The DMS Is the System of Record — and You Do Not Own the Write Path
Fixed operations is where the AI pitch decks land hardest in a franchise dealership. Book more appointments. Draft the repair order. Chase declined work. Catch warranty claims before they bounce. Every one of those is a real workflow with real hours attached to it, and every one of them runs into the same wall within about two weeks of a pilot starting.
The wall is the dealer management system. The DMS holds the customer, the vehicle, the repair order, parts inventory and pricing, the accounting ledger and the warranty claim. Nothing in fixed ops is real until it is an RO in the DMS. Your scheduling tool, your CRM, your texting platform and your inspection app all sit above it and all eventually have to reconcile to it. So the question that decides whether an agent ships is not whether a model can draft a good three-C story. It is whether anything the agent produces can get into the DMS, who is contractually permitted to put it there, and what that permission costs.
This is the sentence the whole cluster hangs on, and dealerships are its clearest illustration: an agent can only be as autonomous as its write path allows. In a dealership the write path is governed by an agreement between your DMS vendor and your integration vendor to which you, the dealer, are generally not a party — even though the data is about your customers and your vehicles.
The vendor landscape matters here because it is concentrated. The dominant DMS providers to franchise dealers are CDK Global, owned by Brookfield since 2022, and The Reynolds and Reynolds Company, alongside Dealertrack DMS from Cox Automotive and Tekion, with smaller players including Autosoft, Dominion, PBS and DealerSocket, now part of Solera. The Federal Trade Commission, in its 2018 challenge to CDK's proposed acquisition of Auto/Mate, described CDK and Reynolds as the two largest providers of DMS software to new-vehicle dealers in the United States.
Here is the map of fixed ops as a set of write paths rather than as a set of features. Read the third column first — it is the one that decides your architecture.
| Fixed-ops object | Where it lives | Who controls the write | What a third-party agent realistically gets |
|---|---|---|---|
| Customer and vehicle record | DMS | The DMS vendor, through its certified-integration programme | Read through a sanctioned extract. Writes sit in a separate, separately-priced tier. |
| Repair order — open, dispatch, story, labor lines, close | DMS | The DMS vendor, plus whatever your DMS agreement says about third-party access | Read is common. Writeback exists where the vendor sells a writeback package and the dealer authorizes it. |
| Parts inventory, pricing, special orders | DMS, with OEM parts ordering running through OEM-certified interfaces | DMS vendor for inventory; OEM for ordering rails | Read for availability and pricing. Ordering generally stays inside the DMS and OEM rails. |
| Warranty claim | DMS, submitted through an OEM-certified interface | The OEM certifies the DMS; the dealer submits and attests | No verified third-party submission path. Agents work up to the claim, not through it. |
| Accounting ledger and monthly financial statement | DMS | DMS vendor; statement submission is an OEM-certified interface | Read access to accounting data is the most expensive tier described in any public source we located. |
| Service appointment and shop capacity | A scheduling layer writing into the DMS | Depends on corporate ownership as much as on architecture | Cox's Xtime markets bi-directional repair-order management and parts writeback specifically into Dealertrack DMS — same corporate family, deepest published write path. |
Fixed-ops systems of record as of August 2026. The write-control column reflects certified-integration programme structure as described in vendor materials and in public litigation and forum artefacts; no DMS vendor publishes a certification or fee schedule.
Notice the last row. The deepest published write path in service scheduling belongs to a product inside the same corporate family as the DMS it writes to: Cox's Xtime markets bi-directional repair-order management — opening and editing ROs from Xtime — and parts lookup and writeback of labor and parts from service appointments, specifically into Dealertrack DMS. That is Cox writing into Cox. We could not source a comparable statement of write depth for Xtime against CDK or Reynolds, and we do not assume one exists. The asymmetry is the story: the vendor that owns the system of record can grant itself a write path it does not have to sell to anyone else.
Which Rung of the Integration Ladder Fixed Ops Is Actually On
Across this cluster we use a five-rung ladder to describe integration options, defined in the pillar on integrating agents with legacy and closed systems: documented public API, certified partner programme, EDI or batch file, screen scraping and RPA, and no path at all. Each rung down means less vendor cooperation, more fragility and more contractual exposure.
Dealership fixed ops sits, for practical purposes, on rung two — with rung three doing a lot of quiet, unglamorous work and rung four doing more than anyone likes to admit.
| Rung | What it looks like in a dealership | Realistically available? | The exposure |
|---|---|---|---|
| Rung 1 — documented public API | A published spec with self-serve credentials and a versioning policy that any developer can build against | Not available for franchise DMS access. CDK publishes an API product page; it does not publish certification criteria, a consent process or fees. | Low, if it existed. It does not exist here. |
| Rung 2 — certified partner programme | CDK Third Party Access; the Reynolds Certified Interface; OEM certification for warranty and financial-statement rails | Yes. This is the realistic rung for fixed ops, and it is where the gatekeeping and the money are. | Recurring, unilateral, renewable terms drafted by the vendor. Your access is contingent on somebody else's contract. |
| Rung 3 — EDI or batch file | Nightly extracts, flat-file drops, scheduled reports landing on SFTP | Frequently yes, and frequently underrated. The file is a natural reconciliation checkpoint. | Latency. You reason about a world that is up to a day stale, and you must say so on screen. |
| Rung 4 — screen scraping or RPA | A robot driving the DMS user interface with a real user's credentials | Often the only path available for a small vendor. Also the most exposed. | You are consuming a presentation layer the vendor may change without notice, under an agreement you signed, on a system holding consumer financial data. |
| Rung 5 — no path at all | Warranty submission for third parties; several OEM rails; anything the DMS vendor has not exposed | Yes, and this is a legitimate finding rather than a failure. | None, if you accept it. The architecture becomes: the agent drafts, a human commits. |
The integration ladder applied to dealership fixed operations, August 2026.
Rung four deserves an honest treatment rather than a euphemism, because in this industry it is frequently what is actually happening behind the word "integration." A robot driving your DMS interface with a real user's credentials is technically possible almost everywhere. It is also structurally fragile — you are consuming a presentation layer the vendor may change without notice or versioning — and it is contractually exposed in a way that public-web scraping is not.
The case everyone cites for the legality of scraping does not say what it is usually said to say. In hiQ Labs v. LinkedIn (9th Cir., No. 17-16783, filed 18 April 2022) the Ninth Circuit was reviewing a preliminary injunction under its sliding-scale standard, and what it actually concluded was narrow. In the panel's own words: "HiQ has therefore raised serious questions about whether LinkedIn may invoke the CFAA to preempt hiQ's possibly meritorious tortious interference claim." A serious question is not a holding that something is legal.
And hiQ then lost. On remand, a November 2022 summary judgment held that hiQ had breached LinkedIn's user agreement through automated scraping and through hiring crowdsourced workers to create fake profiles, and that website terms prohibiting scraping and fake accounts are enforceable in a breach-of-contract claim. In December 2022 a stipulated consent judgment imposed $500,000 plus a permanent injunction requiring hiQ to stop scraping LinkedIn and to destroy source code, data and algorithms derived from scraped profile data. The CFAA claim was never decided on the merits.
The Supreme Court left the decisive question open. In Van Buren v. United States the Court held that an individual "exceeds authorized access" when he accesses a computer with authorization but then obtains information located in particular areas of the computer—such as files, folders, or databases—that are off limits to him." But it expressly reserved the part that matters to a dealer: "For present purposes, we need not address whether this inquiry turns only on technological (or 'code-based') limitations on access, or instead also looks to limits contained in contracts or policies."
