PENGO Workbench
Workbench / Lenses / Authority Overlay Lens

LEN-0110

Authority Overlay Lens

Maps declared authority hierarchies onto observed structure to detect absence, override, or conflict.

Primary Pattern Matches

PAT-0100

Authority Collision

A structural condition where multiple authorities claim governance over the same region without a declared precedence or resolution rule.

Lens Application

The Authority Overlay Lens is a primary inspection mechanism for Authority Collision because it maps stated governance relationships against actual structural control. It helps identify where multiple authorities govern the same region, where hierarchy is missing, or where observed override behavior conflicts with declared authority.

Inspect For

  • Overlapping authority claims over the same governed region
  • Missing precedence rules between governing actors
  • Observed override behavior that conflicts with declared hierarchy
  • Declared authority structures that do not match actual control

Avoid

Treat overlapping authority as an inspection signal, not confirmation of Authority Collision, until the conflicting claims and missing resolution rule are identified.

PAT-0230

Authority Shadowing

A structural condition where a declared authority is functionally overridden by another authority without an explicit override rule.

Lens Application

The Authority Overlay Lens is a strong inspection mechanism for Authority Shadowing because it places formal authority claims beside actual decision, escalation, and enforcement behavior. It helps identify where an undeclared authority may be directing outcomes despite another authority being named.

Inspect For

  • Declared authority bypassed in recurring decisions
  • Escalations routed to a different actor or structure
  • Enforcement behavior inconsistent with formal hierarchy
  • Informal approval paths overriding stated authority

Avoid

Treat observed override signals as prompts for deeper inspection, not confirmation of Authority Shadowing, until corroborating structure, records, or behavior are identified.

PAT-0120

Missing Authority

A structural condition where a region, action, state, or decision path exists without a declared governing authority.

Lens Application

The Authority Overlay Lens is a primary inspection mechanism for Missing Authority because it overlays declared authority hierarchies onto the structure being examined. It helps identify areas where activity, decision flow, or state change exists without a corresponding authority assignment, or where authority is ambiguous, bypassed, or undeclared.

Inspect For

  • Actions or decisions without named owners
  • Regions or states outside declared authority paths
  • Overrides that lack an authorized source
  • Authority assignments that are absent, ambiguous, or bypassed

Avoid

Treat missing or unclear authority as an inspection signal requiring further review rather than evidence that Missing Authority has been established.

Secondary Pattern Matches

PAT-0220

Authority Merge Conflict

A structural condition where multiple authority states are combined over a shared scope without a declared merge, precedence, or reconciliation rule.

Lens Application

The Authority Overlay Lens applies indirectly to Authority Merge Conflict by mapping stated authority relationships against structures where multiple authority states operate together. It can surface places where overlays collide, bypass expected hierarchy, or leave shared control unresolved, supporting further inspection for merge ambiguity.

Inspect For

  • Overlapping authority claims across the same scope
  • Missing precedence between declared authority states
  • Overrides that lack an explicit reconciliation rule
  • Shared control areas with unclear governing hierarchy

Avoid

Treat overlay conflict as an inspection cue, not evidence that Authority Merge Conflict has been established.

Related Issues

ISS-0064

Action Triggered by Confidence Score

A confidence score, certainty label, risk level, or probability-like value triggers an action without enough approval, calibration, or authority control.

ISS-0087

Agent Cannot Choose Tool Without Tool Result

The agent needs a tool result to choose the right tool, but cannot obtain that result without choosing a tool first.

ISS-0115

Agent Gets Conflicting Tool Authority

An agent receives conflicting authority signals about whether, when, or how it may use a tool, connector, function, or integration.

ISS-0099

Agent Permission Expands Over Steps

An agent begins with limited permission but gains, assumes, or exercises broader authority as the workflow continues.

ISS-0109

AI Memory Has No Governance

Saved or persistent AI memory affects output without clear rules for ownership, scope, review, update, expiry, or removal.

