Almost no structure fails on the day it ships. It decays — page by reasonable page, reorganisation by reorganisation, until nobody can find anything and nobody can name the decision that caused it. And the same absence that produces decay produces most of what looks like manipulation. Harm does not require intent. It requires only that no one owns the whole.
Every page has an author. Every feature has a team. The structure connecting them usually has nobody. So it changes the way a garden changes without a gardener: each addition is locally sensible and the total is nobody’s decision. Two years on there are parallel sections from a merger, a category holding thirty-seven unrelated links, a page from 2021 still sitting at the top level, and a section with one page in it. Not one of those was a mistake at the moment it happened. Decay and bad design look identical in an audit and need opposite repairs — one needs a gardener, the other needs a rebuild, and confusing them is how organisations end up redesigning the same site every three years.
A content audit at the European Commission ended with roughly 80% of its online content removed as redundant, outdated or trivial1. Four fifths. Redundant material does not sit quietly in a corner: an old page competes with the current one for the same click, and often wins because it has been there longer and collects more links. No menu rescues a tree where most of the leaves should not exist. On a mature site the highest-yield architectural work is usually subtraction — which is also the least rewarded, because the deliverable is an absence and nobody announces it.
A university site, two years after merging with a neighbouring college. Ten top-level sections. Seven of them carry a structural fault. Click the ones you think are broken — you will be scored on both what you catch and what you flag wrongly.
False positives matter as much as misses. An audit that flags healthy sections costs credibility the first time one is checked, and it is how a maintenance conversation turns into an argument about whether the last redesign was any good.
A named owner for the structure, not only for its pages. A written vocabulary register — one preferred word per concept, the synonyms it replaces, who decides, when it was last reviewed. A scheduled audit, quarterly or annually, that is allowed to remove things. And a redirect discipline, so an address keeps answering for as long as anything points at it. None of that is clever, and its absence is the single best predictor that a site will need another redesign in three years. The register does most of the work, and the column that earns its keep is the forbidden one: recording that Case ID and Reference both mean order number is what stops a fourth name appearing next quarter.
Deliberately small and deliberately opinionated. A register listing every word in the product is unmaintainable and answers no question anyone actually has; one that settles the twenty contested concepts is a lookup instead of a recurring argument.
Structural manipulation runs from honest emphasis to legal exposure, and most real products sit somewhere in the middle two tiers. Naming the tier turns an argument about intentions into a judgement about structure — which can be made from outside, by someone who cannot see anybody’s motives.
The path you want people to take is easy to find, and so is every other path. Nothing is hidden; nothing is further away than it needs to be.
e.g. Upgrade prominently offered on the account page, with cancel in the same list.
✓ Fine — this is just clear structure.Both routes exist and are findable, but one has been made measurably longer than the other with no functional reason.
e.g. Sign-up is two screens; cancellation is five, with a survey and an offer in between.
⚠ Grey zone — would the reader feel misled if they counted the steps?The route is technically present and practically hidden — buried, unlinked, or reachable only by a channel the reader did not choose.
e.g. Cancellation exists only by telephone, during office hours, from a site you joined online in thirty seconds.
✗ This is a dark pattern in structure. Refuse to build it.Obstruction that touches consent, billing or disclosure law — where the structure itself is the compliance failure.
e.g. A consent banner where accepting is one tap and refusing takes four screens; or a cancellation route that does not exist in the medium used to sign up.
🚫 Stop. This is liability, not design. Escalate in writing.No lie is told here. No button is disguised. Every step is individually defensible — a survey to learn why, an offer to help, a confirmation to be safe. Drag the depth and watch what distance alone does.
The completion curve is illustrative rather than measured — every added step in a flow people did not want to be in sheds some of them, and the exact rate depends on the product. What is not illustrative is the asymmetry: two against seven is a decision somebody made, and writing both numbers down is usually enough to end the argument.
A content audit found so much redundant, outdated and trivial material that the Commission removed roughly 80% of its online content. Not a redesign, not a new menu — a decision about what should exist at all. Most structures are not badly organised so much as vastly overfull, and no navigation can rescue a tree where four fifths of the leaves should not be there.
The FTC's click-to-cancel rule required cancelling to be as easy as signing up, and to be available in the same medium. The rule was finalised in 2024, vacated by the Eighth Circuit in July 2025, and the Commission reopened rulemaking in 2026 — while retaining authority to act under ROSCA and the FTC Act. The specific rule is contested; the underlying principle keeps being reasserted, which tells you something about which way this is travelling.
Ask where your privacy settings are in a large product and the honest answer is often four or five places — some in account, some in each feature, some only reachable from an email. Nobody decided to scatter them; each team added theirs where their feature lived. Structural harm rarely requires anyone to intend it.
