Use Topline
Use Topline: Product guide
Complete everyday workflows for workspaces, chat, sources, automations, artifacts, agents, memory, and administration.
Topline Product Guide
This guide explains how customers use Topline day to day. It is organized by jobs operators perform rather than by implementation package.
Product model
Topline combines conversation, data, automation, generated applications, and delegated coding work inside one tenant-scoped workspace.
The major objects are:
- Workspaces group related chats, instructions, documents, artifacts, skills, and data scope.
- Chats are the operator's working conversations with Topline.
- Sources connect external systems and expose approved resources.
- Pipelines ingest or refresh source data.
- Automations run schedules and reminders.
- Artifacts are saved outputs such as documents, reports, dashboards, and hosted artifact apps.
- Coding tasks delegate repository or artifact implementation to a bounded workforce runtime.
- Memory and glossary preserve approved preferences and company language.
- Scopes control who can view or change shared resources.
Access and permissions
Topline hides unavailable actions in the interface and enforces permission again at the API. Common capabilities include chat, sources, browser control, workforce, memory, glossary, token management, billing, and tenant administration.
If an expected feature is missing:
- confirm the operator is in the intended tenant;
- confirm the account and product profile are active;
- ask an administrator to verify the required capability; and
- refresh the application after the grant changes.
Do not share another user's link or token to work around a missing capability.
Start with a workspace
Use a workspace when work will span multiple conversations, data sources, or deliverables.
- Open Apps & Workspaces at
/projects. - Create a workspace with a name that describes the business outcome.
- Open the workspace and set durable instructions or documents.
- Use its main chat and create bounded threads for separate workstreams.
- Add only the data scope and skills required by the workspace.
- Save or move owned apps and outputs into that workspace. The library heading confirms whether the catalog shows all workspaces or one selected workspace.
Workspace instructions should contain stable guidance. Put temporary requests in chat and company-wide terminology in the glossary.
Work in chat
Chats are the main operator entry point. The root page opens the current main chat. The finder can switch between accessible chats and workspaces; a selected workspace keeps its own main chat, threads, todo list, apps, and documents.
Ask for analysis or an answer
Describe the outcome, relevant customer or business scope, time range, and required format. Topline may use approved sources, memory, glossary, artifacts, or workforce tools depending on the request and permissions.
Attach files
Attach supporting files when they are the authoritative input. Do not upload secret files, raw credential exports, or unnecessary PII. Large or reusable files should be saved in the appropriate asset or source workflow instead of repeatedly attached to chats.
Manage files in chat context
Open Thread files in the chat header. Context lists files shared with the conversation and files waiting in your draft. Outputs lists downloadable files created by Topline; outputs are not automatically added as input context.
- Draft: the file is not yet available to Topline. Send the message to make the attachment available. You can remove an unsent file from the draft.
- Included: Topline can inspect the file when needed for future responses.
- Excluded: Topline cannot freshly inspect the file in future responses. The row remains visible with an Excluded label and muted, crossed-out filename. Choose Include in context to restore access without uploading it again. The header counts included, excluded, and draft files separately.
Exclusion is a saved setting for that conversation's attachment, not a personal display filter. The change is available to authorized file managers in an open conversation; shared readers may be able to download a file without being able to change its inclusion. Wait for the saved state before sending the next message. If an update fails, use the displayed recovery action and verify the state after refreshing.
Exclusion does not delete the stored file, its original message, or earlier answers. You can still open and download it. Text already quoted, extracted, or summarized in the conversation can remain in the model's history. A reply already in progress may still use content it received before exclusion. Exclusion is not a request to erase other copies, saved knowledge, or prior model processing.
What uses tokens, and what is cached?
The Context list is an inventory of available files, not a token meter or a list of documents fully loaded into the model. Storing a file does not by itself send its full contents to the model. For each reply, Topline supplies a short list of included files with their names, types, sizes, and source IDs. That list uses input tokens. Reading a document supplies extracted content as model input; visual PDF analysis supplies selected pages to a separate analysis call. Images attached to the current message are sent as visual input. Older included images can be opened when needed.
