MEJE BOOKS Knowledge Library

KIM DONG-EUN · FTUE: First-Time User Experience (30 chapters)

Chapter 17. Errors and Recovery: How Not to Take Away a Sense of Control

Kim Dong-eun WhtDrgon. · Chapter 17

Chapter 17. Errors and Recovery: How Not to Take Away a Sense of Control


A beginner's mistake is not a defect in the user. It is evidence of something the screen has not yet taught.

We quietly believe that a good first experience is one in which the user never fails.

That is why preventing mistakes is often the first thing we do when making a first screen. We hide irreversible buttons, remove choices that could be wrong, force people down a single path, and flatten the road so the user cannot fall. But this kindness contains a trap. A road where falling is impossible is also no fun to walk. An experience where nothing ever blocks you, nothing ever feels close, and every button works equally well is safe, but dull.

This chapter begins with that contradiction. The possibility of failure is not a defect to eliminate, but material to handle well. Without anxiety and tension, there is no joy in success. The moment something almost blocks you and then gives way, or you almost lose and then win, makes a first experience feel alive. The work of this chapter is therefore not to reduce failure to zero, but to let people experience failure without allowing it to drive them away—in other words, without taking away their sense of control. Reading the traces of those mistakes as numbers afterward belongs to the measurement work in Part 5. Here, we examine how the screen treats a person at the very moment a mistake occurs.

The Same Mistake: A Screen That Keeps Someone and a Screen That Drives Them Away

Return to our fictional character game, the mobile game where people collect characters, converse, and watch short videos. The user has spent a long time carefully choosing a character's color and pattern until everything looks just right, but their hand slips and presses "Reset." What happens next depends on how the screen answers.

The bad version goes like this. The moment the button is pressed, the character returns to its initial state without warning or confirmation. There is not even a dramatic failure screen. The screen looks perfectly calm, as if nothing happened, except that the five minutes just invested are gone and there is no way back. This is not an invented exaggeration, but a reality still encountered often. The user pauses in disbelief, cannot bring themselves to choose all the colors again from the beginning, closes the app, and never opens it again. What they lost was not five minutes, but a sense of control. Something happened under their hand regardless of their intention, and they could not reverse it. The better version goes like this. Pressing "Reset" first displays, "Delete everything? The design you just made will disappear." The user presses "No" and breathes a sigh of relief. An even better version lets the reset happen but displays a clear "Undo" on one side of the screen for a while, so one press restores the previous state. Knowing that whatever they do can be reversed, the user is unafraid to touch and try things. It is the same mistake, yet one first screen drives them away while another makes them bolder.

The same principle lives in tools we use every day. "Undo" appearing briefly at the bottom of the screen immediately after an email is sent is a common example. If the sender realizes that they chose the wrong recipient or forgot an attachment, that single button returns the sent message to their hands within a few seconds. What is interesting is that even people who have never pressed it benefit. The fact that the action is reversible lets them press Send with less fear. A path back is useful not only after a mistake; it makes a person bolder before one. "Undo" on a first screen does the same work.

In MEJE IDONG WORLD, this difference grows even larger. The fan is the person who meets, decorates, and cares for IDONG, and it is normal for a fan's hand to slip after careful work and press the wrong thing. A screen that answers the loss of all that work with "You deleted it, so start over" disappoints the fan, and that disappointment becomes departure. By contrast, a screen where nothing disastrous happens no matter what the fan presses, and where errors can be reversed at once, lets the fan freely try everything. IDONG WORLD therefore preserves every change made on the decoration screen automatically, one action at a time. Whether the fan presses Reset or the app closes midway, the last-touched appearance remains and reopens before the returning fan. A path back to the immediately previous appearance also remains visible for a while. A fan's first experience should be decoration where mistakes are safe, not an exam where one wrong answer is punished.

Six Attitudes Toward Errors

Handling failure well is not vague kindness. It can be divided into several clear principles. Before placing all six on one line, however, separate their layers. The first is a design philosophy about what to make. The other five are handling principles for the failures that philosophy leaves in place.

Begin with one philosophy. In an experience centered on challenge and overcoming it, leave failure in. Losing and being wrong must remain possible for victory to feel joyful and a correct answer to feel satisfying. Experiences centered on care, observation, or creation, by contrast, can produce depth through rhythm and attachment without constructing defeat. If failure remains, leave only as much as the experience's central pleasure requires, and do not make it fatal.

Once failure has been left in place this way, five principles for handling it follow.

Make recovery possible. When a person makes a mistake, there must be a path back from that point: undo, retry, go back. Do not trap someone in a dead end.