Why the scraping analysis is worse for a dealership than for a web scraper
Three facts stack against you, and they stack in the same direction.
First, your DMS is behind a login under a signed agreement. hiQ's contract loss was made easy precisely because it had agreed to LinkedIn's terms when it created a corporate account. You have signed something considerably more specific.
Second, the data is consumer financial data at a business the FTC treats as a financial institution. A screen-scraping architecture that requires sharing or bypassing credentials sits badly against the access-control and multi-factor authentication elements of the Safeguards Rule.
Third, these questions are decided circuit by circuit. hiQ is Ninth Circuit law about public, unauthenticated pages. It is not a national rule and it is not about authenticated enterprise systems. We did not survey circuit splits after 2022 and we do not claim national uniformity.
One more thing this rung does not do: it does not get better because you put a modern protocol in front of it. The Model Context Protocol's current specification, dated 2026-07-28, is a stateless rewrite of the prior stable version — real engineering, genuinely useful, and completely orthogonal to your problem. MCP standardizes how a tool is described and called. It does not decide whether your agent may issue a write into a system whose access is governed by a certified-integration agreement. MCP is a wrapper around whatever rung you were already on.
Certified Integration: 3PA, RCI, and the Extract-vs-Writeback Split
CDK runs Third Party Access. Reynolds runs the Reynolds Certified Interface. Both are gated, contract-based programmes that a software vendor must join to obtain sanctioned DMS access, and both companies publicly justify them on security grounds. This is the rung where the real gatekeeping lives, and — as in every industry in this cluster — it is the rung where the costs are least visible before you commit.
Start with what is actually published. CDK's public API page lists a Data Extract API Bundle, Business Office APIs, Modern Retail APIs, Fixed Operations APIs and Parts APIs. On commercial terms it says only: "We offer pay-as-you-go options." There are no certification criteria on it, no approval requirements, no dealer-consent process, and no fees. Fortellisis CDK's developer marketplace.
On the Reynolds side we hold no fetched programme language at all — the RCI third-party page rendered as title-only to our fetcher — so we do not characterize its terms, and we do not put quotation marks around anything attributed to Reynolds. We can say only that the programme exists and that it is gated.
Because the vendors publish nothing, it is worth setting out every figure in circulation next to what it actually is. This is the sort of table that makes a vendor conversation shorter.
| Figure in circulation | Where it comes from | What it actually is | How to use it |
|---|---|---|---|
| Integration fees of at least $10,000, possibly closer to $40,000 | DealerRefresh forum thread, July 2017 — dealer and vendor testimony | Practitioner testimony, nine years old, never an official schedule | Order of magnitude only. Date it every time you use it. |
| $30,000 upfront plus an annual renewal plus roughly $200 per month per rooftop, for repair-order and invoice access to CDK accounting data | Same 2017 thread, one vendor's account | Same | Useful for the shape — upfront plus recurring plus per-rooftop — not for the amount. |
| Extract-Only Pricing as a distinct tier from Data Writeback Packages, priced per dealer per month and marked subject to change | Images of a CDK pricing guide posted to the same 2017 thread | Same | The most durable detail in the set. Reading is one tier; writing is another. Assume that is still true and confirm it in writing. |
| Roughly $250–$300 per connection, against about $70 previously for the same services | Alleged in vendor antitrust complaints | Pleadings. Allegations, never adjudicated to a finding. | Cite as an allegation with the case named, or not at all. |
| A monthly rate of about $210, alleged as a 500 percent increase | Alleged in a complaint by a vendor that said it was forced into a certified programme | Same | Same. |
| Roughly $79 per month per rooftop with independent integrators rising to more than $730 per month per rooftop | Alleged in a complaint | Same | Same. |
| A current, published CDK 3PA or Reynolds RCI fee schedule | Neither vendor's current published materials contain one | Does not exist in public | This absence is the finding. Do not let a vendor treat your ignorance of the fee as your problem. |
Every figure above is either practitioner testimony from a July 2017 DealerRefresh forum thread or an allegation pleaded in an antitrust complaint. None is a current published price, and we do not present any of them as one.
The most durable item in that table is the third row, and it is worth stating on its own because it drives your entire architecture: the 2017 forum thread contains images of a CDK pricing guide that distinguished Extract-Only Pricing from Data Writeback Packages, priced per dealer per month and marked subject to change. Reading is one commercial tier. Writing is another. Any plan that assumes a read integration entitles you to write is a plan with an unpriced line item in it.
There is a useful period detail on how thinly write access was available even for the most obvious fixed-ops use case. On a Fortellis community thread in April 2019, a CDK staff member wrote that the Appointments API had not yet been published and was in testing, and that its pricing would likely be released at the same time as the API. That is seven years old and we do not present it as the current state of anything. What it illustrates is that service scheduling — the single most commonly pitched fixed-ops integration — was not generally available at a published price at a point when the industry already assumed it was.
Model the certified-programme fee as per-interface, recurring, and forever. Then ask which party is paying it — you or your software vendor — and what happens to your price when their fee changes. In a market where neither DMS vendor publishes a schedule, the party that absorbs an unpublished, unilaterally variable cost is the party carrying the risk.
— Frenchy Digital procurement principle
The Litigation Record, Stated Precisely
Dealership data access has a longer and better-documented legal history than almost any integration question in this cluster. It is also the subject most often overstated in trade writing, usually in the direction of "the courts opened up DMS data." They did not. What follows is the record with the posture stated exactly, because a partial dismissal is not a denial, a vacated injunction is not a merits loss, and a settlement is not a finding.
| Case or matter | Posture, stated precisely | What it established | What it does NOT establish |
|---|---|---|---|
| Authenticom, Inc. v. CDK Global, LLC & Reynolds — 874 F.3d 1019 (7th Cir. 2017), Nos. 17-2540 and 17-2541 | Decided 6 November 2017. Chief Judge Diane Wood, unanimous panel. Preliminary injunction VACATED. | That the injunction exceeded the proper scope of preliminary relief, did not preserve the status quo, and improperly imposed a duty to deal. The proper Sherman Act section 1 remedy is to set aside the offending agreement, not to compel access. | It does not hold that CDK and Reynolds did nothing wrong. It holds that compelling access was the wrong preliminary remedy. |
| In re Dealer Management Systems Antitrust Litigation — MDL No. 2817, No. 18-cv-00864 (N.D. Ill., Judge Rebecca R. Pallmeyer) | Consolidated dealer and vendor claims about DMS and data integration services. Resolved by settlement. | Dealer class: $129.5M — Reynolds $29.5M in 2019, CDK $100M plus $250,000 for notice and administration, CDK settlement approved 25 February 2025, class period 1 September 2013 to 15 August 2024. | No merits verdict. Neither defendant admitted wrongdoing. |
| Vendor class settlement — the one that is actually about integration access | CDK agreed to pay $630 million to a class of 243 companies that purchased data integration services from CDK or Reynolds since October 2013. Class certified July 2024; agreement filed 25 January 2025; approved 25 February 2025. | Reported as roughly $140 million above the $490 million single-damages figure the vendor class had put forward. | Money, not access. No court ordered an integration path to open. We could not verify which court entered this approval, so we give the date and name no court. |
| In the Matter of CDK Global, Inc. — FTC File No. 171 0156 (March 2018) | Administrative complaint challenging CDK's proposed acquisition of Auto/Mate. The parties abandoned the transaction. | The FTC described CDK and Reynolds as the two largest providers of DMS software to new-vehicle dealers in the United States, and described Auto/Mate as having competed on lower prices, flexible contract terms, free upgrades and training, service quality — and modest fees to integrate third-party applications. | There was no merits adjudication; the deal was abandoned. And there is no FTC document we could verify containing a market-share percentage. |
| CDK Global LLC v. Brnovich — 16 F.4th 1266 (9th Cir. 2021) | Unanimous panel AFFIRMED the DENIAL of a preliminary injunction on 25 October 2021. | Arizona's Dealer Data Security Law, A.R.S. sections 28-4651 et seq. (March 2019), survived a preliminary challenge founded on Copyright Act and CFAA preemption, the Contracts Clause, the Takings Clause and vagueness. | Affirming a denial of preliminary relief is not a final judgment on the statute's validity. We could not verify whether certiorari was sought or denied. |
Litigation record as of August 2026. Settlement figures and the FTC matter are trade-sourced; the Seventh and Ninth Circuit opinions are reported at 874 F.3d 1019 and 16 F.4th 1266 respectively.
