untouched ZIP or CSV. The file is parsed in the browser. Users do not need to unzip or reformat it.
- Review the normalized records. The importer merges clear duplicates and flags weaker identity keys for review.
- Confirm the first ring. A platform connection proves first-degree membership; it does not automatically prove a strong relationship.
- Choose whether to save. The raw archive is not retained. A signed-in user can save normalized graph records in a private workspace.
- Invite one direct contact. If that person signs in, reviews the policy, explicitly consents, and contributes their own export, their unique contacts become a genuine second ring.
- Take the shortest honest action. Contact a direct person directly. For a second-ring target, ask the strongest supported bridge for permission to make an introduction.
The product now includes a dedicated How Second Ring Works guide with exact LinkedIn, Facebook, and Google Contacts export instructions, the six-step workflow, evidence rules, privacy controls, and common questions.
Why we do not scrape LinkedIn or Facebook
The attractive shortcut is not a dependable product foundation. LinkedIn’s supported Connections API is restricted and does not provide connections-of-connections. Meta’s supported friends endpoint returns only friends who also use and authorize the same application. Automated scraping also creates policy, security, reliability, and consent problems.
Second Ring therefore starts with portable data the account owner requests and chooses to upload. The product currently parses:
- LinkedIn’s Connections CSV, including a CSV found inside the larger ZIP archive;
- Facebook JSON exports, using semantic discovery because Meta does not promise one stable friends-file shape;
- Google Contacts CSV;
- a six-column relationship CSV for reviewed CRM, community, podcast, or manual evidence.
We also normalize diacritics and explicit aliases. That matters because Marko Sipilä initially failed an exact-name check when one source represented his name without accents. Common names such as Tim Brown remain unresolved until identity evidence is strong enough.
How the evidence model works
A line in the graph carries provenance instead of pretending all edges are equal:
- Confirmed direct: reviewed by the owner or directly asserted by an involved person.
- Documented direct: supported by an authorized export or attributable interaction record.
- Contributed: supplied by a signed-in direct contact under recorded, revocable consent.
- Public context: a podcast, event, team page, or affiliation that can suggest relevance but does not prove familiarity.
- Unresolved: a possible identity or relationship that still needs human review.
The tool ranks directness first, then goal relevance, recency, relationship evidence, bridge value, and confidence. A celebrity with a weak inferred overlap should not outrank a trusted colleague who has a current, reciprocal relationship with the target.
What changed between the concept and this release
- Dan Antonelli moved from a second-degree example to Dennis’s direct ring.
- The importer became real: LinkedIn CSV/ZIP, Facebook JSON/ZIP, Google Contacts CSV, and relationship CSV.
- We added a dedicated How It Works page instead of burying instructions inside a modal.
- We added signed-in, owner-isolated workspaces backed by relational storage.
- Sensitive email, profile URL, and provider identifiers are encrypted with AES-GCM before storage; deterministic private lookup keys use keyed HMAC.
- Raw archives are never retained. The database enforces that rule.
- Contributor links use opaque, hashed, expiring tokens kept in the URL fragment to reduce accidental leakage.
- Contributors must explicitly check a consent statement before uploading and can revoke their snapshot later.
- Workspace owners can permanently delete the workspace and dependent graph records.
This extends the kind of evidence inventory we previously documented in Marko Sipilä’s authority audit. That project mapped publicly checkable authority signals. Second Ring adds owner-authorized private membership, consented contributions, and an interactive graph without confusing public context with a personal relationship.
How we tested it
Fixture tests cover LinkedIn’s preamble rows, direct CSV import, ZIP discovery, duplicate merging, nested Facebook JSON values, relationship paths, and the rule that direct membership takes precedence over a second-degree path. The release also passes the application’s lint, production build, database migration generation, schema checks, and source-diff validation.
Testing is not the same as claiming the product knows every relationship. It means the software handles the formats and rules we documented. Every imported graph still needs a human identity-review step because platform exports are incomplete and names are ambiguous.
August 13 update: from prototype to an engineering project
Dennis asked us to separate product development from the marketing work without separating the truth. We now run Second Ring as three explicit workstreams:
- Product code: importer, identity resolution, private graph, consent, ranking, and security.
- Figurehead data: one typed registry for canonical names, first-party profiles, Spotlight relevance, public evidence, and reusable map views.
- Build-in-public marketing: this living article, the public examples, and the explanation of what changed and why.