Provider caching is separate from file inclusion. Topline requests caching for supported repeated prompt content and may resume compatible Gemini interaction history. Inclusion does not promise a cache hit, pre-cache the entire file, or make future reads free. Actual token and cache usage comes from provider reports. Changing inclusion clears Topline's saved provider continuation so future responses rebuild from the current file selection and persisted conversation. This is not deletion of a provider's retained data. Earlier discussion remains.
For example, including a 100-page PDF initially advertises the file. Reading or visually analyzing it incurs model input for the content actually supplied. Excluding it stops fresh access, but numbers already discussed can remain in the chat.
Mention a teammate, app, artifact, or schedule
Type @ in the composer and choose a visible result. Apps, artifacts, and
schedules become exact structured context references; their display name also
stays in the editable sentence. Add a short instruction before sending a
schedule or app reference so the requested action is explicit.
People appear only in a thread you own, and existing participants are omitted. Selecting a teammate is consequential: it adds that person to the thread roster and shares the thread; it is not decorative text. A participant in a thread shared to them cannot add more people. Confirm the intended person and thread before selecting.
If search fails, retry the @ query without sending a guessed name. If adding a
person fails, Topline reloads the authoritative roster and shows the failure;
verify the person still appears before continuing. For an app, artifact, or
schedule, verify the context pill is attached. Plain @Name text without the
roster or context pill does not prove the structured action succeeded.
Choose when the assistant responds in a thread
Each thread header has a Mention only (@) control. Any current thread
participant can turn it on or return the thread to automatic responses.
- In automatic mode, Topline responds to each message.
- In Mention only mode, messages without a standalone
@Toplinemention are saved and shared with the thread but do not start an assistant turn. Mention@Toplinewhen a response is wanted; the next addressed turn also receives the human context accumulated while responses were paused.
An email address or a longer word containing the same characters is not an assistant mention. If the setting change fails, verify the control still shows the intended mode before relying on it.
Save an output
Save durable work as an artifact. Give it a descriptive name, verify its scope, and review the rendered output before sharing or publishing.
Threads, attention, and todos
Use a thread for one bounded branch of a workspace conversation. Keep the thread in its owning workspace, respond to explicit attention items, and use the workspace todo list for durable follow-up. A thread or coding-task ID from another conversation does not transfer control to the current chat.
Archive and restore
Archive completed chats to reduce clutter. Archiving does not erase audit history or automatically delete attached artifacts and tasks.
Archive a whole workspace from its More menu when the complete body of work
should leave active navigation. Restore it at /projects/archived. Permanent
deletion is a separate inventory-gated workflow and remains blocked while
dependencies or active work exist.
Use the secure browser
The secure browser is an isolated AWS AgentCore browser for human sign-in and approved browser assistance. Open it from the monitor button in an eligible chat, select or create a profile, and optionally provide a starting URL.
Enter passwords, MFA, payment details, CAPTCHAs, and recovery values yourself through the secure-browser page. Never paste them into chat. See Secure Browser for profiles, controls, agent approvals, security, and errors.
Connect data sources
Open Account > Data Sources to configure and operate customer data connections. See Data Sources, Tables, and Pipelines for every data page, initial loads, reporting schemas, offices, identity, trusted calculations, and failure recovery.
If a Google Sheet already exists and a Topline task only needs direct access, do not create a source or pipeline. Use Use an existing Google Sheet to find the current reader and writer sharing identities, grant restricted least-privilege access, and revoke or troubleshoot it safely.
The normal lifecycle is:
- create or select the connection;
- store credentials through the credential workflow;
- verify identity and authorization;
- discover available resources;
- select only required resources;
- run a bounded sample or schema inspection;
- configure ingestion or refresh behavior;
- verify the first successful run; and
- monitor freshness and failures.
Source credentials are secret references. They must not appear in chat, artifact code, generated documentation, logs, or committed configuration.
Resource schemas
Review field meaning, data classification, retention, and identifiers before building reports. Do not infer business meaning from a column name when a connector reference or glossary definition is available.
Pipeline failures
Start with the latest run, error category, and last successful refresh. Retry only after addressing authentication, schema, throttling, or configuration errors. Repeated blind retries can increase provider load and obscure the original failure.
Build and operate automations
Automations contains schedules and reminders.
Schedules
Schedules run supported recurring work such as artifact refresh. Review the timezone, cadence, target, enabled state, and recent runs before saving.
Disable a schedule when investigating repeated failures. Re-enable it only after a manual or smoke run verifies recovery.
