Operator Series · Field Manual
01
01

The WestNet Operator Series

Sovereign Commerce
The 90-Day E-Commerce
Independence Audit

Systems for high-volume scaling and inventory syncing
without Amazon, eBay, or Shopify dependence

Abdou Traya · Founder, Abdou Express · Masks.Health · WestNet N.A.
WestNet Publications · Calgary, Alberta · First Edition
Catalog UPC-A 7 31985 46105 9 · 6×9 operator workbook · USD $150

About This Field Manual

This is a working document, not a narrative. It is structured as a four-phase infrastructure audit, conducted over ninety days against your own operation: dependency analysis, master-record design, channel fan-out, and automation hardening.

Each phase closes with a pass/fail diagnostic. Fifty-four audit items in total, each provable or failable on inspection. The final scorecard reduces the result to a single figure and a verdict.

The methods documented here were developed in continuous production use: three decades of multi-channel retail at Abdou Express, and the 2020 scale-up of Masks.Health under WestNet N.A. during the global supply-chain failure. Nothing in this manual is theoretical.

Published By

WestNet Publications
A division of WestNet North America Inc.
www.westnet.ca/learning

Field Operations

Abdou ExpressAbdouExpress.comMasks.Health
facebook.com/WestNetfacebook.com/AbdouExpress

WestNet Catalog (UPC-A): 7 31985 46105 9
ISBN 9798192139875 • First Edition

UPC-A barcode 731985461059
7 31985 46105 9
WestNet Publications

Imprint

FM-01 · i

Sovereign Commerce: The 90-Day E-Commerce Independence Audit
WestNet Operator Series, Field Manual 01 · First Edition, 2026
Written by Abdou Traya. Published by WestNet Publications, a division of WestNet N.A., Calgary, Alberta, Canada.

CATALOG UPC-A  7 31985 46105 9

UPC-A barcode 731985461059
WestNet Catalog UPC-A
EAN-13 barcode for ISBN 9798192139875
ISBN 9798192139875
This manual carries both retail identifiers, printed here as scannable symbols. The catalog UPC-A was allocated with a computed check digit and recorded in the WestNet UPC Registry at upc.westnet.ca — the same registry, and the same allocation procedure, that §2.6 requires for every product identifier in a sovereign catalog (readers can register their own codes there, from $10). The ISBN-13, in EAN-13 symbology, identifies the print edition and appears again as the barcode on the back cover; it too is registered in the same data center.

Print edition: 6×9 in, paperback, premium color. ISBN 9798192139875.
© 2026 WestNet N.A. All rights reserved. This manual documents operational patterns for systems the reader owns and operates. Marketplace terms of service and the laws of the reader's jurisdiction take precedence over any procedure described here.
Field operations: facebook.com/WestNet · facebook.com/AbdouExpress · AbdouExpress.com · Masks.Health

How to Work This Manual

METHOD

The audit is designed to be executed, not read. It assumes an operating e-commerce business of any size — a hundred SKUs or twenty thousand — and it produces, over ninety days, a documented account of where that business actually stands: what it controls, what it rents, and what fails when a dependency is removed.

The four phases run in sequence. Each contains working material — procedures, worked examples from production systems, and fill-in worksheets — and each closes with a scored diagnostic.

PHASE 1

The Dependency Audit

Establish where the business actually lives: revenue concentration, data custody, propagation latency, and manual data entry. Nothing is changed in Phase 1; it is measurement only.

DAYS 1–14
PHASE 2

The Master Record

Establish a single authoritative catalog database under your control, with the schema, backup, bulk-operation, and identifier discipline that lets everything else derive from it.

DAYS 15–45
PHASE 3

Channel Fan-Out

Reduce every sales channel — classifieds, marketplaces, your own storefront — to a generated projection of the master record, each one disposable and rebuildable.

DAYS 46–75
PHASE 4

Stress-Testing & Automation

Verify the system under deliberate failure: scheduling locks, resource ceilings, load rehearsal, reconciliation, and monitoring that reports without a human watching.

DAYS 76–90
THE 90 DAYS, ALLOCATEDDAY 1 → DAY 90
P1 Measure (14d)P2 Master Record (31d)P3 Fan-Out (30d)P4 Hardening (15d)
Scoring Rule

Diagnostic items are scored pass or fail, with N/A reserved for items that genuinely do not apply. An item passes only if it is provable on inspection today — by a query, a log line, a timed drill, or a document. Intentions and near-misses are fails. There is no partial credit anywhere in this manual, because production systems do not award it.

In this web edition the diagnostics are interactive: selections are stored on your device and the scorecard computes continuously. In the print edition the same tables are completed in pen. The two editions are identical in content; the web edition of every WestNet manual remains free to read in full.

Companion software: the systems this manual audits for exist as production code — the WestNet Commerce Engine. The audit does not require it, and the manual is complete without it. Licensing terms appear once, on the final page.

Before Day 1 — The First 72 Hours

QUICK START
Read This First If You Feel Behind

Nothing in this manual asks you to leave Amazon, eBay, or your current platform today — or on Day 90. You keep selling, on every channel you sell on now, through the entire audit. The program runs alongside the business, not instead of it: Phase 1 changes nothing at all, and every later phase is built so that each step leaves the operation strictly safer than the step before. There is no cliff, no cut-over weekend, no moment where revenue depends on new code working the first time. Independence is added underneath the business you already have; the platforms simply matter less every week until, one day, they are optional. That is the whole design.

The ninety days start whenever you are ready. But three moves, made in your first seventy-two hours with this manual, remove most of the fear before the audit even begins:

  1. Hours 0–2: take your catalog back. Run every platform's export — products, prices, quantities, order history, images if offered — and save the files somewhere the platform cannot touch. This single act passes Diagnostic 1.03 and ends the worst-case scenario: whatever happens to any account after today, the catalog is yours. Most readers report this as the moment the anxiety drops.
  2. Day 1–2: secure the ground. Confirm the domain is registered to you (not to an agency, a platform, or a former developer), with auto-renew on a payment method that will not silently expire. If there is no domain, register one tonight — it costs less than lunch and it is the one asset in commerce nobody can suspend.
  3. Day 2–3: power on the machine. A spare desktop in the office or a modest virtual server — the standard web-server / scripting / database stack from §2.1, default install. It does not need to be pretty and nothing customer-facing depends on it yet. It needs to exist, so that every exercise in Phases 2 through 4 has somewhere real to land.
What Done Looks Like — Day 90

A storefront taking orders on a domain you own, served from a machine you control. One master record deciding every price and quantity, with nightly off-site backups you have personally restored. Marketplaces and classifieds fed automatically from that master and closeable without harm. Labels printing from the order record, tracking on your own subdomain, a daily digest replacing dashboard anxiety — and a suspension email demoted from extinction event to inconvenience. Every item on that list is a diagnostic in this manual; the scorecard at the back measures the distance, and the calendar in Appendix A walks it a day at a time.

The Operator's Letter

FM-01 · ii
WestNet
Three decades in commerce
Calgary · Alberta
Abdou Express — One Stop Shop

Calgary, Alberta

In the spring of 2020 the global supply chain did not slow down. It failed. Factories sealed, freight lanes closed, and the price of medical supply moved by the hour. Demand for one product — respiratory masks — went from ordinary to effectively unlimited in roughly seventy-two hours.

By then I had been in e-commerce for twenty-five years. Abdou Express carried thousands of SKUs — electronics, printer consumables, batteries, automotive parts — sold through my own storefront and fanned out across every channel that would take a listing. When the crisis arrived, I stood up Masks.Health under WestNet N.A. — the product's own name, on the health top-level domain. Understand what that address meant in the spring of 2020: the single most demanded product on earth, reachable at the domain that literally names it. No marketplace listing buried in sponsored results, no seller account at anyone's mercy — the address itself was the storefront. I pointed that quarter-century of infrastructure at the hardest logistics problem of the decade: procure, list, price, sell, and ship medical supply at volume, into a market repricing itself faster than a person could type.

