PENGO Workbench
Workbench / Issues / Tool Can Act Without Responsible Authority

Issue

Tool Can Act Without Responsible Authority

A tool, connector, function, or integration can perform an action without a declared responsible authority for that action.

What This Looks Like

A tool, connector, function, or integration can change state, send data, update records, trigger workflows, or perform actions without a clear responsible authority. The tool may be callable by an agent, but the system does not declare who owns the action, who approved it, or who can reverse it.

Why It Matters

Tools turn AI decisions into operational effects. If a tool can act without responsible authority, the workflow may allow state changes without accountability. This creates risk around permissions, approvals, audit trails, and recovery when something goes wrong.

Structural Signal

A tool action exists without a connected authority owner. The issue is not only that the tool can act; it is that the action is not governed by a declared approval or responsibility structure.

Common Triggers

  • Tool access is granted broadly without action-level ownership
  • The tool schema declares what can be done but not who authorizes it
  • Agent permissions are inherited from a workspace or account
  • Tool calls can modify state without a review gate
  • Audit metadata records execution but not responsible authority
  • The workflow treats tool availability as permission to act

When to Use This Issue

Use this Issue when a tool, connector, function, or integration can perform an action without a declared responsible owner, authority, or approval path.

When Not to Use This Issue

Do not use this Issue when the tool fails because of missing inputs or wrong schema. Do not use it when the authority is declared and the tool simply executes incorrectly.

Category

Permissions & Approvals

Primary Pattern

PAT-0120 — Missing Authority

Declared Patterns

Derived Primary Lenses

Derived Secondary Lenses

Related AI-Adjacent Issues

Search Intents

  • tool can act without responsible authority
  • AI tool has no responsible authority
  • tool action lacks owner
  • MCP tool can act without approval
  • connector action has no authority
  • tool permission without responsibility