Reminders
Reminders return an operator task at the requested time. Use them for human follow-up, not for unattended production work that needs retries, idempotency, or operational monitoring.
Work with artifacts and artifact apps
Artifacts are durable outputs owned by a tenant and scope.
Use Apps & Workspaces to select a workspace scope, search, filter, and file apps or outputs. Artifact row menus open item details and symbol settings. Automated tests remain part of the build and validation workflow instead of a customer-managed artifact drawer. If something is wrong, describe it in normal chat and attach or mention the artifact; default Coding agent instructions require a regression test for a customer-reported bug before the fix and relevant suite run. Workspace owners and artifact editors can upload square PNG, JPEG, WebP, or GIF symbols up to 10 MB or restore the generated default. Use Assets for reusable tenant files and folders. See Artifacts, Assets, and Workspaces for workspace lifecycle, artifact review, draft and live access, asset operations, Storybook, and feedback.
Review an artifact
Check title, source, content, sharing, scope, versions, and acceptance evidence. For data-backed output, verify the refresh model and whether the displayed data is live, scheduled, or a bounded snapshot.
Artifact-app lifecycle
- Create or update a private draft.
- Validate the manifest and package.
- Deploy through the trusted broker.
- Run route, data, browser, and acceptance checks.
- Review draft content and logs.
- Promote through the operator UI.
- Monitor the live version and keep rollback evidence.
External MCP can create, deploy, inspect, and open private drafts within its granted scopes. Live promotion remains an operator-controlled UI action.
Build a hosted MCP server
An artifact app can be a customer-owned MCP server when its tools need to be
available in Topline chat, Cursor coding tasks, or both. Ask a Topline coding
task to start from the blessed fastmcp-server template. Topline hosts the live
Python/FastMCP runtime and manages its private machine credential; the artifact
owns only its typed tool implementation and approved server-side external API
integrations. External Build MCP can inspect and deploy an already-complete MCP
package, but its generic initializer does not scaffold this template today.
After validation and operator promotion, open the live artifact and choose Connect to Topline. This opens Developer Access > Connected tools with the artifact selected. Every discovered tool starts blocked. A workspace MCP manager reviews its read, write, or destructive risk, then chooses workflow surfaces and eligible agents. A later promotion or rollback requires another connection check before new code can run.
Hosted MCP artifacts are for on-demand tools, not ingestion, scheduled work, webhooks, or direct Topline dataset access. See Build a hosted MCP server for the supported manifest, build flow, examples, and current limits.
Sharing and publishing
Before sharing, confirm the audience, scope, data sensitivity, live refresh behavior, and expiration expectations. Public routes must never expose credentials or tenant-private data.
Use the Artifact in Topline tab for people who can view or edit an artifact inside Topline:
- Viewer grants the named person read-only access to the artifact. For an artifact app, the viewer can open the current draft, immutable version routes, and the live version, but cannot edit, publish, share, or manage schedules.
- Editor grants the named person access to drafts and versions plus write-capable artifact controls. Sharing, workspace visibility, and deletion remain owner-controlled.
Workspace sharing works like sharing a folder. Viewer lets a teammate view the contained artifacts, drafts, and versions. Editor also lets them create and edit artifacts and change workspace names, descriptions, and symbols. New shares and existing legacy workspace shares default to Viewer. Everyone in your company can optionally receive Viewer access; workspaces have no anonymous public link.
Artifact access inherits workspace access. Direct artifact grants apply only to that artifact; they do not reveal siblings or workspace contents. The strongest applicable role wins: direct Viewer does not reduce inherited Editor. Removing a direct grant leaves workspace or scope access in place. Workspace ownership grants editing of contained artifacts, while each artifact's owner retains sharing, relocation, and deletion controls. Workspace sharing does not share private conversations. Access changes send no notification email.
Members of a co-authored scope have the same draft and version access while their scope membership remains active.
Use Live app authentication for the live app's sign-in and audience. Other artifact types use Published artifact access. A restricted or public viewer link opens only the live version; it does not grant workspace access and never exposes a draft or an immutable version route. To review work in progress inside Topline, add the collaborator as a named Viewer instead of adding the address only to a published-link audience.