The repository now has a product README, architecture, security, product, free-scan, metrics, release, and Spotlight-integration documents; GitLab CI definitions; privacy-aware issue templates; production route tests; and migration-drift checks. The engineering source is stored in the confirmed BlitzMetrics Second Ring GitLab project.
We rewrote the homepage around the business outcome
The earlier homepage explained what the graph was before making the value obvious. The revised promise is direct: your best opportunity is already one relationship away. Second Ring is for founder-led businesses, podcast hosts and speakers, and personal-brand teams that grow through customers, guests, partners, and hires reached through trust.
The first-use sequence is now equally clear: export your data, drop the file unchanged, choose a goal, and see the strongest honest path. The product still states the non-negotiables beside that promise: no social passwords, no scraping, and private by default.
The Spotlight layer is public; the relationship layer stays private
We added a Spotlight Network hub, a public example directory, reusable figurehead pages, and compact no-index embed views for Spotlight sites. Those public views show only sources anyone can inspect: official team pages, first-party biographies, published interviews, event records, and documented collaborations.
The private workspace is different. That is where account-owner exports, reviewed identities, interaction evidence, and consented contributions can rank an actionable path. A Spotlight embed cannot query a private workspace and cannot accept a workspace ID, contact ID, invitation token, or email in its URL.
The first inventory normalizes the people Dennis named: Nathaniel Stevens, Tommy Mello, Dan Leibrandt, Marko Sipilä, Ethan Van De Hey, George Paladichuk, Dennis Yu, Dylan Haugen, and Cam Hazzard. Each public map keeps a complete evidence ledger. Tommy’s example is intentionally labeled shared event context rather than a current direct relationship. Ethan’s current role is sourced to the latest first-party ecosystem profile instead of silently relying on older copy.
We also inventoried first-party portrait candidates but did not reuse them. A photo appearing on someone’s own site helps confirm identity; it does not automatically grant permission to copy, crop, cache, or hotlink it. Public nodes render initials until the image owner or site approves reuse. Image permission and relationship consent are tracked as separate rights.
This makes Second Ring a reusable part of the Spotlight Network without turning the network into a public address book. We observed all 13 canonical Spotlight root domains returning HTTPS 200 on August 13, 2026. That proves the front doors were reachable on that date; it does not prove that every figurehead embed has already propagated to every vertical.
How one relationship compounds across a personal brand
The product now makes the propagation loop visible: a real relationship produces an interview or collaboration; the collaboration becomes a podcast or article; the Content Factory turns it into clips and posts; the person and company entity homes connect the people and brands; the relevant Spotlight site adds sourced public context; and that clearer authority creates the next relevant opportunity.
The critical rule is that each public step needs its own source and approval. A private edge does not become public just because the software can see it. A public co-appearance does not become a warm introduction just because the graph can draw a line.
August 13 release update: the free scan is real
Second Ring now has a dedicated free network scan. A visitor chooses an official LinkedIn, Facebook, Google Contacts, or reviewed relationship export; the browser normalizes it; and the result becomes an explainable review queue for customers, partners, podcasts and speaking, or hiring. Direct contacts and introduction paths are deliberately separate. If the target is direct, the product recommends direct outreach instead of drawing an unnecessary hop.
The free result stays on the device. A one-time, 24-hour browser handoff can carry only the normalized snapshot through Sign in with ChatGPT; it is not placed in analytics or a normal server URL. Paid plans are enforced by the server: Athlete Spotlight is the one $30/month exception with one workspace and three active contributor invitations; Spotlight is $99/month with five workspaces and 25 active invitations. We do not infer an athlete plan from somebody’s age. A new scan creates a new workspace while capacity remains; at the limit, the owner must choose and confirm the exact workspace before anything is updated.
Archive handling now fails closed at 25 MiB compressed, 100 MiB expanded, 5,000 entries, 20 MiB per CSV or JSON entry, a 50:1 expansion ratio, 50,000 contacts, 100,000 relationships, and 40 JSON levels. Those are conservative product limits based on OWASP file-upload guidance, not a claim that one universal industry number exists.
We also added privacy-safe operational measurement for scan completion, first actionable result, sign-in handoff, recommendation usefulness, contributor acceptance, checkout, and plan activation. General product events reject filenames, contact fields, target-search text, graph edges, evidence text, and invitation tokens. The operator view returns aggregate counts only.
