PENGO Workbench
Workbench / Patterns / Overreach

PAT-0340

Overreach

A structural condition where actions, effects, authority, or modifications extend beyond declared scope without authorization.

Primary Lenses

LEN-0240

Overreach Lens

Detects structure that exceeds declared scope or authority reach.

Lens Application

The Overreach Lens is a primary inspection mechanism for Overreach because it directs attention to mismatches between stated scope and actual reach. It helps surface cases where authority, modification, access, or downstream impact may exceed what was declared, bounded, or permitted.

Inspect For

  • Actions extending past stated scope
  • Authority used beyond assigned boundaries
  • Modifications affecting undeclared areas
  • Effects reaching unintended systems or parties

Avoid

Treat scope mismatch as a signal for inspection rather than a settled finding of Overreach.

LEN-0120

Boundary Compliance Lens

Evaluates observed structure against declared boundary posture, including allow, block, and exception rules.

Lens Application

The Boundary Compliance Lens is a primary inspection mechanism for Overreach because it focuses on whether observed behavior stays within declared allow, block, and exception boundaries. It helps surface scope expansion, unauthorized effects, or modifications that exceed stated boundary posture.

Inspect For

  • Actions operating outside declared scope
  • Effects crossing blocked or restricted boundaries
  • Exceptions used without clear authorization
  • Modifications extending beyond approved limits

Avoid

Treat boundary mismatch as an inspection signal requiring review, not as proof that Overreach has occurred.

Secondary Lenses

LEN-0250

Propagation Lens

Traces how structural declarations, effects, or state changes propagate across boundaries or stages.

Lens Application

As a secondary lens, the Propagation Lens helps inspect Overreach indirectly by following how declarations, effects, or state changes travel across stages or boundaries. It can highlight where an authorized action begins producing consequences outside its stated scope.

Inspect For

  • Effects crossing declared scope boundaries
  • Permissions or authority extending downstream
  • State changes applied outside intended targets
  • Boundary transitions without explicit authorization

Avoid

Treat propagation paths as indicators for further inspection rather than confirmation that Overreach has occurred.

Primary Issue Matches

Supporting Issue Matches

ISS-0008

Agent Keeps Expanding the Task

The agent repeatedly expands the task, plan, scope, or next-step list instead of completing the declared work.

ISS-0113

Agent Modified Unrelated State

An agent changes state outside the requested task, target, file, record, workflow, or authorized scope.

ISS-0099

Agent Permission Expands Over Steps

An agent begins with limited permission but gains, assumes, or exercises broader authority as the workflow continues.

ISS-0044

AI Uses External Information When Forbidden

The AI uses outside knowledge, sources, tools, memory, or assumptions after the task forbids external information or limits the allowed source set.

ISS-0043

Behavior Does Not Match Declared Role

The AI or agent behaves outside, below, or differently from the role, authority, responsibility, or permission posture declared for it.

ISS-0048

File-Bounded Task Uses Outside Content

The AI is asked to work only from a specific file or document but uses content, assumptions, or sources outside that file.

ISS-0096

Local Rule Spreads to Broader Cases

A rule intended for one local case, file, context, user, workflow, or exception begins affecting broader cases.

ISS-0049

Policy Exception Spreads Too Far

A narrow policy exception, allowance, or special case spreads beyond its intended scope and begins governing broader cases.

ISS-0062

Retrieval Exceeds Evidence Limit

The AI retrieves, uses, cites, or considers more evidence than the task permits or more than the review surface can support.

ISS-0061

Too Many Tool Calls

The AI or agent makes more tool calls, searches, retrievals, API calls, or integration actions than the task requires or permits.