Consequence is reversibility and cost together, not one severity knob
Aliases: two-axis consequence · irreversibility · confirm intensity
What it is
The consequence of a spoken action is not one knob labeled “how important.” It is two axes: whether the world can be restored, and what is lost if it is not. Living-room lights: reversible, low cost. An email: hard to take back, cost depends on the recipient. A 50,000 transfer: hard to reverse and high cost. A photo that still sits in a recycle bin: reversible, though reshooting may be expensive. Labeling all four high / medium / low will pin confirm intensity to the wrong cell.
Why it happens
Reversibility asks: in the few seconds the user is still listening, can the system roll the world back. Cost asks: if not, how much money, privacy, time, or social harm. The axes are orthogonal. Reversible and cheap (skip a track) is not worth a confirm turn. Irreversible and expensive (a wire out) must preview the action object before doing. The mixed cells need different tools: reversible but expensive can still work with a post-hoc undo window; irreversible but cheap may need only an action preview, not a yes/no.
Designers often stamp “sensitive” or “important” once, which flattens the two axes. After flattening, a delete that still lives in a recycle bin and a delete already synced off the device get the same confirm, and people cannot infer real risk from confirm intensity. Speech suffers more: there is no icon, no undo button in view. Reversibility has to be spoken or enacted, or people will treat every confirm as worst-case — or every skipped confirm as best-case.
Studying it
Have people rate a battery of actions on reversibility and on cost separately, not on a single “risk” scale. Test whether the two dimensions predict “I want a confirm before this runs” better than the single scale. Cross-check product logs: actions with both high undo rates and frequent pre-confirms may have been stuffed into one cell that fights itself.
Labs can use vignettes: the same delete, one version clearly recoverable, one clearly not, with cost held still, and see whether confirm demand moves with reversibility. Do not treat experts' high/medium/low labels as ground truth — that is the object being split.
Where it stops holding
When users believe an act is reversible and the system is not (looks local, actually clears the cloud), ratings are systematically optimistic; use system fact. Emergency calling is high cost but a confirm can cost time that cannot be spent; a third axis, delay, overrides the two. Experts recalibrate their own cost (small transfers every day). Actions that affect other people cannot be scored from the speaker's reversibility and cost alone — that is a separate escalation.
Applying it
- Label every world-changing action in two columns, not one: reversibility window (can it be restored in seconds, fully?) and cost (money / privacy / redo time / social). Empty cells do not ship.
- Reversible × low cost: do it and speak the result; no pre yes/no. Irreversible × high cost: preview the object before acting. Pick tools for the other two cells separately; do not upgrade both to the same confirm sentence.
- Make reversibility perceptible: recycle bin, a ten-second undo, and “call support” must not share one “deleted.”
- How to check: ask people who did not design it “if this goes wrong, can it be undone” and “if not, what breaks.” If the answers disagree with the two columns, the grade is still a designer's hunch.
Related
- Same group: M2.09.2 Reversible actions can replace a pre-confirm with undo · M2.09.3 Frequent low-risk confirms train a blind yes · M2.09.4 Actions that affect other people escalate on their own
- Nearby: M2.03 Confirmation strategies · M2.08 Explicit and implicit confirmation · M4.05 Retention of voice data
- Search terms:
reversibility·action cost·consequence rating