ARK BUSINESS INC.  /  MARKETING · SALES · OPERATIONSWINNIPEG, CANADA

01 / WORK / CARS SELECTED, NOT SOLD

CS-001v1.0

Cars Selected, Not Sold

How ARK turned a business philosophy into an operating system.

Automotive · 2026 · MyRide Auto · Build

17 MIN

The code is not the story. The business rules are the story.

04 / SCOPE

MyRide Auto is a Winnipeg dealership that behaves like a concierge: a customer says how they live, the team narrows the market, and three vehicles are recommended — or one, or none. ARK Marketing elevated the brand and runs the acquisition system. ARK Operations built the operating system underneath it: seven applications on one database, a hundred and five record types, thirty-three governed agents, four websites, and every rule the company wrote down enforced by software rather than by memory.

Fourteen decisions, each frozen in a ledger before code was written, each backed by a paper, a law or a failure that made it a decision rather than a taste. This is the record of those decisions and what each one became.

04.1 / ROUTING

Four speeds. One platform.

The dealership funnel has one speed. It treats the person who has found their car and the person browsing on a Tuesday night identically, which serves neither. MyRide has four lanes: Express, Concierge, Explore and Seller. Fast when you are certain, thoughtful when you are not, patient when you are early, invisible when you just want the car.

The lane is the intent, not the person. Express is five questions and a booking in ninety seconds — the account is an outcome of booking, never a prerequisite. Concierge is a brief and a curated three. Explore is tags, a garage and a value watch, with no salesperson until you say so. Seller is a labelled range and a list of what still needs verifying. A curator can move a person between lanes with a reason, and the reason is mandatory: the button does not work without one. Every override is a record, and every record feeds the lab.

Behaviour needs ability as much as motivation. Matching the ask to the person's ability right now is that model as a product.

A PRINCIPLE

Source → Rule → System → Measurement

“AN EXPLORER SHOULD NOT BE PURSUED.”

true, and unenforceable as written

A rule nobody can cross is worth more than a policy everybody has read.

04.2 / CHOICE

Three cars. Or one. Or none.

Twenty-four jams on a table drew a crowd; six sold ten times as many. A marketplace with forty thousand listings is the twenty-four-jam table. The Three is the six-jam table with a curator standing behind it: Best Fit, Best Value, Wild Card — each with its reasoning and each with a replace-this-one button.

The Vehicle Curator scores every candidate on five dimensions — fit, evidence, concern, ownership, economics — and writes the for and against in plain sentences with the fact that produced each one. Then a human selects. Ron's override note on the wild card is on the record: the scorer ranked it fourth on price; he overrode because the brief's use case was the point. AI searches. Humans select. The record shows both.

And when nothing deserves the slot, the scorer says so. Tomasz wanted a manual wagon before ski season. Two candidates, one failed his brief, one failed the standard. The selection set has zero slots and a reason: “None of them is a vehicle we can defend, so we are not recommending one.” That is the sentence a dealership cannot afford to say, and the software says it by default.

RUL-003

A claim requires evidence.

PRINCIPLE

When the seller knows more than the buyer, trust collapses and good stock leaves.

OPERATING RULE

A vehicle file cannot be published without an inspector of record.

SOFTWARE

The controller refuses the state change. An owner's assertion and an inspector's evidence are never quietly merged.

MEASUREMENT

Unpublished files, and the specific evidence each one is missing.
RUL-004

An invented third choice is worse than a short list.

PRINCIPLE

Six jams outsell twenty-four. A fabricated sixth is worse than five.

OPERATING RULE

The scorer may recommend three, one, or none.

SOFTWARE

A selection set accepts a reason for none and stays empty. Nothing forces a slot to fill.

MEASUREMENT

The honest-none rate, reported rather than hidden.

04.3 / TRUTH

Flaws first.

When the seller knows more than the buyer, trust collapses and good cars leave the market. Losses weigh about twice what gains do, so every dealership hides the flaw and every buyer knows it. The vehicle file inverts both: a named inspector, a versioned checklist, evidence, and the flaws printed above the features. A 4 cm star chip. A pen mark the detailer could not lift. Then the line that matters for Danielle: timing chain, not belt.

