Actions that affect other people escalate on their own
Aliases: affects others · shared-device confirm · social spillover
What it is
If consequence is scored only from the speaker's reversibility and cost, people who are not in the dialogue drop out. Sending a message, ringing someone else's phone, posting to a family group, opening a shared door, writing a shared calendar, charging a joint account — when it goes wrong, the person who finds out is someone else, and they find out late. An act that is “just undo” for the speaker can already be an interruption, a disclosure, or an obligation for them. Affecting others is its own escalation, not a cell inside the speaker's two-axis table.
Why it happens
The confirm loop closes between speaker and device. The affected person neither hears the confirm nor gets a veto in time. The speaker's undo window is clocked on their own attention; the other party has already read it, been woken, or is standing at the door — the window is still open for the speaker and already shut for the world. Near-duplicate contacts, or “play this in the living room” on a speaker that has an audience, put social cost outside the speaker's redo time.
Reversibility and cost usually take values from “can I undo this, what do I lose.” A third party changes the function: disclosure does not undo locally, obligations land on someone else's calendar, and safety (door, alarm, camera) is asymmetric. Scoring a shared doorbell and skipping one's own track in the same speaker-only table puts them in the same cell.
Studying it
Use paired vignettes: the same action affecting only the self versus a named other. Measure how much confirm intensity jumps, and whether that jump exceeds what reversibility and cost ratings can explain. In-home studies of shared devices catch “I thought I was talking to myself” executions. Other dependents: delay until a third party discovers the error, and whether the speaker heard the other person's name in the confirm.
In logs, flag whether the recipient or device belongs to someone else, and compare later complaint rates. Treat “sent” as success of the pipe, not as safety of the target.
Where it stops holding
Living alone with no shared devices often empties the third-party axis — except remote messages and calls, which still exist. Some “others” are services, not people (a support bot); escalation can sit lower than for a human. A guardian acting on a child's device does affect someone else, but accountability stays with the adult; the confirm should name whose device is changing, not invite the child to veto. Broadcast into the speaker's own headphones does not escalate. Social cost of speaking in public is a different issue: that is overhearing, not the action's object being someone else.
Applying it
- Tag actions that affect others: messages, calls, shared calendars, shared home devices, locks and cameras, joint accounts. Tagged acts get a higher confirm than their cell on the speaker's two-axis table.
- The confirm must name the other party or target: “send to Manager Zhang,” not “send”; “open the front door,” not “run the scene.” If it cannot be named, escalation has not happened.
- Do not replace pre-confirm on these acts with a short undo window: the other party may already have received it. Windows are for drafts that still sit on the speaker's side.
- How to check: run a near-miss on the target (Mom's other number). If the confirm never names a discriminable object, or a skip-track “yeah” lets it through, escalation has not occurred.
Related
- Same group: M2.09.1 Consequence is reversibility and cost together, not one severity knob · M2.09.2 Reversible actions can replace a pre-confirm with undo · M2.09.3 Frequent low-risk confirms train a blind yes
- Nearby: M4.03 Multi-user recognition · M4.01 Social cost of using voice in public · M2.03 Confirmation strategies
- Search terms:
third-party consequence·shared device·recipient confirmation