MATH.17:5.1 - Individually permitted changes and a permitted whole
Let X={0,1} x {0,1}. An update is allowed to change at most one coordinate of each input pair. Flipping the first coordinate is allowed; flipping the second is allowed. Their composite sends (0,0) to (1,1) and changes two coordinates. The proposed collection is not closed under composition.
If the requirement limits each elementary step, keep a sequence of these steps and inspect intermediate states. If it limits the difference between initial and final states, test the composite against that bound and reject this pair. The same counterexample distinguishes the two intended uses.
Now take another requirement: the two coordinates must stay equal. Put P={(0,0),(1,1)} and admit functions sending P into P. The joint flip belongs; either single-coordinate flip fails. Closure follows from :4.3. This change of admissibility supplies a composable class suited to the equality requirement.