The infrastructure held. Not because it was sophisticated — much of it ran on hardware most consultants would have condemned — but because every layer of it answered to me. The catalog lived in my own database. Listings were generated, not typed. When a sales channel failed, and channels failed weekly that spring, its entire presence was rebuilt from the master record by script, and shipping continued. In the same months, I watched capable sellers with seven-figure run rates go to zero in a single email — not because demand disappeared, but because their whole operation existed inside an account that somebody else controlled.

That season reduced to one principle, and this manual is that principle worked out in full: a platform is a sales channel, not a foundation. Amazon can suspend an account on a Tuesday morning. eBay can hold funds pending review. Shopify can reprice its terms at will. None of this is misconduct; it is what the agreements say. A business whose catalog, customers, and order flow live inside those agreements is not an asset its owner controls. The audit in these pages measures exactly how much of your business that describes — and then removes the dependency, system by system, over ninety days.

Every procedure here comes from production: the schema discipline, the channel engines, the reconciliation loops, and the failures — documented as field reports, with their causes and corrections — that produced each rule. Work the manual honestly. The diagnostics are strict because December is strict.

Abdou Traya

Founder — Abdou Express · Masks.Health · WestNet N.A.

April 2020 Canada Post Priority envelope, stickered urgently needed medical supplies — label obscured Stacked cartons of Level 1 masks, each carrying the urgently-needed-medical-supplies sticker Outbound envelopes under the operation's own WestNet-branded shipping labels, beside the Masks.Health mask-order mailer — addresses obscured
Figure ii-1 · Spring 2020, from the operation's archiveLeft: a Canada Post Priority envelope leaving the pipeline, carrier-stickered for urgent medical supply. Center: mask cartons staged outbound, same sticker, applied by the case. Right: envelopes under the operation's own printed shipping labels beside the Masks.Health mailer of the period. Addresses and label details obscured. These photographs exist because the fulfillment system photographs shipments as a matter of procedure — evidence discipline, applied to logistics.

The Ten Axioms

FM-01 · iii

Everything in the four phases descends from these ten statements. Each is stated once here and then enforced by specific diagnostic items later in the manual. Each one exists because its violation, at some point in twenty years of operation, produced a documented failure.

  1. Every platform you do not run makes you a tenant. Tenancy is an acceptable arrangement for a sales channel and a fatal one for a foundation.
  2. There is exactly one master record. One database decides what exists, what it costs, and how many remain. Every other copy is a projection.
  3. Marketplaces are satellites. They receive data from the master. They do not write back to it, with the single exception of orders through an audited importer.
  4. Every human retype is a defect. A person re-entering data that already exists digitally is functioning as a slow, error-prone interface between systems that should be connected.
  5. Propagation latency is measurable, and it is money. The interval between a decision and that decision being live on every channel is quantifiable margin loss.
  6. Write, then read back, then believe. No automated write is confirmed until an independent read verifies it — ideally from the public side, as a customer would see it.
  7. Locks precede loops. Any scheduled job will eventually run longer than its interval. Without a non-blocking lock, its invocations will stack until they exhaust the machine.
  8. Control outranks capacity. Modest hardware you fully control is a stronger foundation than rented infrastructure that can be repriced or revoked.
  9. Channels die; catalogs do not. Plan on the assumption that any satellite account can be closed tomorrow. The measure of readiness is the time required to rebuild it from the master record.
  10. Automation is complete when the operation passes the 3 a.m. test: orders flow, inventory synchronizes, listings renew, and failures report themselves, with no one awake.
Phase 1 of 4

The Dependency Audit

Establish where the business actually lives.

DAYS 1 – 14 · MEASUREMENT ONLY — NOTHING IS CHANGED IN THIS PHASE

1.1  The Suspension Simulation

P1 · 1.1

Begin with one written exercise: assume your largest sales channel suspends your account tomorrow at 09:00, without warning and without a stated reason. Document, in the table below, what stops and for how long. This is not a hypothetical scenario; it is a standard event in platform commerce, executed by risk algorithms at scale, and the 2020 crisis multiplied its frequency.

Note that selling on two platforms is not diversification if both use the same payment processor, the same manually-duplicated catalog, and the same class of risk model. Diversification is measured at the level of failure domains, not logos.

Channel% of monthly revenueWho holds the customer recordWho holds the funds, and how longDays to replace this revenue if closed today
Channel 1:
Channel 2:
Channel 3:
Own storefrontYou, if it existsYour processor
Interpretation

If the "own storefront" row reads zero — or the row does not exist — the business under audit is not an e-commerce operation. It is a supplier to somebody else's e-commerce operation, working under revocable permission. That is a legitimate arrangement only if it is a deliberate one, priced accordingly.

1.2  The Latency Measurement

P1 · 1.2

Propagation latency is the elapsed time between an operational decision — a price change, a stock-out, a new SKU — and that decision being live on every channel. It is the single most honest measurement of infrastructure quality, because it cannot be estimated flatteringly: it is taken with a clock.

Execute each event below once, in production, and time it to live-everywhere. Human steps count in full; if a step waits until "someone gets to it," the waiting is part of the measurement.

EventSystem changed firstPropagation path (every hop)Measured time to live-everywhereHuman touches en route
Price change, 1 SKU
Stock-out, 1 SKU
New product, 1 SKU
Bulk reprice, 100 SKUs
Reference Bands

Under five minutes to live-everywhere with zero human touches is enterprise-grade. Under one hour, automated, is workable. A result measured in days, or dependent on a person's availability, means the operation is either selling at stale prices or overselling stock during every propagation window. In 2020, mask pricing moved faster than a human could retype it across channels; operations with single-touch propagation repriced in minutes, and operations without it absorbed the difference as losses.

1.3  The Manual-Entry Census

P1 · 1.3

Trace the full life of your product data, from supplier to sold, and record every point where a person re-enters information that already exists in digital form somewhere in the operation. Each instance carries three costs: the wage paid for the entry, the latency it adds, and an error rate that compounds with volume. A price retyped in four systems is not verified four times; it is exposed to four opportunities for a misplaced decimal to reach a public listing.

#Data retypedFrom → toPerformed byTimes / weekMinutes eachWeekly cost (wage × time)
1
2
3
4
5

Multiply the weekly total by fifty-two and record the annual figure. This census is revisited in Phase 4, where each row is either automated, absorbed into the master record, or accepted in writing with a stated reason.

Web Edition Tool · 01

Retype-Tax Calculator

A fast estimate for the most common census row — price and stock changes re-entered per channel. Enter your numbers; the figure updates as you type and is saved on this device.

Hours spent re-typing
Annual retype tax

The figure excludes the error cost — the mispriced listings and oversells that each manual entry risks — and the latency cost measured in §1.2. Treat it as the floor.

1.4  The Single-Source Test

P1 · 1.4

Ask the operation one question: which system decides how many units of a given SKU exist? A sound operation answers in one sentence. An answer that requires qualification — the store says one number, the marketplace another, and a spreadsheet is what staff actually trust — means there is no master record; there are several databases in unmanaged disagreement, and the disagreement is discovered by whichever customer orders the unit that was already sold.

Every oversell in this industry has the same root cause: two systems each believed they owned the quantity, and both sold the last unit. Complete the table for your three fastest-moving SKUs:

SKUEvery location a quantity is storedWhich is authoritativeHow the others learn of a changeWorst-case disagreement window
Field Report 1The Silent Save Failure

A production storefront stopped persisting customer configuration data. The administrative interface reported success on every save; the files on disk never changed. The root cause was a file-ownership mismatch introduced during routine maintenance: the web server's user could no longer write the data files the application depended on, and the application layer discarded the failure without logging it. The condition was discovered by a paying customer, after an unknown period of silent loss, and was resolved with a refund and a permissions audit.

Correction AdoptedSuccess messages are claims, not evidence. Every write path is now verified by an independent read-back, and file ownership on application-writable data is audited on a schedule, with the same seriousness as credentials. Both practices appear as diagnostic items below and as design rules in Phase 2.

1.5  The Take-Rate Audit

P1 · 1.5

The final Phase 1 measurement is the one most sellers have never computed end-to-end: of every hundred dollars a customer pays, how many do you keep? Marketplace selling stacks costs that are individually tolerable and collectively decisive — the referral commission, fulfillment and storage where used, and the advertising that visibility increasingly requires as marketplaces convert search placement into auctioned inventory. Selling on owned infrastructure carries one material per-order cost: payment processing.

