Selection-scope handoff — fictional exhibition-material list Goal: process exactly the scope the user confirmed. Add a Needs review marker;240 results and 20 per page are illustrative. Page: selecting adds visible eligible IDs; clearing its checkbox removes only current-page IDs. Clear all removes every selection. Preserve IDs from other pages. All results: a separate server operation freezes accessible matching IDs, time, query, selection version and actual count. Disable execution while preparing. If unsupported, omit this action. Failure leaves zero selected with a reselect route. Membership:240 minus 1 equals 239. Five later arrivals are not included. Reselecting all results replaces the set and invalidates the previous confirmation. Navigation: sorting, page and page-size changes keep the set. Applied search/filter/workspace changes clear selection and confirmation with advance notice and a status message. A failed query must not restore old selection. Refresh does not restore unsubmitted selection. Responses: accept only the current query/selection generation. No execution during loading or selection preparation. Display: Select 20 on this page / Select all 240 results /239 selected,19 on this page. Partial state reflects eligible rows on this page. Name row checkboxes clearly; support keyboard and announce counts without stealing focus. Confirmation: connect operation, count, query scope, exclusions, capture time and selection version. Any selection edit invalidates it. Zero selected cannot execute. Server: immediately before execution validate current permission, eligibility and confirmation version for the same IDs. If one of 239 is no longer allowed, execute zero; show the reason and ask to confirm 238. Engineering must verify consistency between recheck and commit. After acceptance: preserve the accepted job target set and identifier. Later filters or refresh neither expand nor cancel it. Unknown response means checking that existing job before any retry. Owners: planning covers scope/copy/transitions; engineering covers snapshot, permissions and concurrency; QA compares actual IDs; support uses execution scope and reasons. Analytics must not contain personal record contents. Evidence: record build, owner, expected and actual targets, and evidence location after running the QA sequences. This is a design handoff, not a completed production integration test.