K7.10.4explicit visual confirmation of payment and identity session enddesignresearch

Payment and identity sessions need an explicit visual end, not a silent exit

Aliases: session-ended screen · take-your-card · logout confirmation · kiosk end state

What it is

After a payment or an identity check, if the screen fades straight back into the attract loop, the operator is unsure whether it has ended, and the next person is unsure whether the machine is free. Payment and identity sessions need an explicit visual confirmation of end means that after end the UI has to hold on a full-screen state that says so—logged out, take your card, session cleared—rather than cutting silently to the attractor. The claim is how the boundary of a high-stakes session is seen, not whether an End control exists, and not whether fields were wiped. The confirmation itself should not still show line items, an ID image, or a name. It has to prove the cut, not replay the private business that just happened.

Why it happens

Payment and identity in public leave two uncertainties: whether the money or the document actually went through, and whether the person is still signed in. A silent exit serves the system's state machine; both uncertainties stay in the person's head. People look back, reach again, and either reopen a session already cleared or treat the next user's start as their own receipt. ATMs make “please take your card” an unskippable screen because a card still in the throat is a harder boundary than screen state; a cardless login has no such object, so the screen has to finish saying the boundary. Sound can add a beat, but it is unreliable in a noisy station; visual confirmation remains the main channel. A tick that flashes for half a second in a corner is not confirmation. The next person in line is also reading this glass: a clear “ended” is less likely to be taken as a session they can continue than a leftover payment page.

Studying it

Compare fade-to-attract after end with a held confirmation screen, on payment and identity tasks: look-back re-entry, next-user walk-in, and rated certainty of “you are logged out.” In the field, code whether people still watch the screen before taking a card or leaving, and whether they reach to tap again.

Independent variables: presence of a confirmation screen, dwell, whether taking a card or receipt is required at the same time, whether the confirmation still shows personal fields. Dependent variables: taps after end, next users who think they are continuing the previous transaction, rated “already logged out,” cards or receipts left in the throat.

Lab participants asked “did you log out?” have certainty lifted by the question. In the field, watch whether the back has already turned. A confirmation that still prints a name and last digits is a new exposure; do not report only “users felt more sure.”

Where it stops holding

A pure lookup with no login can return to attract faster; not every “I looked it up” needs five seconds of hold. A confirmation that holds too long blocks throughput and looks like a dead machine to the queue; dwell has to last long enough to be read and short enough not to occupy the pit. Switch-scanning or voice users need the confirmation in their ring or speech, not only a flash of full-screen motion. Where regulation requires a receipt on the spot, the confirmation can point at “please take the print,” not leave the full receipt on the public glass. If the network failed and end did not actually complete, confirmation must not pretend the session is gone—that is a more dangerous silence.

Applying it

  • After payment or identity end, go to a full-screen confirmation: logged out / take your card or receipt / you may leave; hold until it can be read, then return to attract.
  • Show no name, ID image, full card number, or line items on that screen; send a receipt to paper or a phone, and do not linger it on the public glass.
  • When there is a card throat or a printer, bind confirmation to taking the object; do not return to a state the next person can start before it is taken.
  • Verify by asking, after the task, whether any login of theirs remains, and by watching look-back taps; check whether the next user treats the confirmation or a leftover as continuable. After switching to full-screen confirmation, compare look-back and walk-in at the same site.

Related

  • Within the group: K7.10.1 Public-device sessions need an explicit end action, not timeout alone · K7.10.2 Ending a session must clear personal data and login so the next user inherits nothing · K7.10.3 Walk-away timeout length trades convenience against privacy risk
  • Adjacent: O3.17 Sensitive information on screen · K7.04 Simultaneous Multi-user Use
  • Search terms: session-ended screen · take your card · logout confirmation

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/K7.10.4