MARKETPLACE SALE — TYPICAL FEE STACK$100 GMV
OWN STOREFRONT SALE$100 GMV
Referral commissionFulfillment / processingAdvertising for visibilityRetained

Illustrative composition using commonly published marketplace rate ranges; enter your own category's numbers below. Own-storefront retention excludes your fixed costs — hosting, which Phase 2 showed is a machine you own, and the marketing you choose rather than rent.

Web Edition Tool · 02

Take-Rate Calculator

Your item, your category's real rates. Net-per-unit on a marketplace versus your own storefront (card processing assumed at 2.9% + 30¢), and the annual difference at your volume.

Marketplace net / unit
Own storefront net / unit
Annual difference

The point is not that marketplaces are never worth their take — Phase 3 treats them as legitimate satellites. The point is that the number must be known, per channel, per quarter, and compared against a written threshold. Diagnostic 3.14 will ask whether it is.

Diagnostic 1 — Platform Dependency & Data Custody
PASS ONLY IF PROVABLE ON INSPECTION TODAY · NO PARTIAL CREDIT
Audit itemPassFailN/A
1.01 — Less than 50% of gross revenue flows through any single account the business does not own.Concentration above half in one revocable account is an existential dependency.
1.02 — A storefront operates on a domain the business owns, on infrastructure it controls or can relocate within 24 hours.A subdomain inside a platform is a booth in that platform's building, whatever the branding says.
1.03 — A complete, current, machine-readable export of the catalog (every SKU, price, quantity, image) exists outside every platform.A catalog that exists only inside a platform is that platform's catalog.
1.04 — Customer contact records (where lawfully collected) are held outside every platform.Marketplaces withhold buyer identity deliberately; the direct customer list is the asset being withheld.
1.05 — The Suspension Simulation (§1.1) has been completed in writing within the last quarter.A continuity plan that has never been written has never been tested.
1.06 — Measured propagation latency for a single price change is under 60 minutes, automated, with zero human touches.Per §1.2, taken with a clock. Estimates do not qualify.
1.07 — A stock-out on any channel propagates to all other channels without human observation as the trigger.If a person is the synchronization mechanism, the oversell rate is a function of their schedule.
1.08 — The Manual-Entry Census (§1.3) totals under two person-hours per week.Above this threshold, the operation employs people as interfaces between unconnected systems.
1.09 — One named system is authoritative for every SKU's quantity, and all staff give the same answer to "which system decides."Disagreement among staff reflects disagreement among databases.
1.10 — Every data file the web application writes has passed a permissions audit within 90 days, and writes are verified by read-back.Field Report 1. Silent save failures are otherwise discovered by customers.
1.11 — Every scheduled job that touches inventory can be named from memory, with the location of its log.Unknown automation is not automation; it is an unmonitored actor with write access.
1.12 — The storefront and its payment processing share no single kill-switch with the largest marketplace channel.A shared parent company or processor is a shared failure domain.
SCORE: UNANSWERED: NOT SCORED
TEAR-SHEET · COPY BEFORE USE

Phase 1 — Dependency Risk Register

One line per external dependency: platform, processor, courier, data feed. Reviewed monthly. Any entry scoring 3 or above in both columns is a Phase 3 conversion candidate.

DependencyWhat stops if it stopsLikelihood (1–5)Damage (1–5)Exit or fallback (one line)
Phase 2 of 4

The Master Record

One authoritative database, under your control, from which everything else derives.

DAYS 15 – 45

2.1  Infrastructure Under Your Control

P2 · 2.1

The systems that carried a national-scale medical supply operation through 2020 ran on consumer-grade hardware of considerable age. This is stated not as a recommendation for old equipment but as evidence about what actually matters: control, not capacity. Sovereignty does not require a data center. It requires that the storefront, the database, and the files run somewhere that cannot be repriced, suspended, or discontinued by a third party's product decision. A used tower in an office qualifies. An inexpensive virtual server that can be re-imaged and relocated in an afternoon qualifies. A commerce SaaS whose export function defines the limit of what you can take with you does not.

The Stack, and Why It Is Deliberately Unfashionable

A web server, a scripting runtime, and a relational database, together on one machine — the arrangement the industry has spent fifteen years calling obsolete — remains the most efficient retail architecture available to an independent operator, for a reason rarely stated plainly: everything is one memory bus away. When the page process and the database share a machine, a catalog query costs microseconds and no network hop; there is no service mesh to fail, no per-request egress meter running, and no third party's outage that can take the storefront down. The efficiency practices that matter are old and boring — opcode caching on the scripting layer so code compiles once, indexes on every column a query filters by, connection reuse instead of reconnect-per-page, static assets served with long cache lifetimes so the disk is not asked twice for the same logo — and together they let a modest single machine serve a catalog of thousands of SKUs with headroom to spare. Phase 4's worker arithmetic completes the picture.

This is also the honest argument against building on rented cloud: the cloud is somebody else's computer, somebody else's invoice, and somebody else's deprecation schedule — a landlord relationship (Axiom 1) applied to the infrastructure layer itself, with pricing that punishes exactly the traffic success brings. A sovereign operation is vertically integrated instead: storefront, database, image pipeline, label generation, the printer on the LAN, the tracking portal, the barcode endpoint — every layer in-house, on hardware the operation owns, each layer feeding the next with no rented seam in between. Every system in this manual assumes, and rewards, that posture.

2.2  The Master Products Table

P2 · 2.2

Everything in the operation projects outward from one table. The following is the minimum viable master record, refined across thousands of production SKUs; adapt names to your storefront software, but keep every constraint.

Reference Schema

CREATE TABLE master_products (
  id           INT UNSIGNED AUTO_INCREMENT PRIMARY KEY,
  sku          VARCHAR(32)  NOT NULL UNIQUE,   -- issued once, never reused
  upc          CHAR(12)     NULL,           -- valid check digit or NULL (2.6)
  title        VARCHAR(255) NOT NULL,
  price_cents  INT UNSIGNED NOT NULL,        -- integer minor units only
  qty          INT          NOT NULL DEFAULT 0, -- the only authoritative quantity
  status       ENUM('active','paused','retired') NOT NULL,
  cost_cents   INT UNSIGNED NULL,
  image_key    VARCHAR(64)  NULL,          -- deterministic, e.g. p<id>.jpg (2.5)
  updated_at   TIMESTAMP    NOT NULL DEFAULT CURRENT_TIMESTAMP
                  ON UPDATE CURRENT_TIMESTAMP, -- maintained by the database
  KEY idx_status_updated (status, updated_at)
) ENGINE=InnoDB;  -- row-level locking; see Phase 4, Field Report 5

Three of these decisions carry most of the weight:

Storefront software — an osCommerce-lineage cart, WooCommerce, a purpose-built catalog — either uses these tables directly or is a downstream projection of them. What is not permitted after Day 45 is any channel, spreadsheet, or employee's memory holding a quantity the master does not know about.

2.3  Bulk Operations Against the Database

P2 · 2.3

An administrative dashboard — including your own storefront's — is one client of the database, and for bulk work it is the wrong one. Forty new SKUs entered through an admin panel is an afternoon of page loads; the same forty SKUs as a single SQL transaction is seconds. Operating directly on the master record is a standard capability of a sovereign operation. It is performed under a fixed discipline:

  1. Snapshot first. Before any bulk write, dump the affected tables to a dated file. An error against eight thousand rows is a ninety-second rollback if the snapshot exists, and an incident if it does not.
  2. Rehearse with SELECT. Run the exact WHERE clause as a SELECT and inspect the row count and a sample. An expected 120 rows returning 8,000 is the error caught at the rehearsal stage, where it costs nothing.
  3. Transactions for multi-table changes. Products, descriptions, and category mappings change together or not at all.
  4. Read back before believing (Axiom 6). After the commit, an independent query — count, checksum, spot-check — confirms the result, followed by a check of the rendered public page, since the database and the storefront are separated by every cache layer in between.
  5. Record the operation. One line in an operations journal: date, change, reason, row count, snapshot filename.
Field Report 2Diagnosing the Projection Instead of the Source

A category tree on a high-SKU storefront rendered incorrectly for an extended period: branches failed to expand and the active category did not highlight. Repeated fixes were attempted against the rendering layer, because the rendering layer was where the symptom appeared. The actual causes, established much later by examining the data directly, were an incomplete ancestor path being supplied to the navigation code, and a layout-cache flag that had been assumed enabled but had been off throughout. One hour spent querying what the database actually contained resolved what years of adjusting the output had not.