For published artifact apps, account admins can connect multiple company-owned subdomains in Account > Domains and choose the workspace default. The artifact owner then chooses any connected domain and a unique path in the Share drawer's Web address settings. Customer-facing addresses stay clean, while protected sign-in continues through Topline's identity domain. Existing routes do not move when the default changes. See Company domains for artifact apps for DNS states, audience behavior, route changes, and safe removal.
In App address settings, enter only the path segment, such as
sales.v2. A full URL is rejected before saving. Once Topline has provisioned
and verified wildcard DNS and TLS for your account host, you can also choose a
one-label prefix such as stack. The live app then has an address such as
https://stack.hawx.topline.build/sales.v2/. The prefix applies to that app;
its path stays the same. If hosted prefixes are unavailable, an account admin
can connect a company-owned domain in Account > Domains instead.
Artifact-level company and view-only scope visibility provide broader discovery access. For artifact apps, these policies open only the live route when the deployed app's viewer policy permits company viewing. Workspace company access and workspace scope access instead grant Viewer access to contained artifacts inside Topline, including drafts. Explicit workspace Editor grants allow editing.
Delegate coding work
Use a coding task for repository changes, hosted applications, substantial UI work, or implementation that requires checks and source edits.
Provide:
- goal and target user;
- acceptance criteria;
- constraints and non-goals;
- relevant data or integration context;
- expected validation; and
- whether deployment or promotion is explicitly authorized.
The task-scoped workforce bridge lets the coding agent read instructions, use approved platform tools, ask for operator input, report progress, and return validation evidence. It does not grant general production or database access.
Review changed files, checks, remaining risks, and deployment requirements before accepting the result.
Manage memory, preferences, and glossary
Use preferences for explicit guidance about how Topline should respond or operate for an authorized user. Use the glossary for company terms, abbreviations, and definitions that should be resolved consistently.
Prefer a concise, testable statement. Do not store passwords, tokens, customer rows, or transient task instructions in memory or glossary entries.
When a proposed memory conflicts with an existing entry, resolve the conflict instead of silently creating competing rules.
Capture conversation memory from Slack or Google Chat
An administrator can connect Slack or Google Chat from Account > Chat Integrations. Slack supports permission-scoped capture after Topline is added to a supported channel. The current Google Chat Marketplace app supports linked direct messages by default; shared spaces are available only through exact platform enrollment in the disabled-by-default pilot. Its card retains the separate domain-enable, Marketplace install, Chat-only member, and direct-message verification steps so a saved domain is not mistaken for a completed installation. Topline does not scan the whole provider workspace or read person-to-person conversations where the app is absent.
Google Chat's /help, Help quick command, plain help, and @Topline help return setup and usage guidance even before a Workspace is connected. Real questions still require an enabled domain and an active Topline member; the Chat-only member profile grants external-chat access without the web workspace or builder.
Send plain check connection or my access for a metadata-only readiness check. When Google Chat displays the native /access or Check connection command, it performs the same check. When Ask Topline about this appears in a message's three-dot menu, it explains the selected message using the caller's authorized context. Selected message text is untrusted quoted material and that action is restricted to read-only tools, so an imperative inside the message cannot authorize a change. Do not claim a native command is installed unless it is visible in the current Google Chat command menu.
See Slack and Google Chat Memory for provider setup, intake timing, exact memory-control phrases, historical import, visibility, and recovery.
Developer Access and MCP
Open Account > Assistant > Developer Access. Choose Connect an AI assistant for ChatGPT, Codex, or Claude Code setup, Connected tools to manage MCP servers used by Topline, or Developer credentials for Bedrock local access and manual tokens. Back returns to the menu and preserves unfinished work while the drawer stays open.
Personal Connect Drive and Calendar and Fingerprint verification are under Account > Personal > Profile > Connections and security. Passkey setup remains in Profile's Passkeys section. Personal Google authorization does not install the Marketplace app or enable a Workspace domain.
This area also manages MCP servers used by Topline workflows. To create a hosted-artifact connection, choose Connect to Topline on the promoted live artifact; Developer Access then opens with that artifact selected for tool review and separate chat and coding enablement. See Build a hosted MCP server.
Choose the product that matches the job:
- Topline Build MCP supports artifact apps, deployment status, offline package inspection, logs, Storybook access, and handoff links.