Every line carries an evidence class. One is marked owner assertion with a review flag, because an owner's statement and an inspector's evidence are never quietly merged. Try to publish the file without an inspector of record and the controller refuses. Not a policy document. A controller.

Nothing on the demo site has a published file — on purpose. A demo is not allowed to claim an inspection it did not have, so every evidence score sits below the floor and the scorer will not fill a slot. An invented third choice is worse than a short list.

04.4 / DATA

Tell MyRide once. Correct us anytime.

Zero repetition. Known facts pre-fill everywhere: finance reuses what sales collected, and the person who booked a drive never types their trade-in again. Every important fact carries a last-confirmed date, and the concierge asks “still accurate?” rather than assuming.

The other half is control. “Why are we asking?” sits on every question; if the answer does not change the recommendation, the question is not asked. Every inference has forget-this, do-not-use and private controls. The passport is an exportable history the customer owns. Delete-my-account honours retention classes instead of pretending finance records can vanish.

One identity across three domains. The company site is the only place money moves. The publication carries the evidence only an operator can produce — why we passed, what we got wrong, owner follow-ups at thirty days, six months, a year. The seasonal site is a car-discovery game. A profile made in any room opens every door.

04.5 / KERNEL

The kernel survives everything.

Assume every elegant idea fails. The community starts empty, the AI is wrong or offline, the vehicle sells mid-questionnaire, the rep ignores the CRM. MyRide is not a funnel; it is a transaction kernel wrapped in optional layers. Vehicle, truth, appointment, numbers, decision, transaction. That path completes with everything above it switched off, and there is a degradation test that turns each product application off in turn and proves it.

Nothing above the kernel may become mandatory. Not the full profile, not the community, not the Three when you have already chosen your car, not an AI conversation. If the seasonal site crashes on Christmas Eve, MyRide still sells a car.

THE KERNEL — MUST COMPLETE WITH EVERYTHING ABOVE IT OFF

VEHICLE

TRUTH

APPOINTMENT

NUMBERS

DECISION

TRANSACTION

ABOVE IT — EACH WITH A KILL SWITCH

  • Full profile
  • Community
  • The Three, when the car is already chosen
  • AI conversation
  • The seasonal site

Nothing above the kernel may become mandatory.

04.6 / GOVERNANCE

Agents observe first. They earn autonomy.

Thirty-three agents — eight services, twenty-four specialists, a chief of staff — and every one deploys at OBSERVE. Each has an identity card: what it reads, what it writes, whether it may contact a customer, where it reports, and its ceiling. No card, no deploy. To send anything to a customer it needs three recorded evaluations and a deterministic rule, and even then the message goes through the same consent gate a human's would.

Twenty-nine decisions are human-owned permanently: credit submissions, deal terms, vehicle claims, disputes, legal commitments. The test suite tries to cross every one with every agent at every rung — 3,828 times — and confirms they all fail. The database is memory, AI is interpretation, the channel is attention, automation is execution. Approve creates a record; the chain executes, never the click.

Eight of the thirty-three, as records:

AGT-001

Sales Copilot

READS

Lead
Customer
Vehicle
Conversation

WRITES

Draft briefing
Suggested response

CONTACT CUSTOMER

No

AUTONOMY

Observe

OWNER

Sales

CEILING

Cannot send. A drafted reply becomes an approved action; a human decides, and the send chain runs — never the click.
AGT-002

Management Agent

READS

Sales
Marketing
Operations
Finance

WRITES

Morning brief

CONTACT CUSTOMER

Never

AUTONOMY

Draft

OWNER

Management

CEILING

Composes the brief. Posting it is an owner decision, and it is held until made.
AGT-003

Vehicle Curator

READS

Buyer brief
Inventory
Vehicle file

WRITES

Candidate score
For and against, with the fact behind each

CONTACT CUSTOMER

No

AUTONOMY

Observe

OWNER

Curation

CEILING

May return zero recommendations, and does. It is not permitted to fill a slot to avoid an empty list.
AGT-004