Correction AdoptedDebugging order is fixed: master record first, transformation second, channel rendering last. A projection cannot be more correct than the table it projects, and time spent adjusting a projection without verifying its source is generally wasted.

2.4  The Interchange Layer

P2 · 2.4

Between the master record and the outside world sits a format that every system in commerce can produce and consume — accounting packages, marketplace bulk uploaders, courier tools, and a text editor in an emergency. That format is the delimited flat file, and a sovereign operation treats it with the same discipline as the database. The working pattern: one file per purpose, generated from the master, never edited downstream.

2.5  The Image Pipeline

P2 · 2.5

Past a few hundred SKUs, product imagery is not managed by hand. It is treated as derived data under three rules:

  1. Deterministic naming. The image for product 4117 is p4117.jpg, in one flat directory. Given a product ID, any script, template, or channel exporter constructs the image path without consulting a database or a person. This single convention eliminates an entire category of lookup software.
  2. Automated acquisition with a repair loop. New SKUs receive their primary image by script — from a supplier feed, a manufacturer asset, or a staged photo drop — normalized to standard dimensions and written to the canonical name. A daily job walks the catalog for missing or unreadable images and repairs them, so that missing imagery is a metric, not a recurring chore.
  3. The catalog stores keys, not paths. The master record holds image_key; recompression, resizing, or relocating storage later touches no database rows.
Two Implementation Notes From Production

First: automated fetch jobs must present complete, browser-equivalent requests. A substantial fraction of the web silently rejects anything that resembles a script, and a naive pipeline will report success while collecting error pages saved under image filenames. Fetched bytes are validated as a decodable image before installation.

Second: image libraries have format blind spots — a validator that cannot read a newer format will reject valid files indefinitely. The rejection rule is therefore "confirmed bad," never "could not confirm."

2.6  Identifier Discipline

P2 · 2.6

Identifiers outlive everything else in the operation. A SKU that has been printed on a label, quoted in correspondence, or sold on a channel is never reassigned to a different product. Barcode identifiers additionally carry arithmetic: the final digit of a UPC is a checksum over the preceding eleven, and marketplace ingestion, scanners, and feed validators verify it.

Field Report 3Invalid Check Digits, Surfacing Years Later

Early in one catalog's life, product codes were assigned informally: twelve digits shaped like UPCs, with the check digit chosen arbitrarily. Nothing objected at the time, because the storefront did not validate. Years later, as those items flowed toward stricter channels and modern tooling, each invalid check digit surfaced individually as a rejected feed row requiring investigation. The defect cost nothing at creation and a sustained cleanup effort at scale, long after the context of the original assignments was gone.

Correction AdoptedCheck digits are computed correctly from the first assignment — the algorithm is a few lines of code — validation occurs on write at the master record, and an allocation log records every identifier ever issued, with its product and date. This manual's own catalog number, 731985461059, was allocated under that procedure.

2.7  Orders Are History: Retention and Evidence Discipline

P2 · 2.7

Products are state — they change and the master reflects the change. Orders are the opposite: orders are history, and history is never edited. The order log is append-only from the moment of capture (§2.4's rules apply in full), and it is retained effectively forever, because its value compounds with age in ways that are invisible on the day of the sale:

Lawful-basis note: retain what your jurisdiction permits, secure it like the asset it is (the leads-and-logs class of files must never be publicly readable — audit web-server exposure of data files the same way §1.10 audits their ownership), and treat customer data as borrowed, not owned.

2.8  Standing Up the Store

P2 · 2.8

Readers who arrive at this manual as pure marketplace sellers — no storefront at all — build one in this phase, on the machine from §2.1, beside the master record. This is less work than platform marketing has taught you to believe, and the software choice matters less than four criteria that any candidate must meet:

  1. It runs on your machine. Installed from files you keep, on the stack you control. Anything that only exists as someone's hosted service fails Phase 1 by definition, however good it looks.
  2. It gives you the database. Direct access to its tables, so it can serve from — or be wired to — the master record of §2.2, and so §2.3's bulk discipline applies. A storefront whose data you can only touch through its own admin screens is a landlord with extra steps.
  3. It is boring, documented, and old enough to trust. The reference implementation has run an osCommerce-lineage cart for decades; WooCommerce on your own box, or any mature open cart, meets the same test. Every failure a boring cart can have has already happened to someone who wrote up the fix. Novelty is a liability in the money path.
  4. It can be left. Standard tables, exportable in full, restorable elsewhere. You are not marrying the software; you are renting its rendering layer for as long as it behaves.

The go-live checklist is deliberately short, because ugly and live beats perfect and hosted:

Confidence Note

The store does not need traffic to justify existing. On Day 45 its job is to exist, to take that one test order, and to prove the pipeline. Traffic is Phase 3's problem — generated landing pages, classifieds funneling buyers, parcel inserts converting marketplace customers — and every one of those channels points at a storefront that is already, quietly, working. Sellers who build in this order never launch to silence, because by the time anyone is looking, the machine has been running for weeks.

Working Infrastructure — Get Your UPCs at upc.westnet.ca

The allocation discipline above is available to the reader as a running service. The WestNet UPC Registry at upc.westnet.ca issues retail UPC-A codes with correctly computed check digits, instantly activated and accepted by major retailers — single registrations from $10, with 10-pack, 100-pack, and unlimited enterprise tiers for growing catalogs. Each registration includes the digital certificate and the barcode assets (print-grade PNG and vector SVG), served from one endpoint so a code is drawn identically on a product label, a listing, and a shelf tag. The barcode on this manual's own imprint page was produced by that system, under the same allocation log the register requires. Whether you use this registry or another issuer, the diagnostic items below apply unchanged: valid check digits, validated on write, logged at allocation.

The WestNet UPC Registry portal at upc.westnet.ca — official UPC barcodes with instant activation, registrations from $10
Figure 2-1 · The WestNet UPC Registry — upc.westnet.caThe registry portal: code lookup, instant registration from $10, certificates and barcode assets per code. Twenty-eight years in operation; the identifier infrastructure behind this manual's own catalog number.
Diagnostic 2 — Master Record Integrity
PASS ONLY IF PROVABLE ON INSPECTION TODAY · NO PARTIAL CREDIT
Audit itemPassFailN/A
2.01 — One database table (or tightly joined set) is the declared master for products, price, and quantity, documented and known to all staff.Axiom 2, in writing.
2.02 — The master runs on infrastructure that can be archived, moved, and restored within 24 hours, and a restore has been drilled within the last quarter.A backup that has not been restored is an assumption.
2.03 — A nightly automated database dump and file backup ships off-machine to a second location, unattended.Shared premises are a shared failure domain.
2.04 — Monetary values are stored as integer minor units throughout the pipeline.Floating-point currency eventually publishes its rounding error.
2.05 — Every product row carries a database-maintained modification timestamp, and sync jobs run incrementally against it.Full-table synchronization on every run is deferred failure under load.
2.06 — Inventory-critical tables use a row-locking storage engine.One word in the schema; see Phase 4, Field Report 5, for its absence.
2.07 — A 100-SKU bulk price change can be executed in under ten minutes, including snapshot, rehearsal SELECT, and read-back verification — demonstrated, not estimated.§2.3 as a timed drill.
2.08 — A pre-write snapshot precedes every bulk operation, and an operations journal records each one.The discipline is needed rarely and then absolutely.
2.09 — Every generated feed has a written column contract and exactly one writer; downstream editing is prohibited.Two writers on one feed is two masters.
2.10 — Product images follow a deterministic naming scheme derivable from the product identifier alone.If locating an image requires a search, a system is missing.
2.11 — A scheduled job detects and repairs missing or unreadable product images, validating fetched files as decodable images before installation.Error pages stored under image filenames are the standard silent failure.
2.12 — All UPC/EAN identifiers in the catalog carry mathematically valid check digits, validated on write.Field Report 3. The defect is free today and expensive in year three.
2.13 — SKUs are never reused, and an allocation log records every identifier ever issued.Identifiers are permanent; their reuse corrupts history.
2.14 — Files written by the web application are owned by its user, and a permissions audit runs on a schedule.The permanent prevention of Field Report 1.
SCORE: UNANSWERED: NOT SCORED
TEAR-SHEET · COPY BEFORE USE

Phase 2 — Feed Contract

One copy per generated feed, posted where the feed's consumers can see it.

