Confirmations and destructive actions

Confirmation dialogs interrupt. Use them only when an action cannot be undone; for everything else, do it immediately and offer Undo.

ActionPattern
Reversible (archive, hide, move, mark as read)Do it now, show a toast with Undo
Irreversible, low stakes (delete a draft, remove a filter)AlertDialog with a clear verb
Irreversible, high stakes (delete a project, revoke all keys, transfer ownership)AlertDialog with a typed confirmation

Undo instead of confirm

Give the toast a stable id so repeated clicks replace it rather than stack, and a longer duration so there is time to react.

Typed confirmation

Writing the dialog

  • Title is a question with the object: "Delete “northwind”?" — not "Are you sure?".
  • Description states the consequence in concrete numbers, and says it cannot be undone.
  • The confirm button repeats the verb: "Delete project", never "OK" or "Yes".
  • Cancel is the safe default. AlertDialog focuses Cancel when it opens, so pressing Enter by reflex does nothing destructive. Clicking the backdrop does not dismiss it; Escape acts as Cancel.
  • Use tone="danger" on the action only when it destroys something.

Where the button lives

Keep destructive actions away from the primary path. On a settings page, put them in a separate section at the bottom ("Danger zone"), with a danger button that opens the dialog — never a primary button that deletes directly.