> For the complete documentation index, see [llms.txt](https://docs.lpp-minduniverse.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lpp-minduniverse.org/lingua-pactum-protocol-lpp-documentation/5.-lpp-admission-kernel/5.4-scope-containment.md).

# 5.4 Scope Containment

Authority is bounded.

An Action Candidate must remain inside the scope authorized by the applicable Authority Object.

The core invariant is:

```
ExecutionIntent
⊆
AuthorizedScope
```

Conceptually:

```
ScopeContains(AO, E)
```

must hold before the action can be admitted.

#### Scope Dimensions

Scope may include constraints on:

* action,
* function,
* target,
* parameters,
* account,
* resource,
* jurisdiction,
* environment,
* amount,
* data domain,
* tool,
* privilege level,
* or other execution boundaries.

#### Example

Suppose authority permits:

```
Action:
isolate_host

Target:
host:A
```

The same authority must not silently permit:

```
Action:
modify_network_policy

Target:
entire_production_network
```

even if the same AI agent possesses technical access to both.

#### Scope and Capability

The architectural distinction is:

```
System can reach target
≠
Authority includes target
```

Likewise:

```
Tool supports operation
≠
Authorized scope permits operation
```

#### Scope Expansion

Scope expansion may occur through:

* tool chaining,
* task decomposition,
* principal substitution,
* delegated subtasks,
* parameter changes,
* target expansion,
* or semantic reinterpretation.

The kernel must evaluate the resulting concrete action rather than relying only on the scope of the original task description.

#### Current Decision Semantics

Current LPP research consistently treats scope failure as a non-admissible condition.

Published operational documents have evolved in whether specific scope failures are labeled `DENY` or structural `COLLAPSE` under particular formalizations.

GitBook v2.0 preserves the higher-level invariant here:

> **Out-of-scope execution may never produce ADMIT.**

The canonical reason-code and decision mapping is centralized later in the Reference & Governance and Appendix decision-mapping sections rather than duplicated inconsistently across chapters.

***