FieldEntry
Feed name and path
Purpose (one sentence)
Sole writer (system or job)
Consumers (all)
Columns: name — type — nullable — example
Regeneration schedule and trigger
File owner and permissions
Append-only or regenerated whole
Read-back verification method
Phase 3 of 4

Channel Fan-Out

Every channel a projection; every projection disposable.

DAYS 46 – 75

3.1  The Satellite Doctrine

P3 · 3.1

With a master record in place, every sales channel is reduced to what it structurally is: a projection of the catalog. Data flows outward from the master through exporters; orders and inquiries flow back through importers; nothing else crosses the boundary in either direction.

★ MASTER RECORD ★ YOUR DATABASE · YOUR MACHINE Own storefrontthe projection never banned SEO landing pagesgenerated from data Amazon / eBayexport target, not master Kijiji / Craigslistclassifieds engine Walled gardenssame doctrine applies solid — catalog data OUT (exporters) dashed — orders IN (importers)
Figure 3-1 · The Satellite DoctrineSolid lines are the only path by which product data moves. The single inbound write is the order stream, through an importer the operator audits. A channel whose data can overwrite the master has inverted the architecture.

Two rules give the diagram force:

3.2  The Owned Channel First: Generated Landing Pages

P3 · 3.2

Before paying marketplace fees, extract full value from the channel with none: structured catalog data plus one template yields hundreds of indexable, permanent landing pages on your own domain — each answering a specific buyer question, each terminating at your own checkout.

A worked example from production: a compatibility dataset — which consumable fits which machine, in this case printer cartridges — was rendered through a single template into 127 model-specific landing pages, with clean rewritten URLs, structured-data markup, an automatically regenerated sitemap, and reciprocal links between products and their pages. Each page matches the exact phrase a buyer types when a specific machine needs a specific consumable, and each lands the buyer on the operator's own domain rather than a marketplace results page listing competitors alongside. The pages have no per-month cost and do not expire.

  1. Identify the repeating buyer question the catalog data can answer at scale: what fits X, what is compatible with Y, what replaces Z.
  2. One template, one query, N pages. Clean URLs by rewrite rule; a search engine should never see a raw query string where a readable path is available.
  3. The sitemap regenerates on a schedule from the same data.
  4. Landing pages link to purchasable products; product pages link back to their landing pages.
  5. These pages are generated projections, so Phase 2's feed rules apply in full: correct the data, regenerate the page. Page 83 of 127 is never edited by hand.

3.3  The Classifieds Engine

P3 · 3.3

Classifieds — Kijiji in Canada, Craigslist in the United States — are structurally undervalued: free or near-free listings, local buyers with immediate intent, and no ranking algorithm auctioning your visibility to competitors. Their operational friction, which discourages casual sellers at roughly the dozenth manual listing, is precisely what makes them defensible for an operator with generation infrastructure. The engine that operates them at volume has five components:

Field Report 4The Adjacent Category ID

Marketplace posting interfaces resolve every visible choice to an internal numeric identifier. During one bulk classifieds campaign, the engine performed correctly by every internal measure — sessions held, posts published, the state ledger updated — while the ads themselves were effectively invisible, because the category identifier in use, numerically adjacent to the correct one, belonged to an unrelated consumer-appliance category. No error was raised at any point: an incorrect identifier does not fail, it succeeds somewhere unintended. The same campaign established a second property of these systems: location taxonomies are trees in which only leaf nodes accept postings — a region-level identifier bounces or misfiles where a specific city posts cleanly.

Correction AdoptedNo internal identifier is trusted until the live result has been read back from the public side, as a buyer would see it. One verification post per category precedes any bulk run, and the verification is repeated whenever the channel revises its taxonomy. Axiom 6, applied at the channel boundary.
Working Infrastructure — AbdouPost, at calgaryfinder.com/AbdouPost

The engine described in this section exists as a commercial service. AbdouPostpost once, sell everywhere — takes a single listing and publishes it to Facebook Marketplace, Kijiji, eBay, and Amazon simultaneously, running entirely server-side: no browser extension, no computer left on, sessions and renewals managed the way §3.3 prescribes. It is operated on the same infrastructure that runs CalgaryFinder.com and Abdou Express, and it is built for exactly the operators this phase addresses — dealerships, realtors, pawn shops, resellers, and power sellers, where one additional sale per month covers the service. It is also the honest answer to the walled-garden problem of §3.6: a channel you cannot script yourself is a channel you staff or license, and AbdouPost is that capability as a managed service.

AbdouPost at calgaryfinder.com/AbdouPost — post once, sell everywhere: server-side posting to Facebook Marketplace, Kijiji, eBay and Amazon
Figure 3-2 · AbdouPost — calgaryfinder.com/AbdouPostThe multi-channel posting engine as a product: one listing in, four channels out, server-side. The architecture on this page — single source listing, per-channel publishers, no client machine — is the satellite doctrine of Figure 3-1 in commercial form.

3.4  Marketplaces as Export Targets

P3 · 3.4

Nothing in this manual argues against selling on Amazon or eBay; they are large rivers of buyers. The doctrine concerns architecture: they are retail outlets the operation stocks, not systems the operation lives in. The distinction is auditable:

3.5  Loss-of-Channel Readiness

P3 · 3.5

The operating assumption, fixed in Phase 1, is that any satellite account can close tomorrow morning. Readiness for that event is a set of standing practices:

  1. Nothing irreplaceable resides in a channel. Catalog: the master. Images: owned files under deterministic names. Customer contact: captured to the operation's own records at every lawful opportunity — invoices, package inserts, warranty registration, storefront accounts.
  2. One identity per channel, operated within its rules. Account-evasion schemes create a treadmill that ends in the same place with higher losses; the durable alternative to fearing a ban is a business that a ban cannot kill.
  3. Every parcel carries the operation's domain. A marketplace buyer costs a commission once; whether the repeat purchase also pays a commission depends on what the customer remembers. A printed insert is the cheapest customer acquisition in commerce.
  4. The regeneration drill, executed on Day 70: select the smallest live channel and rebuild its full presence from the master record and scripts alone, in a test run, timed. The resulting figure — hours, if the phases were done properly — is the measured size of the risk that platform dependence holds over the operation.

3.6  The Walled Gardens

P3 · 3.6

Some marketplaces — social-network venues and app-only markets — offer no serviceable bulk interface and actively resist automation. This manual does not document techniques against those defenses; any such documentation would be obsolete within a season, and the channels' terms govern in any case. What remains permanently true is that the doctrine does not change: the master record feeds whatever presence is maintained there, the state ledger tracks what is live, the channel justifies its total cost quarterly or is closed, and the harder a garden makes departure, the smaller the share of the business it should be permitted to hold. A channel that cannot be scripted is a channel that must be staffed or licensed — that cost belongs in the quarterly review at its full value, and the staffing works from the same generated templates as everything else, so the manual-entry census stays clean. For operators who want the walled gardens served without building the capability, the managed route is AbdouPost (§3.3, Figure 3-2), which publishes to Facebook Marketplace alongside the open channels.

3.7  Closing the Loop: Labels, the Printer, and Tracking on Your Own Domain

P3 · 3.7

The order pipeline of §3.4 does not end at "order received." A sovereign operation carries the same discipline through the last physical meter — the label, the printer, and the tracking link the customer refreshes for a week. Each of the three is a dependency most sellers hand back to a carrier or a marketplace without noticing.

