Owning a retailer's entire technical platform, and holding it to one standard
One architect, our principal, owns a luxury retailer's whole technical estate: point of sale, staff and customer applications, identity, telephony, and an AI assistant layer, rebuilt from an inherited, broken integration into one platform held to a single rule: every decision defensible as the long-term-correct one.
Anonymized case study. A luxury menswear retailer; name withheld. The retailer's own vendors and products are generalized. Describes the system, not how it was built. Engagement led by Ryan Luccioni, principal.
The estate
What we inherited
The retailer's systems had been in place for years before we touched them, and the existing implementation was broken at the foundation. The clearest example: the data had two databases with no referential integrity between them. One held who was a VIP member, the other was the point-of-sale record, and nothing reliably linked them. ~11,000 associations were wrong. We reconstructed them with SQL matching down to the last ~400 pairs, which our principal resolved by hand: best-effort, labeled as best-effort, no false precision.
That was the first phase: database surgery and mapping the workflows we'd later rebuild the platform around.
What we built
A single platform, one monorepo, architected and largely implemented by our principal, directing two of the firm's engineers:
- A point-of-sale integration that can't corrupt the POS. The POS is the financial and inventory system of record and is treated as read-only except one owned, authenticated write path. Everything else reads a Postgres read-model kept current by change data capture, so reporting, lookups, and AI queries never compete with live sales traffic on the POS server. (Same desired-state / read-isolation discipline as the VoIP control plane, a different domain.)
- A staff operations console and a customer kiosk, on shared identity (Keycloak) and a shared design system with a defined visual identity.
- An AI assistant layer built on a self-hosted local model, kept on-premises for data residency and cost, and governed by one rule: direct manipulation is the floor, AI is the ceiling. Every screen is fully usable by hand at native speed; the model is never on the critical path, only an additive lane that turns several steps into one sentence when asked. Anything the assistant would do renders as a preview the human confirms. Nothing fires silently.
- Telephony and messaging integrations for customer communications.
- Security we own, not assume: the platform carries its own security CI, and we run penetration testing against it rather than trusting that it's fine.
The standard
The thing that makes this different from a pile of features is a written rule the whole platform is held to: every decision must be defensible as the world-class optimal solution for long-term, pristine architecture and product quality. Not "good enough to ship" but defensible as correct. The principal holds the team to it and enforces it against his own work first.
It rests on one design philosophy we apply everywhere: use AI to leverage judgment, and code to leverage mechanical work. Most teams invert it: a model bolted onto a problem a loop solves better, hand-written logic where judgment was needed. The console's "floor and ceiling" law and the POS read-isolation are the same principle in two places.
Outcome
- One architecture spanning point of sale, two applications, identity, telephony, AI, and security: the full stack of a working retailer.
- Rebuilt from a broken inherited integration into a platform held to a world-class-architecture bar.
- In production and actively running the business today.
This is what platform ownership actually means: not advice from the sidelines. Owning the whole technical estate, setting the standard, and being accountable that it's correct.