Account switching must show which identity is current
Aliases: account switcher · who am I signed in as · current profile
What it is
When the same app holds a work account, a personal account, and a client account, someone must be able to answer “who is this now.” A current-identity indicator is a distinguishable name, email, or avatar kept in primary navigation or the account entry, with the current row marked when the switcher opens—not a flash only at sign-in. This entry is visibility of who is current. It is not about whether caches clear after a switch, and not about which account a notification badge came from.
Why it happens
Multiple accounts turn “I” into a list. A generic avatar in the top bar lets spatial memory treat the previous account’s page as this one’s. Send, pay, and delete bind to the current primary key; the wrong identity is the wrong object. If the switcher collapses and the top bar does not change, people forget they switched. The indicator should be recognition, not recall: color, name, org badge beat “Account 2.” A deep link that lands on the default account rather than the account the link belongs to pits the indicator against the content; people think the indicator is wrong.
Studying it
With at least two signed-in accounts, ask “who is this now” immediately after a switch, then again after one task.
Independent variables: persistent distinguishable indicator in the top bar, current row marked in the switcher, whether deep links switch to the owning account. Dependent variables: immediate and delayed identity accuracy, actions sent to the wrong account.
In the lab both accounts were just signed in, so memory is fresh. The field needs one frequent and one rare account. Opening the switcher sometimes is healthy checking; sending content to the wrong account is failure.
Where it stops holding
Single-account users are bothered by a heavy switcher; the indicator can collapse to one avatar and expand when a second account is added. Accessibility must put the current account name in the title or an accessibility label, not color alone. When an agency manages many client accounts, the indicator must include the client name; a personal name collides. Guest plus a signed-in account must mark guest as not an account.
Applying it
- Persist a distinguishable name or email for the current account at the primary account entry; mark the current row in the switcher.
- If a deep link belongs to another signed-in account, switch first, then open, and let the indicator follow.
- High-consequence confirms (pay, delete, post) echo the current account name.
- Verify: after switching back and forth, without opening the switcher, people should name who is current. Opening a link that belongs to B while A is showing should land identity and content on B. On a confirm dialog, watch whether people notice the account name.
Related
- Within the group: H6.13.2 Switching must not leave the previous account's sensitive state · H6.13.3 Notifications must name the source account · H6.13.4 Isolation boundaries between coexisting accounts must be explicit
- Adjacent: H6.02 Third-party login · H6.07 Sign out
- Search terms:
account switcher·current identity·multi-account