Working Infrastructure — track.westnet.ca

The production implementation is public: WestNet Tracking at track.westnet.ca tracks WestNet Express shipments alongside Canada Post, USPS, FedEx, UPS, Canpar, and DHL — up to ten tracking numbers in one query — on WestNet's own domain, in WestNet's own styling. Carrier responses are cached and archived on WestNet's side, so a shipment's history remains retrievable long after carriers purge their own records; delivered shipments are archived permanently and never re-polled. It is the loop-closer for every channel in this phase: whatever marketplace or classifieds channel produced the order, the buyer's tracking experience ends on infrastructure the operation owns.

WestNet Tracking at track.westnet.ca — multi-carrier shipment tracking: WestNet Express, Canada Post, USPS, FedEx, UPS, Canpar, DHL
Figure 3-3 · WestNet Tracking — track.westnet.caThe self-hosted, multi-carrier tracking portal: one query box, seven carriers, ten shipments at once, served from the operation's own domain with its own archive — the customer's post-purchase attention kept on owned property.

3.8  Signal Over Noise: The Uncluttered Storefront

P3 · 3.8

One more property separates an owned storefront from every marketplace, and it is not technical: on your own property, nobody is auctioning your customer's attention against you. Open a major marketplace's product page and count what surrounds the buy button — sponsored competitors on the same page as your listing, recommendation carousels, cross-sell rows, program badges, upsell interstitials. That density is not poor design; it is the business model. The marketplace's customer is the advertiser, and your listing is the shelf its ads are sold against.

The cost of that noise lands on two people. The buyer pays in decision fatigue: every additional element on a page competes with the one decision that matters, and a distracted buyer defers, compares, and leaves. The operator pays twice — once in conversion, and once in maintenance, because every widget on a page is code to maintain, cache to invalidate, and a place for failure to hide. Clutter is expensive at both ends of the wire, and the marketplace collects on both.

The reference storefront's homepage carries roughly ninety-six links: a search box, a cart, account controls, category navigation, and products — priced, in stock, with an add-to-cart button. Nothing else. That restraint has held across two decades of the same catalog and two generations of theme, and it is a discipline, not an aesthetic:

The Abdou Express storefront — a clean product grid: surgical masks, software licenses, commercial cleaner, and OEM auto parts with barcoded product cards, no sponsored placements
Figure 3-4 · The reference storefront — AbdouExpress.com / Masks.HealthOne master record, projected without noise: Level 1 surgical masks (the 2020 line, still listed) beside operating-system licenses, commercial cleaner, and OEM Toyota parts, each new-arrival card carrying its barcode on its face. Search, cart, categories, products — and no third party bidding for the customer's attention.
Diagnostic 3 — Channel Fan-Out
PASS ONLY IF PROVABLE ON INSPECTION TODAY · NO PARTIAL CREDIT
Audit itemPassFailN/A
3.01 — Every live channel's listings are generated from the master record; no listing content exists only inside a channel.The regeneration drill depends on this being literally true.
3.02 — No channel writes to the master except order decrements through the audited importer.Axiom 3, enforced at the boundary.
3.03 — A state ledger maps every master SKU to every live listing identifier per channel, and is backed up nightly.Without the map there is no idempotency, and without idempotency, duplicates.
3.04 — Expired or decayed classifieds are detected and renewed automatically on a schedule.Freshness at volume is the position; manually it does not exist.
3.05 — Items marked sold or paused in the master are withdrawn from every channel automatically.A live listing for a dead SKU is an oversell on a delay.
3.06 — Category and location identifiers are verified by public-side read-back before every bulk run.Field Report 4. An incorrect identifier does not fail; it succeeds somewhere unintended.
3.07 — Posting cadence is paced, with delays and daily ceilings, per channel.Every channel has a rate budget whether or not it publishes one.
3.08 — Marketplace exports reconcile after every push: read back the channel's state, compare with what was sent, queue the differences.Partial feed failure is routine; unobserved partial failure is not survivable.
3.09 — Marketplaces receive stock allocations, not the full quantity.Allocations fail as undersells of one channel; mirrors fail as oversells of the business.
3.10 — All channel orders flow through one importer into one fulfillment pipeline.Several pipelines is several businesses, each run part-time.
3.11 — Structured catalog data generates landing pages on the operation's own domain, with an automatically regenerated sitemap.§3.2 — the channel with no fees, exploited first.
3.12 — Every outbound parcel, on every channel, carries the operation's domain to the buyer.The commission was paid to meet this customer once, not every time.
3.13 — The regeneration drill has been executed and timed on at least one channel within the last quarter.§3.5. Readiness is a stopwatch figure, not a feeling.
3.14 — Per-channel total cost of selling is reviewed quarterly against a written closure threshold.Satellites justify their orbit on schedule.
SCORE: UNANSWERED: NOT SCORED
TEAR-SHEET · COPY BEFORE USE

Phase 3 — Channel Ledger

One line per live channel. A line that cannot be completed identifies a channel that is operating the business rather than the reverse.

ChannelIdentity labelSession storeState ledger locationCadence & ceilingsExporter jobClosure threshold (% take)Regen drill: date & time
Phase 4 of 4

Stress-Testing & Automation Hardening

A system is verified under deliberate failure or it is not verified.

DAYS 76 – 90

4.1  The Stacking Incident

P4 · 4.1

Phase 4 opens with the incident that produced most of its rules. It is reconstructed here from logs, in full, because every element of it — the schedule, the lock, the storage engine, the memory ceiling — is an ordinary default that thousands of operations are running at this moment.

Field Report 5Scheduled-Job Stacking Under a Held Lock

Configuration. An inventory synchronization job, scheduled every minute. Each run normally completed in seconds, so the one-minute interval had months of uneventful history. The tables it wrote used a table-locking storage engine, unchanged from the software's defaults years earlier. The job had no lock guard, because it had never needed one.

Trigger. One morning, an unrelated long-running query held a lock on a table the synchronization needed. The scheduled run blocked and waited. The scheduler, which has no knowledge of a previous run's state, started the next invocation one minute later, which queued behind the first. Invocations continued to accumulate, each holding a database connection and its own memory.

Cascade. The queued jobs held locks of their own, which blocked the storefront's ordinary page queries. Web requests began to hang; the web server responded by spawning additional workers — more than a hundred and thirty at peak — while visitors retried. One runaway process grew past eight gigabytes of memory on a sixteen-gigabyte machine, and the kernel's out-of-memory handler began terminating processes without regard for which ones mattered. Every site on the server went down. Elapsed time from nominal operation to total outage: under one hour. Root cause: a scheduling assumption and a storage-engine default, both years old, both invisible until they combined.

Corrections AdoptedFour permanent changes, none exotic: (1) every scheduled job runs under a non-blocking lock — if the previous invocation is alive, the new one exits immediately and logs that it did; (2) hot tables were migrated to a row-locking engine so a single slow write cannot dam the whole table; (3) every job received a hard memory ceiling, enforced by the system rather than by expectation; (4) the web server's worker limit was recalculated from measured per-worker memory against actual machine capacity. Each correction is a diagnostic item below.

The generalized laws, applicable to every scheduled job the operation will ever run:

Web Edition Tool · 03

Worker-Arithmetic Calculator

The honest concurrency ceiling for your web server, from measured numbers. Measure per-worker memory from your own process list under real load — not from a tuning guide.

Honest ceiling
Configure at

"Everything else" includes the database's working set, the operating system, and every scheduled job's ceiling from this phase — at their peaks, not their averages. Configure below the honest ceiling; the margin is what absorbs the day the measurement was wrong.

4.2  Deliberate Failure Drills

P4 · 4.2

With locks and ceilings in place, each is verified the only way that produces knowledge: by attempting to defeat it.

  1. The stacking drill. Artificially extend the synchronization job's runtime past its schedule interval and observe the next invocation exit immediately with a logged refusal. If two instances ever run concurrently, the drill has found the defect at drill cost rather than incident cost.
  2. The interruption drill. Terminate the synchronization mid-run, without warning, and re-run it. A correct system heals on the second pass — no duplicate postings, no double decrements, state ledger intact. Idempotency is demonstrated here or it is absent.
  3. The load rehearsal. Replay a multiple of the worst recorded hour against the storefront, observing memory alongside response time. A machine that completes the hour at 95% memory has reported its capacity for next month; the rehearsal is where that report is read.
  4. The disk-exhaustion drill. Fill the log partition in a test window and observe every job's behavior. Systems are lost to full disks more often than to attackers, and disproportionately on weekends.