Do not burden the user with something they cannot fix. This means not blaming the user for a problem outside their control. If a pause caused by a slow server is passed off as "Your connection is unstable," the user is scolded for something they cannot repair. The system should carry the problems the system caused.

Keep control in the user's hands. The user must be able to know what is happening now and to stop or undo it. When something the user did not initiate proceeds without permission, they feel seated in the passenger seat rather than behind the wheel.

Do not let information be lost. What the user invested must not disappear. If a carefully decorated character, a name they wrote, or settings they chose vanish wholesale because of one small mistake or error, the memory of that loss keeps them from trying again.

Do not interrupt the workflow. Do not throw up a large window in the middle of a task, block the flow, or return work to the beginning. Even when announcing an error, allow the user to continue from where they were.

At this point, one might ask whether the philosophy and handling principles cancel each other out. If everything can be undone and nothing can be lost, does the feeling that something is at stake disappear, emptying the source of tension? The answer lies in distinguishing what can be lost. Recovery should protect the user's possessions and progress. Tension should attach to this one attempt. The time-loop space exploration game Outer Wilds is often cited as a clean example of this distinction. Every 22 minutes, the sun explodes and the protagonist returns to the beginning of the loop, but the knowledge gained and the ship's exploration log are said to remain. One loop is lost, while all progress remains. The tension of death stays sharply alive even though almost nothing is actually lost by dying. Unlimited recovery and living tension can coexist this way. Let this attempt fail, but do not let that failure destroy what has been accumulated so far.

There is a method for applying these six ideas to a screen one step at a time. Take the same error point and compare three levels: bad handling, better handling, and the best handling. Bad handling leaves the user in a dead end. Better handling opens a door out. The best handling prevents fear from arising in the first place. Placing the three levels side by side shows where our current screen stands and how to raise it one step. Take one incorrect password as an example. The bad version displays only "Error" and clears everything entered. The better version says what was wrong and preserves the input. The best version shows the requirements in advance and, even after an error, points only to what needs correction. The detailed work of applying these levels to every error point and redrawing it belongs to the error-handling ladder in Appendix C (→ Appendix C). In the main text, keep only the fact that the ladder exists and that our screen can always aim one rung higher.

The Old Agreement That a Game Means Dying and Trying Again

Because this chapter handles errors, it is time to call a gaming convention to the checkpoint. It is actually a bundle rather than one convention: Game Over, save and load, Continue, and even deliberately punishing hardcore difficulty—the old agreement that "a game means dying and trying again."

Begin with what this agreement takes for granted. In games, failure is not an ending but a beat. Die, and a Game Over screen appears. Start again from the last saved point. Insert another coin, metaphorically or literally, and continue. Some people deliberately choose the hardest difficulty and choose to die more often. This framework is a deep grammar of games that has grown since the arcade era. To gamers, death is not punishment but learning. They die once, learn an enemy's pattern, try again, and finally win; that entire process is the fun of the game. Saving and loading are safeguards that let people experiment without fearing loss. Within this agreement, Game Over is not frustration but the starting line for the next attempt.

Ordinary people do not share this agreement. To someone who has watched dramas all their life, the red words "Game Over" read not as a next challenge but as the judgment "You failed." They came to wait for the next episode, not to watch the same scene again. To someone accustomed to endlessly scrolling short-form video, "Return to the last save point" is like being forced to replay a video they just saw from the beginning. To someone accustomed to filling a shopping cart in commerce, losing all progress because of one instant's mistake is as absurd as having the cart emptied immediately before checkout. A gamer reads Game Over as "Try again." A newcomer reads it as "This is where it ends." The same red words are an invitation to one and expulsion to the other.

The fee this agreement charges ordinary people is lost control and frustration. A screen that says to die and try again demands that someone erase the time just invested and walk the same road again. To a newcomer, that is not a rhythm of learning but an event in which time was taken away. A screen recommending a harder difficulty is a challenge to a gamer, but a notice saying "This is not for you" to an ordinary person. Returned to the beginning after dying only once, the user counts what they lost before considering what they did wrong.

Games also contain examples that turn failure from punishment into rhythm. One indie platform game known for being demanding does not punish death. It simply restarts the player immediately at the beginning of that section, and only shows the accumulated death count at the end of the chapter. That number is said to read not as shame but as evidence that "I endured this much and reached the end." Even the text explaining how to turn an easier Assist Mode on and off is known to frame it not as taking something away, but as helping more people reach the experience. When a screen uses different words for the same death, whether a person receives it as frustration or as rhythm changes.

