The WestNet Operator Series
Systems for high-volume scaling and inventory syncing
without Amazon, eBay, or Shopify dependence
This is a working document, not a narrative. It is structured as a four-phase infrastructure audit, conducted over ninety days against your own operation: dependency analysis, master-record design, channel fan-out, and automation hardening.
Each phase closes with a pass/fail diagnostic. Fifty-four audit items in total, each provable or failable on inspection. The final scorecard reduces the result to a single figure and a verdict.
The methods documented here were developed in continuous production use: three decades of multi-channel retail at Abdou Express, and the 2020 scale-up of Masks.Health under WestNet N.A. during the global supply-chain failure. Nothing in this manual is theoretical.
Sovereign Commerce: The 90-Day E-Commerce Independence Audit
WestNet Operator Series, Field Manual 01 · First Edition, 2026
Written by Abdou Traya. Published by WestNet Publications, a division of WestNet N.A., Calgary, Alberta, Canada.
CATALOG UPC-A 7 31985 46105 9
Print edition: 6×9 in, paperback, premium color. ISBN 9798192139875.
© 2026 WestNet N.A. All rights reserved. This manual documents operational patterns for systems the reader owns and operates. Marketplace terms of service and the laws of the reader's jurisdiction take precedence over any procedure described here.
Field operations: facebook.com/WestNet · facebook.com/AbdouExpress · AbdouExpress.com · Masks.Health
The audit is designed to be executed, not read. It assumes an operating e-commerce business of any size — a hundred SKUs or twenty thousand — and it produces, over ninety days, a documented account of where that business actually stands: what it controls, what it rents, and what fails when a dependency is removed.
The four phases run in sequence. Each contains working material — procedures, worked examples from production systems, and fill-in worksheets — and each closes with a scored diagnostic.
Establish where the business actually lives: revenue concentration, data custody, propagation latency, and manual data entry. Nothing is changed in Phase 1; it is measurement only.
DAYS 1–14Establish a single authoritative catalog database under your control, with the schema, backup, bulk-operation, and identifier discipline that lets everything else derive from it.
DAYS 15–45Reduce every sales channel — classifieds, marketplaces, your own storefront — to a generated projection of the master record, each one disposable and rebuildable.
DAYS 46–75Verify the system under deliberate failure: scheduling locks, resource ceilings, load rehearsal, reconciliation, and monitoring that reports without a human watching.
DAYS 76–90Diagnostic items are scored pass or fail, with N/A reserved for items that genuinely do not apply. An item passes only if it is provable on inspection today — by a query, a log line, a timed drill, or a document. Intentions and near-misses are fails. There is no partial credit anywhere in this manual, because production systems do not award it.
In this web edition the diagnostics are interactive: selections are stored on your device and the scorecard computes continuously. In the print edition the same tables are completed in pen. The two editions are identical in content; the web edition of every WestNet manual remains free to read in full.
Companion software: the systems this manual audits for exist as production code — the WestNet Commerce Engine. The audit does not require it, and the manual is complete without it. Licensing terms appear once, on the final page.
Nothing in this manual asks you to leave Amazon, eBay, or your current platform today — or on Day 90. You keep selling, on every channel you sell on now, through the entire audit. The program runs alongside the business, not instead of it: Phase 1 changes nothing at all, and every later phase is built so that each step leaves the operation strictly safer than the step before. There is no cliff, no cut-over weekend, no moment where revenue depends on new code working the first time. Independence is added underneath the business you already have; the platforms simply matter less every week until, one day, they are optional. That is the whole design.
The ninety days start whenever you are ready. But three moves, made in your first seventy-two hours with this manual, remove most of the fear before the audit even begins:
A storefront taking orders on a domain you own, served from a machine you control. One master record deciding every price and quantity, with nightly off-site backups you have personally restored. Marketplaces and classifieds fed automatically from that master and closeable without harm. Labels printing from the order record, tracking on your own subdomain, a daily digest replacing dashboard anxiety — and a suspension email demoted from extinction event to inconvenience. Every item on that list is a diagnostic in this manual; the scorecard at the back measures the distance, and the calendar in Appendix A walks it a day at a time.
Calgary, Alberta
In the spring of 2020 the global supply chain did not slow down. It failed. Factories sealed, freight lanes closed, and the price of medical supply moved by the hour. Demand for one product — respiratory masks — went from ordinary to effectively unlimited in roughly seventy-two hours.
By then I had been in e-commerce for twenty-five years. Abdou Express carried thousands of SKUs — electronics, printer consumables, batteries, automotive parts — sold through my own storefront and fanned out across every channel that would take a listing. When the crisis arrived, I stood up Masks.Health under WestNet N.A. — the product's own name, on the health top-level domain. Understand what that address meant in the spring of 2020: the single most demanded product on earth, reachable at the domain that literally names it. No marketplace listing buried in sponsored results, no seller account at anyone's mercy — the address itself was the storefront. I pointed that quarter-century of infrastructure at the hardest logistics problem of the decade: procure, list, price, sell, and ship medical supply at volume, into a market repricing itself faster than a person could type.
The infrastructure held. Not because it was sophisticated — much of it ran on hardware most consultants would have condemned — but because every layer of it answered to me. The catalog lived in my own database. Listings were generated, not typed. When a sales channel failed, and channels failed weekly that spring, its entire presence was rebuilt from the master record by script, and shipping continued. In the same months, I watched capable sellers with seven-figure run rates go to zero in a single email — not because demand disappeared, but because their whole operation existed inside an account that somebody else controlled.
