Z3.02.3Higher thresholds for actions affecting othersdesignresearch

Actions affecting others need a higher bar

Aliases: third-party consequences · other-regarding actions

What it is

When the bearer of an automated action extends beyond its initiator — turning off lights for the whole household, letting a visitor be captured on camera, messaging a colleague, adjusting a device a co-resident depends on — the action crosses into the "other-affecting" category and needs a higher bar than "self-only": a lower ceiling on automatic level, clearer disclosure, and sometimes the bearer's consent. The test is not "who benefits" but on whom the consequences land: the beneficiary may be the user; if the bearer is someone else, the bar rises regardless.

This goes a step beyond "irreversible needs confirmation": confirmation settles whether the initiator approves; the other-affecting problem settles that the bearer never appears in the decision loop at all. However solemnly the user confirms, the third party affected still had no say — which is why the bar cannot be implemented by confirmation alone.

Why it happens

The structural problem is the missing consenting subject: the system's automated decisions are trained on one person's preferences and data, while the action's consequences distribute across several. The initiator's "yes" cannot substitute for the bearer's "yes" — and the two often conflict outright (the child afraid of the dark wants the light; the adult saving power wants it off).

A second layer is asymmetric amplification of consequences. When a self-only action errs, the person who generated the error is the one equipped to intervene — the feedback loop is complete and the motive to correct immediate. When an other-affecting action errs, the bearer typically has no entry point into the system at all — the visitor accidentally recorded in home footage does not know the footage exists, let alone where its settings live. Consequences land on those with the least control, which is precisely why the bar must be front-loaded (raised at action-design time) rather than left to after-the-fact correction.

A third layer is the household power structure. Whoever configures the automation hardens their own preferences into everyone's default: the configurator is usually the most technically fluent member, so automation systematically amplifies the configurator's preferences. This is not hypothetical — smart-home research repeatedly finds configuration rights unevenly distributed, and who configures directly shapes whose needs get served.

Studying it

  • Socio-technical studies of multi-user smart homes (Crabtree and Rodden's ethnographies of domestic technology) document how household automation embeds itself in existing divisions of labour and negotiation — the empirical base for "whose action, who bears it".
  • Value sensitive design (the Friedman line of method) takes "stakeholders affected by a technology but holding no decision power" as its unit of analysis, with systematic examinations of home video and monitoring technologies; its direct/indirect stakeholder analysis transfers directly to identifying other-affecting actions.
  • Deployment studies tallying conflict incidents: the frequency and type of arguments between co-residents triggered by automation, reverse-engineering which action classes need negotiation up front in real homes.

One methodological caution: other-affectingness cannot be measured in the lab — participants are recruited homogeneous individuals with no shared living history or power relations; the research must go into the field (real households, real visitors), or at minimum track real conflicts through diary methods.

Where it stops holding

  • Other-affecting and consequence magnitude multiply rather than add. Actions whose effect on others is mild and visible (skipping a track on a shared playlist) need no heavy gate; the bar should rise with "bearer's consequence × bearer's lack of control" together, without turning every shared scenario into an approval workflow.
  • The bearer's consent is not always obtainable. Transiently present people (visitors, passers-by) cannot join the configuration; the bar then takes the form of default minimisation (act most conservatively toward anyone not on a consent list), not of soliciting consent.
  • "It's for their own good" waives nothing. Adjusting an elder's temperature or limiting a child's use is well-intentioned but still other-affecting; guardianship confers proxy authority, not a licence for unilateral automation — especially where the person can express preferences.

Applying it

  • Add a third column, "bearer", to the action risk register: for each action, who is affected and whether the bearer has any entry into the system; where the bearer has none, cap the automatic level outright.
  • Separate default policies for self-only versus other-affecting: for shared devices and spaces, default to "notify only, no action" or "execute the most conservative interpretation", leaving affirmative action to configurations made after explicit negotiation.
  • Give bearers a veto without configuration rights: any household member can disable automation affecting themselves without contesting configuration power — veto needs no admin privileges.
  • How to check: observe verbal and non-verbal reactions in the home after other-affecting automations fire (who complains, who falls silent, and whether the silent ones are the bearers); track the share of other-affecting actions whose bearers have no entry point, as a running measure of design debt.

Related

  • Same group: Z3.02.1 Reversible, low-consequence actions can be automatic · Z3.02.2 Irreversible and outward-facing actions need confirmation
  • Nearby: Z6.01 Control conflicts · Z6.04 Presence of non-users
  • Search terms: third-party consequences · value sensitive design · multi-user smart home · stakeholder analysis

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Z3.02.3