Three points from that table deserve to be pulled out.
- The duty-to-deal holding is the operative law: In Authenticom, decided 6 November 2017, Chief Judge Diane Wood wrote for a unanimous Seventh Circuit panel vacating a preliminary injunction that had ordered continued access. The panel held the injunction exceeded the proper scope of preliminary relief, did not preserve the status quo, and improperly imposed a duty to deal — and that the proper Sherman Act section 1 remedy is to set aside an offending agreement rather than to compel access. Note the date: the citation is 2017, not 2018, and November, not October. Both errors circulate.
- The $630 million settlement is the one about integration, and it is the one nobody quotes: The dealer-class figure of $129.5 million is the number that reached general trade coverage. The vendor-class settlement of $630 million is defined by a class of 243 companies that had purchased data integration services — meaning the price of access to the DMS is literally what that class bought and what that settlement is about. Lead with $630 million; mention $129.5 million as the separate dealer-side recovery. We could not verify which court entered the $630 million approval, with trade reports split between the Northern District of Illinois where the MDL sits and a federal court in Madison, Wisconsin, so we give the date and name no court.
- The FTC treated integration fees as a dimension of competition: In its March 2018 administrative complaint over the Auto/Mate acquisition, the FTC described the target as having won business on lower prices, flexible contract terms, free software upgrades and training, service quality — and modest fees to integrate third-party applications. That last item is the reason this matter belongs in an article about AI agents: a federal antitrust agency treated the level of third-party integration fees as a competitive dimension worth protecting. The parties abandoned the transaction rather than litigate. We note that ftc.gov returns a 403 to our fetcher, so we have not read the agency document directly; the characterization above is corroborated in contemporaneous trade coverage of the release and we paraphrase rather than quote it.
Then there is the legislative route, which turned out to be the more effective one. Arizona's Dealer Data Security Law, A.R.S. sections 28-4651 and following, enacted in March 2019, attacks the problem directly: it bars DMS providers from acting by contract, technical means or otherwise to prohibit or limit a dealer's ability to protect, store, copy, share or use DMS data; bars charges beyond direct costs incurred for database access; and requires DMS providers to adopt and publish a standardized data-exchange framework. Reporting also describes a right for dealers to terminate DMS contracts on ninety days' notice.
CDK and Reynolds sued, arguing preemption by the Copyright Act and the Computer Fraud and Abuse Act, plus Contracts Clause, Takings Clause and vagueness theories. A unanimous Ninth Circuit panel affirmed the denial of a preliminary injunction on 25 October 2021 in CDK Global LLC v. Brnovich, 16 F.4th 1266. Comparable statutes exist in Oregon at ORS 650.123, and in Montana and North Carolina among others.
Scheduling, Repair Orders and Parts: Where Agents Actually Earn Their Keep
With the write path understood, the workflow question becomes tractable. The pattern that works in fixed ops is the same one that works in every closed-system industry: the agent does the reading, the assembling, the cross-checking and the drafting, and a named human performs the act that has a consequence. Nearly all the labour saving lives in the first four verbs.
| Workflow | What the agent produces | Where the human commits | Systems touched |
|---|---|---|---|
| Inbound service scheduling triage | A proposed appointment — concern captured in the customer's words, vehicle matched by VIN, opcode suggested, shop capacity checked against the scheduling layer | The advisor or BDC agent confirms the booking. Capacity overrides stay human. | Scheduling platform, DMS customer and vehicle read, texting platform |
| Repair-order drafting | A drafted RO story with the three Cs, suggested labor operations, and the parts likely to be required, attached to the appointment | The advisor edits and opens the RO. Nothing is dispatched on the agent's authority. | DMS read; writeback only where the certified programme and the dealer both permit it |
| Declined-work follow-up | A ranked list of previously declined lines with the vehicle, the date, the original estimate and a drafted outreach message | The advisor or BDC sends. Consent status is checked before any automated voice or text goes out. | DMS RO history, CRM, texting platform, consent register |
| Parts special-order chasing | A daily exception list — orders past their promised date, backorders with no ETA, ROs waiting on parts with a customer already notified | The parts manager decides what to expedite, substitute or cancel. | DMS parts read, supplier portals, OEM ordering rails |
| Warranty claim pre-check | A pre-submission review flagging missing or inconsistent labor operations, parts and fail codes, plus the claims statistically most likely to bounce | The warranty administrator submits and attests. Always. | DMS RO and warranty data read; the OEM-certified interface remains human-operated |
| Effective labor rate and warranty reimbursement evidence | An assembled sample of qualifying non-warranty repairs and the derived markup and labor-rate calculation, with the exclusions listed | The controller or general manager reviews and files the submission with the manufacturer. | DMS accounting and RO history, state statute requirements, manufacturer forms |
| Multi-point inspection reconciliation | A comparison of inspection findings against RO lines, showing what was found, what was recommended, what was sold and what was never presented | The service director acts on it. No customer communication is generated automatically from it. | Inspection app, DMS RO read |
| Appointment reminder and status updates | A drafted status message tied to the RO stage, with consent checked and revocation honored before send | Automated send is permissible for text where consent exists. An AI voice call is a robocall and needs the consent record for that channel. | DMS RO status read, texting platform, consent register |
Fixed-ops agent workflows and their commit boundaries. Every write into the DMS assumes a sanctioned, dealer-authorized path.
A few notes on the ones that surprise people.
Scheduling is not one system. The appointment usually lives in a scheduling layer, the customer and vehicle live in the DMS, and shop capacity lives in whichever of the two your store actually trusts. An agent that books appointments has to reconcile all three, and in our experience the failure that ends a scheduling pilot is rarely a bad model — it is the agent booking against capacity the shop had already committed elsewhere. Build the capacity check as a hard gate, not as context in a prompt.
RO drafting is the highest-value read-only workflow in the department.An agent that produces a clean, complete three-C story from the customer's own words, with a suggested opcode and the parts likely to be required, saves advisor time on every single ticket and improves the downstream warranty claim without ever touching a write path. If you only do one thing, do this one, and do it in draft-only mode for a quarter before you argue about writeback pricing with anybody.
Declined-work follow-up is where consent law bites. The list is easy to build and the outreach is where dealers get into trouble. Any automated voice outreach is governed by the TCPA position set out below, and the value of the workflow depends entirely on having a consent register that is real, current and honoured immediately on revocation.
