> For the complete documentation index, see [llms.txt](https://docs.lpp-minduniverse.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lpp-minduniverse.org/lingua-pactum-protocol-lpp-documentation/8.-security-and-enforcement/8.7-revocation-enforcement.md).

# 8.7 Revocation Enforcement

Authority must remain revocable.

Revocation is not meaningful if a system continues accepting execution indefinitely after authority has been withdrawn.

The core rule is:

```
AuthorityRevoked
        ↓
No continued legitimate reliance
```

#### Active Authority State

At relevant admission or execution checkpoints, the system must determine whether the applicable authority remains active.

A simplified condition is:

```
Authority_ID matches
∧
Authority State = ACTIVE
∧
not expired
∧
not revoked
```

#### Gate-Time Check

The reference execution hook includes authority and revocation verification at execution time or through an applicable bounded revocation mechanism.

This matters because authority state may change after initial admission.

Consider:

```
T0:
Authority ACTIVE
        ↓
Permit issued

T1:
Authority REVOKED

T2:
Agent attempts execution
```

The existence of a Permit created at `T0` must not automatically erase the revocation event at `T1`.

#### Permit Invalidation Implications

Revocation creates an important relationship:

```
Upstream authority invalidated
        ↓
Downstream authorization
cannot be treated as permanently independent
```

Different implementation profiles may realize this through:

* online revocation checks,
* short Permit lifetime,
* push revocation updates,
* continuous revocation channels,
* or other bounded revocation mechanisms.

#### Revocation Unknown

If revocation status is mandatory but cannot be determined, the reference CP / EP model uses a restrictive response.

Depending on the deployment profile this may be:

```
DENY
```

or a defined safe mode that prohibits irreversible action.

It must not silently become unrestricted execution.

#### Revocation Propagation

A high-assurance system must address how quickly revocation state reaches the execution boundary.

The existing security specifications identify **revocation propagation latency** as a threat.

A revocation mechanism that updates only after the action has completed may provide evidence but not effective interruption.

#### Current MVP Boundary

The present MVP validation set includes:

```
Post-revocation execution attempt
        ↓
DENY / blocked
```

This demonstrates that an already revoked authority state can block subsequent execution in the tested prototype.

It should not be overstated as proof that all forms of mid-execution revocation propagation have been validated.

That stronger problem belongs to continuous admissibility.
