@sydneyrunkle Yes—this is what we’re building for security audits, with one constraint: the agent can expand a typed graph (fan-out, split, synthesize, attack-chain loops), while Go/Postgres/River own checkpoints, retries, accounting and approvals. Dynamic semantics, deterministic execution.