- Topline Workspace MCP provides documentation, workspace discovery, accessible conversations, approved preferences, permission-filtered context, glossary terms, and reviewed company knowledge.
Install both when the assistant needs both capabilities. Each product has an independent setup snippet and OAuth audience; the legacy combined Harness MCP is retained only for existing integrations.
In Connect an AI assistant, choose your client and expand the product. For ChatGPT or Claude Code, View setup message lets you review the text. Send setup to ChatGPT sends that message to ChatGPT; Open in Claude Code opens a prefilled prompt. Copy message is available as a fallback. Codex shows configuration instructions. ChatGPT Build access covers hosted tools; use Claude Code or Codex for local application folders.
Complete browser sign-in and approve the needed OAuth scopes. Then choose Verify connection, run the one-time check in the same client, and check the result in Topline. Opening or copying setup does not verify the connection. Access and activity shows OAuth permissions and the last successful call; Check connection refreshes that Topline-side status.
The recommended path is OAuth with PKCE. Manual connector tokens are a fallback for environments that cannot complete OAuth. Grant the narrowest scopes, choose a bounded lifetime, store the token in a secret manager, and revoke it when no longer needed.
Use the documentation tools before guessing tool behavior:
platform_search_documentationsearches product and API documentation.platform_read_documentationreads a complete result.
See External API Guide, MCP Server Reference, and the generated MCP tool reference for integration details.
Tenant administration
The Account rail uses the visible groups Personal, Workspace, Organization, and Activity. Within them, capability-filtered sections include Profile, Assistant, Data Sources, Billing, Resources, Members, Credentials, Brand, Audit Log, Task Monitor, and App Builder Health. Administrators manage members, capacity requests, access rules, credentials, brand, audit history, billing, sources, skills, coding agents, Storybook, and product settings. See Pages and Workflows for the canonical route and primary task on every page.
Office and audit recovery
In Offices, a loading or failed request does not mean the office list is empty. Use Try again after a load failure. Address lookup remains a separate action inside the editable office spreadsheet.
Audit Log distinguishes an empty audit trail from filters or search hiding results. Reset filters or clear event search only when that restriction is active. A load failure offers Retry.
Members and scopes
Grant access through roles, capabilities, product profiles, and resource scope. Remove access promptly when responsibilities change. Verify both the identity record and resource memberships during offboarding.
Credentials
Create named secret references with a clear owner and purpose. Rotate through the supported workflow, verify consumers, promote the new version, and revoke the old value. Topline should display metadata and health, never the stored secret value after creation.
Audit investigation
Search by actor, action, resource, outcome, and time range. Start narrow, then expand. Preserve relevant IDs and timestamps without copying sensitive payloads into tickets or chat.
Billing and usage
Use current-period usage for operational monitoring and exports for analysis. Provider billing delays and attribution rules can make very recent totals provisional.
When costs are incomplete, Billing shows known amounts with a Costs updating status. Topline handles technical reconciliation issues in its Admin tools; the customer page, printed bill and CSV do not ask customers to resolve those issues. Availability requires the web/API release.
The billing-period picker uses compact month labels such as Sep 2026. Billing controls and Resources capacity details wrap on narrow screens with enlarged text. Availability requires the web release. The monthly cost chart can scroll horizontally within its card when its labels need more space. Focus the chart and use the arrow keys, or open View monthly amounts for the complete values in a table.
Open Usage from the account menu or Billing to review your attributed feature usage and daily coding limits. Authorized administrators can also review the organization and assign tiers with daily allowances or an unlimited user allowance within the organization spending cap. Members see quantities and allowances, with detailed dollar spending kept in authorized billing views. Daily coding limits reset at 00:00 UTC while the monthly organization spending cap remains in effect. See Usage metering by user and customer for supported measurements, privacy, reset behavior, recovery and billing boundaries.
Troubleshooting sequence
For most product problems:
- capture the visible error and the action that produced it;
- confirm tenant, user, capability, and resource scope;
- check whether the feature backend is configured;
- inspect the most specific status, run, or audit record;
- retry only when the error is retryable or its cause is fixed; and
- escalate with IDs, timestamps, environment, and bounded redacted evidence.
Do not include passwords, tokens, cookies, typed browser values, raw PII, or unredacted provider payloads in support evidence.