That season reduced to one principle, and this manual is that principle worked out in full: a platform is a sales channel, not a foundation. Amazon can suspend an account on a Tuesday morning. eBay can hold funds pending review. Shopify can reprice its terms at will. None of this is misconduct; it is what the agreements say. A business whose catalog, customers, and order flow live inside those agreements is not an asset its owner controls. The audit in these pages measures exactly how much of your business that describes — and then removes the dependency, system by system, over ninety days.
Every procedure here comes from production: the schema discipline, the channel engines, the reconciliation loops, and the failures — documented as field reports, with their causes and corrections — that produced each rule. Work the manual honestly. The diagnostics are strict because December is strict.
Abdou Traya
Founder — Abdou Express · Masks.Health · WestNet N.A.
Everything in the four phases descends from these ten statements. Each is stated once here and then enforced by specific diagnostic items later in the manual. Each one exists because its violation, at some point in twenty years of operation, produced a documented failure.
Begin with one written exercise: assume your largest sales channel suspends your account tomorrow at 09:00, without warning and without a stated reason. Document, in the table below, what stops and for how long. This is not a hypothetical scenario; it is a standard event in platform commerce, executed by risk algorithms at scale, and the 2020 crisis multiplied its frequency.
Note that selling on two platforms is not diversification if both use the same payment processor, the same manually-duplicated catalog, and the same class of risk model. Diversification is measured at the level of failure domains, not logos.
| Channel | % of monthly revenue | Who holds the customer record | Who holds the funds, and how long | Days to replace this revenue if closed today |
|---|---|---|---|---|
| Channel 1: | ||||
| Channel 2: | ||||
| Channel 3: | ||||
| Own storefront | You, if it exists | Your processor |
If the "own storefront" row reads zero — or the row does not exist — the business under audit is not an e-commerce operation. It is a supplier to somebody else's e-commerce operation, working under revocable permission. That is a legitimate arrangement only if it is a deliberate one, priced accordingly.
Propagation latency is the elapsed time between an operational decision — a price change, a stock-out, a new SKU — and that decision being live on every channel. It is the single most honest measurement of infrastructure quality, because it cannot be estimated flatteringly: it is taken with a clock.
Execute each event below once, in production, and time it to live-everywhere. Human steps count in full; if a step waits until "someone gets to it," the waiting is part of the measurement.
| Event | System changed first | Propagation path (every hop) | Measured time to live-everywhere | Human touches en route |
|---|---|---|---|---|
| Price change, 1 SKU | ||||
| Stock-out, 1 SKU | ||||
| New product, 1 SKU | ||||
| Bulk reprice, 100 SKUs |
Under five minutes to live-everywhere with zero human touches is enterprise-grade. Under one hour, automated, is workable. A result measured in days, or dependent on a person's availability, means the operation is either selling at stale prices or overselling stock during every propagation window. In 2020, mask pricing moved faster than a human could retype it across channels; operations with single-touch propagation repriced in minutes, and operations without it absorbed the difference as losses.
Trace the full life of your product data, from supplier to sold, and record every point where a person re-enters information that already exists in digital form somewhere in the operation. Each instance carries three costs: the wage paid for the entry, the latency it adds, and an error rate that compounds with volume. A price retyped in four systems is not verified four times; it is exposed to four opportunities for a misplaced decimal to reach a public listing.
| # | Data retyped | From → to | Performed by | Times / week | Minutes each | Weekly cost (wage × time) |
|---|---|---|---|---|---|---|
| 1 | ||||||
| 2 | ||||||
| 3 | ||||||
| 4 | ||||||
| 5 |
Multiply the weekly total by fifty-two and record the annual figure. This census is revisited in Phase 4, where each row is either automated, absorbed into the master record, or accepted in writing with a stated reason.
Ask the operation one question: which system decides how many units of a given SKU exist? A sound operation answers in one sentence. An answer that requires qualification — the store says one number, the marketplace another, and a spreadsheet is what staff actually trust — means there is no master record; there are several databases in unmanaged disagreement, and the disagreement is discovered by whichever customer orders the unit that was already sold.
Every oversell in this industry has the same root cause: two systems each believed they owned the quantity, and both sold the last unit. Complete the table for your three fastest-moving SKUs:
| SKU | Every location a quantity is stored | Which is authoritative | How the others learn of a change | Worst-case disagreement window |
|---|---|---|---|---|
A production storefront stopped persisting customer configuration data. The administrative interface reported success on every save; the files on disk never changed. The root cause was a file-ownership mismatch introduced during routine maintenance: the web server's user could no longer write the data files the application depended on, and the application layer discarded the failure without logging it. The condition was discovered by a paying customer, after an unknown period of silent loss, and was resolved with a refund and a permissions audit.
The final Phase 1 measurement is the one most sellers have never computed end-to-end: of every hundred dollars a customer pays, how many do you keep? Marketplace selling stacks costs that are individually tolerable and collectively decisive — the referral commission, fulfillment and storage where used, and the advertising that visibility increasingly requires as marketplaces convert search placement into auctioned inventory. Selling on owned infrastructure carries one material per-order cost: payment processing.
