FitWhen to use it — and when not
Use it when
- Reversible actions that are too frequent to confirm one by one
- Inbox, file, task and CRM agents
- Bulk operations (archive 200 emails, relabel 50 tickets)
Skip it when
- Truly irreversible actions — use human-in-the-loop approval
- Actions with external side effects you cannot recall (a sent email)
AnatomyThe parts of the pattern
- Activity feedEach action in past tense with count and target.
- Per-action undoUndo next to every reversible entry.
- Undo toastShort, timed undo right after a bulk action.
- Undo runRoll back everything one run did.
GuidelinesDo & don’t
Do
- Describe actions as outcomes: "Archived 23 newsletters".
- Keep undo available after the toast fades, in the feed.
- Group actions by run so one click reverts a bad run.
Don’t
- Offer undo for things you cannot actually reverse.
- Make the toast so short nobody can react.
- Undo silently — confirm what was restored.
In the wildReal-world examples
Gmail (undo send)SuperhumanCursor checkpointsClaude Code checkpoints
Products named for reference only — no affiliation, and the demo above is an original illustration, not a copy of their UI.
For engineersImplementation notes
- Log every tool call as a command with its inverse (or a snapshot) at execution time.
- Prefer soft deletes and delayed side effects (send after N seconds) so undo is real.
- Tag actions with run_id so you can revert a whole run transactionally.