Separate the essence to preserve from the shell to remove. Preserve the tension of failure and the joy of succeeding on another attempt, but remove the parts that make death a punishment. In a first experience, erase the words Game Over, change failure into "Want to try once more?" and restart directly at the blocked point rather than returning someone to the beginning. Do not make saving homework the user must remember; let the system automatically hold on to everything the user has done. Do not push a difficulty choice at the very beginning. Watch the shape of the user's struggle and quietly adapt. The value of failure remains alive, but failure does not take time and control away from the user. That is the first experience's responsibility. The deeper pleasure of dying and trying again can emerge slowly after the user has come to love this world.

▶ Three Questions to Apply to My Screen

  1. Is this screen blaming failure on the user?
  2. Is the path back visible at a glance?
  3. Is the mistake a punishment or a beat? If any one of the three blames the user or traps them in a dead end, that failure drives people away.

So, Design the Path Back Before Preventing the Mistake

Once failure is seen as material, the order of designing errors in a first experience changes. Instead of asking first how to prevent mistakes, begin by designing how someone returns after a mistake occurs. People will make mistakes anyway, and distraction makes them more frequent. Rather than spending all effort on prevention, lay down a path first where mistakes do not cause disaster and can immediately be reversed.

One proposition that may sound provocative follows. If the path back is reliable, there is no need to hide dangerous buttons. A screen where anything can be undone has fewer things that need to be prevented. Go one step further, and most processions of "Are you sure?" can also be removed. A confirmation dialog is fundamentally a patch for an absence of recovery, justified only before an action that cannot be undone. A screen that asks for confirmation before every reversible action does not become safer, only slower. People soon learn to press "Yes" without reading, rendering even the confirmation before an irreversible action powerless. Every time we want to display a confirmation window, we should ask first: can this action be given an Undo instead?

Numbers tell us whether this order was right. Handling failure well is revealed by the rate at which people try again after failing. Observe where people become blocked and whether, after that block, they try again or simply leave. If many people retry at the blocked point, it was a failure they wanted to try again. If people disappear immediately at the block, it took away their sense of control. Whether a person stays or leaves immediately after their first failure reveals whether we made failure a beat or a punishment.

Reference Content

Examples from other media that reveal this chapter's concepts.

Video Games

  • Celeste's Assist Mode: It treats death as rhythm rather than punishment and makes the death count at the end of a chapter read as evidence of having endured to the finish. The guidance for turning the mode on and off is also written not as taking something away, but as a way to let people previously excluded by difficulty reach the experience. It is said that the original phrase "lower the difficulty" was later softened to "adjust the rules to fit your needs." Both the handling of death and the tone of the guidance are useful references.
  • Dark Souls' bonfires, soul retrieval, and "YOU DIED": Death restarts at the previous checkpoint and gives one opportunity to recover what was lost, but the red words divide into an invitation to gamers and expulsion to ordinary people.
  • Outer Wilds: Death returns the player to the beginning of a 22-minute time loop, but all knowledge gathered and ship records remain, so nothing is actually lost. It shows how death ceases to be loss when progress resides not in points or equipment, but in what the user has learned. General Apps
  • Gmail's Undo Send: It displays a path back for a few seconds after sending, letting even people who have never pressed it send with less fear.
  • Showing password rules in advance: It presents requirements before an error, preserves the input after one, and points only to what needs correction.

The remaining reference content appears in the "Chapter 17 Appendix" at the end of this chapter. (In the print edition, it is collected in Appendix D.)


Design Notes ▶ Try It Yourself

Find three places in our game's first experience where the user can make a mistake or become blocked: a button that can be pressed accidentally, an input that can be wrong, or a choice that becomes a dead end.

For each of the three, write one line describing how the screen currently responds, then ask beside it: does this burden the user with something they cannot fix? Does it make the user lose what they invested? Does it interrupt the flow of their work? If any answer is yes, raise that point one rung. Rewrite it to open a door in the dead end, preserve what would disappear, or reconnect the interrupted flow.

If any of the three smells like "Game Over" or "Start from the beginning," mark it. There, the screen is turning death into punishment. Revise it to preserve the tension of failure while removing the punishment. Detailed redesign continues in the error-handling ladder in Appendix C (→ Appendix C).

A screen that blames mistakes on the user drives people away. A screen that lays down the path back first makes people bold. Begin by determining which of the two ours is.