| Audit item | Pass | Fail | N/A |
|---|---|---|---|
| 1.01 — Less than 50% of gross revenue flows through any single account the business does not own.Concentration above half in one revocable account is an existential dependency. | |||
| 1.02 — A storefront operates on a domain the business owns, on infrastructure it controls or can relocate within 24 hours.A subdomain inside a platform is a booth in that platform's building, whatever the branding says. | |||
| 1.03 — A complete, current, machine-readable export of the catalog (every SKU, price, quantity, image) exists outside every platform.A catalog that exists only inside a platform is that platform's catalog. | |||
| 1.04 — Customer contact records (where lawfully collected) are held outside every platform.Marketplaces withhold buyer identity deliberately; the direct customer list is the asset being withheld. | |||
| 1.05 — The Suspension Simulation (§1.1) has been completed in writing within the last quarter.A continuity plan that has never been written has never been tested. | |||
| 1.06 — Measured propagation latency for a single price change is under 60 minutes, automated, with zero human touches.Per §1.2, taken with a clock. Estimates do not qualify. | |||
| 1.07 — A stock-out on any channel propagates to all other channels without human observation as the trigger.If a person is the synchronization mechanism, the oversell rate is a function of their schedule. | |||
| 1.08 — The Manual-Entry Census (§1.3) totals under two person-hours per week.Above this threshold, the operation employs people as interfaces between unconnected systems. | |||
| 1.09 — One named system is authoritative for every SKU's quantity, and all staff give the same answer to "which system decides."Disagreement among staff reflects disagreement among databases. | |||
| 1.10 — Every data file the web application writes has passed a permissions audit within 90 days, and writes are verified by read-back.Field Report 1. Silent save failures are otherwise discovered by customers. | |||
| 1.11 — Every scheduled job that touches inventory can be named from memory, with the location of its log.Unknown automation is not automation; it is an unmonitored actor with write access. | |||
| 1.12 — The storefront and its payment processing share no single kill-switch with the largest marketplace channel.A shared parent company or processor is a shared failure domain. |
One line per external dependency: platform, processor, courier, data feed. Reviewed monthly. Any entry scoring 3 or above in both columns is a Phase 3 conversion candidate.
| Dependency | What stops if it stops | Likelihood (1–5) | Damage (1–5) | Exit or fallback (one line) |
|---|---|---|---|---|
The systems that carried a national-scale medical supply operation through 2020 ran on consumer-grade hardware of considerable age. This is stated not as a recommendation for old equipment but as evidence about what actually matters: control, not capacity. Sovereignty does not require a data center. It requires that the storefront, the database, and the files run somewhere that cannot be repriced, suspended, or discontinued by a third party's product decision. A used tower in an office qualifies. An inexpensive virtual server that can be re-imaged and relocated in an afternoon qualifies. A commerce SaaS whose export function defines the limit of what you can take with you does not.
A web server, a scripting runtime, and a relational database, together on one machine — the arrangement the industry has spent fifteen years calling obsolete — remains the most efficient retail architecture available to an independent operator, for a reason rarely stated plainly: everything is one memory bus away. When the page process and the database share a machine, a catalog query costs microseconds and no network hop; there is no service mesh to fail, no per-request egress meter running, and no third party's outage that can take the storefront down. The efficiency practices that matter are old and boring — opcode caching on the scripting layer so code compiles once, indexes on every column a query filters by, connection reuse instead of reconnect-per-page, static assets served with long cache lifetimes so the disk is not asked twice for the same logo — and together they let a modest single machine serve a catalog of thousands of SKUs with headroom to spare. Phase 4's worker arithmetic completes the picture.
This is also the honest argument against building on rented cloud: the cloud is somebody else's computer, somebody else's invoice, and somebody else's deprecation schedule — a landlord relationship (Axiom 1) applied to the infrastructure layer itself, with pricing that punishes exactly the traffic success brings. A sovereign operation is vertically integrated instead: storefront, database, image pipeline, label generation, the printer on the LAN, the tracking portal, the barcode endpoint — every layer in-house, on hardware the operation owns, each layer feeding the next with no rented seam in between. Every system in this manual assumes, and rewards, that posture.
Everything in the operation projects outward from one table. The following is the minimum viable master record, refined across thousands of production SKUs; adapt names to your storefront software, but keep every constraint.
CREATE TABLE master_products (
id INT UNSIGNED AUTO_INCREMENT PRIMARY KEY,
sku VARCHAR(32) NOT NULL UNIQUE, -- issued once, never reused
upc CHAR(12) NULL, -- valid check digit or NULL (2.6)
title VARCHAR(255) NOT NULL,
price_cents INT UNSIGNED NOT NULL, -- integer minor units only
qty INT NOT NULL DEFAULT 0, -- the only authoritative quantity
status ENUM('active','paused','retired') NOT NULL,
cost_cents INT UNSIGNED NULL,
image_key VARCHAR(64) NULL, -- deterministic, e.g. p<id>.jpg (2.5)
updated_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP
ON UPDATE CURRENT_TIMESTAMP, -- maintained by the database
KEY idx_status_updated (status, updated_at)
) ENGINE=InnoDB; -- row-level locking; see Phase 4, Field Report 5
Three of these decisions carry most of the weight:
Storefront software — an osCommerce-lineage cart, WooCommerce, a purpose-built catalog — either uses these tables directly or is a downstream projection of them. What is not permitted after Day 45 is any channel, spreadsheet, or employee's memory holding a quantity the master does not know about.
An administrative dashboard — including your own storefront's — is one client of the database, and for bulk work it is the wrong one. Forty new SKUs entered through an admin panel is an afternoon of page loads; the same forty SKUs as a single SQL transaction is seconds. Operating directly on the master record is a standard capability of a sovereign operation. It is performed under a fixed discipline:
A category tree on a high-SKU storefront rendered incorrectly for an extended period: branches failed to expand and the active category did not highlight. Repeated fixes were attempted against the rendering layer, because the rendering layer was where the symptom appeared. The actual causes, established much later by examining the data directly, were an incomplete ancestor path being supplied to the navigation code, and a layout-cache flag that had been assumed enabled but had been off throughout. One hour spent querying what the database actually contained resolved what years of adjusting the output had not.
Between the master record and the outside world sits a format that every system in commerce can produce and consume — accounting packages, marketplace bulk uploaders, courier tools, and a text editor in an emergency. That format is the delimited flat file, and a sovereign operation treats it with the same discipline as the database. The working pattern: one file per purpose, generated from the master, never edited downstream.