4.3  Monitoring Without an Operator

P4 · 4.3

Automation is complete when the operation reports on itself to an absent operator (Axiom 10). The monitoring that satisfies this is inexpensive and specific:

4.4  Reconciliation

P4 · 4.4

Drift occurs in correct systems: a channel glitch, an importer interruption, a unit sold over the counter and unrecorded. The defense is a nightly variance report comparing three figures per SKU — the master's quantity, each channel's believed quantity, and physical count for a rotating weekly sample. Every variance receives a line: SKU, location, magnitude, resolution. Within a month of operation, zero-variance nights are the norm and the report's function is to make exceptions loud. An oversell reaching a customer is thereafter a rare event with a written postmortem, not an accepted cost.

4.5  Closing the Census

P4 · 4.5

Return to the manual-entry census of §1.3. Each row is now dispositioned one of three ways: automated (an exporter, importer, or template now performs it), absorbed (the master record made it unnecessary), or accepted — retained deliberately, in writing, with a reason and a revisit trigger. The census is closed when no human touch in the operation is unexamined. The goal is not zero touches; it is zero undocumented ones.

Census rowDisposition (automated / absorbed / accepted)Job or change responsibleDate closedIf accepted: reason & revisit trigger

4.6  The Peak-Season Playbook

P4 · 4.6

Everything in this phase exists for the fourth quarter, when volume multiplies and every latent defect is called at once. The hardened operation enters peak season under a written playbook, prepared in October, unchanged after mid-November:

  1. The freeze window. No schema changes, no new channel integrations, no storefront redesigns, and no "quick improvements" from the first week of the peak until it ends. Every incident in the archive with a self-inflicted cause traces to a change made during load. Peak season runs on the system as rehearsed, or it does not run.
  2. The rehearsal has a date. The load rehearsal of §4.2 runs against projected peak volume — last year's peak hour times this year's growth, times a safety factor — no later than six weeks out, leaving time to fix what it finds.
  3. Allocations pre-scale. Channel stock allocations (§3.4) are re-budgeted for peak velocity in advance, with the reconciliation loop's cadence increased to match — drift that takes a week to matter in July takes a day in December.
  4. Cutoffs are published, then beaten. Carrier deadlines for the season go on the storefront and in the channel listings with margin held in reserve. The reserve absorbs the storm, the courier backlog, and the box that comes back — and every parcel that beats the promise is a review.
  5. The digest goes twice daily. The §4.3 morning digest gains an evening edition for the season. Same content, doubled cadence, still no dashboards to sit and watch.
  6. Exceptions get a human rota. Automation handles the flow; the playbook names who handles the exceptions — the variance report line, the failed feed row, the customer whose parcel stalled — with hours and a handoff. Undefined responsibility at 10× volume is how exceptions become refunds.
  7. January holds the postmortem. One page, written while it is fresh: what held, what strained, what the rehearsal missed. It is the first input to next October's playbook, and the annual proof that the operation learns on schedule.
Diagnostic 4 — Automation Hardening
PASS ONLY IF PROVABLE ON INSPECTION TODAY · NO PARTIAL CREDIT
Audit itemPassFailN/A
4.01 — Every scheduled job runs under a non-blocking lock; a live previous instance causes immediate, logged exit.The permanent prevention of Field Report 5.
4.02 — Every scheduled job has a memory and/or runtime ceiling enforced by the system.A job policy cannot terminate will be terminated by the kernel, with bystanders.
4.03 — Web server worker limits are computed from measured per-worker memory, and headroom is monitored.Arithmetic, verified against the actual machine.
4.04 — The stacking drill has been executed: a deliberately extended run proved the lock holds.Locks are demonstrated, not assumed.
4.05 — The interruption drill has been executed: a mid-run termination followed by a re-run healed with no duplicates and an intact ledger.Idempotency is a demonstrated property.
4.06 — A load rehearsal at a multiple of the worst recorded hour has run this quarter, with memory observed alongside latency.Peak season arrives whether or not it was rehearsed.
4.07 — Every job writes a heartbeat; a watchdog flags staleness; a dead job is detected by silence within one cycle.The failure mode that matters is the one the job cannot report.
4.08 — The storefront is probed from the public side, browser-equivalent, on a schedule.The operation's own defenses filter naive probes, in both directions.
4.09 — Error-log rates are monitored, not only error patterns.Familiar lines at unfamiliar rates are an event.
4.10 — A nightly variance report reconciles master, channel, and physical counts, and every variance receives a logged resolution.Drift is inevitable; unobserved drift is elective.
4.11 — An automated daily digest summarizes orders, heartbeats, variances, and machine headroom in one message.Monitoring that requires attendance is staffing, not monitoring.
4.12 — The manual-entry census is closed: every remaining human touch carries a written disposition and revisit trigger.Zero undocumented touches.
4.13 — A cron register lists every scheduled job with its lock, ceiling, log, and owner, current as of this week.Item 1.11 asked for recall; this closes it in writing.
4.14 — The full stack has passed the 3 a.m. test for 14 consecutive days: orders flowed, synchronization ran, failures self-reported, and no human intervened.Axiom 10. This is the graduation criterion.
SCORE: UNANSWERED: NOT SCORED
TEAR-SHEET · COPY BEFORE USE

Phase 4 — Cron Register

Every scheduled job in the operation, without exception, reviewed monthly. A job absent from this sheet is not authorized to exist.

JobScheduleLock mechanismMemory / runtime ceilingLog locationHeartbeat checkOwner

The Sovereignty Scorecard

FM-01 · S

Four diagnostics reduce to one figure: passes over applicable items, across all fifty-four. In this edition it computes from the selections above; in print, the tally is carried here by hand.

DiagnosticScorePass / applicable
Complete the diagnostics above.

Complete the four diagnostics to compute a verdict.

BandVerdictReading
85 – 100%Sovereign OperatorCatalog, customers, and order flow survive the loss of any single platform, account, or machine. The channels work for the operation. Maintain the quarterly drills; expand the fan-out.
60 – 84%Tenant With a PlanThe exits are identified and some are built. Rank every failed item by likelihood times damage, from the Phase 1 risk register, and close them in that order. Most operations at this band complete the work in one further quarter.
Below 60%One Suspension From ZeroThe verdict is literal: a single account decision at a company with no knowledge of this business separates it from zero revenue. The first corrective action is item 1.03 — a complete catalog export, held outside every platform, tonight.

Your answers, worksheet notes, and calendar checkmarks are stored only in this browser — nothing is transmitted.

The Final Page

The Closing Letter

What the completed audit establishes, and the two ways forward from it.

If you worked this manual honestly, you now hold something few sellers ever produce: an itemized, scored account of every point where your operation depends on someone else's permission. Each failed item corresponds to a system documented in these pages — a master schema, an exporter, a state ledger, a reconciliation loop, a watchdog. None is beyond a competent operator. The designs are complete as written, and building them yourself is a legitimate road; the appendix calendar is sequenced for exactly that.

The honest accounting is that the road has length. Each failed item represents somewhere between a weekend and a month of engineering, and the dependency the audit measured continues at full weight while the work proceeds. It took me years to make these mistakes and derive the corrections in this manual — the invalid check digits, the silent save failure, the stacked jobs at dawn, one global supply-chain failure as the final examination. The manual shortens your road considerably. It does not shorten it to zero.

So the offer, stated once: the infrastructure this manual audits for exists as production software. The WestNet Commerce Engine is the master record, the exporters, the classifieds engine, the reconciliation loops, and the watchdogs described here, licensed as a working stack and fitted to your catalog — so that the ninety-day audit becomes a ninety-day deployment, with your failed items as the work plan. It was built where this manual says it was built, and it is in production today.

Build from the blueprint, or license the machine. Either way, do not remain a tenant.

Abdou Traya

Founder — Abdou Express · Masks.Health · WestNet N.A.

Engine — Self-Hosted License
$9,500 one-time · first-year support included

The full stack installed on your hardware or VPS. Schema, exporters, state ledgers, hardening, handover session.

