Work/KIR
A test-drive platform where the car cannot leave until the paperwork is right.
A prestige used-car dealership in Melbourne was running test drives and loan cars through an off-the-shelf app that didn't fit how their floor actually works. They sent me a detailed brief: licence scanning, electronic agreements, loan tracking and live reporting. I built KIR, a multi-tenant platform with their dealership as the first tenant.
- Client
- A prestige used-car dealership, Melbourne
- Industry
- Automotive retail
- Services
- Product design, custom software, integrations
- Stack
- React, FastAPI, PostgreSQL, Redis
- Timeline
- Phase 1 from September 2026, three weeks to go-live

The problem
A test drive at a prestige dealership is a few hundred thousand dollars of someone else's car leaving the lot with a stranger. Before it goes, a salesperson has to check the licence, record the odometer and condition, and get an agreement signed. Loan cars add expected returns, extensions and the awkward phone call when one doesn't come back. As their dealer principal put it, the old app made the salesperson fit the software, when it should have been the other way around.
Their brief asked for all of it in one place, on whatever device was in the salesperson's hand: phone, tablet or desktop. It also asked for privacy controls that most dealership software treats as an afterthought, because a driver licence is the most sensitive thing the system would hold.
What I built
KIR is an installable web app for the floor and a FastAPI backend behind it, built so native iOS and Android apps can sit on the same API later. Every screen opens on the day read as a sentence, 9 drives today, 1 loan overdue, with the numbers beside it.
- 1Stock imported from the dealership's website on a schedule, behind an interface a DMS connection can replace. Staff edits survive the next import until someone re-syncs that car.
- 2Licence scanning with the phone camera. Fields are extracted in our own process, the ones it wasn't sure about are highlighted for a human to check, and an expired licence stops the drive.
- 3Versioned test-drive and loan agreements, signed on the dealership's device or sent to the customer's phone as a secure link with a date-of-birth check. The signed PDF is attached to the customer, vehicle and booking.
- 4Bookings, a week calendar by vehicle, live tiles for what's out, overdue and due back, and notifications by email and SMS.

The hard part
Double bookings had to be impossible, not just unlikely. Two salespeople at one counter can tap at the same moment, so overlap is a Postgres exclusion constraint on the vehicle and its time range, and creating or moving a booking takes an advisory lock on the vehicle so the cleaning buffer between drives holds under concurrency too. A walk-in loan has no booking at all, so every availability check reads bookings and cars that are physically out as one answer.
What was signed can never change. A manager can edit the agreement template, but the moment an agreement leaves draft its text, merge fields and excess tier are frozen onto it. The markdown renderer is built up from an allow-list, so a template can't smuggle in links, images or HTML, and unknown merge fields are refused at publish time rather than rendered as a blank in a legal document.
Licence data is treated as the liability it is under the Australian Privacy Principles. Each dealership's data is isolated with row-level security, licence images and fields are encrypted at rest, retention runs on two clocks, and reading a licence requires a manager role plus a fresh two-step verification on that session, with every view written to the audit log.

How it went
The first three weeks produced 249 commits: the vehicle catalogue and website import, bookings and the calendar, licence scanning, the full agreement and remote-signing flow, staff invitations and two-step verification. Each decision with consequences is written up as an architecture record so the next developer, or the next phase, knows why it is the way it is. After their first week on it, the floor team's main feedback was that a hand-over now takes a couple of minutes at the car instead of ten at the desk.
Phase 2 brings a direct DMS connection, CRM integration and wider SMS automation; Phase 3 is native apps on the same API. Phase 1 went live with the dealership's sales floor in September 2026 and is rolling out stage by stage, starting with stock, bookings and licence scanning, with signed agreements and loan tracking following as each one is signed off.
More work
All case studiesInternal tool, private credit funds
Investor onboarding for Bowery
An internal onboarding workspace for a private credit fund manager. Staff upload a signed application, check what the app read off it, work Bowery's 26-item AML/KYC checklist, and the result is filed into their Microsoft 365 investor register.
Ops dashboard, WooCommerce, Keap and Meta
TakeShape Adventures operations dashboard
A staff operations dashboard for an adventure travel company: every departure's manifest and check-in, trip pages edited and published back to WordPress, and the Keap and Meta automations that used to live in third-party glue, all running off one Postgres database.