Past a few hundred SKUs, product imagery is not managed by hand. It is treated as derived data under three rules:
p4117.jpg, in one flat directory. Given a product ID, any script, template, or channel exporter constructs the image path without consulting a database or a person. This single convention eliminates an entire category of lookup software.image_key; recompression, resizing, or relocating storage later touches no database rows.First: automated fetch jobs must present complete, browser-equivalent requests. A substantial fraction of the web silently rejects anything that resembles a script, and a naive pipeline will report success while collecting error pages saved under image filenames. Fetched bytes are validated as a decodable image before installation.
Second: image libraries have format blind spots — a validator that cannot read a newer format will reject valid files indefinitely. The rejection rule is therefore "confirmed bad," never "could not confirm."
Identifiers outlive everything else in the operation. A SKU that has been printed on a label, quoted in correspondence, or sold on a channel is never reassigned to a different product. Barcode identifiers additionally carry arithmetic: the final digit of a UPC is a checksum over the preceding eleven, and marketplace ingestion, scanners, and feed validators verify it.
Early in one catalog's life, product codes were assigned informally: twelve digits shaped like UPCs, with the check digit chosen arbitrarily. Nothing objected at the time, because the storefront did not validate. Years later, as those items flowed toward stricter channels and modern tooling, each invalid check digit surfaced individually as a rejected feed row requiring investigation. The defect cost nothing at creation and a sustained cleanup effort at scale, long after the context of the original assignments was gone.
Products are state — they change and the master reflects the change. Orders are the opposite: orders are history, and history is never edited. The order log is append-only from the moment of capture (§2.4's rules apply in full), and it is retained effectively forever, because its value compounds with age in ways that are invisible on the day of the sale:
Lawful-basis note: retain what your jurisdiction permits, secure it like the asset it is (the leads-and-logs class of files must never be publicly readable — audit web-server exposure of data files the same way §1.10 audits their ownership), and treat customer data as borrowed, not owned.
Readers who arrive at this manual as pure marketplace sellers — no storefront at all — build one in this phase, on the machine from §2.1, beside the master record. This is less work than platform marketing has taught you to believe, and the software choice matters less than four criteria that any candidate must meet:
The go-live checklist is deliberately short, because ugly and live beats perfect and hosted:
The store does not need traffic to justify existing. On Day 45 its job is to exist, to take that one test order, and to prove the pipeline. Traffic is Phase 3's problem — generated landing pages, classifieds funneling buyers, parcel inserts converting marketplace customers — and every one of those channels points at a storefront that is already, quietly, working. Sellers who build in this order never launch to silence, because by the time anyone is looking, the machine has been running for weeks.
The allocation discipline above is available to the reader as a running service. The WestNet UPC Registry at upc.westnet.ca issues retail UPC-A codes with correctly computed check digits, instantly activated and accepted by major retailers — single registrations from $10, with 10-pack, 100-pack, and unlimited enterprise tiers for growing catalogs. Each registration includes the digital certificate and the barcode assets (print-grade PNG and vector SVG), served from one endpoint so a code is drawn identically on a product label, a listing, and a shelf tag. The barcode on this manual's own imprint page was produced by that system, under the same allocation log the register requires. Whether you use this registry or another issuer, the diagnostic items below apply unchanged: valid check digits, validated on write, logged at allocation.
| Audit item | Pass | Fail | N/A |
|---|---|---|---|
| 2.01 — One database table (or tightly joined set) is the declared master for products, price, and quantity, documented and known to all staff.Axiom 2, in writing. | |||
| 2.02 — The master runs on infrastructure that can be archived, moved, and restored within 24 hours, and a restore has been drilled within the last quarter.A backup that has not been restored is an assumption. | |||
| 2.03 — A nightly automated database dump and file backup ships off-machine to a second location, unattended.Shared premises are a shared failure domain. | |||
| 2.04 — Monetary values are stored as integer minor units throughout the pipeline.Floating-point currency eventually publishes its rounding error. | |||
| 2.05 — Every product row carries a database-maintained modification timestamp, and sync jobs run incrementally against it.Full-table synchronization on every run is deferred failure under load. | |||
| 2.06 — Inventory-critical tables use a row-locking storage engine.One word in the schema; see Phase 4, Field Report 5, for its absence. | |||
| 2.07 — A 100-SKU bulk price change can be executed in under ten minutes, including snapshot, rehearsal SELECT, and read-back verification — demonstrated, not estimated.§2.3 as a timed drill. | |||
| 2.08 — A pre-write snapshot precedes every bulk operation, and an operations journal records each one.The discipline is needed rarely and then absolutely. | |||
| 2.09 — Every generated feed has a written column contract and exactly one writer; downstream editing is prohibited.Two writers on one feed is two masters. | |||
| 2.10 — Product images follow a deterministic naming scheme derivable from the product identifier alone.If locating an image requires a search, a system is missing. | |||
| 2.11 — A scheduled job detects and repairs missing or unreadable product images, validating fetched files as decodable images before installation.Error pages stored under image filenames are the standard silent failure. | |||
| 2.12 — All UPC/EAN identifiers in the catalog carry mathematically valid check digits, validated on write.Field Report 3. The defect is free today and expensive in year three. | |||
| 2.13 — SKUs are never reused, and an allocation log records every identifier ever issued.Identifiers are permanent; their reuse corrupts history. | |||
| 2.14 — Files written by the web application are owned by its user, and a permissions audit runs on a schedule.The permanent prevention of Field Report 1. |
One copy per generated feed, posted where the feed's consumers can see it.
| Field | Entry |
|---|---|
| Feed name and path | |
| Purpose (one sentence) | |
| Sole writer (system or job) | |
| Consumers (all) | |
| Columns: name — type — nullable — example | |
| Regeneration schedule and trigger | |
| File owner and permissions | |
| Append-only or regenerated whole | |
| Read-back verification method |
With a master record in place, every sales channel is reduced to what it structurally is: a projection of the catalog. Data flows outward from the master through exporters; orders and inquiries flow back through importers; nothing else crosses the boundary in either direction.
