H1.09.2disclose smart prefill sourcedesignresearch

Prefill must name its source

Aliases: prefill attribution · sourced from profile · data provenance

What it is

Once the application writes a profile or a past order into a box, people need to know where that string came from before they can decide whether to trust it. Naming the source is a human sentence beside the field or on the group heading—“from your profile,” “from your 12 March order”—not a filled box with no caption, and not a vague grant on a legal page. Browser autofill brings its own system-level source cue (a key icon, a highlight). That does not replace the application’s own attribution; the two stores are not the same library. This entry does not score whether prefill will be wrong, and it does not require that a named source also be editable.

Why it happens

A filled value with no origin is read as “the current fact the system just decided for me.” People cannot tell “old company on the profile” from “new quote the API just computed,” so checking has no target. A source pins the value back to a record that can be doubted: the profile may be stale, the last order may have been for someone else, the company directory may not have been updated. A second layer is conflict across sources. The same field may come from the profile, the last order, or an invoice-title store. When they disagree, omitting the source lets the product pick one in private. Naming the source does not by itself lay the conflict open, but it at least tells people which ledger they are checking. The source must enter the viewport with the value. In a footer or a first-run permission dialog it is useless at fill time.

Studying it

Take the same prefilled value with no source, a vague “we filled this for you,” and a specific “from your 12 March order.” Ask what it is, whether they dare change it, and what they would do if it turned out to be a purchase for someone else.

Independent variables: source granularity (none / vague / pointing at a record), whether a multi-source choice names which one was picked. Dependent variables: ability to name the origin, willingness to edit after spotting staleness, times values from different sources are treated as one fact.

Do not treat the browser autofill highlight as application source already named. Turn browser fill off and measure the application copy. A correct source in type too small or contrast too weak is as if unwritten; separate “seen” from “understood.”

Where it stops holding

A value the user just chose on the previous screen (the coupon, the store) has source “you just picked this”; attributing it to the profile misleads. When the source would expose someone else’s privacy (a coworker’s mobile in a directory), do not write an origin that can identify them—do not prefill. Where regulation demands a minimal notice, the source sentence can be short, but not so short it becomes an empty phrase like “smart fill” that points at no record.

Applying it

  • Write a source beside every application-prefilled field or group, down to profile, a dated order, or a named directory—not “smart fill.”
  • When several sources could apply, the default must still say which source was chosen, and offer a switch of source, not only an edit of the text.
  • Keep source and value in the same viewport; do not leave it only in a privacy policy or a first-run grant.
  • Verify by covering the source sentence and asking where the address came from; “don’t know” or “the site just filled it” is failure. Give two conflicting addresses and see whether people can say which source is in use. Turn browser fill off and confirm the application’s own source sentence remains.

Related

  • Within the group: H1.09.1 Prefill cuts typing but can insert the wrong value · H1.09.3 Prefill must remain editable
  • Adjacent: O1.03 Purpose limitation · O2.02 Data purpose explanation · H1.13 Smart prefill and autofill
  • Search terms: prefill source · data provenance · attribution

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/H1.09.2