In One Line: The possibility of failure is not a defect to eliminate, but material that provides tension and joy. Yet that failure must not take away a sense of control. Make recovery possible, do not burden the user with what they cannot fix, do not lose information they invested, and do not break their flow. Game Over, save/load, Continue, and hardcore difficulty may be natural to gamers, but they bring frustration and lost control to newcomers. Remove the parts that make death a punishment and preserve only the joy of succeeding on another try. Next Chapter: This completes our treatment of people inside the first experience: people who press, receive responses, become distracted, and make mistakes. Now we move our gaze from inside the screen to outside it. Long before people open the first screen, they arrive carrying expectations about us. Where and how should those expectations be planted? Part 4 begins with previews and first impressions.


Chapter 17 Appendix: Reference Content Collection

The cases collected here show how this chapter's argument—lay recovery down first instead of eliminating failure—appears inside and outside games. They are grouped by medium, and each entry ends with "What to Observe." Keep in mind the framework established in the main text: the philosophy of preserving failure without taking away control, the distinction in stakes through which tension belongs to this one attempt while accumulated progress and possessions remain protected, and language that does not pass the system's fault onto the user. You will then see what each failure makes someone lose and what it protects, and whether that failure reads as punishment or rhythm.

Video Games

  • Super Meat Boy (2010): Death immediately restarts the section, reducing the interval between failure and retry almost to zero. After clearing the section, a replay shows every failed attempt running simultaneously on one screen, turning accumulated deaths into a record rather than shame. What to Observe: Alongside the principle that a faster restart turns failure from punishment into rhythm, watch the ending that returns traces of death as a spectacle. Handling failure has two layers: immediate speed and retrospective meaning.
  • Prince of Persia: The Sands of Time (2003) and Braid (2008): Immediately after a mistake, time can be rewound to undo even the protagonist's death along the same trace. After falling to his death, the narrator prince says, "No, that is not how it happened," corrects the story, and returns to the previous moment. That one line renames death from "failure" to "a story told incorrectly," turning the same failure from punishment into rhythm. What to Observe: Alongside rewind as a mechanism, see how the language used to name failure changes the texture of the experience. The same function can be received differently depending on the sentence the screen offers.
  • Console and PC autosave, and Resetti in Animal Crossing: In early Animal Crossing games, turning off the power without saving caused the mole Resetti to appear and deliver a long scolding. In New Horizons (2020), where autosave became the default and the system held onto progress automatically, even that scolding role disappeared. What to Observe: When the era of saving as the user's homework ended, the need for a scolding character disappeared with it. When the system takes responsibility, there are fewer reasons to reprimand the user.
  • Hades (2020): Death is not the end of progress but a beat in the story. Every return home after death brings different dialogue from characters such as Hypnos, who points out what defeated the player this time. What to Observe: See a structure that attaches a new story to every failure, making death itself a reward. If immediately after failure is the moment when people are most likely to leave, this example decides in advance what to give them at precisely that moment.
  • Cuphead's boss retry screen (2017): After death, a progress line shows which stage of the boss was reached, putting "You got this far" first, then immediately restarts the boss. What to Observe: Notice that the failure screen shows progress before loss. When progress is visible, the same failure becomes one a person wants to try again.
  • Super Mario's Super Guide and Invincibility Leaf: Beginning with New Super Mario Bros. Wii (2009), dying several times in the same section produces a block that demonstrates play. Later games are known to quietly offer items such as a white Tanooki leaf that grants invincibility. They do not force a difficulty choice at the beginning. What to Observe: Notice the order in which help arrives as a suggestion after observing how someone is blocked, rather than as an advance choice. Observe before asking, and offer a hand only after observing.

Literature

  • Save and undo in interactive fiction such as Zork: They allow readers to reverse a choice and test another path, preventing mistakes from becoming dead ends. What to Observe: See how the guarantee of reversibility leads a reader toward bolder choices. Recovery increases the amount of exploration.

Board Games

  • Allowing takebacks in introductory cooperative games such as Pandemic: When a beginner makes an obvious mistake, allow one move to be taken back so the first game does not become punishment. What to Observe: See facilitation that protects the first game's experience above strict adherence to rules. A takeback does not ruin the game but invites another one. Among experts, the same takeback reduces tension, revealing that recovery mechanisms also have an audience and a time.

Film

  • Edge of Tomorrow (2014) and Groundhog Day (1993): The protagonist returns to the beginning of the same day after every death, but memory and skill accumulate, turning death from an ending into practice for the next attempt. What to Observe: See the distinction in stakes—only that day is lost, while everything learned remains—translated into film grammar. It forms a useful bridge when explaining to audiences outside games how a gamer learns one run.

