L4.11.5treat outward acts as irreversibledesignresearch

Outward acts should be treated as irreversible even if they can be deleted later

Aliases: socially irreversible · delete is not never-happened · recall is not undo

What it is

Mail can be recalled, a post can be deleted, a permission can be taken back. Those “cans” are technical options. The other party has already seen, forwarded, acted on that mail; the social fact does not vanish with the delete. Treat outward acts as irreversible takes acts on the world boundary out of “deletable, therefore reversible,” and puts them in the heavy gate, not in the undo prescription.

Delete is a correction, not time reversed. Correction can exist; it cannot take the confirm away.

Why it happens

Reversibility has two layers. System layer: can the state vector return to its prior values. Social layer: can other people’s memory, copies, later acts be treated as never-happened. An agent’s tool return reports only the system layer. If a product grades on the system layer, send, publish, change someone else’s permission get marked “recall afterwards is enough,” and they either grind the confirm budget or never enter the list. Qualification already requires outward acts to be gated; this entry treats a mis-grade — marked reversible because the API offers delete.

A test environment with no real other person is the easiest place to drop the social layer.

Studying it

Use a real outward channel (the test recipient is a real person, asked to forward or act as soon as they receive). Compare: marked reversible because the system can delete (undo only) versus marked irreversible because outward (heavy gate before). Dependent variables: whether the other party has already acted after a wrong send, stop rate before send, whether people report “I can always take it back.” Independent variables: whether recall succeeds before the other party reads, whether the UI paints recall as “equals never sent.”

The rate of the other party having acted is ground truth for social irreversibility. Copy that claims reversible while ground truth is not, is a mis-grade.

Where it stops holding

Sending to a test inbox you control, a sandbox with no other person, has no social layer and can be practised as system-reversible — but that grade must not move to production. Inward drafts only you can see take undo. How instances are shown, how a batch is inspected, does not change this grading. The qualification list puts outward in the gate; this entry forbids using “can delete” to demote them onto the undo rung.

Applying it

  • Add a column to the tool table: “does this cross a person outside the organisation.” If yes, the floor is heavy gate; do not mark reversible because a delete API exists.
  • A recall entry may stay; its copy is “correct / try to take back,” never “undo send, they will not see it.”
  • Check: send a wrong mail to a real person in the test, have them read and reply. If the product had no heavy gate before send, or still shows “undone, equals never happened” after they have read, it mis-graded on the system layer. Re-mark that tool as outward-irreversible; the heavy gate must appear before send.

Related

  • Same group: L4.11.1 Confirmation should show the concrete objects that will be affected, not just the action category · L4.11.2 Batch confirmation needs an inspectable list; a count is not enough to judge · L4.11.3 Confirmation fatigue strips high-frequency confirms of their protection; confirms must be graded by consequence · L4.11.4 Reversible acts are cheaper overall if post-hoc undo replaces pre-action confirm
  • Nearby: L4.07 Pre-action Confirmation · L1.05 Human in the Loop · L4.05 Interruptibility and Rollback
  • Search terms: social irreversibility · outward action · recall is not undo

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/L4.11.5