> For the complete documentation index, see [llms.txt](https://docs.lpp-minduniverse.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lpp-minduniverse.org/lingua-pactum-protocol-lpp-documentation/5.-lpp-admission-kernel/5.3-authority-validation.md).

# 5.3 Authority Validation

Authority validation determines whether the proposed action has a legitimate upstream authority basis.

The Admission Kernel must not infer authority from:

* model confidence,
* tool possession,
* API credentials,
* access rights,
* task completion,
* operational urgency,
* or agent consensus.

The kernel resolves the applicable **Authority Object**.

Conceptually:

```
AO ← resolve_authority(
    subject,
    target,
    action_type,
    current governance state
)
```

#### No Authority

If no applicable Authority Object exists:

```
No Authority Object
        ↓
No legitimate authority basis
        ↓
No ADMIT
```

The published formal model maps absence of authority to:

```
Deny(NO_AUTHORITY)
```

#### Malformed Authority

A structurally invalid Authority Object is different from simply having no authority.

Malformed authority means the purported legitimacy object cannot be coherently evaluated.

This is a structural failure.

The formal research model therefore treats malformed authority as a collapse-class condition.

#### Issuer Validation

The issuer must be recognized under the applicable governance constitution or authority model.

An AI agent cannot appoint itself as a legitimate issuer merely because it controls the execution path.

```
Self-issued authority
by the action-producing AI
≠
legitimate authority
```

#### Subject Binding

The Authority Object must apply to the relevant subject or principal.

Authority granted to:

```
Principal A
```

cannot silently become authority for:

```
Principal B
```

unless legitimate delegation or transfer conditions are satisfied.

#### Signature / Approval State

Where signatures or approvals are required, the kernel must determine whether the required authorization state is satisfied.

Missing or unresolved required signatures do not become implicit approval.

#### Authority as Mandatory Predicate

The overall rule is:

```
If authority fails,
admissibility fails.
```

No downstream runtime permission may compensate for invalid authority.

***