Two rules give the diagram force:
Before paying marketplace fees, extract full value from the channel with none: structured catalog data plus one template yields hundreds of indexable, permanent landing pages on your own domain — each answering a specific buyer question, each terminating at your own checkout.
A worked example from production: a compatibility dataset — which consumable fits which machine, in this case printer cartridges — was rendered through a single template into 127 model-specific landing pages, with clean rewritten URLs, structured-data markup, an automatically regenerated sitemap, and reciprocal links between products and their pages. Each page matches the exact phrase a buyer types when a specific machine needs a specific consumable, and each lands the buyer on the operator's own domain rather than a marketplace results page listing competitors alongside. The pages have no per-month cost and do not expire.
Classifieds — Kijiji in Canada, Craigslist in the United States — are structurally undervalued: free or near-free listings, local buyers with immediate intent, and no ranking algorithm auctioning your visibility to competitors. Their operational friction, which discourages casual sellers at roughly the dozenth manual listing, is precisely what makes them defensible for an operator with generation infrastructure. The engine that operates them at volume has five components:
Marketplace posting interfaces resolve every visible choice to an internal numeric identifier. During one bulk classifieds campaign, the engine performed correctly by every internal measure — sessions held, posts published, the state ledger updated — while the ads themselves were effectively invisible, because the category identifier in use, numerically adjacent to the correct one, belonged to an unrelated consumer-appliance category. No error was raised at any point: an incorrect identifier does not fail, it succeeds somewhere unintended. The same campaign established a second property of these systems: location taxonomies are trees in which only leaf nodes accept postings — a region-level identifier bounces or misfiles where a specific city posts cleanly.
The engine described in this section exists as a commercial service. AbdouPost — post once, sell everywhere — takes a single listing and publishes it to Facebook Marketplace, Kijiji, eBay, and Amazon simultaneously, running entirely server-side: no browser extension, no computer left on, sessions and renewals managed the way §3.3 prescribes. It is operated on the same infrastructure that runs CalgaryFinder.com and Abdou Express, and it is built for exactly the operators this phase addresses — dealerships, realtors, pawn shops, resellers, and power sellers, where one additional sale per month covers the service. It is also the honest answer to the walled-garden problem of §3.6: a channel you cannot script yourself is a channel you staff or license, and AbdouPost is that capability as a managed service.
Nothing in this manual argues against selling on Amazon or eBay; they are large rivers of buyers. The doctrine concerns architecture: they are retail outlets the operation stocks, not systems the operation lives in. The distinction is auditable:
The operating assumption, fixed in Phase 1, is that any satellite account can close tomorrow morning. Readiness for that event is a set of standing practices:
Some marketplaces — social-network venues and app-only markets — offer no serviceable bulk interface and actively resist automation. This manual does not document techniques against those defenses; any such documentation would be obsolete within a season, and the channels' terms govern in any case. What remains permanently true is that the doctrine does not change: the master record feeds whatever presence is maintained there, the state ledger tracks what is live, the channel justifies its total cost quarterly or is closed, and the harder a garden makes departure, the smaller the share of the business it should be permitted to hold. A channel that cannot be scripted is a channel that must be staffed or licensed — that cost belongs in the quarterly review at its full value, and the staffing works from the same generated templates as everything else, so the manual-entry census stays clean. For operators who want the walled gardens served without building the capability, the managed route is AbdouPost (§3.3, Figure 3-2), which publishes to Facebook Marketplace alongside the open channels.
The order pipeline of §3.4 does not end at "order received." A sovereign operation carries the same discipline through the last physical meter — the label, the printer, and the tracking link the customer refreshes for a week. Each of the three is a dependency most sellers hand back to a carrier or a marketplace without noticing.
The production implementation is public: WestNet Tracking at track.westnet.ca tracks WestNet Express shipments alongside Canada Post, USPS, FedEx, UPS, Canpar, and DHL — up to ten tracking numbers in one query — on WestNet's own domain, in WestNet's own styling. Carrier responses are cached and archived on WestNet's side, so a shipment's history remains retrievable long after carriers purge their own records; delivered shipments are archived permanently and never re-polled. It is the loop-closer for every channel in this phase: whatever marketplace or classifieds channel produced the order, the buyer's tracking experience ends on infrastructure the operation owns.
One more property separates an owned storefront from every marketplace, and it is not technical: on your own property, nobody is auctioning your customer's attention against you. Open a major marketplace's product page and count what surrounds the buy button — sponsored competitors on the same page as your listing, recommendation carousels, cross-sell rows, program badges, upsell interstitials. That density is not poor design; it is the business model. The marketplace's customer is the advertiser, and your listing is the shelf its ads are sold against.
The cost of that noise lands on two people. The buyer pays in decision fatigue: every additional element on a page competes with the one decision that matters, and a distracted buyer defers, compares, and leaves. The operator pays twice — once in conversion, and once in maintenance, because every widget on a page is code to maintain, cache to invalidate, and a place for failure to hide. Clutter is expensive at both ends of the wire, and the marketplace collects on both.