The workflow test we apply before quoting anything
Three questions, in this order. If the answer to the first is no, nothing else matters.
1. Can the agent read what it needs, lawfully and reliably, today? Not through a promised API. Through a credential that exists, on a schedule you have seen work, under an agreement somebody has read.
2. If the output is a draft that a human commits, does the workflow still pay for itself? If it only pays with autonomous writes, you are betting your business case on a contractual concession you do not control. That is not a technology risk, and no amount of engineering will retire it.
3. Can you measure the before-state? Thirty days of real counts and cycle times. If the department cannot produce them, the first deliverable is measurement, not automation — and that is usually worth the engagement on its own.
Warranty Claims and the OEM-Certified Rail
Warranty is the sharpest boundary in the article, and it is worth understanding why the boundary is structural rather than a matter of caution.
Franchise dealers do not choose their warranty path. OEM certification of the DMS is a precondition, and the OEM-certified interfaces carry warranty claim submission, incentive reporting, parts ordering, inventory feeds and monthly financial-statement submission. That is a second layer of certification sitting on top of the DMS vendor's own programme — and it is one reason the FTC's Auto/Mate complaint mentioned both modest third-party integration fees and a full roster of OEM certifications as things the market was losing.
For an agent, this means the useful work sits entirely before submission.
| Element of the warranty workflow | Who owns it | What an agent can safely do |
|---|---|---|
| The certified rail itself | The OEM. Certification of the DMS is a precondition, and the certified interfaces carry warranty claim submission, incentive reporting, parts ordering, inventory feeds and monthly financial-statement submission. | Nothing. There is no verified third-party submission path. Assume rung five here and design around it. |
| Claim composition — labor operations, parts, fail codes | The technician and the warranty administrator. Vendor and trade write-ups consistently describe claims bouncing when these do not line up; treat that as practitioner description, not as a published rule. | Pre-check for presence and internal consistency, flag likely rejections, and rank the queue. Never silently rewrite a code. |
| Attestation and submission | A named human. A warranty claim is a representation to the manufacturer, with audit exposure attached. | Nothing. This is the hardest human-only line in the article. |
| Retail warranty reimbursement rate submissions | The dealer, under state statute. These statutes generally require OEMs to reimburse for warranty parts and labor at retail rates keyed to the dealer's declared non-warranty retail rate, and typically override contrary dealer-agreement language. | Assemble the qualifying sample and compute the proposed rate — parts commonly as dealer cost multiplied by one plus the average percentage markup from a sample of non-warranty repairs. The controller reviews and files. |
| Manufacturer pushback on a declared rate | The dealer and counsel. Several states rewrote these statutes in 2025, and five of them eliminated or sharply limited a manufacturer's ability to rebut a declared labor rate as unreasonable. | Assemble the evidence. Do not have an agent write correspondence to a factory representative. We could not verify which five states, and we do not name them. |
Warranty workflow boundaries. Operational detail about labor operations, parts and fail codes is drawn from vendor-adjacent trade writing and is described here as practitioner observation, not as a published rule.
The retail warranty reimbursement side is quietly the most agent-shaped work in the whole department. State statutes generally require manufacturers to reimburse dealers for warranty parts and labor at retail rates, usually keyed to the dealer's declared non-warranty retail rate, and typically overriding contrary language in the dealer agreement. Parts reimbursement is commonly computed by multiplying dealer cost by one plus the dealer's average percentage markup derived from a sample of qualifying non-warranty repairs.
That is a data-assembly task with statutory exclusion rules, performed infrequently, usually by someone who has other things to do, and worth real money when it is done well. An agent can assemble the qualifying sample, apply the exclusions, compute the proposed rate and produce the evidence file. A controller reviews it and files it. Nobody automates the assertion.
Two Compliance Regimes That Constrain the Agent: Safeguards and the TCPA
Two regimes shape what an AI agent may do in a dealership, and both are frequently absent from vendor conversations until somebody's counsel joins the call.
The first is the GLBA Safeguards Rule, 16 CFR Part 314. Auto dealers are financial institutions under it because they arrange consumer credit. That framing surprises people who think of the rule as a bank obligation, and it has a direct consequence for AI procurement: every third party touching dealer customer data is a service provider you must select, contractually bind and oversee under 314.4(f). That subsection is the compliance hook for the entire question of who is allowed to write to your DMS.
Most of the 2021 amendments took effect on 9 June 2023. The breach-notification amendment took effect on 13 May 2024 and requires reporting to the FTC within 30 days of discovering unauthorized acquisition of unencrypted information of 500 or more consumers. Here is the rule mapped element by element onto an agent deployment.
| Safeguards Rule element (16 CFR Part 314) | What it means once an AI agent is in the workflow |
|---|---|
| Written, comprehensive information security programme | The agent, its prompts, its tool definitions, its credentials and its logs are all in scope. If your programme document does not mention the agent, your programme is out of date the day it goes live. |
| Designated Qualified Individual | May be an employee of a service provider, but the dealer retains responsibility. Ask, in writing, who this is once an AI vendor is involved — and get the answer before the pilot, not after. |
| Risk assessment | An agent with a DMS write credential is a new asset with a new blast radius. It belongs in the assessment as its own line, not folded into the vendor that hosts it. |
| Access controls and encryption | Least privilege applies to the agent as much as to a person. Give it its own identity, never a shared service account, and scope its permissions to the workflow rather than to the vendor's whole API surface. |
| Multi-factor authentication | This is where screen-scraping architectures break, and where they should. An RPA robot holding a human's credentials to defeat MFA is a control failure written into your architecture. |
| Monitoring and testing | Per-action audit logging, exportable. You need it to answer an FTC question, an OEM warranty audit and your own post-incident review. |
| Staff training | Advisors and BDC staff need to know what the agent drafts, what it sends, and how to override it. An override path nobody has been trained on does not exist. |
| Service-provider selection and oversight (314.4(f)) | This is the compliance hook for the whole article. Every AI vendor touching dealer customer data is a service provider you must select, contractually bind and oversee. Their subprocessors are your exposure. |
| Incident response plan | Add an agent-specific branch: revoke the agent's credentials, freeze its write path, and reconcile everything it wrote in the affected window. |
| Annual report to the board or equivalent | Include the agent's override rate, its write volume and any reconciliation exceptions. If you cannot produce those numbers, you do not have oversight, you have a subscription. |
| Breach notification — since 13 May 2024 | Report to the FTC within 30 days of discovering unauthorized acquisition of unencrypted information of 500 or more consumers. Note that entities maintaining information on fewer than 5,000 consumers are exempt from some, not all, requirements — check the specific carve-out with counsel rather than assuming. |
Safeguards Rule element list compiled from practitioner guidance; the FTC's own dealer FAQ returned an HTTP 403 to our fetcher, so we cite it and treat the element list as secondary. Confirm the specifics with counsel.
The second regime is the TCPA, and it contains the single most load-bearing legal fact for any outbound AI voice in fixed ops. On 8 February 2024 the FCC adopted a Declaratory Ruling, FCC 24-17, holding that an AI-generated voice is an "artificial or prerecorded voice" under the statute. It took effect on adoption. Calls using one require prior express consent — and prior express written consent if the content is marketing.
One more moving part: the FCC's revoke-all rule, under which a single revocation ends future calls and texts from that caller on unrelated subjects, has had its effective date pushed twice. It was originally due on 11 April 2025; the Consumer and Governmental Affairs Bureau delayed it by a year on 7 April 2025, and on 6 January 2026 extended the effective date again to 31 January 2027. The right engineering response is not to wait. Build revocation handling that already behaves as though the rule is live, because that is the behaviour you will need and because the alternative is a data-model change under time pressure.
