Great catch — you're describing exactly the tension I'm sitting in. The second-run story is partially built: the pipeline's first node diffs against last_processed_commit, so incremental runs only re-parse and re-generate docs for changed files, and the review queue is scoped to those. The full-repo re-approval problem doesn't exist on paper. The honest gap is what you hinted at with "invalidated a section": Invalidation is file-level, not dependency-aware. If auth.py changes, the docs for modules importing it aren't flagged. The AST call graph is already extracted by the parser, so dependent-aware invalidation is the natural next step — likely a Part 8 topic. Thanks for reading so closely.
