Destructive actions do not belong on a notice
Aliases: shade destructive · no delete on lock screen · irreversible shade action
What it is
Buttons on a notice live in low context and high mis-tap risk: lock screen, shade, a watch face. Destructive actions—delete, permanent decline, moving money, wiping a meeting off someone else's calendar, an unretractable reply to everyone—do not belong there. Shortcuts are for reversible, local, recoverable work. Destruction belongs in the app, where the object, the consequence, and the undo conditions are present together.
This is what must not be placed. It does not deny that shortcuts save a switch, and it does not cover how the card acknowledges a tap.
Why it happens
Notification actions are designed to be pressed at a glance. A glance means small targets, adjacent cards, a device in a pocket or one hand, attention still on another task. Mis-tap rates exceed those of primary buttons in-app. In-app, the full object, a second step, or an undo window still exist. On a notice those guards are missing, or they are crushed into a second button the same size as the primary, which is no guard.
Destruction also often exceeds what the card shows: this message or the whole thread, this invitation or all future ones, money to which destination. The card cannot state the scope. The press is a reaction to the visible line, not a decision about consequences.
Studying it
Place the same destructive action on a notice and behind an in-app drill-in. Compare error rate, later undo, and whether people can name the scope.
Independent variables: lock-screen placement, adjacency to a safe action such as archive, whether scope is written on the button, presence of a short undo window. Dependent variables: mis-tap rate, share who realize the scope was wrong, undo use, reports of "I didn't see."
Labs that tell people to be careful understate mis-taps. A harder test is walking while aiming at an adjacent safe action, counting how often the destructive control is grazed. Adding a confirm is not safety if the confirm is as light as the original tap—it is one more mis-tap.
Where it stops holding
Some roles are high-risk decision-making on notices (trading, dispatch). Those are workbenches, not consumer shades, and they need their own guards and audit. Irreversible legal acknowledgements ("confirm receipt") are destructive as liability rather than as deletion; they still belong on a surface that can show the full text. If the system truly recovers (trash plus undo on the notice), "delete" can be demoted to reversible; permanent purge still leaves the notice.
Applying it
- Put only reversible actions on notices; move delete, payment, global decline, and unretractable group replies onto the object page.
- Do not give destruction to a swipe or to a red button beside archive.
- If a business insists on decline-in-shade, write the scope on the button and offer a few seconds of undo; a failed undo must not count as done.
- Verify by placing archive next to delete on a test card and asking someone to archive while walking. If delete is hit, or they cannot say whether one item or the thread would go, the action does not belong on the notice.
Related
- Within the group: H5.06.1 Acting on the notice should skip launching the app · H5.06.2 The notice must show what the action did
- Adjacent: H3.06 Friction for destructive actions · H3.04 Undo over confirm · H7.05 Order confirmation
- Search terms:
destructive notification action·accidental tap·scope of action