Import what you have
Don't start over. Upgrade.
LangGraph, n8n, CrewAI, AutoGen, Copilot Studio, custom Python: every existing graph compiles into the same governed intermediate representation. Your prior work isn't replaced; it's adopted.
Importing someone else's agent is the riskiest thing you'll do this quarter.
Every import is a stranger's code entering your environment, and Operon treats it that way. The graph is analysed statically before anything runs. The archive is validated before it is unpacked. Code nodes are scanned against a blocked-pattern list covering network access, filesystem and process access, and dynamic evaluation — eval, new Function, child_process, subprocess, __import__ — and every match carries a severity rather than a bare flag, so a hardcoded os.environ read and an outbound socket don't land in the same bucket.
Hardcoded credentials are found and named: bearer tokens, AWS access keys, GitHub and Slack tokens, private key blocks. Tool names are checked against reserved namespaces, so an imported agent cannot shadow a platform capability by claiming its name. Every discovered tool is then evaluated against your own OPA policy, and the gate passes only when there are zero blocking violations. Where the incoming execution context leaves something unspecified, restrictive defaults apply — the safe answer is the default answer.
What does need to execute, executes inside a pooled, lifecycle-managed container with a hook at the Python import boundary. And the scrutiny doesn't stop once the agent is through the gate: imported agents are given a behavioural baseline, and deviations from it surface afterward, which is when the interesting failures actually happen.
01Analysed statically. Never executed to find out what it does.
02Archive validated before unpacking. Secrets found and named.
03Your OPA policy decides. Zero blocking violations, or no import.
04Baselined after admission, so drift is visible later.