> For the complete documentation index, see [llms.txt](https://docs.lpp-minduniverse.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lpp-minduniverse.org/lingua-pactum-protocol-lpp-documentation/5.-lpp-admission-kernel/5.11-fail-closed-semantics.md).

# 5.11 Fail-Closed Semantics

The Admission Kernel follows a fail-closed rule.

The core principle is:

> **No execution may proceed under unresolved admissibility state.**

The formal model represents unresolved governance state as:

```
⊥
```

where `⊥` may represent:

* unresolved,
* malformed,
* unavailable,
* contradictory,
* or unverifiable state.

The rule is:

```
Verify₀(AR, G, Σ) = ⊥
        ↓
Admit₀(AR, G, Σ)
∈
{ DENY, DEFER, COLLAPSE }
```

and never:

```
Verify₀(AR, G, Σ) = ⊥
        ↓
ADMIT
```

#### Silence Is Not Permission

Failure to receive a decision does not mean execution may continue.

```
No response
≠
ADMIT
```

#### Timeout Is Not Permission

A network or authority-resolution timeout must not be interpreted as implicit authorization.

#### Unavailable Authority Is Not Permission

If required authority state cannot be verified, the system cannot simply assume it remains valid.

#### Unavailable Revocation State Is Not Permission

Revocation uncertainty is handled according to consequence and governance requirements.

Higher-consequence actions require stronger fail-closed treatment.

#### Malformed State Is Not Permission

Malformed requests, authority objects, evidence, or decisions cannot be coerced into execution through permissive parsing.

#### Invalid Permit Is Not Permission

Layer 1 must reject unverifiable or invalid Permits.

The entire rule can be compressed into:

> **Uncertainty may increase restriction. It may not create authority.**