Two adjacent items are worth knowing so you do not plan around a rule that no longer exists. The FTC's CARS Rule — Combating Auto Retail Scams, promulgated in December 2023 — was vacated by the Fifth Circuit on 27 January 2025, two to one, on procedural grounds: the Commission proceeded under section 18(a)(1)(B) without the required advance notice of proposed rulemaking, depriving NADA and TADA of a procedural benefit. The rule is not in effect and the FTC would have to restart rulemaking. Separately, Massachusetts' right-to-repair and telematics law was upheld by a federal judge in February 2025; Auto Innovators appealed to the First Circuit, No. 25-1262; at oral argument on 3 February 2026 Auto Innovators conceded that its members could comply as the district court had construed the law; and on 25 February 2026 the Massachusetts Attorney General declined mediation. The case remains pending. Enforcement began on 1 June 2023, and Subaru and Kia responded to the earlier law by disabling telematics on Massachusetts-sold vehicles.
The Write Path: Exactly What to Ask Your DMS Rep
Certified access in this industry is, in practice, read-first. The read path is the one vendors sell readily and describe in their materials; the write path is a separate commercial decision, separately priced and separately gated, and in some places it does not exist for third parties at all. That means every write your agent performs is vendor-discretionary — permitted by an agreement that can be renegotiated, repriced or not renewed.
Which is why the most valuable hour in an agent programme is not spent with an engineer. It is spent on a call with your DMS representative and your software vendor together, working through the following list, and writing down the answers. Take the good-answer column as a script.
| Ask your DMS rep and your software vendor | A good answer looks like | A bad answer, and what it tells you |
|---|---|---|
| Which certified programme covers this integration — 3PA, RCI, an OEM-certified interface, or none of them? | A named programme, a named agreement, and a copy of the terms the dealership is being asked to authorize | We have a connection. Vendors who cannot name the programme are usually on rung four. |
| Is our access read-only, or does it include writeback — and are those priced separately? | An explicit split, in writing, with the write surface enumerated field by field | It is all included. In every public artefact we located, extract and writeback were distinct commercial tiers. |
| Exactly which objects can be written, and which cannot? | A list: appointment, RO header, RO line, note, customer contact, parts reservation — with the ones excluded named too | We can write to the DMS. That is a marketing sentence, not a specification. |
| What is the fee, per rooftop, per month, and for how long is it fixed? | A written number for your rooftop count and a stated term, with renewal mechanics | Contact sales. Neither DMS vendor publishes a schedule, so your vendor has to be the one who commits a number to paper. |
| What is the dealer-consent process, and what exactly are we authorizing? | A signed authorization naming the data categories and the purposes, with an expiry and a revocation path | A one-line consent form with no data-category detail. |
| What happens at renewal if the programme terms or fees change? | Notice periods, price-protection language, and a written exit with data portability | Silence. Certified-programme terms are unilateral and renewable; assume they can move and price the risk. |
| Does the integration survive a DMS change or an acquisition? | A named migration path and a data-export commitment that is not conditioned on the DMS vendor's cooperation | Anything that assumes your current DMS is permanent. |
| Are we the customer of record for the interface, or is the vendor? | Clarity on who holds the agreement, because that determines who can cut off whom | Do not worry about the paperwork. That is precisely the paperwork that decides whether your agent works next quarter. |
Write-path due diligence checklist. Ask both parties in the same meeting; the disagreements are the most informative part.
When you get the answers, three architectural decisions follow almost automatically. If writes are unavailable or unaffordable, you build a drafting agent and a good review surface, and you capture most of the value. If writes are available but narrow, you build to the narrow surface and you never let the agent improvise around a field it cannot write. And if writes are available and broad, you still put a human on the commit for anything with a financial, warranty or safety consequence — because the constraint there is not the contract, it is the consequence.
A note on identity while you are at it. Give the agent its own identity rather than running it as a member of staff. Microsoft's own agent-identity documentation makes the argument well: application identities carry "the expectation of long-term stability, known ownership, and managed lifecycle," whereas an agent "might exist for minutes during a specific task, or might be created and destroyed thousands of times per day."The practical dealership consequence is mundane and important — if the agent acts through a person's account, your audit log says a person did it, and you cannot answer a Safeguards question or an OEM warranty audit cleanly.
The Human-in-the-Loop Boundary
This is the table to print and put on the service director's wall. The principle underneath it is simple: an agent may act alone where the action is reversible, low-stakes and bounded by rules a human wrote in advance. Everything with a financial, warranty, legal or safety consequence gets a named human signature.
| Fixed-ops action | Autonomy boundary | Who signs | Why the line sits here |
|---|---|---|---|
| Reading DMS data and building a work queue | Agent alone | Nobody signs — this is a read | No external effect, fully reversible, and the highest-value thing an agent does in fixed ops. |
| Drafting an RO story, opcode suggestion or estimate | Agent drafts, human commits | Service advisor | The advisor owns the customer conversation and the estimate. A drafted story that a human edits is a keystroke saving, not a decision transfer. |
| Booking or moving an appointment inside published capacity rules | Agent alone, within a named, narrow envelope | Service director owns the envelope | Reversible, low stakes, and the envelope is defined by humans in advance. Overrides and exceptions escalate. |
| Sending an appointment reminder or status text where consent exists | Agent alone | Service director owns the consent register | Permissible with a consent record and immediate revocation handling. The register, not the agent, is the control. |
| Placing an outbound AI voice call | Agent drafts the campaign, human authorizes the list | General manager or compliance owner | An AI voice is an artificial or prerecorded voice under the TCPA per FCC 24-17. Consent is required, and written consent if the content is marketing. |
| Ordering parts or committing a special order | Agent drafts, human commits | Parts manager | It spends money and creates an obligation to a supplier. Reversible only with cost and friction. |
| Quoting a price or authorizing additional work | Human only | Service advisor and customer | This is a commercial commitment to a consumer. It is also where a wrong number turns into a chargeback and a complaint. |
| Submitting or attesting a warranty claim | Human only | Warranty administrator | A representation to the manufacturer with audit exposure. There is no verified third-party submission path in any case. |
| Filing a retail warranty reimbursement rate submission | Agent assembles evidence, human files | Controller or general manager | A statutory filing to a manufacturer. The arithmetic can be assembled; the assertion cannot be delegated. |
| Posting to the accounting ledger or closing an RO financially | Human only | Office manager or controller | Financial statement integrity, and the write tier most likely to be both expensive and irreversible. |
| Anything touching a safety recall or an open-recall disclosure | Human only | Service director | Safety consequence. Never automate a communication about whether a vehicle is safe to drive. |
| Responding to a customer complaint, a chargeback or a legal notice | Human only | General manager | Legal consequence, and exactly the inbound content most likely to carry an injection attempt. |
Human-in-the-loop boundaries for a dealership service department. Boundaries move down the table over time, never up by default.
The security literature arrives at the same boundary from a different direction, which is a good sign that it is the right one. The 2026 edition of the OWASP GenAI LLM Top 10, published on 4 August 2026, lists LLM01:2026 Prompt Injection, LLM03:2026 Excessive Agency and LLM10:2026 Improper Output Handling. For an agent with tool access to production systems, LLM03 and LLM10 are the priority pair, and the mitigations cited for excessive agency are exactly least privilege, confirmation for high-impact actions, and tool-usage logging — the three columns of the table above.
