PENGO Workbench
Workbench / Lenses / Boundary Compliance Lens

LEN-0120

Boundary Compliance Lens

Evaluates observed structure against declared boundary posture, including allow, block, and exception rules.

Primary Pattern Matches

PAT-0340

Overreach

A structural condition where actions, effects, authority, or modifications extend beyond declared scope without authorization.

Lens Application

The Boundary Compliance Lens is a primary inspection mechanism for Overreach because it focuses on whether observed behavior stays within declared allow, block, and exception boundaries. It helps surface scope expansion, unauthorized effects, or modifications that exceed stated boundary posture.

Inspect For

  • Actions operating outside declared scope
  • Effects crossing blocked or restricted boundaries
  • Exceptions used without clear authorization
  • Modifications extending beyond approved limits

Avoid

Treat boundary mismatch as an inspection signal requiring review, not as proof that Overreach has occurred.

Secondary Pattern Matches

PAT-0140

Boundary Leakage

A structural condition where effects, permissions, state, data, or authority cross a declared boundary without an authorized exception.

Lens Application

The Boundary Compliance Lens applies indirectly to Boundary Leakage by checking whether effects, permissions, state, data, or authority cross declared boundaries in ways that match the stated boundary posture. It helps surface crossings that lack allow rules, appear to bypass block rules, or require exception review.

Inspect For

  • Cross-boundary flows without matching allow rules
  • Permissions or authority extending beyond declared scope
  • State or data movement relying on unclear exceptions
  • Block rules bypassed by informal paths

Avoid

Treat boundary posture mismatches as review signals, not proof that Boundary Leakage has occurred.

PAT-0180

Compatibility Violation

A structural condition where a graph, object, behavior, or runtime state exceeds a declared compatibility envelope without an authorized exception.

Lens Application

The Boundary Compliance Lens applies indirectly to Compatibility Violation by helping inspect whether observed behavior, graph shape, object state, or runtime posture sits outside declared allow, block, or exception boundaries. It can surface compatibility concerns when boundary rules and compatibility envelopes overlap, but should not be treated as a standalone determination.

Inspect For

  • Declared allow or block rules near compatibility limits
  • Runtime states outside expected boundary posture
  • Missing, expired, or unauthorized exceptions
  • Boundary rule changes that expose compatibility drift

Avoid

Treat boundary noncompliance as an inspection signal, not sufficient evidence that Compatibility Violation is present.

PAT-0390

Threshold Breach

A structural condition where an observed metric, value, state, or condition exceeds a declared quantitative or qualitative threshold.

Lens Application

As a secondary lens, the Boundary Compliance Lens supports inspection of Threshold Breach by checking whether a reported limit-crossing condition aligns with stated boundary posture. It can surface mismatches between allowed ranges, blocked states, exception handling, and observed metric behavior without treating the breach itself as fully established.

Inspect For

  • Declared allow, block, or exception rules
  • Observed values near or beyond stated limits
  • Boundary conditions that change threshold interpretation
  • Exception paths masking repeated breaches

Avoid

Treat boundary noncompliance as an inspection signal, not as confirmation that Threshold Breach has been established.

Related Issues

ISS-0046

Action Changed Something Else Too

An AI or agent action makes the requested change but also changes another object, field, file, state, rule, or workflow element that was not supposed to change.

ISS-0064

Action Triggered by Confidence Score

A confidence score, certainty label, risk level, or probability-like value triggers an action without enough approval, calibration, or authority control.

ISS-0008

Agent Keeps Expanding the Task

The agent repeatedly expands the task, plan, scope, or next-step list instead of completing the declared work.

ISS-0113

Agent Modified Unrelated State

An agent changes state outside the requested task, target, file, record, workflow, or authorized scope.

ISS-0099

Agent Permission Expands Over Steps

An agent begins with limited permission but gains, assumes, or exercises broader authority as the workflow continues.

ISS-0009

AI Adds Work Not Requested

The AI adds tasks, steps, analysis, checks, changes, or follow-up work that the user did not ask for.

ISS-0109

AI Memory Has No Governance

Saved or persistent AI memory affects output without clear rules for ownership, scope, review, update, expiry, or removal.

ISS-0114

AI Memory Updated Without Asking

AI memory, saved context, preference, or durable state is updated without the user clearly asking for or approving that update.

ISS-0026

AI Output Breaks Parser

The AI output causes a parser, validator, importer, or structured-output consumer to fail.

ISS-0045

AI Touches Unrelated Scope

The AI affects, edits, analyzes, changes, or reasons over material outside the scope of the requested task.

ISS-0044

AI Uses External Information When Forbidden

The AI uses outside knowledge, sources, tools, memory, or assumptions after the task forbids external information or limits the allowed source set.

