
Texas requires a method-specific access and effective-consent analysis, not a blanket rule that read-only prospect reviews are permitted. An MSP should establish who can authorize the work, which systems are covered and the purpose for which consent was given.
Evidence before outreach · Part 9: Texas. Official statutory text retrieved October 6, 2026. Educational information, not legal advice or clearance. Decisions, amendment reconciliation and exact-method application remain pending.
- Texas effective consent concerns both authority and the approved purpose.
- Section 33.02(a) does not expressly require damage for its basic access offense.
- The security-contract defense in § 33.02(f) applies to a specified subsection, not every allegation.
- SCOUTz distinguishes indexed public observations from verified findings and authorized tenant evidence.
- Official Texas text is available; method-specific legal clearance remains incomplete.
What should MSPs review under Texas security scanning laws?
Official Penal Code § 33.02(a) states that knowingly accessing a computer, network or system without the owner's effective consent is an offense. Separate § 33.02(b-1)(1)–(2) provisions contain intent and conduct requirements involving fraud, harm or property changes. Do not import every enhanced element into subsection (a).
Section 33.01(1) defines access to include approaching, communicating with, retrieving data from or otherwise using computer resources. That definition is broader than a successful private-account login, but the definition alone does not establish an offense.
The official Texas source replaces the earlier draft's reliance on secondary reproduction. Retrieval is not an assertion that every recent enactment, effective-date question or relevant decision has been reconciled.
| Official provision | Question highlighted | Important limit |
|---|---|---|
| § 33.01(1) | What resources were approached, communicated with or used? | The access definition alone is not an offense |
| § 33.01(12) | Was consent effective for this person and purpose? | A meeting invitation is not system permission |
| § 33.02(a) | Was knowing access without effective consent established? | Lack of damage does not resolve the stated basic offense |
| § 33.02(b-1) | Were the separate intent and conduct elements met? | Keep this analysis distinct from subsection (a) |
Who can provide effective consent, and for what purpose?
Section 33.01(12) includes consent from a person legally authorized to act for the owner. Subparagraphs (A), (B) and (E) address deception or coercion, a known lack of authority and consent used for a different purpose. Other stated conditions also appear in the definition; this is not an exhaustive defense opinion.
A person can agree to a meeting without being authorized to approve a tenant review. Approval of one assessment does not automatically authorize later investigation, broad disclosure or unrelated reuse. Use the authorization guide to record the boundaries before protected access.
Suggested records include:
- The organization and systems in scope.
- The authorizing person and their organizational role.
- The assessment purpose and approved methods.
- Evidence categories and excluded conduct.
- Report recipients and permitted uses.
- Withdrawal or changes in permission.
This is an operating structure for counsel to review, not a universal Texas form requirement. The purpose is to make the permission reproducible by someone who did not attend the meeting.
Does public reachability establish consent for every request?
No universal conclusion follows. Reading a third-party index, querying published DNS and contacting the target for HTTP, TLS or port observations create different request records. The methods guide defines those actions precisely.
An indexed reference does not establish that the prospect service was contacted, currently responds or contains sensitive material. If no verification request was sent, leave that limit visible. A tool's commercial purpose does not establish the owner's effective consent.
For each collector, preserve the source, date, request destination, information sought and permission basis. Review any restriction, objection or withdrawal separately. Public availability and read-only operation alone do not resolve the statutory inquiry.
Does every security contract provide a defense?
No. Section 33.02(f) identifies a contract-based defense to prosecution under subsection (b-1)(2). The text requires conduct consisting solely of action under a contract with the owner for security assessment or other security-related services.
Do not turn that limited provision into a universal exemption for any vendor selling security work. Section 33.02(e) separately addresses legitimate law-enforcement purposes; a commercial MSP should not claim that role merely because its work concerns security.
Relevant decisions and the actual contract still need review. The described defense does not by itself decide possible civil remedies, other offenses or jurisdiction.
How do Texas and federal access questions differ?
18 U.S.C. § 1030(e)(6) defines exceeding authorized access for federal purposes; § 1030(a)(2)(C) addresses intentional unauthorized or excessive access obtaining information from a protected computer. Texas effective consent is a separate state-law inquiry.
Federal source limit: this is GovInfo's official 2024 edition, effective January 6, 2025, not a verified current 2026 compilation. A comparison against later changes and controlling decisions remains pending.
DOJ Justice Manual § 9-48.000 B.2, B.3(8), C discusses federal charging and good-faith research. It is guidance, not immunity from state prosecution, civil claims or other federal offenses. It creates no enforceable right or benefit, and commercial prospecting is not automatically qualifying research.
Where does the described SCOUTz workflow fit?
The team describes the free domain review as public-record collection and passive enumeration. Indexed means publicly discoverable, with no request sent to verify the indexed resource. That is a source observation, not automatic evidence of a current vulnerability or breach.
The deeper Microsoft 365 assessment is separate, following prospect authorization and full sign-up through OAuth. OAuth grants scoped technical access, not unlimited organizational or legal authority. The described workflow is read-only and excludes content reads, exploit checks, brute-forcing and authentication testing.
SCOUTz's trust boundary supports the customer-approved configuration-and-metadata distinction and no-content design. The team's claims narrow the facts to review; they do not establish Texas legal clearance for every collector or later use of evidence.
Reports are diagnosis only, without threatened disclosure or a built-in remediation upsell. Commercial emails still need their own purpose, accuracy and opt-out review. Collection permission does not retroactively come from sending a report.
What research remains pending?
The official §§ 33.01–33.02 text has been read. Effective-date reconciliation, decisions applying consent to the actual methods, civil remedies and jurisdictional facts remain incomplete. The state research index keeps that distinction visible.
Suggested interim controls include approved public-source methods, no unapproved verification of indexed targets, a named scope for protected access and a stop process after objections. These are conservative operating choices, not a claim that Texas requires signed permission for every public lookup.
Compare Texas's person-and-purpose consent language with Pennsylvania's express or implied-consent defense. Neither state should be reduced to a national safe-or-unsafe label.
FAQ
Does Texas's basic access offense require damage?
Section 33.02(a) does not expressly require damage. Knowing access and effective consent still need method-specific review.
Who can provide effective consent?
Section 33.01(12) includes a person legally authorized to act for the owner. Establish the actual person's authority.
Can consent cover a different purpose?
Section 33.01(12)(E) identifies use for a different purpose as a condition in which consent is not effective.
Does OAuth prove every required authority?
No. OAuth grants scoped technical permission; organizational authority, systems and agreed purpose still matter.
Is a security contract always a defense?
No. Section 33.02(f)'s defense is directed to subsection (b-1)(2), with its stated conditions.
Has official Texas text been retrieved?
Yes, October 6, 2026. Decisions, amendment reconciliation and method-specific legal clearance remain incomplete.
One last thing
A permission record should survive the meeting. The next person handling the assessment should know who approved which work, for which system and purpose, without relying on a seller's recollection.
Sources
Statutes: official Texas §§ 33.01(1), (12), 33.02(a), (b-1), (e), (f), linked beside claims. Federal § 1030(e)(6), (a)(2)(C) uses the official 2024 edition, effective January 6, 2025; current-2026 comparison remains pending.
Court decisions: none is asserted. Effective-consent and assessment-purpose decisions remain pending.
Agency guidance: DOJ Justice Manual § 9-48.000, linked above; charging policy, not immunity.
Product sources: SCOUTz trust and the team's workflow description. Sources consulted October 6, 2026. No legal reviewer, numerical risk rating or clearance is claimed.