The dealership translation is direct. Your agent reads customer texts, forwarded emails, supplier PDFs and OEM bulletins — all content written by people outside your control. If that same session also holds a DMS write credential and can send outbound messages, you have assembled all three legs. Remove one. In practice that means the reading agent runs against a replica with no write credential, and the writing step happens in a separate, narrowly-scoped context that a human has approved.
It is worth being precise about what protocols do and do not contribute here. The MCP specification's security best-practices document contains genuine normative requirements — servers must not accept tokens that were not explicitly issued for them, proxy servers must obtain per-client consent before forwarding, redirect URIs must be validated by exact string matching rather than pattern matching, and scope minimization is called out by name with expanded blast radius, privilege chaining and audit noise as the risks. Every one of those is a blast-radius control. None of them prevents injection. That the specification's own security document is entirely about containment is the clearest possible signal about the state of the field.
A Sequenced Implementation Path
This is the part most articles skip, and it is the reason this one exists. What follows is a phased path with an owner, an entry criterion, an exit criterion and a documented failure response for each phase. The failure responses matter more than the exits: a programme that has not decided in advance what it does when a phase fails will simply carry on into the next one.
| Phase (weeks) | Owner | Entry criterion | Exit criterion | If the phase fails |
|---|---|---|---|---|
| Phase 0 — Contract and data-rights audit (weeks 1–2) | Dealer principal or GM, with counsel | Signed engagement and a copy of the current DMS agreement | A written statement of what your DMS agreement permits, which certified programme applies, whether your state has a dealer-data statute, and a dealer authorization on file | If there is no lawful write path, stop and adopt a drafting-only architecture. That is a legitimate outcome, not a failed project. |
| Phase 1 — Workflow selection and baseline (weeks 2–5) | Service director and fixed-ops manager | Phase 0 exit met | One workflow chosen, with 30 days of measured before-state: volumes, cycle times, abandonment, rework | If you cannot measure the before-state, the workflow is not instrumentable. Pick another rather than proceeding blind. |
| Phase 2 — Read-only integration and shadow mode (weeks 5–9) | Integration engineer with the DMS administrator | Certified read credentials issued and the extract landing on schedule | The agent runs on live data producing artefacts nobody acts on, with a diff against what humans actually did, across at least 200 real cases | If schema surprises dominate, fix the mapping or drop to scheduled export files. Do not proceed to writes on an unstable read. |
| Phase 3 — Human-committed writes (weeks 9–14) | Service director, with the integration engineer | Shadow-mode agreement above the threshold you set in Phase 1, before you saw the results | Every write passes an approval screen, carries an idempotency key derived from business intent, and lands in an exportable audit log with a documented rollback | Revert to draft-only. The agent still saves the keystrokes, and you have lost weeks rather than trust. |
| Phase 4 — Narrow autonomy on reversible actions (weeks 14–20) | Service director and general manager | 60 days of committed writes with a measured override rate and zero unrecoverable events | A short, named list of reversible actions the agent takes alone, each with a stop condition | The list shrinks. It never grows by default, and it never grows because a quarter went well. |
| Phase 5 — Operate, measure, renew (ongoing) | General manager and whoever owns vendor management | Phase 4 exit met | Quarterly review against the Phase 1 baseline, plus a calendar entry 120 days before every DMS and integration renewal | If you discover a term change at renewal rather than before it, you are negotiating from the weakest possible position. That is the expensive failure mode. |
A twenty-week path from contract review to narrow autonomy. Weeks are indicative; the criteria are not.
Two things about this sequence are deliberately unusual. The first is that Phase 0 is a legal and contractual phase, not a technical one, and it comes before workflow selection. In most industries you would pick the workflow first. In a dealership, the contract determines which workflows are even candidates, so doing it in the other order wastes a discovery cycle.
The second is that the shadow-mode threshold in Phase 2 is set in Phase 1, before anyone has seen a result. Thresholds chosen after the fact are not thresholds; they are rationalizations. Write the number down, in the statement of work, with the workflow owner's name next to it.
What Phase 3 actually requires, in engineering terms
The approval screen is the easy part. The hard parts are idempotency and reconciliation, and they are the difference between a pilot and a system.
Idempotency. There is no standard for this. The IETF's draft-ietf-httpapi-idempotency-key-header reached revision -07 on 15 October 2025 and its IESG state is Expired. It is not an RFC. The de-facto convention is Stripe's, and two details from it transfer directly: the client generates the key, and keys may be pruned after at least 24 hours — meaning a retry a week later is a fresh write, not a deduplicated one. Derive your key from business intent (rooftop, VIN, appointment slot) rather than generating a fresh one per attempt, persist it before the call rather than after, and make your own dedupe table outlive the downstream retention window.
Reconciliation.Agents write over unreliable networks and can be interrupted mid-plan. Read back and compare against the DMS on a schedule. Treat the DMS as truth and the agent's belief as a hypothesis. If your integration is a nightly batch, you get this checkpoint for free — the file is the reconciliation. If it is a real-time API, you have to build it, and it is the thing most likely to be left out of a first release.
What Breaks First
Every failure mode below has been chosen because it is specific to dealership fixed ops rather than generic to software. Each one gets a detection signal, because a failure you cannot see is a failure you discover from a customer.
| Failure mode | What it looks like in fixed ops | Detection signal | Rollback |
|---|---|---|---|
| Certified-programme renewal or repricing | Your integrator's terms change at renewal, or writeback moves to a different tier | A renewal notice, a new order form, or a line item nobody budgeted | Keep drafting-only mode maintained and tested. It is the fallback that keeps working when the write path does not. |
| The DMS vendor ships the feature natively | Your scheduling or RO-drafting vendor is suddenly competing with a first-party feature bundled into the DMS | Product announcements at industry events; a DMS rep offering the same capability at no extra cost | Own your prompts, your evaluation set and your data model so you can re-platform without rebuilding the workflow logic. |
| Schema drift in the extract | A field changes type, a code list gains a value, ROs start failing validation for no visible reason | Row-count and null-rate monitors on every extract, plus a canary set of known ROs run daily | Pin the mapping, fail closed into the review queue, and never let the agent guess at an unrecognized code. |
| Duplicate writes on retry | Two identical repair orders, two parts special orders, two texts to the same customer | A reconciliation job comparing the agent's intent log against the DMS on a schedule | Derive the idempotency key from business intent — rooftop, VIN, appointment slot — never a fresh identifier per attempt. Persist it before the call, not after. |
| Batch latency and rate limits | The nightly extract is late and the agent reasons about yesterday's shop | A freshness stamp on every figure the agent displays | Show a staleness banner and block writes when the underlying data is older than your threshold. |
| The DMS goes down | Everything stops. June 2024 is the reference case, and the recovery ran for weeks rather than hours. | Your own uptime monitor against a real transaction, not the vendor's status page | A documented paper process, an offline capture form, and a reconciliation routine the agent runs when service returns. |
| Prompt injection through inbound content | A customer text, a supplier PDF or a forwarded email contains instructions aimed at the agent | You cannot reliably detect this. That is the whole point. | Never let a session that reads untrusted content also hold a write credential. Remove one leg of the trifecta rather than trusting a filter. |
| Acquisition or ownership change | Your integrator or your DMS changes hands and the terms follow | Deal news; a new master agreement arriving at renewal | Negotiate exit rights and data portability at signature, when you have leverage, not at renewal when you do not. |
| Model non-determinism | Behaviour changes without a deployment, and last quarter's answers are no longer reproducible | A golden set of real ROs and real appointments run in CI on every change, watching the override rate | Pin model versions, canary upgrades, and keep prompts and tool definitions in the repository under review. |
| Credential sprawl | The agent runs as a person, and the audit log says that person did it | An access review that cannot distinguish agent actions from human actions | Give the agent its own identity with its own scope. Microsoft's own documentation makes the case that application identities are the wrong primitive for agents, because an application identity assumes long-term stability while an agent may be created and destroyed thousands of times a day. |
Failure modes ranked roughly by how often we see them, not by severity.
