Sign-out must be findable
Aliases: log out discoverability · account menu sign out
What it is
Sign-out is the deliberate end of this device’s session. Findable means someone can reach “Sign out / Log out” from the usual account or settings places without searching help or guessing a hidden gesture, and the control is named as that action. This entry is only about whether it can be found. It is not about whether local caches are wiped afterwards, and not about extra prompts on a shared device—those are after and during sign-out.
Why it happens
Sign-in is placed on the home, the launch screen, any prominent navigation, because conversion wants it. Sign-out has no commercial incentive and is often buried in nested settings, the bottom of an avatar menu, or next to “Delete account” in small gray type. People use location memory: account actions belong in avatar, account, settings schemas. When the control is missing, substitutes are closing the window, clearing the app, powering off—none of which end the server session. On mobile, burying sign-out on the third “More” screen, and on desktop making it hover-only, break the schema. Naming takes part in discovery: “Switch account” and “Close” are not sign-out; in Chinese, 注销 collides with account deletion and needs context.
Studying it
Give a signed-in task: “Leave the account on this device so the next person cannot continue,” and measure time and path to find sign-out. Do not only ask “do you know there is a sign-out.”
Independent variables: depth of the entry (first screen of the avatar menu, Nth level of settings), wording (sign out / log out / switch), adjacency to delete account. Dependent variables: share who find it, number of wrong paths tried, taps that become delete or switch.
Lab participants briefed on location find it faster. Use people not told where it lives. Mobile and desktop schemas differ; thresholds do not transfer. “They eventually signed out” is not findability—if the path was clearing app data, the measure is a desperation tactic.
Where it stops holding
On a single-user device that is the person (a personal phone by default), sign-out is rare; the entry must still be findable because repair, borrowing, and resale suddenly need it. Enterprise apps under mandatory SSO may forbid local sign-out; the entry should explain “controlled by the company account” rather than hide. Guest-only state has no sign-out to find. A command-palette item that appears only on search is findable for keyboard users, not for touch.
Applying it
- Put “Sign out” on the first screen of the avatar or account menu, not only deep in settings; separate it spatially from “Delete account.”
- Use the verb “Sign out / Log out”; if a locale must use a word that also means delete, pair it with “sign-in” in the same phrase to kill the deletion reading.
- Do not make sign-out a hidden gesture or voice-only command; searching settings for “sign out,” “log out,” “logout” should hit the same entry.
- Verify with signed-in people uninvolved in the design: “Leave your account on this device,” no location hint. Record first path and whether they enter delete. More than one extra level of trial-and-error, or asking for help, is a failed entry.