The reference storefront's homepage carries roughly ninety-six links: a search box, a cart, account controls, category navigation, and products — priced, in stock, with an add-to-cart button. Nothing else. That restraint has held across two decades of the same catalog and two generations of theme, and it is a discipline, not an aesthetic:
| Audit item | Pass | Fail | N/A |
|---|---|---|---|
| 3.01 — Every live channel's listings are generated from the master record; no listing content exists only inside a channel.The regeneration drill depends on this being literally true. | |||
| 3.02 — No channel writes to the master except order decrements through the audited importer.Axiom 3, enforced at the boundary. | |||
| 3.03 — A state ledger maps every master SKU to every live listing identifier per channel, and is backed up nightly.Without the map there is no idempotency, and without idempotency, duplicates. | |||
| 3.04 — Expired or decayed classifieds are detected and renewed automatically on a schedule.Freshness at volume is the position; manually it does not exist. | |||
| 3.05 — Items marked sold or paused in the master are withdrawn from every channel automatically.A live listing for a dead SKU is an oversell on a delay. | |||
| 3.06 — Category and location identifiers are verified by public-side read-back before every bulk run.Field Report 4. An incorrect identifier does not fail; it succeeds somewhere unintended. | |||
| 3.07 — Posting cadence is paced, with delays and daily ceilings, per channel.Every channel has a rate budget whether or not it publishes one. | |||
| 3.08 — Marketplace exports reconcile after every push: read back the channel's state, compare with what was sent, queue the differences.Partial feed failure is routine; unobserved partial failure is not survivable. | |||
| 3.09 — Marketplaces receive stock allocations, not the full quantity.Allocations fail as undersells of one channel; mirrors fail as oversells of the business. | |||
| 3.10 — All channel orders flow through one importer into one fulfillment pipeline.Several pipelines is several businesses, each run part-time. | |||
| 3.11 — Structured catalog data generates landing pages on the operation's own domain, with an automatically regenerated sitemap.§3.2 — the channel with no fees, exploited first. | |||
| 3.12 — Every outbound parcel, on every channel, carries the operation's domain to the buyer.The commission was paid to meet this customer once, not every time. | |||
| 3.13 — The regeneration drill has been executed and timed on at least one channel within the last quarter.§3.5. Readiness is a stopwatch figure, not a feeling. | |||
| 3.14 — Per-channel total cost of selling is reviewed quarterly against a written closure threshold.Satellites justify their orbit on schedule. |
One line per live channel. A line that cannot be completed identifies a channel that is operating the business rather than the reverse.
| Channel | Identity label | Session store | State ledger location | Cadence & ceilings | Exporter job | Closure threshold (% take) | Regen drill: date & time |
|---|---|---|---|---|---|---|---|
Phase 4 opens with the incident that produced most of its rules. It is reconstructed here from logs, in full, because every element of it — the schedule, the lock, the storage engine, the memory ceiling — is an ordinary default that thousands of operations are running at this moment.
Configuration. An inventory synchronization job, scheduled every minute. Each run normally completed in seconds, so the one-minute interval had months of uneventful history. The tables it wrote used a table-locking storage engine, unchanged from the software's defaults years earlier. The job had no lock guard, because it had never needed one.
Trigger. One morning, an unrelated long-running query held a lock on a table the synchronization needed. The scheduled run blocked and waited. The scheduler, which has no knowledge of a previous run's state, started the next invocation one minute later, which queued behind the first. Invocations continued to accumulate, each holding a database connection and its own memory.
Cascade. The queued jobs held locks of their own, which blocked the storefront's ordinary page queries. Web requests began to hang; the web server responded by spawning additional workers — more than a hundred and thirty at peak — while visitors retried. One runaway process grew past eight gigabytes of memory on a sixteen-gigabyte machine, and the kernel's out-of-memory handler began terminating processes without regard for which ones mattered. Every site on the server went down. Elapsed time from nominal operation to total outage: under one hour. Root cause: a scheduling assumption and a storage-engine default, both years old, both invisible until they combined.
The generalized laws, applicable to every scheduled job the operation will ever run:
With locks and ceilings in place, each is verified the only way that produces knowledge: by attempting to defeat it.
Automation is complete when the operation reports on itself to an absent operator (Axiom 10). The monitoring that satisfies this is inexpensive and specific:
Drift occurs in correct systems: a channel glitch, an importer interruption, a unit sold over the counter and unrecorded. The defense is a nightly variance report comparing three figures per SKU — the master's quantity, each channel's believed quantity, and physical count for a rotating weekly sample. Every variance receives a line: SKU, location, magnitude, resolution. Within a month of operation, zero-variance nights are the norm and the report's function is to make exceptions loud. An oversell reaching a customer is thereafter a rare event with a written postmortem, not an accepted cost.
Return to the manual-entry census of §1.3. Each row is now dispositioned one of three ways: automated (an exporter, importer, or template now performs it), absorbed (the master record made it unnecessary), or accepted — retained deliberately, in writing, with a reason and a revisit trigger. The census is closed when no human touch in the operation is unexamined. The goal is not zero touches; it is zero undocumented ones.