The sixth row deserves expansion because it is the one dealers have lived through. In June 2024, BlackSuit ransomware hit CDK Global on 18 and 19 June, with a second intrusion on 19 June during recovery. Roughly 15,000 dealer locations in North America were affected, and phased restoration ran to about 4 July. CNN and others reported that CDK likely paid a ransom of around 25 million dollars.
Anderson Economic Group estimated $1.02 billion in direct losses to franchised dealers over the three calendar weeks including 19 June through 5 July 2024, revised up from an initial estimate of $944 million. Their methodology is published: roughly 56,200 lost new-unit sales plus lost used-vehicle earnings, lost parts-and-service earnings, added staffing and IT cost, and added floorplan interest, corroborated against public dealer groups' investor disclosures — and it explicitly excludes consumer damages, reputational damage and litigation costs.
The design conclusion from that episode is not about vendor selection. It is that your agent needs a documented degraded mode: what it does when the DMS is unreachable, what it captures offline, how a service department keeps writing ROs on paper, and how the agent reconciles that capture when service returns. Almost nobody builds this before they need it. We have no data on which departments recovered fastest in 2024 and we are not going to invent any — the argument for rehearsing a paper process is simply that a department that has never rehearsed one will be inventing it under maximum pressure.
Red Flags in Vendor Selection
Fixed ops attracts a lot of AI vendors, and the good ones are easy to distinguish from the rest with a short list of questions. Each red flag below is diagnostic rather than disqualifying — but each one tells you something specific about how the vendor will behave on the facts you cannot check.
| Red flag | What it actually tells you |
|---|---|
| We integrate with CDK and Reynolds, with no programme named | Ask whether it is 3PA, RCI, an OEM-certified interface, a dealer-authorized extract, or a robot driving your screens. The answer determines your contractual and Safeguards exposure, not theirs. |
| Refusal to put DMS integration fees in writing for your rooftop count | Neither DMS vendor publishes a schedule. That is exactly why your vendor has to be the one who commits a number to paper before you sign. |
| A published containment, booking or deflection rate | No independent benchmark exists for service-agent performance. Every accuracy figure in this market is vendor-published, which is why we exclude them from evaluation entirely rather than reprinting them. |
| An outbound AI voice with no consent story | FCC 24-17 makes an AI-generated voice an artificial or prerecorded voice under the TCPA. Ask to see the consent capture, the revocation handling and the audit trail before the first call goes out. |
| Our agent writes directly into the DMS, with no mention of a writeback tier | Either somebody is paying for a writeback package, or a robot is driving your DMS user interface. Find out which, in writing. |
| No answer on who the Qualified Individual is | Under 16 CFR Part 314 the dealer retains responsibility even where the Qualified Individual is a service provider's employee. A vendor that has not thought about this has not thought about your compliance at all. |
| Screen scraping described as integration | It may genuinely be the only rung available. It is still a contract question first, and the case most often cited for its legality ended in a $500,000 judgment and a destruction order against the scraper. |
| No exportable per-action audit log | You need it for a Safeguards review, an OEM warranty audit and your own incident response. A dashboard you can look at is not an export you can produce. |
| We always run the latest model | Then your system's behaviour can change without a deployment and you cannot answer what it did last quarter. Ask for pinned versions, a changelog and a rollback path. |
| Citing the CDK settlements as proof that DMS data access is now open | The settlements moved money. No court compelled an integration path, and the Seventh Circuit specifically said compelling access was the wrong preliminary remedy. |
| Quoting a franchise DMS market-share percentage as if it came from the FTC | We could not verify any FTC document containing a percentage. The agency's own characterization was that CDK and Reynolds are the two largest providers of DMS software to new-vehicle dealers in the United States. A vendor that inflates a citation once will do it again in the parts of the deck you cannot check. |
| No rollback story for a bad write | If the answer to what happens when the agent writes the wrong thing is that it does not, you are talking to marketing. |
Vendor selection red flags for dealership fixed-ops AI, August 2026.
The third row is the one we would defend hardest, because it is where our own approach differs from the market. There is no independent, methodologically-disclosed benchmark for service-agent accuracy, booking rate, containment or deflection in this category. Every figure in circulation is vendor-published, usually with no sample size, no baseline and no description of what counted as a success. We do not reprint them, we do not score vendors on them, and we would encourage you to treat their presence in a deck as information about the vendor rather than about the product.
The same discipline applies to the claim that a DMS vendor is difficult and a challenger is open. Openness is a contract, not a temperament. Ask for the agreement.
What It Costs to Build This Properly
These are Frenchy Digital's published bands. They are the same across this cluster, because the engineering discipline is the same whatever the system of record happens to be called.
| Engagement | Range | Timeline | What is included |
|---|---|---|---|
| Discovery + workflow audit | $9k–$22k | 2–4 weeks | DMS contract and data-rights review, write-path assessment per system, data-flow map across DMS, scheduling, CRM and inspection tools, and a prioritized workflow shortlist with a measurable baseline for each |
| Single-workflow agent (scheduling triage, RO drafting, parts chasing, warranty pre-check) | $28k–$70k | 4–9 weeks | One workflow end to end, extraction with confidence scores, an exception queue, human-in-the-loop review, idempotent writes and exportable audit logging |
| Multi-workflow platform with DMS and scheduling integration | $70k–$180k | 9–16 weeks | Several workflows, certified read integration, a human-mediated write path, an evaluation set running in CI, a role matrix and a documented degraded mode |
| Enterprise / multi-rooftop / regulated build (audit logging, HITL, SOC 2 posture) | $180k–$420k+ | 14–24 weeks | Multi-rooftop isolation, a full audit pipeline, disaster-recovery testing, a Safeguards documentation package, service-provider oversight artefacts and security review support |
Frenchy Digital engagement bands, August 2026. These figures exclude any certified-integration programme fee charged by your DMS vendor, which is not published by any DMS vendor and must be quoted to you separately.
- Senior-led rates: $150–$225 per hour. There is no junior bench doing the work under a senior byline.
- Ongoing retainer: $2,500–$9,500 per month for operation, evaluation maintenance, model-version management and integration monitoring.
- Post-launch warranty: 30 days. If something we shipped is broken, we fix it inside the engagement.
- Proposal turnaround: A written, fixed-price phased proposal within 5 business days of discovery.
- Ownership: Full source-code and IP ownership transfers to you at delivery. No vendor lock-in, no hostage data model, and your evaluation set is yours.
- Who we are: A senior-led Black-owned Los Angeles agency. Reachable at +1 (424) 272-5601.
One budgeting note specific to this industry: leave a line for the interface fee and leave it unpriced. Because neither major DMS vendor publishes a schedule, you cannot responsibly estimate it, and putting a made-up number in a capital request is worse than putting a placeholder with a named owner and a date by which it will be resolved. Phase 0 exists to convert that placeholder into a written number before the build starts.