Identity and evidence now fail closed. Name-only records from different imports or contributors remain separate until a human resolves them, profile links accept only HTTP or HTTPS, and labels such as “unverified” or “not confirmed” cannot be scored as verified evidence. Revoking a contribution is also checked atomically so an in-flight import cannot reappear after revocation.
The exact engineering source is now in merge request at commit fce8cdfa0de8aff183b039f25cb120b7f052a1f5, and Sites version 9 is the immutable deployment receipt. GitLab’s first pipeline failure was an infrastructure failure, not a code failure: the jobs queued without a runner, produced no trace, timed out, and skipped the test stage. We opened a runner-repair issue and independently ran the same lint, type, schema, build, migration, and test commands.
We are keeping checkout fail-closed while the Keap custom-field mapping and signed activation relay receive a real test transaction. Showing a price is not permission to take money before automatic entitlement activation is proven. The free scan and signed-in pilot can launch while that final billing receipt remains visible as an operational gate.
August 13 trust pass: prove the value before asking for the file
The free scan now starts with LinkedIn because that is the export most professionals are likely to have. Before the file chooser, it shows an illustrative network result, the kind of recommendation the owner will receive, public examples, and a plain-language privacy boundary. The example is labeled as illustrative; we did not invent testimonials or imply that a public co-appearance proves a private relationship.
The scary part is stated precisely: the visitor chooses a ZIP, CSV, or JSON file in the browser; the raw archive is parsed locally and is not sent to the Second Ring API. Only after review and an explicit paid save or consented contribution do normalized records leave the browser. We do not ask for a LinkedIn or Facebook password, and we do not scrape either platform.
LinkedIn says a larger archive can take up to 24 hours. That is now a supported product state instead of a dead end. The owner can mark the request as pending, download a private calendar reminder without giving us an email address, return to a visible “continue” banner, dismiss a stale request, or scan Google Contacts while waiting. The product measures these steps only as coarse aggregate funnel events; it does not record filenames, contacts, graph edges, target text, or invitation tokens.
The result screen now comes before pricing, the recommendation text and rating controls are readable on a phone, saved-network links have a real destination, and the mobile graph opens centered without changing the geometry between people and their connecting lines. The current release passed the production build, 47 automated tests, type checking, linting, migration drift, and a production dependency audit with zero known vulnerabilities.
We also wrote an Operations field-pilot checklist for five owner-authorized participants before the August 25 Big Dunk Contest. Operations will capture clean desktop and mobile steps, get separate permission for screenshots, quotes, and named case studies, and measure a real outcome—an introduction, meeting, podcast booking, partner conversation, hire, or useful reconnection. A completed import by itself is not ROI.
The user-supplied LinkedIn screenshot was useful QA evidence but was not published: it included browser chrome, extensions, an account avatar, a debugging banner, and an exact request time. That is the point of building in public with boundaries—we can show the work without turning private operational context into marketing collateral.
Engineering receipt: GitLab source at commit 311ee8716abf0d23147667f2e61aba09d3ee8e2f; Sites version 10. Checkout remains fail-closed until the Keap custom-field mapping and signed activation relay pass a real test purchase.
What is still incomplete
This is an early public release, not a promise that the whole social graph is available through an API. The next work is operational:
- make contact-level corrections durable instead of reapplying them after each new import;
- add a full invitation dashboard with resend, expiry, and owner-side revocation controls;
- add opt-in Gmail and Calendar enrichment without storing bodies or subjects;
- add goal-specific recommendations and introduction-request drafts;
- test larger real exports across more LinkedIn and Facebook archive variants;
- add a redacted owner-approved sharing view that never exposes private identity keys;
- restore an active GitLab Runner and rerun the full merge-request pipeline;
- propagate each figurehead embed one Spotlight vertical at a time with a read-back check.
We are documenting those gaps because that is the point of building in public. A polished screenshot hides the decisions. A useful meta-article tells the next builder what the software does, why it does it, where it failed, and what to fix next.
Try Second Ring or follow the build
Open Second Ring and build your private network map. Start with a LinkedIn export if you have one. The public product explains every step, while saving and contributor actions require an authorized account.
You can also browse our public tools, see the broader Local Service Spotlight professional network, or follow the artifacts in our public asset tracker.
Published August 12, 2026; updated August 13, 2026. This is a living build log. We will update the same URL as the product changes rather than publishing competing versions of the same story.
