H4.07.3visible authorization-duration indicatordesign

Grant duration needs a visible indicator

Aliases: once versus always indicator · grant-mode badge · duration disclosure

What it is

People need to see whether the current grant is this time only, while using, or always. The indicator belongs on the surface that is using the capability, not only deep in system Settings. Without a duration cue, Once and Always look the same on screen, so it is impossible to tell whether the capability will still be live after leaving. This entry is about making the time mode of the grant visible. It is not about whether the camera dot is lit in the status bar, and not about whether Settings has a jump link.

Why it happens

Once / Allow / Always on the system dialog is a one-shot choice; the result then leaves the viewport. If later UI only shows the feature's own glyph (a location chevron, a waveform) for "in use," people read "in use" as "allowed for good." A duration indicator keeps the lease mode beside the task: Once is labeled as stopping when this ends; Always is labeled as possibly continuing after leaving the app. Visibility gives the next decision a reference—discovering Always is how someone knows to change it. When it is invisible, three modes collapse into one experience, and the risk reduction of one-time grants fails in the interaction.

Where it stops holding

If the platform already badges duration on the in-use surface, the app should not stack a second label with a different meaning. For an instantaneous act (snap one photo and close the preview), a single confirmation that this was one shot is enough; a persistent badge is not required. When Always is locked by enterprise policy, the indicator should read "kept on by your organization," so no one thinks it can be changed in-app.

Applying it

  • On the surface using the capability, a short label names the current mode: Once / While Using / Always. The label is tappable and opens that permission's status row.
  • For Once, a closing beat before the task ends or the app is left: "This location use has ended." Always must not pretend to have stopped when the person leaves the foreground.
  • Align label wording with the system's grant grades; do not invent a third vocabulary.
  • Verify by granting Once and Always separately, then asking uninvolved people looking at the same in-use UI whether it will keep going after they leave. The same answer for both modes means the indicator failed. Confirm that tapping the label reaches a changeable status, not empty copy.

Related

  • Within the group: H4.07.1 A one-time grant lowers the person's risk · H4.07.2 Ongoing grants need periodic review
  • Adjacent: H4.10 Visibility of Permission State · H4.08 Camera and Microphone Permission · O2.03 Sensor-Use Indicators
  • Search terms: Allow Once · authorization duration · permission indicator

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/H4.07.3