Reversible acts are cheaper overall if post-hoc undo replaces pre-action confirm
Aliases: undo replaces confirm · do not gate the reversible · spend confirm budget elsewhere
What it is
If an act can be returned fully to the prior state after the fact, a gate beforehand is spending everyone’s attention to insure a regret that rarely happens. Undo instead of confirm when reversible moves protection from before execute to after: do it, leave a clear recall window, and recall must truly restore. Overall cost is lower because most of the time people will not recall, and need not read a dialog first.
Popping confirm on “add a tag” spends protection that should have been left for “pay.”
Why it happens
Confirm’s cost is paid every time; undo’s cost is paid on regret. Reversible acts have a low regret rate, so expected cost lands on the undo side. Confirm also has a negative externality of habituation: it makes the high-consequence gate cheaper. Taking reversible acts off the confirm list both cuts count and frees heavy-grade quota. The premise is that undo is a real contract: state restorable, window long enough, entry findable. Fake undo (only the UI badge changed, the external system did not) turns this prescription into a hole.
Outward acts, even if deletable, are often socially irreversible, and do not take this prescription.
Studying it
Hold the same reversible act (edit a draft, tag, move to a folder), compare pre-confirm versus a post-hoc undo window. Dependent variables: share of erroneous acts that finally remain, time per person per act, stop rate of a high-consequence gate in the same session (the externality). Independent variables: undo window length, salience of the entry, whether undo truly restores.
Look at this act’s safety and at whether the high-consequence gate is rescued. Looking only at this act yields the illusion that “confirm is also fine.”
Where it stops holding
If the undo window is too short for the error to be noticed, the prescription fails — lengthen the window or promote the act. In collaboration, others may already have acted on the new state; technical reversibility becomes social irreversibility, and it is treated as outward. Grading decides the rung; this entry decides that the default means on the reversible rung is undo, not a light gate. Which acts count as irreversible/outward is a qualification question, not a choice of means.
Applying it
- Tools marked reversible and inward: no pre-confirm by default; after doing, offer recall inside a time limit, wired to a real inverse.
- Put the recall entry next to the result, not only in history. Time the window to how people notice errors, not to an animation.
- Check: have people make a reversible error on purpose, and see whether they can restore without an engineer. If not, undo is fake and confirm should not have been removed. Then count whether dwell on the high-consequence gate rises after these confirms are gone — if it rises, overall cost has actually fallen.
Related
- Same group: L4.11.1 Confirmation should show the concrete objects that will be affected, not just the action category · L4.11.2 Batch confirmation needs an inspectable list; a count is not enough to judge · L4.11.3 Confirmation fatigue strips high-frequency confirms of their protection; confirms must be graded by consequence · L4.11.5 Outward acts should be treated as irreversible even if they can be deleted later
- Nearby: L4.05 Interruptibility and Rollback · L4.07 Pre-action Confirmation · L1.01 Mismatch Between Stochastic Output and Deterministic UI
- Search terms:
undo·reversible action·confirmation fatigue
Cards in the same group
- L4.11.1Confirmation should show the concrete objects that will be affected, not just the action category
- L4.11.2Batch confirmation needs an inspectable list; a count is not enough to judge
- L4.11.3Confirmation fatigue strips high-frequency confirms of their protection; confirms must be graded by consequence
- L4.11.5Outward acts should be treated as irreversible even if they can be deleted later