ISS-0111

Automation Skips Required Approval

An automated AI or workflow step proceeds past an approval gate that should have been required before action.

ISS-0043

Behavior Does Not Match Declared Role

The AI or agent behaves outside, below, or differently from the role, authority, responsibility, or permission posture declared for it.

ISS-0003

Citation Points to Wrong Source

A citation, reference, link, or source pointer is present, but it points to the wrong source, wrong passage, wrong document, or unsupported evidence.

ISS-0032

Context Leaks Between Tasks

Context, assumptions, constraints, examples, files, or decisions from one task affect another task where they should not apply.

ISS-0015

Declared Owner Cannot Control Outcome

A person, role, system, or policy is declared responsible for an outcome but does not have the actual authority or control needed to govern it.

ISS-0048

File-Bounded Task Uses Outside Content

The AI is asked to work only from a specific file or document but uses content, assumptions, or sources outside that file.

ISS-0023

Hallucinated Fields

The AI adds fields, keys, attributes, columns, or structured elements that were not declared, requested, or allowed by the expected schema.

ISS-0039

Hidden Rule Overrides Visible Instruction

A hidden, upstream, system, policy, tool, or product rule changes or overrides the visible instruction the user expects the AI to follow.

ISS-0101

Local Exception Grows Into Policy

A local exception, special case, or one-off allowance begins to function like a general policy.

ISS-0096

Local Rule Spreads to Broader Cases

A rule intended for one local case, file, context, user, workflow, or exception begins affecting broader cases.

ISS-0038

Model and Workflow Disagree on Next Step

The AI model recommends or selects a next step that conflicts with the workflow state, required handoff, routing rule, or process sequence.

ISS-0052

Output Breaks After Model Change

Output that previously worked begins failing after a model, mode, runtime, or product behavior changes.

ISS-0018

Output Breaks the Next Step

The AI output looks acceptable by itself but cannot be used by the next tool, workflow step, parser, reviewer, or downstream consumer.

ISS-0059

Output Changed Without Declared Change

Output shape, content, format, fields, or behavior changes without a declared change to the prompt, schema, model, workflow, or governing rule.

ISS-0060

Output Exceeds Length Limit

The AI output exceeds a declared length, token, word, character, section, field, or size limit.

ISS-0049

Policy Exception Spreads Too Far

A narrow policy exception, allowance, or special case spreads beyond its intended scope and begins governing broader cases.

ISS-0054

Prompt Changed but Workflow Did Not

A prompt changes but the workflow, parser, review step, routing rule, or downstream expectation still assumes the old prompt behavior.

ISS-0076

Prompt Does Not Say What to Exclude

The prompt declares what to include but does not declare what should be excluded, allowing unwanted scope, sources, content, or actions into the result.

ISS-0062

Retrieval Exceeds Evidence Limit

The AI retrieves, uses, cites, or considers more evidence than the task permits or more than the review surface can support.

ISS-0051

Review Outcome Changes Unrelated Environment

A review result, approval, rejection, or classification changes state outside the environment, case, file, or workflow it was meant to govern.

ISS-0065

Risk Score Triggers Wrong Escalation

A risk score, severity label, confidence value, or threshold result triggers the wrong escalation path.

ISS-0095

Risk Signal Escalates Beyond Evidence

A risk signal, warning, score, or concern escalates farther than the available evidence supports.

ISS-0112

Routing Overrides Task Intent

Routing, mode selection, agent behavior, or workflow classification sends the task down a path that overrides what the user was trying to accomplish.

ISS-0004

Saved Reference No Longer Works

A saved source, citation, file reference, prompt reference, or workflow pointer previously worked but no longer resolves to the expected object or meaning.

ISS-0102

Severity Increases Without New Evidence

The severity, risk, confidence, or escalation level increases even though no new evidence has been added.

ISS-0106

Small Change Produces Large Downstream Effects

A small prompt, schema, policy, output, or workflow change creates unexpectedly large effects in downstream steps.

ISS-0098

Small Issue Keeps Escalating

A small issue, warning, uncertainty, or correction keeps increasing in severity, scope, or workflow impact across later steps.

ISS-0061

Too Many Tool Calls

The AI or agent makes more tool calls, searches, retrievals, API calls, or integration actions than the task requires or permits.

ISS-0017

Tool Call Contract Mismatch

The AI or agent calls a tool with names, arguments, types, modes, or shapes that do not match the declared tool interface.

ISS-0053

Version Change Breaks Existing Prompt

A prompt that previously produced usable results stops working after a version change in the model, tool, policy, schema, product surface, or workflow.

ISS-0024

Wrong Field Types

The AI returns fields with values whose types do not match the expected schema, such as strings where numbers, booleans, arrays, objects, or enums are required.