Vehicle File Reviewer

READS

Inspection checklist
Evidence
Owner assertions

WRITES

Evidence class
Review flag

CONTACT CUSTOMER

No

AUTONOMY

Observe

OWNER

Inspection

CEILING

Cannot publish a vehicle file. Publication requires an inspector of record, a timestamp and evidence, enforced in the controller rather than in a policy document.
AGT-005

Seller Range Drafter

READS

Seller brief
Market observations

WRITES

Labelled range
Verification list

CONTACT CUSTOMER

No

AUTONOMY

Observe

OWNER

Sales

CEILING

Never releases an offer. A committed number needs a named human's approval, and the queue for that human is the morning brief.
AGT-006

Demand Match

READS

Active briefs
Customer-owned vehicles

WRITES

Match signal

CONTACT CUSTOMER

No

AUTONOMY

Observe

OWNER

Acquisition

CEILING

Finds the supply and puts it in front of a person. Contacting the owner is a separate decision, through the consent gate.
AGT-007

Experiment Analyst

READS

Events
Outcomes
Route overrides

WRITES

Correlation note

CONTACT CUSTOMER

Never

AUTONOMY

Observe

OWNER

Lab

CEILING

Cannot promote a correlation to a result. Only a human, from an experiment with a control group, changes an operating rule.
AGT-008

Follow-Up Drafter

READS

Intent
Consent record
Contact history

WRITES

Draft message
Structured reason

CONTACT CUSTOMER

No — through the gate only

AUTONOMY

Observe

OWNER

Sales

CEILING

A draft with no structured reason is refused before it becomes a message. “Just checking in” is banned by name.

04.7 / MANAGEMENT

Dashboards contain information. Management needs significance.

An interruption costs roughly twenty-three minutes to recover from; a CRM that badges everything is an interruption machine. The command centre opens with the five things that need you — severity computed from the facts of each record by one central function, not from anyone's filter — and folds the rest below.

Marcus booked the F-150 for four o'clock, cash, no trade. Two things are wrong and the system knows both: his intent has no curator, and his booking has no briefing. Top of the queue: critical, showroom at 16:00, briefing not drafted. Nobody configured that. It was computed.

Four funnels, never combined; the function that would merge them raises. Every contact suggestion carries a why-now, and “call Sarah” is refused by name. Team performance returns scorecards, not a rank, because the system should not rank people by units alone.

01

3 high-intent leads unassigned

Potential revenue at risk

02

Show rate fell 12 pts this week

Concentrated in evening bookings

03

Meta campaign C CPL +31%

Qualified rate unchanged

04

7 vehicles over 90 days

Capital tied up

05

One integration failed overnight

Fallback active

DSH-001

A dashboard that names the constraint

REVENUE

$418,223

GROSS PROFIT

$94,812

MARKETING SPEND

$31,400

LEAD → SALE

6.8%

GROSS PROFIT / LEAD

$112

AGED INVENTORY

18 units

PRIMARY CONSTRAINT

Appointment show rate

The shape of the record, not a client's figures. The last field is the point.

04.8 / EXPERIMENTATION

Correlation → Hypothesis → Experiment → Result.

The lab will tell you that people who watch the seasonal video close at twice the rate — and label it a correlation in the same sentence, because engaged buyers also watch more videos. Nothing changes an operating rule except a result a human decided, from an experiment that had a control group.

Every feature faces four tests: does it increase funded transactions, reduce time or labour, reduce mistakes or risk, or create supply, acquisition or retention. Unmeasured is its own verdict. And if reps keep bypassing a step and the outcomes hold, the lab produces the candidate to delete the step. The process serves the sale.

The doctrine the whole product hangs on: no fake counters, no fake urgency, no invented third choice, no message without a reason. Every customer-visible number is live and dated, visibly an example, or absent. Every state has a next state. Never make relationship-building necessary to transact; never let transacting end the relationship. That is what “cars selected, not sold” means when you write it as software.

Two men standing side by side in front of a vehicle
Derek and Cam. The owners — the accountability layer behind the experience.
A man handing keys to a customer beside a delivered vehicle
A delivery. Province-wide delivery is the wedge, and the ownership record starts here.