Engine — Deployed & Managed
$2,500 setup + $490 / month

Deployed and fitted to your catalog and channels; monitoring, reconciliation, and renewals managed. Your data remains exportable in full, at any time.

Full Sovereign Buildout
$25,000 complete, 90 days

The entire manual executed for you, all four diagnostics driven to pass. The scorecard is the acceptance test.

QR code for the WestNet Commerce Engine licensing page

www.westnet.ca/learning/Sovereign-Commerce/license.htm

Workbook owners: the $150 purchase is credited in full against any tier. Bring the scorecard — the failed items are the deployment plan.
WestNet N.A. · Calgary, Alberta · 403-813-7045

Appendix A — The 90-Day Calendar

FM-01 · A
DaysObjectiveDeliverable (provable)
1–3Suspension Simulation; Dependency Risk RegisterCompleted §1.1 table and Phase 1 tear-sheet
4–7Propagation latency measurementsCompleted §1.2 table, timed with a clock
8–11Manual-Entry Census; Single-Source Test§1.3 and §1.4 tables; annual cost figure recorded
12–14Diagnostic 1 scored; full catalog export secured off-platformScore, and a dated export file that opens
15–22Master schema stood up; storefront wired to itSchema in version control; store serving from master
23–29Backups: nightly dump, off-site shipment, restore drillA restore, performed and timed
30–37Bulk-operation discipline; operations journalOne real bulk change under full procedure
38–45Image pipeline; identifier audit; Diagnostic 2 scoredRepair job live; check-digit validation on write
46–53First exporter and state ledger, highest-volume channelChannel regenerated from master in a test run
54–61Classifieds engine: sessions, cadence, renewal automationLedger-driven renewals running unattended
62–68Marketplace allocation and reconciliation; landing-page generatorPost-push difference report; N pages and sitemap live
69–75Regeneration drill; parcel inserts; Diagnostic 3 scoredDrill time recorded on the Channel Ledger
76–80Locks, ceilings, worker arithmetic; stacking drillCron Register complete; drill refusal in the log
81–84Interruption, load, and disk-exhaustion drillsThree drill logs, three clean recoveries
85–87Heartbeats, watchdog, public-side probe, daily digestThe first digest, delivered automatically
88–90Variance report live; census closed; Diagnostic 4 and ScorecardThe sovereignty score, recorded on the scorecard

Appendix B — Glossary

FM-01 · B
TermDefinition
Master recordThe single database that determines what exists, its price, and its quantity. All other copies are projections.
SatelliteAny sales channel: a receiver of projections and a source of orders, closeable at any time without ending the business.
Propagation latencyMeasured elapsed time from an operational decision to that decision being live on every channel.
Manual-entry censusThe itemized record of every point where a person re-enters data that already exists digitally, with its annual cost.
State ledgerThe per-channel map of master SKU to live listing identifier and lifecycle dates; the basis of idempotent posting.
AllocationThe budgeted slice of stock a marketplace receives in place of a mirror of full quantity; its failure mode is an undersell.
Read-back verificationConfirmation of any automated write by an independent read, preferably from the public side. Axiom 6.
StackingThe accumulation of scheduled-job invocations behind a blocked predecessor, absent a non-blocking lock, until resources exhaust.
Leaf-node ruleMarketplace taxonomies are trees in which only leaf nodes accept postings; parent and region identifiers bounce or misfile.
Regeneration drillThe timed rebuild of a channel's entire presence from the master record and scripts alone.
Variance reportThe nightly reconciliation of master, channel, and physical quantities, with a logged resolution per difference.
3 a.m. testThe condition in which orders flow, inventory synchronizes, listings renew, and failures self-report with no operator awake.

Appendix C — The Reference Implementation

FM-01 · C

Every system in this manual corresponds to a component running in production at Abdou Express and WestNet N.A. — most of them for many years, several of them public. The mapping below is provided so the reader can verify the manual's standing claim: nothing in it is theoretical. Internal mechanics are described at the level of architecture; the operating specifics of any carrier, channel, or defense are the operator's own business, yours and mine alike.

Manual systemProduction implementation
Master record (§2.2)A MySQL catalog serving the storefront continuously since the 1990s — thousands of live SKUs across software, consumables, cleaning products, and OEM auto parts; hot tables on a row-locking engine since the incident of Field Report 5.
Bulk operations (§2.3)Administrative CSV import plus direct SQL under the snapshot / rehearse / read-back procedure, journalled per operation.
Supplier ingestion (§2.4)Feed processors that ingest supplier catalogs — auto-parts lines among them — normalizing price, stock, and imagery into the master without a keystroke of retyping.
Image pipeline (§2.5)An image manager that fetches, validates, and installs product photography to deterministic per-product filenames, with a daily self-heal pass for missing or unreadable files.
Identifier discipline (§2.6)The WestNet UPC Registry (Figure 2-1); storefront product cards carry their barcodes on the card face, drawn by the same endpoint that produced this manual's imprint barcode.
Generated landing pages (§3.2)127 printer-compatibility pages generated from one template and one data table, with pretty URLs and a sitemap regenerated on schedule.
Classifieds engine (§3.3)The bulk posting system behind AbdouPost (Figure 3-2): persistent sessions, a JSON state ledger per channel, paced posting, automated renewal.
Marketplace exports (§3.4)Feed-based Amazon and eBay projection from the master record, with allocation quantities and post-push reconciliation.
Fulfillment loop (§3.7)Labels generated from the order record, printed direct-to-Zebra over the LAN; tracking served to customers at track.westnet.ca (Figure 3-3) with a permanent archive.
Hardening & monitoring (Phase 4)Non-blocking locks on every cron, per-process memory ceilings, worker limits from measured arithmetic, heartbeat watchdogs, and the daily digest — each one adopted after the field reports in this manual.
The 2020 proofMasks.Health, stood up under WestNet N.A. during the supply-chain failure, still serving from the same infrastructure — surgical masks listed alongside the rest of the catalog, as they were in 2020.

The storefront itself is shown at Figure 3-4 — masks beside operating systems beside OEM parts, one uncluttered grid. On the significance of the Masks.Health address: in 2020 it was the plainest possible demonstration of the whole doctrine — the most demanded product on earth, at the domain that names it, on infrastructure no platform could suspend.

Cartons of medical face masks labeled medical@westnet.ca staged on a hand truck over a wrapped pallet Outbound poly mailers under WestNet-branded shipping labels — addresses obscured A mixed outbound batch: Xpresspost tube, envelopes, and certified mail under the operation's own labels — addresses obscured Xpresspost parcels under WestNet-branded labels — addresses obscured Carton stack staged for an FBA shipment, urgent medical supply stickers applied by the case A shrink-wrapped liquidation pallet arriving for the AbdouExpress.com catalog
Figure C-1 · The order flow, photographed by procedureFrom the same archive as Figure ii-1, spanning the operation's inbound and outbound sides: mask cartons addressed for medical distribution, batches of outbound mailers and Xpresspost parcels under the operation's own printed labels, cases staged for marketplace fulfillment, and an inbound liquidation pallet feeding the catalog. Addresses and label details obscured throughout. Every frame exists because §2.7 makes the camera part of the packing bench.

Appendix D — About the Author

FM-01 · D

Abdou Traya is the founder of Abdou Express, a multi-channel retail operation that has run for three decades on self-hosted infrastructure, listing and synchronizing thousands of SKUs across an owned storefront, classifieds networks, and major marketplaces. By 2020 he had twenty-five years in e-commerce; that year he established Masks.Health under WestNet N.A., applying the accumulated infrastructure to the procurement and distribution of medical mask supply at scale through the global supply-chain failure. The systems described in this manual are the systems that operation ran on, together with the corrections earned from their documented failures. He operates from Calgary, Alberta.

Field operations, in public: AbdouExpress.com · Masks.Health · facebook.com/AbdouExpress · facebook.com/WestNet

Sovereign Commerce · WestNet Operator Series, Field Manual 01 · Catalog UPC-A 7 31985 46105 9
WestNet Publications · WestNet N.A. · Calgary, Alberta · westnet.ca/learning