| Census row | Disposition (automated / absorbed / accepted) | Job or change responsible | Date closed | If accepted: reason & revisit trigger |
|---|---|---|---|---|
Everything in this phase exists for the fourth quarter, when volume multiplies and every latent defect is called at once. The hardened operation enters peak season under a written playbook, prepared in October, unchanged after mid-November:
| Audit item | Pass | Fail | N/A |
|---|---|---|---|
| 4.01 — Every scheduled job runs under a non-blocking lock; a live previous instance causes immediate, logged exit.The permanent prevention of Field Report 5. | |||
| 4.02 — Every scheduled job has a memory and/or runtime ceiling enforced by the system.A job policy cannot terminate will be terminated by the kernel, with bystanders. | |||
| 4.03 — Web server worker limits are computed from measured per-worker memory, and headroom is monitored.Arithmetic, verified against the actual machine. | |||
| 4.04 — The stacking drill has been executed: a deliberately extended run proved the lock holds.Locks are demonstrated, not assumed. | |||
| 4.05 — The interruption drill has been executed: a mid-run termination followed by a re-run healed with no duplicates and an intact ledger.Idempotency is a demonstrated property. | |||
| 4.06 — A load rehearsal at a multiple of the worst recorded hour has run this quarter, with memory observed alongside latency.Peak season arrives whether or not it was rehearsed. | |||
| 4.07 — Every job writes a heartbeat; a watchdog flags staleness; a dead job is detected by silence within one cycle.The failure mode that matters is the one the job cannot report. | |||
| 4.08 — The storefront is probed from the public side, browser-equivalent, on a schedule.The operation's own defenses filter naive probes, in both directions. | |||
| 4.09 — Error-log rates are monitored, not only error patterns.Familiar lines at unfamiliar rates are an event. | |||
| 4.10 — A nightly variance report reconciles master, channel, and physical counts, and every variance receives a logged resolution.Drift is inevitable; unobserved drift is elective. | |||
| 4.11 — An automated daily digest summarizes orders, heartbeats, variances, and machine headroom in one message.Monitoring that requires attendance is staffing, not monitoring. | |||
| 4.12 — The manual-entry census is closed: every remaining human touch carries a written disposition and revisit trigger.Zero undocumented touches. | |||
| 4.13 — A cron register lists every scheduled job with its lock, ceiling, log, and owner, current as of this week.Item 1.11 asked for recall; this closes it in writing. | |||
| 4.14 — The full stack has passed the 3 a.m. test for 14 consecutive days: orders flowed, synchronization ran, failures self-reported, and no human intervened.Axiom 10. This is the graduation criterion. |
Every scheduled job in the operation, without exception, reviewed monthly. A job absent from this sheet is not authorized to exist.
| Job | Schedule | Lock mechanism | Memory / runtime ceiling | Log location | Heartbeat check | Owner |
|---|---|---|---|---|---|---|
Four diagnostics reduce to one figure: passes over applicable items, across all fifty-four. In this edition it computes from the selections above; in print, the tally is carried here by hand.
| Diagnostic | Score | Pass / applicable |
|---|---|---|
| Complete the diagnostics above. | ||
Complete the four diagnostics to compute a verdict.
| Band | Verdict | Reading |
|---|---|---|
| 85 – 100% | Sovereign Operator | Catalog, customers, and order flow survive the loss of any single platform, account, or machine. The channels work for the operation. Maintain the quarterly drills; expand the fan-out. |
| 60 – 84% | Tenant With a Plan | The exits are identified and some are built. Rank every failed item by likelihood times damage, from the Phase 1 risk register, and close them in that order. Most operations at this band complete the work in one further quarter. |
| Below 60% | One Suspension From Zero | The verdict is literal: a single account decision at a company with no knowledge of this business separates it from zero revenue. The first corrective action is item 1.03 — a complete catalog export, held outside every platform, tonight. |
If you worked this manual honestly, you now hold something few sellers ever produce: an itemized, scored account of every point where your operation depends on someone else's permission. Each failed item corresponds to a system documented in these pages — a master schema, an exporter, a state ledger, a reconciliation loop, a watchdog. None is beyond a competent operator. The designs are complete as written, and building them yourself is a legitimate road; the appendix calendar is sequenced for exactly that.
The honest accounting is that the road has length. Each failed item represents somewhere between a weekend and a month of engineering, and the dependency the audit measured continues at full weight while the work proceeds. It took me years to make these mistakes and derive the corrections in this manual — the invalid check digits, the silent save failure, the stacked jobs at dawn, one global supply-chain failure as the final examination. The manual shortens your road considerably. It does not shorten it to zero.
So the offer, stated once: the infrastructure this manual audits for exists as production software. The WestNet Commerce Engine is the master record, the exporters, the classifieds engine, the reconciliation loops, and the watchdogs described here, licensed as a working stack and fitted to your catalog — so that the ninety-day audit becomes a ninety-day deployment, with your failed items as the work plan. It was built where this manual says it was built, and it is in production today.
Build from the blueprint, or license the machine. Either way, do not remain a tenant.
Abdou Traya
Founder — Abdou Express · Masks.Health · WestNet N.A.
The full stack installed on your hardware or VPS. Schema, exporters, state ledgers, hardening, handover session.
Deployed and fitted to your catalog and channels; monitoring, reconciliation, and renewals managed. Your data remains exportable in full, at any time.
The entire manual executed for you, all four diagnostics driven to pass. The scorecard is the acceptance test.
www.westnet.ca/learning/Sovereign-Commerce/license.htm
Workbook owners: the $150 purchase is credited in full against any tier. Bring the scorecard — the failed items are the deployment plan.
