---
title: "3GPP TS 33.127: architecture and functions"
chapter: "14"
---

# 3GPP TS 33.127: architecture and functions

TS 33.127 is the Stage 2 architecture specification for modern 3GPP LI. It allocates responsibilities among administration, points of interception, mediation/delivery, and receiving functions across mobile-system services.

> **Safety boundary:** this chapter teaches lawful, governed system design from
> public standards. It does not provide operational targeting, activation,
> decryption, surveillance-evasion, or covert collection instructions.

## The mental model

| Concept | Plain meaning | Control that must travel with it |
|---|---|---|
| **Stage 2** | Turns requirements into logical functions and reference points | Products may combine roles only with preserved controls |
| **ADMF** | Administers authorized LI state | Protect from service-plane and ordinary operations |
| **POI** | Observes relevant authorized information in a network function or service | Bind output to current provisioning |
| **MF/DF** | Mediates and delivers IRI or CC | Transformation must be traceable |
| **LEMF** | Authorized receiving environment | Endpoint and jurisdiction are verified |
| **Service coverage** | Architecture applies across defined 5G/EPS/IMS services | Capability claims must name the release and service |

## Apply it as a controlled workflow

1. Select the 3GPP release and supported service set.
2. Map logical functions to real network functions, vendors, and responsibility.
3. Draw control, IRI, and CC flows with trust boundaries.
4. Define state propagation, correlation, scaling, and failover.
5. Test roaming, slicing, service chaining, and mixed-release conditions conceptually.
6. Keep a release-aware architecture decision and conformance record.

## Evidence to demand

- Each logical function has an accountable owner and least-privilege identity.
- Co-located functions retain separate authorization and audit boundaries.
- Topology change cannot orphan active lawful state.
- Unsupported services fail visibly rather than appearing compliant.

## Failure to reason about

A vendor appliance combines ADMF and mediation for simplicity. This can be acceptable only if access, data, logging, key, approval, and failure boundaries still enforce separation. A box boundary is not a control boundary.

## Feynman check

33.127 assigns jobs: who manages the lawful task, where allowed service information is observed, who prepares it, and where it is received.
