C3.17.4Destructive actions not the default full-swipedesignresearch

Destructive actions should not be the default full-swipe action

Aliases: swipe to delete · destructive default · archive not delete

What it is

Full-swipe-to-perform commits “the default on this side.” If that default is delete, empty, or unbind, an overshoot or a coast destroys the object. Destructive commands may sit on a revealed button that still needs a tap. They should not occupy the full-swipe default slot. That slot belongs to archive, mark-read, pin—reversible or low-harm. Delete stays a tap, preferably with confirm or a trash.

Why it happens

The default slot’s power is ballistic: people often lift past the rest point, and the system must fill in “travel-to-end means what.” Filling it with delete assigns the dearest outcome to the least precise commit. Mail that defaults to archive and leaves delete on a button or the other side is taking harm out of the ballistic. If a product has only delete as a swipe command, full-swipe still makes it the default—then full-swipe should be off, leaving reveal-then-tap. Color (red) does not replace slot choice: a red full-swipe is still a full-swipe. Trash or an undo bar is a net after the fact, not a license to put delete in the default slot.

Studying it

Two defaults: full-swipe = delete versus full-swipe = archive (delete button-only). In fast browsing and “see the buttons” tasks, log vanished objects, undo use, and time cost of an intentional delete. Ask “what did you think swipe-to-end would do,” checking whether the model is “end = delete.” Split with-trash and without-trash; trash hides the default slot’s real harm.

Where it stops holding

In Drafts or Trash, delete is the list’s primary meaning, so full-swipe delete hurts less, but it should still be undoable. Real-world irreversible acts (ship, transfer, wipe a key) need confirmation even as buttons, and must not enter the full-swipe slot. Archive in system mail feels like delete to some people (the message left the inbox); “low harm” for the default slot has to be validated per audience, not only by an engineer’s taxonomy.

Applying it

  • Make the full-swipe default archive, read, or pin. Keep delete as a revealed button, with a confirm if needed.
  • If delete is the only action, turn full-swipe-to-perform off.
  • Skim-swipe ten rows. If the default is delete, count how many entered trash or vanished. Switch the default to archive and swipe ten more; vanish should be zero. Intentional delete should still be completable via the button.

Related

  • Same group: C3.17.1 Actions revealed by swiping a row are hidden functions · C3.17.2 Matching swipe distance to the number of actions · C3.17.3 The danger of a full swipe that executes immediately
  • Adjacent: C3.05 Swipe · C3.24 Accessible alternatives to gestures
  • Search: swipe to delete · destructive default · archive versus delete

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/C3.17.4