> For the complete documentation index, see [llms.txt](https://docs.lpp-minduniverse.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lpp-minduniverse.org/lingua-pactum-protocol-lpp-documentation/8.-security-and-enforcement/8.5-permit-integrity.md).

# 8.5 Permit Integrity

An **Execution Permit** carries a successful admission decision into the execution boundary.

Its security depends on preserving the relationship between:

```
Authority
+
Intent
+
Scope
+
Policy State
+
Time
+
Specific Execution
```

A Permit must not become a generic reusable bearer credential.

The reference execution hook verifies several minimum properties.

***

#### Signature

The Permit must be verifiably issued by the legitimate Control Plane or applicable Permit issuer.

Conceptually:

```
Verify(
    Permit.signature,
    CP_public_key
) = TRUE
```

If signature verification fails:

```
No valid Permit
        ↓
No execution
```

The Execution Plane cannot replace the expected Control Plane signature with its own assertion.

***

#### Expiry

A Permit is time-bound.

A Permit whose validity window has ended must no longer authorize execution.

```
now < permit.expires_at
```

must hold under the applicable profile.

Permit lifetime also cannot legitimately exceed the upstream authority state on which it depends.

#### Intent Hash

The Permit is bound to the admitted Execution Intent.

Conceptually:

```
permit.intent_hash
=
H(admitted_execution_intent)
```

If the agent changes:

* function,
* target,
* relevant parameters,
* or other material execution content

after Permit issuance, the binding must fail.

This prevents:

```
Permit for Action A
```

from becoming:

```
Permit for Action B
```

through post-admission mutation.

#### Scope Binding

The Permit must remain bound to the admitted scope envelope.

Verification may include:

* function,
* parameters,
* target,
* resource,
* or other relevant scope elements.

#### Policy Binding

The reference architecture binds a Permit to the applicable policy version.

Conceptually:

```
permit.policy_hash
=
H(governing_policy_version)
```

This prevents an Execution Plane from relying on a Permit generated under one governance state while silently evaluating execution under a different or downgraded policy state.

#### Authority State

The Permit does not become independent from the Authority Object simply because it was once issued.

At execution time, the applicable profile may require verification that upstream authority remains valid and unrevoked.

#### Permit Integrity Rule

The canonical security rule is:

```
Valid Signature
∧ Valid Time
∧ Valid Intent Binding
∧ Valid Scope
∧ Valid Policy Binding
∧ Required Authority State
        ↓
Permit may be accepted
```

Failure of a mandatory Permit property must not be compensated by model confidence or business utility.

***