Limitations: What We Could Not Verify
This section is the point of the article as much as any other. What follows is a specific list of things we chased and could not establish, because a vague acknowledgement that the evidence is mixed helps nobody making a budget decision.
- No published fee schedule exists for CDK 3PA or Reynolds RCI: Neither vendor's current published materials contain one. Every number in circulation is either July 2017 forum testimony or an allegation in an antitrust complaint. We label and date each and we do not present any as current.
- We hold no fetched Reynolds programme language at all: The RCI third-party page rendered as title-only to our fetcher. We therefore do not quote Reynolds, do not characterize RCI's terms, and do not compare its gatekeeping to CDK's.
- FTC-hosted documents returned HTTP 403: That includes the Safeguards Rule dealer FAQ and the March 2018 CDK/Auto/Mate press release. We cite the URLs and treat their contents as secondary, corroborated through contemporaneous trade coverage. We paraphrase rather than quote them.
- We could not verify the seventy-percent franchise DMS market share attributed to an FTC filing: Nor the roughly-fifteen-thousand-rooftop and roughly-half-the-market figures for CDK, which circulate from June 2024 outage coverage rather than from a primary filing. We use the FTC's own characterization and omit percentages.
- We could not verify which court entered the $630 million vendor-class approval: Trade reports split between the Northern District of Illinois, where MDL 2817 sits before Judge Rebecca R. Pallmeyer, and a federal court in Madison, Wisconsin, the original Authenticom venue. We give the approval date of 25 February 2025 and name no court.
- We could not verify whether certiorari was sought or denied in CDK Global v. Brnovich: Nor could we verify a complete, current list of states with dealer-data-access statutes. We name Arizona, Oregon, Montana and North Carolina because those appear in our sources, and we publish no state count.
- We could not verify which five states limited manufacturer rebuttal of declared warranty labor rates in 2025: The trend is documented; the state list is not, at least not to a source we would put our name next to. Ask your dealer-law counsel about your own states.
- We could not source a comparable Xtime write-depth statement against CDK or Reynolds: The bi-directional repair-order management and parts-writeback claims are sourced only to Cox's own materials and only against Dealertrack DMS. That is a vendor claim about a same-family integration, and we present it as one.
- We could not confirm any Fortellis marketplace listing fee: A monthly per-app listing fee is reported in secondary sources; the Fortellis pricing page 404s, so we do not print an amount. If a fee matters to your business case, get it in writing from CDK.
- We found no documented DMS API deprecation or version-pinning incident with dates: Version churn is a real risk in this category and we would rather say we could not evidence a specific incident than invent an illustrative one.
- There is no independent benchmark for service-agent accuracy in this category: Every accuracy, booking, containment and deflection figure in the market is vendor-published. We exclude them from evaluation by design, and that refusal is deliberate rather than an omission.
- There is no standard for idempotency keys: The IETF draft is expired at revision -07 and is not an RFC. Every vendor's semantics differ slightly, which is exactly why duplicate writes are a design problem rather than a library choice.
- Prompt injection is unsolved: Research-grade architectural defences exist in the literature — a privileged planner, a quarantined reader with no tool access, and a deterministic policy engine outside the model. Our reading of the field is that no production-grade implementation of that pattern is shipping in a mainstream agent harness today, and we state that as our own assessment rather than as an established finding. Design for blast-radius reduction.
None of this argues against building. It argues for building the measurement alongside the agent, choosing one workflow where you already own the baseline, and being straight with your own organisation about which numbers are yours and which are somebody else's marketing.
And the boundary holds throughout. These are administrative, documentation and preparation systems operating under human review. Estimates, authorizations, warranty attestations, ledger postings, recall communications and anything with a safety or legal consequence stay with a named person in your store. The DMS decides what your agent may write. You decide what it should.
Automating Fixed Ops Without Breaking Your DMS Agreement?
Book a free 60-minute discovery call with Frenchy Digital — a senior-led Black-owned LA agency. You leave with a write-path assessment for your DMS, a data-flow map across scheduling, CRM and inspection tools, and a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.
Automating Fixed Ops Without Breaking Your DMS Agreement?
Book a free 60-minute discovery call. You leave with a write-path assessment for your DMS, a data-flow map across scheduling, CRM and inspection tools, and a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1Authenticom, Inc. v. CDK Global, LLC, 874 F.3d 1019 (7th Cir. 2017) — FindLaw report↗
- 2Constantine Cannon — Seventh Circuit Strikes Injunction, Finding No Duty To Deal↗
- 3Digital Dealer — CDK Reaches $630M Settlement in Dealer Data Lawsuit↗
- 4CBT News — CDK Global Settles Antitrust Claims for $630 Million Amid Data Access Disputes↗
- 5Top Class Actions — $129.5M Dealer Management Systems Class Action Settlement↗
- 6CDK preliminary-approval motion, In re Dealer Management Systems Antitrust Litigation (PDF)↗
- 7FTC — FTC Challenges CDK Global, Inc.'s Proposed Acquisition of Competitor Auto/Mate, Inc. (March 2018)↗
- 8CDK Global LLC v. Brnovich, 16 F.4th 1266 (9th Cir., 25 October 2021) — opinion PDF↗
- 9Oregon Revised Statutes § 650.123 — dealer data protection↗
- 10Cox Automotive v. CDK Global — complaint (W.D. Wis., December 2017, PDF)↗
- 11Authenticom v. CDK Global & Reynolds — antitrust complaint (PDF)↗
- 12Hoover Automotive v. CDK Global — complaint (PDF)↗
- 13CDK Global — API Solutions (vendor page)↗
- 14Fortellis — CDK developer marketplace↗
- 15Fortellis community — What APIs are production and what do they cost (2019 thread)↗
- 16DealerRefresh forum — CDK Third Party Access pricing guide (July 2017)↗
- 17Xtime — DMS integrations↗
- 18Cox Automotive — Xtime adds new features to modernize the automotive service experience↗
- 19TechTarget — The CDK Global outage: explaining how it happened↗
- 20Anderson Economic Group — Dealer losses due to CDK cyberattack reach $1.02 billion↗
- 21FTC — Automobile Dealers and the FTC's Safeguards Rule: Frequently Asked Questions↗
- 22FCC — Declaratory Ruling FCC 24-17 on AI-generated voices under the TCPA (PDF)↗
- 23Consumer Financial Services Law Monitor — FCC further extends effective date for TCPA revoke-all rule↗
- 24Nelson Mullins — Reasonableness in state warranty reimbursement statutes takes a hit in 2025↗
- 25NADA — NADA and TADA win court challenge to FTC vehicle shopping rule; rule vacated↗
- 26Auto Care Association — Right to Repair↗
- 27hiQ Labs, Inc. v. LinkedIn Corp., No. 17-16783 (9th Cir., 18 April 2022) — opinion PDF↗
- 28Van Buren v. United States — Cornell Legal Information Institute↗
- 29Model Context Protocol — Security Best Practices (specification 2026-07-28)↗
- 30Simon Willison — The lethal trifecta for AI agents↗
- 31Stripe — Idempotent requests↗
- 32IETF — draft-ietf-httpapi-idempotency-key-header (expired, not an RFC)↗
- 33Microsoft — What are agent identities (Microsoft Entra Agent ID)↗
- 34OWASP GenAI Security Project — GenAI LLM Top 10 repository (2026 edition)↗