WestNet N.A. · Calgary, Alberta · 403-813-7045
| Days | Objective | Deliverable (provable) |
|---|---|---|
| 1–3 | Suspension Simulation; Dependency Risk Register | Completed §1.1 table and Phase 1 tear-sheet |
| 4–7 | Propagation latency measurements | Completed §1.2 table, timed with a clock |
| 8–11 | Manual-Entry Census; Single-Source Test | §1.3 and §1.4 tables; annual cost figure recorded |
| 12–14 | Diagnostic 1 scored; full catalog export secured off-platform | Score, and a dated export file that opens |
| 15–22 | Master schema stood up; storefront wired to it | Schema in version control; store serving from master |
| 23–29 | Backups: nightly dump, off-site shipment, restore drill | A restore, performed and timed |
| 30–37 | Bulk-operation discipline; operations journal | One real bulk change under full procedure |
| 38–45 | Image pipeline; identifier audit; Diagnostic 2 scored | Repair job live; check-digit validation on write |
| 46–53 | First exporter and state ledger, highest-volume channel | Channel regenerated from master in a test run |
| 54–61 | Classifieds engine: sessions, cadence, renewal automation | Ledger-driven renewals running unattended |
| 62–68 | Marketplace allocation and reconciliation; landing-page generator | Post-push difference report; N pages and sitemap live |
| 69–75 | Regeneration drill; parcel inserts; Diagnostic 3 scored | Drill time recorded on the Channel Ledger |
| 76–80 | Locks, ceilings, worker arithmetic; stacking drill | Cron Register complete; drill refusal in the log |
| 81–84 | Interruption, load, and disk-exhaustion drills | Three drill logs, three clean recoveries |
| 85–87 | Heartbeats, watchdog, public-side probe, daily digest | The first digest, delivered automatically |
| 88–90 | Variance report live; census closed; Diagnostic 4 and Scorecard | The sovereignty score, recorded on the scorecard |
| Term | Definition |
|---|---|
| Master record | The single database that determines what exists, its price, and its quantity. All other copies are projections. |
| Satellite | Any sales channel: a receiver of projections and a source of orders, closeable at any time without ending the business. |
| Propagation latency | Measured elapsed time from an operational decision to that decision being live on every channel. |
| Manual-entry census | The itemized record of every point where a person re-enters data that already exists digitally, with its annual cost. |
| State ledger | The per-channel map of master SKU to live listing identifier and lifecycle dates; the basis of idempotent posting. |
| Allocation | The budgeted slice of stock a marketplace receives in place of a mirror of full quantity; its failure mode is an undersell. |
| Read-back verification | Confirmation of any automated write by an independent read, preferably from the public side. Axiom 6. |
| Stacking | The accumulation of scheduled-job invocations behind a blocked predecessor, absent a non-blocking lock, until resources exhaust. |
| Leaf-node rule | Marketplace taxonomies are trees in which only leaf nodes accept postings; parent and region identifiers bounce or misfile. |
| Regeneration drill | The timed rebuild of a channel's entire presence from the master record and scripts alone. |
| Variance report | The nightly reconciliation of master, channel, and physical quantities, with a logged resolution per difference. |
| 3 a.m. test | The condition in which orders flow, inventory synchronizes, listings renew, and failures self-report with no operator awake. |
Every system in this manual corresponds to a component running in production at Abdou Express and WestNet N.A. — most of them for many years, several of them public. The mapping below is provided so the reader can verify the manual's standing claim: nothing in it is theoretical. Internal mechanics are described at the level of architecture; the operating specifics of any carrier, channel, or defense are the operator's own business, yours and mine alike.
| Manual system | Production implementation |
|---|---|
| Master record (§2.2) | A MySQL catalog serving the storefront continuously since the 1990s — thousands of live SKUs across software, consumables, cleaning products, and OEM auto parts; hot tables on a row-locking engine since the incident of Field Report 5. |
| Bulk operations (§2.3) | Administrative CSV import plus direct SQL under the snapshot / rehearse / read-back procedure, journalled per operation. |
| Supplier ingestion (§2.4) | Feed processors that ingest supplier catalogs — auto-parts lines among them — normalizing price, stock, and imagery into the master without a keystroke of retyping. |
| Image pipeline (§2.5) | An image manager that fetches, validates, and installs product photography to deterministic per-product filenames, with a daily self-heal pass for missing or unreadable files. |
| Identifier discipline (§2.6) | The WestNet UPC Registry (Figure 2-1); storefront product cards carry their barcodes on the card face, drawn by the same endpoint that produced this manual's imprint barcode. |
| Generated landing pages (§3.2) | 127 printer-compatibility pages generated from one template and one data table, with pretty URLs and a sitemap regenerated on schedule. |
| Classifieds engine (§3.3) | The bulk posting system behind AbdouPost (Figure 3-2): persistent sessions, a JSON state ledger per channel, paced posting, automated renewal. |
| Marketplace exports (§3.4) | Feed-based Amazon and eBay projection from the master record, with allocation quantities and post-push reconciliation. |
| Fulfillment loop (§3.7) | Labels generated from the order record, printed direct-to-Zebra over the LAN; tracking served to customers at track.westnet.ca (Figure 3-3) with a permanent archive. |
| Hardening & monitoring (Phase 4) | Non-blocking locks on every cron, per-process memory ceilings, worker limits from measured arithmetic, heartbeat watchdogs, and the daily digest — each one adopted after the field reports in this manual. |
| The 2020 proof | Masks.Health, stood up under WestNet N.A. during the supply-chain failure, still serving from the same infrastructure — surgical masks listed alongside the rest of the catalog, as they were in 2020. |
The storefront itself is shown at Figure 3-4 — masks beside operating systems beside OEM parts, one uncluttered grid. On the significance of the Masks.Health address: in 2020 it was the plainest possible demonstration of the whole doctrine — the most demanded product on earth, at the domain that names it, on infrastructure no platform could suspend.
Abdou Traya is the founder of Abdou Express, a multi-channel retail operation that has run for three decades on self-hosted infrastructure, listing and synchronizing thousands of SKUs across an owned storefront, classifieds networks, and major marketplaces. By 2020 he had twenty-five years in e-commerce; that year he established Masks.Health under WestNet N.A., applying the accumulated infrastructure to the procurement and distribution of medical mask supply at scale through the global supply-chain failure. The systems described in this manual are the systems that operation ran on, together with the corrections earned from their documented failures. He operates from Calgary, Alberta.
Field operations, in public: AbdouExpress.com · Masks.Health · facebook.com/AbdouExpress · facebook.com/WestNet
Sovereign Commerce · WestNet Operator Series, Field Manual 01 · Catalog UPC-A 7 31985 46105 9
WestNet Publications · WestNet N.A. · Calgary, Alberta · westnet.ca/learning