ISS-0114

AI Memory Updated Without Asking

AI memory, saved context, preference, or durable state is updated without the user clearly asking for or approving that update.

ISS-0088

Approval Depends on Output That Needs Approval

A required approval depends on an AI output or workflow result that itself cannot be produced or trusted until approval is granted.

ISS-0111

Automation Skips Required Approval

An automated AI or workflow step proceeds past an approval gate that should have been required before action.

ISS-0043

Behavior Does Not Match Declared Role

The AI or agent behaves outside, below, or differently from the role, authority, responsibility, or permission posture declared for it.

ISS-0085

Cannot Identify Authoritative State

The user or workflow cannot tell which state, version, review result, decision, source, or output is currently authoritative.

ISS-0035

Conflicting Instructions From Different Authorities

Instructions from different sources, roles, policies, prompts, tools, or workflow authorities conflict without a clear rule for which one governs.

ISS-0015

Declared Owner Cannot Control Outcome

A person, role, system, or policy is declared responsible for an outcome but does not have the actual authority or control needed to govern it.

ISS-0014

Fallback Authority Is Missing

The system does not declare who or what has authority when the primary owner, rule, tool, source, or decision path is unavailable or inconclusive.

ISS-0039

Hidden Rule Overrides Visible Instruction

A hidden, upstream, system, policy, tool, or product rule changes or overrides the visible instruction the user expects the AI to follow.

ISS-0036

Human Review and Automation Disagree

A human review result and an automated AI or workflow result disagree without a declared rule for resolving the difference.

ISS-0084

Merge Step Leaves Unresolved Differences

A merge, reconciliation, or consolidation step combines outputs or reviews but leaves important differences unresolved.

ISS-0074

Missing Fallback for Unavailable Information

The task does not declare what the AI should do when required information, sources, tools, fields, or evidence are unavailable.

ISS-0050

Model Output Triggers Unapproved Action

AI output causes, recommends, or triggers an action that has not passed the required approval, permission, or authority check.

ISS-0070

Multiple Policies Say the Same Thing

Multiple policies, rules, or guidance documents express the same requirement, creating redundancy and uncertainty about which one governs.

ISS-0012

No Owner for Agent Action

An agent action can affect the system without a declared responsible owner, authority, or accountable decision path.

ISS-0083

Parallel Reviews Never Agree

Parallel AI, human, workflow, or tool reviews keep producing different results without resolving into a shared decision state.

ISS-0016

Permissions Conflict After Being Combined

Permissions, approvals, roles, policies, or authority rules that seem valid separately conflict when combined in the same workflow or AI action.

ISS-0090

Policy Decision Depends on Itself

A policy decision requires the outcome of the same policy decision before it can be made.

ISS-0065

Risk Score Triggers Wrong Escalation

A risk score, severity label, confidence value, or threshold result triggers the wrong escalation path.

ISS-0095

Risk Signal Escalates Beyond Evidence

A risk signal, warning, score, or concern escalates farther than the available evidence supports.

ISS-0037

Same Case Has Conflicting Policies

The same case appears to be governed by multiple policies, rules, or standards that point to incompatible outcomes.

ISS-0102

Severity Increases Without New Evidence

The severity, risk, confidence, or escalation level increases even though no new evidence has been added.

ISS-0103

Single Step Carries Too Many Decisions

One prompt, workflow step, review stage, or agent action carries too many decisions for the system or user to evaluate cleanly.

ISS-0108

Tool Can Act Without Responsible Authority

A tool, connector, function, or integration can perform an action without a declared responsible authority for that action.

ISS-0110

Tool Rules and Prompt Rules Conflict

Tool, connector, function, or MCP rules conflict with prompt instructions, causing the AI or agent to face incompatible requirements.

ISS-0013

Workflow Step Has No Decision Owner

A workflow step requires a decision, approval, judgment, or routing choice, but no owner is declared for making it.