Reserve confirms for irreversible high-stakes acts
Aliases: confirmation budget · irreversible confirm · high-stakes confirm
What it is
In a recovery system, confirm is a scarce resource. Keep it for acts that have no equivalent undo and cost a lot when wrong: destroying the only original, sending money out, turning a secret public. Spending confirm on reversible, low-cost acts both interrupts the success path and dilutes attention on the actually dangerous trial. This entry states the conditions under which a confirm should remain. It is not about why confirms get clicked through, and not about why they fail to catch slips.
Why it happens
Confirm’s entire value is forcing one more judgment of object and consequence. That judgment has a cost, paid only when “this one cannot be taken back” feels true. Irreversibility makes “cannot be taken back” a fact; high stakes make the fact worth paying for. Missing either condition, confirm has nothing to protect: if reversible, a later correction is cheaper; if low-stakes, the benefit of re-judging is below the cost of the interruption. Spreading confirm across everyday acts spends scarce judgment where it is not worth it, and the act that needs judgment grows the same face as the everyday ones.
Where it stops holding
Where law or audit forces “click once more,” the confirm may be immovable, but it should still be irreversible or high-stakes—otherwise it is compliance décor. High-stakes work that can be split into two stages (disable then destroy, private then public) should put the confirm on the last cut, not on every step. For an expert repeating the same irreversible act in a short session, the first confirm may be followed by “don’t ask again this session,” if the consequence can still be chased elsewhere or audited. A dangerous but reversible act (into trash) plus a confirm is double billing.
Applying it
- Tick two boxes on every confirm: is there an equivalent undo, and is the cost of being wrong high. If both boxes cannot be ticked, delete the confirm.
- Remaining confirms must make the object name and the irreversible consequence checkable; the button names the act.
- If the flow can become disable / archive / draft, change the flow first, then decide whether a confirm is still needed.
- Verify by tabulating every confirm in the product and writing, for each row, what it is blocking. If the answer is “prevent a slip” or “look careful,” that row should not exist.