Skip to content
The Product Guys
All lessons
Craft6 min read

Most Confirmation Dialogs Are a Design Failure

Are you sure? asks the user to do the checking your system should have done.


Stillwater is a client portal for accountants. Deleting a client folder pops a dialog: Are you sure you want to delete this? This action cannot be undone. Cancel / Delete. In a support review, the team finds eleven cases in a year where a folder was deleted and the customer wanted it back. Every one of those users clicked through the dialog. The dialog did not fail because it was badly written. It failed because reading it was never going to happen.

A confirmation dialog is usually a note from the design to the user saying: we built something dangerous and we would like you to be careful on our behalf.

What a confirmation dialog actually catches

of the people shown itDialog shown1000Read past the first line210 (-790)Checked which item it named90 (-120)Changed their mind12 (-78)
A schematic pass through a dialog people have seen many times before. Almost everyone clears it, most of them without reading it, and the handful it saves could have been saved by an undo that cost the other nine hundred nothing.

Why they stop working

People learn the shape of a repeated interaction and stop processing its content. Anyone who has used a product for a month is clicking the primary button in that dialog before the text renders. This is the same reason cookie banners and terms checkboxes fail as informed consent. Jef Raskin made the argument bluntly in The Humane Interface: the answer to destructive actions is universal undo, not asking a question the user will learn to dismiss.

Norman's framing helps too. A forcing function is a design that makes the error physically impossible or costly, like the interlock that stops a microwave running with the door open. A dialog is a forcing function that can be satisfied by reflex, which means it forces nothing.

The ladder, cheapest and best first

Make it reversible
Soft delete with a 30-day restore, plus an undo toast. Now a mistaken click costs seconds instead of a ticket. This solves most cases and removes the need to interrupt at all.
Make it safe by construction
Remove the destructive option from where it can be hit by accident. A Delete sitting next to Duplicate in a hover menu will be mis-clicked forever.
Make it specific
If you must interrupt, state exactly what will be lost, in this instance. Delete Mensah & Co? 340 documents and 4 years of filings will go to Trash for 30 days.
Make it deliberate
For rare and truly irreversible actions only: require typing the name. This defeats reflex because it cannot be done without reading.

Dialogs that do nothing

  • Are you sure? / This action cannot be undone. [Cancel] [OK]
  • Do you want to leave this page? Changes you made may not be saved.
  • Are you sure you want to remove this user?
  • Confirm deletion

Designs that actually protect

  • Moved Mensah & Co to Trash. 340 documents. [Undo]
  • Draft saved automatically 2 seconds ago. (no dialog at all)
  • Remove Priya Raman from Stillwater? They lose access to 12 client folders immediately. Their comments stay. [Remove access]
  • This permanently deletes 4 years of filings and cannot be restored. Type MENSAH & CO to confirm.

Row one is the whole lesson in two lines. An undo toast after the fact is faster for the user in the common case (they meant it) and safer in the rare case (they did not). The dialog is worse at both.

Row two is the one most teams can ship this quarter. The unsaved-changes prompt exists because the product does not autosave. Fix the cause and the interruption disappears.

Row three shows that when you do interrupt, the value is in the specifics. Remove this user tells the admin nothing they did not know. Naming the twelve folders tells them whether they are about to break someone's week. Note also that the buttons say what they do. OK and Cancel invite the classic error where a user cannot tell which one cancels the deletion and which cancels the dialog.

Worked example

Stillwater's version

Deleting a client folder now moves it to Trash with a toast reading Moved to Trash. Restore within 30 days. [Undo]. No dialog. Permanently emptying Trash keeps a dialog, and it requires typing the client name. Accidental-deletion tickets go to zero over the following year. The one support request they do get is from a user who wanted a permanent delete faster, which is a much better problem.

When a dialog is the right answer

  • The action is genuinely irreversible: sending money, sending an email to 40,000 people, publishing to a public URL.
  • The consequence is invisible from the current screen, so the user cannot see what they are affecting.
  • The action affects other people, not only the person clicking.
  • It is rare. A dialog a user meets twice a year still gets read. One they meet twice a day does not.

One review question settles most arguments about this. Ask: if a user clicks the confirm button without reading, what happens? If the honest answer is the thing we were warning them about, the dialog is decoration and the work belongs in undo, in placement, or in typing the name.

Quick check

Why does replacing a delete confirmation with an undo toast usually protect users better?

The takeaway

Reflex beats reading, so build reversibility and specificity instead of asking the user to be careful for you.

Try this tomorrow

Pick the confirmation dialog your users hit most often, replace it with a soft delete plus an undo toast, and keep a dialog only for the permanent step.

Answer the check above, then bank the day.

Where this comes from

  • The Humane Interface, Jef Raskin
  • The Design of Everyday Things, Don Norman
  • 10 Usability Heuristics for User Interface Design, Jakob Nielsen, NN Group

Craft is one of six tracks. These lessons summarise and build on the work above, they do not reproduce it. Buy the books, they are better.