# LEN-0220 — Isolation Boundary Lens

## Ontology Metadata

Code: LEN-0220
Version: LEN-0220@0.1.0
Ontology release: 0.1.0
Updated: 2026-05-10T00:00:00Z
Canonical URL: /workbench/lenses/isolation-boundary-lens/

## Summary

Evaluates whether structural constraints, effects, and regions remain contained within declared boundaries.

## Primary Pattern Matches

- PAT-0140 — Boundary Leakage
  - URL: /workbench/patterns/boundary-leakage/
  - Summary: A structural condition where effects, permissions, state, data, or authority cross a declared boundary without an authorized exception.
- PAT-0260 — Cross-Layer Escalation
  - URL: /workbench/patterns/cross-layer-escalation/
  - Summary: A structural condition where escalation originating in one layer propagates into another authority, boundary, or control layer without explicit authorization.
- PAT-0400 — Unbounded Scope
  - URL: /workbench/patterns/unbounded-scope/
  - Summary: A structural condition where an operation, authority, rule, or expansion has no declared upper bound, boundary, or termination condition.

## Secondary Pattern Matches

- PAT-0420 — Undeclared Side Effect
  - URL: /workbench/patterns/undeclared-side-effect/
  - Summary: A structural condition where an operation modifies regions outside its declared target scope without a declared propagation or side-effect rule.