05 / ARCHITECTURE

How the pieces fit.

CUSTOMER SITES

APPLICATION LAYER

ARK INTELLIGENCE

DATA

Click a block to read its job. Sanitised — nothing here is an address, a credential or a port.

06 / WHAT HAPPENS IF IT BREAKS

Assume every elegant idea fails.

BRK-001

STILL WORKS

The transaction kernel. Vehicle, truth, appointment, numbers, decision, transaction.

DEGRADES

The sales interface. Notes and call logs queue rather than write.

FALLBACK

The canonical record is the intent, not the CRM row. An exportable active-deal queue is generated.

NOTIFIED

The sales owner and ARK, immediately.

07 / TESTS

870+

automated tests, framework-free, green

They test the rules the business depends on: routing, permissions, agent boundaries, degradation, data behaviour. A claims guard fails the build if a retired proof number appears anywhere. A tenancy guard fails it if anyone writes a client-ID column.

08 / BUILD LOG

Gates, not dates.

Decisions ledger frozen. Fourteen operating rules, each with its source.

Seven applications on one bench. A hundred and five record types generated from the ledger.

The transaction kernel, and the degradation test that switches every layer off around it.

Thirty-three agent identity cards registered. Every one at OBSERVE. Boundary suite: 3,828 attempts, all refused.

The outbound gate — consent, hours, cadence cap, structured reason. No force flag.

Command centre reading live. A full Winnipeg day seeded through the production functions.

Scope determines actual delivery time. Speed comes after clarity, not instead of it.

09 / CHANGELOG

Software is never finished.

CHG-2026-09-06-01

ADDED

A full Winnipeg day, seeded through the production functions

CHANGED

The command centre now reads live from the site

MEASURED

Four lanes reported separately; unmeasured steps read not measured, never zero
CHG-2026-09-05-01

ADDED

Claims guard: the build fails if a retired proof number appears

CHANGED

Tenancy guard extended to fail on any client-ID column

REMOVED

The manual duplicate-entry step between intake and CRM
CHG-2026-09-04-01

ADDED

Outbound gate: consent, hours, cadence cap, structured reason

REMOVED

The force flag on the send path

FIXED

“Just checking in” is now refused before a row is written
CHG-2026-09-03-01

ADDED

Thirty-three agent identity cards, all at OBSERVE
The AI action log

MEASURED

3,828 boundary crossings attempted, all refused

EVERYTHING, INCLUDING THIS SITE'S OWN →

10 / OUTCOMES

Sourced to this project.

OUT-001

105

canonical record types in one operating system

Seven applications on one database, and one definition of each business fact across all of them. Not 105 tables in 18 tools that disagree — 105 record types with one authoritative home each.

CARS SELECTED, NOT SOLD →

OUT-003

3,828

boundary crossings attempted in the test suite, all refused

Every agent is tried against every permanently human-owned decision at every autonomy rung, and every attempt is confirmed to fail. A rule nobody can cross is worth more than a policy everybody has read.

CARS SELECTED, NOT SOLD →

OUT-004

33

governed AI agents, every one deployed at OBSERVE

Each carries an identity card: what it reads, what it writes, whether it may contact a customer, where it reports, and its ceiling. No card, no deploy. Connecting a language model changes no agent's autonomy.

CARS SELECTED, NOT SOLD →

OUT-005

29

decisions owned by a human, permanently

Credit submissions, deal terms, vehicle claims, disputes and legal commitments are not on a roadmap toward automation. They are fixed to a person, and the test suite proves no agent can reach them.

CARS SELECTED, NOT SOLD →

These are properties of the software. The economic numbers are not yet measured, and the site says so.

11 / LEARNED

The hardest part of the build was not the code. It was getting the company to write its rules down precisely enough that a function could refuse to break them — and then accepting that the refusal, not the feature, is the product. A dealership that says “we are not recommending one” loses a sale today. Whether it earns the next one is the experiment, and it is unmeasured until the first hundred garages are live.

12 / NEXT

Cars Selected, Not Sold — how the business should behave.

The Road to Launch →

How the system becomes real.