> For the complete documentation index, see [llms.txt](https://docs.lpp-minduniverse.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lpp-minduniverse.org/lingua-pactum-protocol-lpp-documentation/1.constitutional-foundation/1.7-amendment-invariants.md).

# 1.7 Amendment Invariants

A constitutional protocol faces a second-order governance problem:

> **Who governs changes to the governance rules themselves?**

If constitutional protections can be silently weakened by ordinary implementation updates, then the Constitution can be bypassed without directly violating an execution rule.

The amendment problem is therefore itself a governance problem.

The current public Amendment Invariant Framework develops this problem through architectural invariants.

#### Constitutional Invariants

An invariant is a condition that must remain true across valid protocol evolution.

The current framework identifies six principal amendment invariants.

**I-1 — Non-Degradation Invariant**

A valid amendment must not reduce established minimum protections for:

* safety,
* accountability,
* interruptibility,
* or auditability.

The objective is to preserve constitutional floors even as technical implementations evolve.

**I-2 — Authority Separation Invariant**

Amendments must not eliminate or materially weaken critical separation between:

```
Control Plane / Execution Plane

Authority Issuer / Executor

Policy Definition / Enforcement Boundary
```

Interfaces may evolve.

The separation itself must not disappear through architectural consolidation.

**I-3 — Proof-Carrying Amendment Invariant**

A constitutional amendment should not become valid merely because an authority asserts that it is safe.

The amendment framework requires reconstructable supporting material such as:

* invariant impact analysis,
* formal or structured checks,
* and an auditable validation path.

The principle is:

> **Legitimacy of amendment must be demonstrated, not merely declared.**

**I-4 — Revocability Preservation Invariant**

Protocol evolution must not make legitimate revocation structurally weaker.

Revocation should remain:

* state-bound,
* enforceable,
* and operationally meaningful.

An amendment that grants authority more easily while making that authority significantly harder to revoke would violate the direction of the constitutional model.

**I-5 — Anti-Capture Invariant**

The amendment framework identifies governance capture as a constitutional threat.

A valid architecture should resist permanent capture by:

* a single organization,
* a single vendor,
* a single jurisdiction,
* a single validator,
* or a unique non-replaceable amendment path.

This principle addresses the possibility that formal governance remains intact while effective control becomes monopolized.

**I-6 — Transparency-of-Legitimacy Invariant**

The legitimacy of a constitutional change should be independently reconstructable.

A third party should not need to trust the mere assertion of the proposer or implementer in order to determine whether the amendment process was legitimate.

The guiding distinction is:

```
Declared legitimacy
≠
Verifiable legitimacy
```

#### Protected Principles

The amendment framework protects several constitutional properties from silent erosion:

* authority separation,
* revocability,
* accountability,
* auditability,
* interruptibility,
* anti-capture,
* and reconstructable legitimacy.

These protections ensure that an implementation cannot claim compatibility merely by retaining constitutional terminology while weakening the structural conditions those terms represent.

#### Amendment Boundaries

Protocol evolution is permitted.

Constitutional erosion is not.

This creates a boundary:

```
Architecture may evolve.
Interfaces may evolve.
Implementations may evolve.
Verification mechanisms may evolve.

Constitutional protections
may not be silently degraded.
```

A future protocol version may introduce:

* stronger verification,
* different cryptographic primitives,
* new execution environments,
* different distributed architectures,
* improved authority objects,
* or new conformance mechanisms.

Such evolution is compatible with the Constitution when protected invariants remain preserved.

#### Proposal, Authorization, and Execution of Amendments

The current Amendment Invariant Framework additionally separates three amendment powers:

```
Proposal Power
        ↓
Authorization Power
        ↓
Execution Power
```

These correspond to:

**Proposal Power**\
Who may propose a constitutional modification.

**Authorization Power**\
Who may establish that the modification has legitimate approval.

**Execution Power**\
Who may write the ratified change into the canonical version chain.

The framework rejects collapsing all three functions into a single uncontrolled authority domain.

This is the constitutional equivalent of preventing an execution system from authorizing itself.

#### Why Amendment Governance Matters

Without amendment constraints:

```
Admission Rule
        ↓
can be bypassed by
        ↓
Changing the Rule
```

Therefore:

> The Admission Kernel governs whether an action has legitimate authority before execution.

> The Constitutional Layer governs whether the rules defining that legitimacy may themselves be validly changed.

These are separate but mutually dependent governance problems.

Without constitutional constraints, admission rules may be weakened through rule mutation.

Without an operational admission mechanism, constitutional principles may remain symbolic.

Structural legitimacy requires both.

***

### Constitutional Foundation Summary

The constitutional layer establishes seven essential constraints for the rest of this documentation:

1. **Language may become action.**
2. **Consequential action requires attributable responsibility.**
3. **AI capability does not create sovereign authority.**
4. **Responsibility must resolve to legitimate human or institutional governance.**
5. **Consequential systems must remain interruptible and revocable.**
6. **Execution systems must not create or restore their own legitimacy.**
7. **The governance rules themselves must not be silently modified around constitutional protections.**

These principles establish the normative basis for Layer 0.

The next chapter moves from constitutional principle to protocol positioning:

## 2. LPP Positioning

There the central question becomes more precise:

> **What exactly is Layer 0 Constitutional Admissibility, and why is it distinct from identity, access, permission, runtime policy, execution security, and operational safety?**
