H3.05.3confirmation reserved for irreversible high-stakesdesign

Reserve confirms for irreversible high-stakes acts

Aliases: confirmation budget · irreversible confirm · high-stakes confirm

What it is

In a recovery system, confirm is a scarce resource. Keep it for acts that have no equivalent undo and cost a lot when wrong: destroying the only original, sending money out, turning a secret public. Spending confirm on reversible, low-cost acts both interrupts the success path and dilutes attention on the actually dangerous trial. This entry states the conditions under which a confirm should remain. It is not about why confirms get clicked through, and not about why they fail to catch slips.

Why it happens

Confirm’s entire value is forcing one more judgment of object and consequence. That judgment has a cost, paid only when “this one cannot be taken back” feels true. Irreversibility makes “cannot be taken back” a fact; high stakes make the fact worth paying for. Missing either condition, confirm has nothing to protect: if reversible, a later correction is cheaper; if low-stakes, the benefit of re-judging is below the cost of the interruption. Spreading confirm across everyday acts spends scarce judgment where it is not worth it, and the act that needs judgment grows the same face as the everyday ones.

Where it stops holding

Where law or audit forces “click once more,” the confirm may be immovable, but it should still be irreversible or high-stakes—otherwise it is compliance décor. High-stakes work that can be split into two stages (disable then destroy, private then public) should put the confirm on the last cut, not on every step. For an expert repeating the same irreversible act in a short session, the first confirm may be followed by “don’t ask again this session,” if the consequence can still be chased elsewhere or audited. A dangerous but reversible act (into trash) plus a confirm is double billing.

Applying it

  • Tick two boxes on every confirm: is there an equivalent undo, and is the cost of being wrong high. If both boxes cannot be ticked, delete the confirm.
  • Remaining confirms must make the object name and the irreversible consequence checkable; the button names the act.
  • If the flow can become disable / archive / draft, change the flow first, then decide whether a confirm is still needed.
  • Verify by tabulating every confirm in the product and writing, for each row, what it is blocking. If the answer is “prevent a slip” or “look careful,” that row should not exist.

Related

  • Within the group: H3.05.1 Habituated confirmations get clicked through · H3.05.2 Confirms catch mistakes, not slips
  • Adjacent: E6.05 Confirmation dialogs · H3.06 Friction for destructive actions · H3.04 Undo over confirm
  • Search terms: irreversible action · high-stakes confirm · confirmation budget

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/H3.05.3