Destructive actions: prefer undo, confirm only the irreversible
A decision rule for delete/remove/reset in apps: routine reversible deletions get immediate action plus an Undo snackbar; rare, irreversible, or bulk actions get a specific confirmation with an action-named destructive button; the heaviest get typed confirmation.
Overview
What: Choosing between confirmation dialogs and undo for actions that remove or overwrite data.
Why: Confirmations shown for everything train people to tap through them (NN/g's "crying wolf" effect), while undo lets them recover from the mistakes that slip through anyway. Apple's HIG advises against alerts for common, undoable destructive actions and for an alert when an uncommon destructive action can't be undone.
Use when: designing delete, remove-from-collection, clear history, reset, sign out, delete account.
Rule of thumb: reversible + frequent → undo; irreversible or large-scope → confirm; catastrophic → confirm with friction.
Implementation
- Classify each destructive action in a table: scope (1 item / many / everything), reversibility (undo available? trash?), frequency.
- Reversible single-item actions (delete item that goes to Trash, remove tag, archive): act immediately, then show a snackbar/toast "Deleted "Dune" · Undo".
- Visible 6–10 s (within Material's 4–10 s snackbar bounds), paused while focused; when a screen reader is on (
AccessibilityInfo.isScreenReaderEnabled()), keep it until dismissed or at least 20 s (WCAG 2.2 SC 2.2.1), and announce it. - Undo restores the item in the same position and selection.
- One snackbar at a time; a new action replaces (and commits) the previous one.
- Don't hide the snackbar behind the tab bar or keyboard.
- Visible 6–10 s (within Material's 4–10 s snackbar bounds), paused while focused; when a screen reader is on (
- Irreversible or bulk actions (empty trash, delete 25 items permanently, delete account): confirmation using the platform component — iOS action sheet/alert, Android dialog:
Alert.alert(
'Delete 25 items permanently?',
'They will be removed from this device and cannot be recovered.',
[{ text: 'Cancel', style: 'cancel' },
{ text: 'Delete 25 Items', style: 'destructive', onPress: purge }]);
Title states the consequence and scope; the confirm button repeats the verb and object; Cancel is always present and never the destructive style.
- Catastrophic actions (delete account and all data): require typing a word or the collection name, and explain what's retained (exports, subscriptions to cancel separately).
- Placement: keep destructive buttons away from frequent ones (not adjacent to Save/Edit); style in the platform destructive colour with text, not colour alone.
- Soft delete underneath so undo is cheap — see the trash pattern item.
- Never confirm-and-undo the same action; pick one layer per action.
Verification
- Every destructive action appears in the classification table with its chosen protection.
- Single-item delete requires one tap + offers Undo; undo restores position.
- Undo snackbar is announced and stays long enough with VoiceOver/TalkBack on.
- Irreversible actions show a dialog naming the item/count and a verb-labelled destructive button; no "OK/Yes".
- No destructive button sits adjacent to Save/Edit.
- Account deletion is available in-app (App Store 5.1.1) and explains consequences.
Sources:
- https://www.nngroup.com/articles/confirmation-dialog/
- https://developer.apple.com/design/human-interface-guidelines/alerts
- https://developer.apple.com/design/human-interface-guidelines/feedback
- https://developer.android.com/develop/ui/compose/components/snackbar
- https://developer.apple.com/app-store/review/guidelines/
- https://developer.apple.com/design/human-interface-guidelines/accessibility
- https://github.com/material-components/material-components-web/tree/master/packages/mdc-snackbar
- https://www.w3.org/WAI/WCAG22/Understanding/timing-adjustable.html
Limitations
- Timed snackbars conflict with WCAG 2.2.1 (timing adjustable) and with slow screen-reader navigation; always provide a second recovery path (Trash).
- Undo after sync to other devices is harder; delay remote deletion until the undo window closes.
- Some regulated domains (finance, health records) require confirmation even for reversible actions.
- Snackbar durations are framework bounds, not usability findings: Material's web snackbar accepts 4–10 s (default 5 s), while Android's
LENGTH_SHORT(1.5 s) andLENGTH_LONG(2.75 s) are too short for undo, so set an explicit 6–10 s duration. - Values verified 2026-09-26: 3 checked against standards, platform docs and published guidance (WCAG 2.2 SC 2.2.1, Material snackbar source, NN/g).