Animation / Comics

  • Return by Death in Re:Zero − Starting Life in Another World: Death returns the protagonist to a fixed point to begin again, but the pain and memory of death return with him. What to Observe: Treat it as a variation that prices recovery. Everything can be undone, but not for free. It helps calibrate that degree, while reminding us of the emotional dimension of recovery: what the user experienced remains even after returning.

Live-Action Television / Drama

  • Prerecording and broadcast delay for live television: A short interval before transmission allows an accident to be reversed so an unfixable mistake does not go out unchanged. What to Observe: See how deliberately inserting delay before an irreversible action creates room for recovery. Buying time can be another path instead of displaying a confirmation dialog.

Music

  • Punching in during recording, rerecording only the mistaken bar: The performer does not sing the entire song again from the beginning, but restarts only at the blocked measure. What to Observe: See how different "restart immediately where blocked" feels from returning to the beginning. Preserving the parts that went well preserves the desire to retry.

General Apps

  • Undo (Ctrl+Z), Trash, and restoration periods: Anything can be undone, and even deleted items receive a period in which they can be restored. What to Observe: See the main text's proposition that a reliable path back reduces the need to hide dangerous actions or obstruct them with confirmation dialogs. The Trash is why a Delete button does not feel frightening.
  • Server error screens, such as GitHub's unicorn 500 page: They do not blame a system-caused failure on the user and lightly communicate that the user did nothing wrong. What to Observe: See blame-free language that turns attention toward a solution rather than scolding over what someone did or did not do. One sentence placing the source of the fault clearly on the system protects trust.
  • Continuous autosave and version history in Google Docs and Figma: There is no separate Save button. Every change is preserved immediately, and if needed, a version from days earlier can be restored. What to Observe: Treat it as an example that makes "do not lose information" a default rather than a feature. Once saving ceases to be homework, people experiment without fearing loss.
  • Forgiving input handling: An input field accepts hyphens or spaces in a phone number and spacing in a card number. If the meaning is clear despite a slightly different format, let it pass; do not make the user adapt something the machine can adapt. What to Observe: Treat it as a stage before handling an error well: a design that never turns it into an error in the first place. The principle of not burdening users with something they cannot fix descends to the level of an input field.
  • Steam's refund policy: A purchase can be refunded without a major justification within two hours of play and fourteen days of purchase. It is said that once a recovery path appeared for the formerly hard-to-reverse action of buying, more people became willing to try unfamiliar games. What to Observe: See whether the main text's principle—that reversibility makes people bold before trying, not only after a mistake—also holds at the scale of commerce.
  • Delayed bank transfer services: When enabled, transferred money arrives after a set period and can be canceled before then, creating time to reverse voice-phishing transfers or money sent by mistake. Such services have existed in South Korea since 2015. What to Observe: Treat it as a design that inserts one deliberate layer of delay into an irreversible action to create a recovery window. Sometimes one layer of delay is a stronger safeguard than one confirmation dialog.

Machines / Appliance UX

  • Error-code displays on microwave ovens and washing machines: They clearly present the cause of a stop as a device state rather than the user's fault. What to Observe: Notice that placing the source of the cause on the machine prevents user self-blame. The code itself is still the maker's language, so also ask whether one line in the user's language can accompany it.
  • Canceling an elevator floor by pressing its button twice: It lets someone undo a mistakenly selected floor immediately at the machine. Support is said to vary by model. What to Observe: A recovery method that exists but is unknown is equivalent to no method. Do not merely create the path back; make it visible.
  • Start and gear confirmation procedures in cars: They add a physical step before an irreversible action so a momentary mistake cannot cause disaster. What to Observe: See the selectivity of adding steps only before irreversible actions. Adding a step to everything merely makes the system slow. Safety comes from adding one only where an action cannot be undone.
  • A "Start Over" button on an unattended kiosk: It remains in the same place on every ordering screen, so a lost person is not trapped in a dead end. What to Observe: The fact that the recovery path is always visible in the same place protects a sense of control. More people benefit from knowing it exists and feeling reassured than from actually pressing it.

Real-World Procedures

  • Checklists in aviation and medicine: They do not assign mistakes to individual responsibility, but recover from and prevent them through procedure. What to Observe: A culture that treats mistakes not as personal defects but as procedural matters is the institutional version of blame-free error language. It fixes the structure instead of trying to fix the person.
  • Flight-simulator training: People learn through repeated failure in an environment where failure is not fatal. Failure is not a dead end but the starting line for another attempt. What to Observe: See the idea of creating a separate space where the cost of failure is artificially lowered. The first-experience section can be designed as a kind of simulator: a place where failure loses nothing.