A bus that cannot be overbooked, and a trip that cannot open unsafely.
Routes carry a vehicle, a driver with a phone number, a capacity and ordered stops. The route refuses riders beyond capacity, so a bus cannot be overbooked on paper and discovered full on the morning. A trip cannot take a single place until a risk assessment is recorded and an approval granted — enforced in code rather than in a policy document nobody rereads.
Live in the product. Each opens its own specification and working demo.