## Related Issues

- ISS-0046 — Action Changed Something Else Too
  - URL: /workbench/issues/action-changed-something-else-too/
  - Summary: An AI or agent action makes the requested change but also changes another object, field, file, state, rule, or workflow element that was not supposed to change.
- ISS-0113 — Agent Modified Unrelated State
  - URL: /workbench/issues/agent-modified-unrelated-state/
  - Summary: An agent changes state outside the requested task, target, file, record, workflow, or authorized scope.
- ISS-0009 — AI Adds Work Not Requested
  - URL: /workbench/issues/ai-adds-work-not-requested/
  - Summary: The AI adds tasks, steps, analysis, checks, changes, or follow-up work that the user did not ask for.
- ISS-0109 — AI Memory Has No Governance
  - URL: /workbench/issues/ai-memory-has-no-governance/
  - Summary: Saved or persistent AI memory affects output without clear rules for ownership, scope, review, update, expiry, or removal.
- ISS-0114 — AI Memory Updated Without Asking
  - URL: /workbench/issues/ai-memory-updated-without-asking/
  - Summary: AI memory, saved context, preference, or durable state is updated without the user clearly asking for or approving that update.
- ISS-0045 — AI Touches Unrelated Scope
  - URL: /workbench/issues/ai-touches-unrelated-scope/
  - Summary: The AI affects, edits, analyzes, changes, or reasons over material outside the scope of the requested task.
- ISS-0044 — AI Uses External Information When Forbidden
  - URL: /workbench/issues/ai-uses-external-information-when-forbidden/
  - Summary: The AI uses outside knowledge, sources, tools, memory, or assumptions after the task forbids external information or limits the allowed source set.
- ISS-0010 — Answer Has Too Many Paths
  - URL: /workbench/issues/answer-has-too-many-paths/
  - Summary: The answer presents too many possible paths, interpretations, options, or next steps without enough structure to choose among them.
- ISS-0111 — Automation Skips Required Approval
  - URL: /workbench/issues/automation-skips-required-approval/
  - Summary: An automated AI or workflow step proceeds past an approval gate that should have been required before action.
- ISS-0032 — Context Leaks Between Tasks
  - URL: /workbench/issues/context-leaks-between-tasks/
  - Summary: Context, assumptions, constraints, examples, files, or decisions from one task affect another task where they should not apply.
- ISS-0048 — File-Bounded Task Uses Outside Content
  - URL: /workbench/issues/file-bounded-task-uses-outside-content/
  - Summary: The AI is asked to work only from a specific file or document but uses content, assumptions, or sources outside that file.
- ISS-0023 — Hallucinated Fields
  - URL: /workbench/issues/hallucinated-fields/
  - Summary: The AI adds fields, keys, attributes, columns, or structured elements that were not declared, requested, or allowed by the expected schema.
- ISS-0039 — Hidden Rule Overrides Visible Instruction
  - URL: /workbench/issues/hidden-rule-overrides-visible-instruction/
  - Summary: A hidden, upstream, system, policy, tool, or product rule changes or overrides the visible instruction the user expects the AI to follow.
- ISS-0101 — Local Exception Grows Into Policy
  - URL: /workbench/issues/local-exception-grows-into-policy/
  - Summary: A local exception, special case, or one-off allowance begins to function like a general policy.
- ISS-0096 — Local Rule Spreads to Broader Cases
  - URL: /workbench/issues/local-rule-spreads-to-broader-cases/
  - Summary: A rule intended for one local case, file, context, user, workflow, or exception begins affecting broader cases.
- ISS-0050 — Model Output Triggers Unapproved Action
  - URL: /workbench/issues/model-output-triggers-unapproved-action/
  - Summary: AI output causes, recommends, or triggers an action that has not passed the required approval, permission, or authority check.
- ISS-0012 — No Owner for Agent Action
  - URL: /workbench/issues/no-owner-for-agent-action/
  - Summary: An agent action can affect the system without a declared responsible owner, authority, or accountable decision path.
- ISS-0049 — Policy Exception Spreads Too Far
  - URL: /workbench/issues/policy-exception-spreads-too-far/
  - Summary: A narrow policy exception, allowance, or special case spreads beyond its intended scope and begins governing broader cases.
- ISS-0076 — Prompt Does Not Say What to Exclude
  - URL: /workbench/issues/prompt-does-not-say-what-to-exclude/
  - Summary: The prompt declares what to include but does not declare what should be excluded, allowing unwanted scope, sources, content, or actions into the result.
- ISS-0047 — Repair Step Created New Breakage
  - URL: /workbench/issues/repair-step-created-new-breakage/
  - Summary: A repair, correction, retry, or fix step addresses one problem but introduces a new failure elsewhere.
- ISS-0062 — Retrieval Exceeds Evidence Limit
  - URL: /workbench/issues/retrieval-exceeds-evidence-limit/
  - Summary: The AI retrieves, uses, cites, or considers more evidence than the task permits or more than the review surface can support.
- ISS-0051 — Review Outcome Changes Unrelated Environment
  - URL: /workbench/issues/review-outcome-changes-unrelated-environment/
  - Summary: A review result, approval, rejection, or classification changes state outside the environment, case, file, or workflow it was meant to govern.
- ISS-0112 — Routing Overrides Task Intent
  - URL: /workbench/issues/routing-overrides-task-intent/
  - Summary: Routing, mode selection, agent behavior, or workflow classification sends the task down a path that overrides what the user was trying to accomplish.
- ISS-0103 — Single Step Carries Too Many Decisions
  - URL: /workbench/issues/single-step-carries-too-many-decisions/
  - Summary: One prompt, workflow step, review stage, or agent action carries too many decisions for the system or user to evaluate cleanly.
- ISS-0093 — Small Error Spreads Into Large Failure
  - URL: /workbench/issues/small-error-spreads-into-large-failure/
  - Summary: A small AI, output, routing, or workflow error propagates through later steps until it becomes a larger failure.
- ISS-0011 — Task Has No Clear Limit
  - URL: /workbench/issues/task-has-no-clear-limit/
  - Summary: The task does not declare where the AI should stop, what is out of scope, or what counts as enough work.
- ISS-0061 — Too Many Tool Calls
  - URL: /workbench/issues/too-many-tool-calls/
  - Summary: The AI or agent makes more tool calls, searches, retrievals, API calls, or integration actions than the task requires or permits.
- ISS-0108 — Tool Can Act Without Responsible Authority
  - URL: /workbench/issues/tool-can-act-without-responsible-authority/
  - Summary: A tool, connector, function, or integration can perform an action without a declared responsible authority for that action.