Structure decides what can be found. Labels decide whether anyone predicts it correctly. Device decides which composition has to win. And ownership decides whether any of it survives contact with two years of ordinary work. Each part rests on the one before: a perfect label on a structure nobody can navigate helps nobody, and a beautifully governed tree named after departments helps only the people who wrote the org chart. The through-line is that all four are decidable with evidence that costs an afternoon — a tree test, a first-click test, a device split, an audit — and that the alternative is a room full of people asserting preferences with nothing to settle them.
Ten well-known subscriptions, their sign-up path against their cancellation path. Grouped by how well the claim is established — because a regulator’s finding, a settlement the company denies, and a consumer-guide ranking are three different kinds of evidence, and an article arguing for evidence discipline has to practise it.
Earlier in this series the argument was that structural harm rarely needs intent — that scattered privacy settings and buried exits are usually what happens when nobody owns the whole. That is true of a great deal of it, and it is not true of all of it. Amazon’s cancellation flow had an internal name. Four pages, six clicks, fifteen options against a two-click sign-up, and the people who built it called it the Iliad Flow after a very long poem. That is not accumulation. That is a design brief.
The uncomfortable reason these flows persist is that they work. Retention teams measure saves; every step that sheds a share of people who came to leave shows up as revenue retained. So the friction is not an oversight to be pointed out — it is a performing feature with a number attached to it, defended by people who can show that number. Which is precisely why the line has to be drawn somewhere other than performance. “It converts” is an argument that cannot lose on its own terms, and the counter-argument is not a better metric but a stated limit: leaving should cost about what arriving cost. Regulators reached for that same sentence because no performance measure will ever produce it from the inside.
Read the tiers, not just the rows. Two of these ten are established through regulator action; one settled while denying wrongdoing; the other seven are widely reported rather than independently measured. Treating all ten as equally proven would be exactly the sloppiness this series keeps arguing against — and the reported cases are still worth listing, because the patterns they describe are checkable by anyone in ten minutes with an account.
Seven question formats, the way Beyond Dictionary serves them. Every question carries layered hints — a nudge, the reasoning, then a deeper connection — so a wrong answer opens a door instead of closing one.
The questions that arrive once everyone agrees the structure has slipped and the argument moves to whose job it is.
Because nobody owns them. Every page has an author and every feature has a team; the structure connecting them usually has no one, so it changes by accumulation rather than by decision. Each addition is locally sensible — a team publishes where their content lives, a merger doubles the servers, an old page is never retired — and two years later the total is nobody's choice. The tell is that decay faults have a characteristic shape: parallel sections, single-member categories, a swelling footer, orphans. None of those describes a taxonomy that was wrong on day one.
Ask of each fault whether it was a decision or an accumulation. A top-level label named after a department was chosen deliberately at launch — that is design failure. Two parallel course sections with different names appeared because a merger combined the servers and not the taxonomy — that is decay. The distinction decides the repair: decay needs an owner and a review cadence, while an original error needs restructuring. Treating decay as a design failure produces another redesign, which then decays in turn, which is how organisations end up rebuilding the same site every three years.
Usually subtraction. A content audit at the European Commission ended with roughly 80% of its online content removed as redundant, outdated or trivial. Redundant material does not sit quietly — an old page competes with the current one for the same click and often wins, because it has been there longer and collects more links. No navigation rescues a tree where four fifths of the leaves should not exist. It is also the least rewarded work available, because the deliverable is an absence that nobody announces.
Three, and most organisations already collect all of them without reading any. Incoming 404s from external referrers show where a rename shipped without redirects. Internal search queries for things already visible in the menu show a label that is not the word people hold — that is free vocabulary research. And repeat questions arriving at customer support point at destinations nobody can reach by browsing. The reason they go unread is organisational: 404 logs belong to engineering, search logs to marketing, tickets to support, and the structure to nobody.
Not always, and the tier matters. Where both routes are findable and comparable in effort, that is ordinary structure. Where cancelling takes five screens against a two-screen sign-up, with a survey and two retention offers, that is asymmetric friction — legal in most places, and the reader would feel misled if they counted the steps. Where the route exists only by telephone during office hours from a service you joined online in thirty seconds, that is obstruction, and it is the thing regulators keep returning to. Naming the tier turns an argument about motives into a judgement about structure, which someone outside the company can make.
No, and assuming it does makes it harder to fix. Ask where a large product's privacy controls live and the honest answer is often four or five places, none referencing the others. Nobody decided to scatter them; each team added theirs where their feature sat, and no one owned the whole. The reader's experience is identical whether the cause was malice or absence. Framing it without accusation is also more effective — "nobody owns this" invites a solution, while "someone did this deliberately" invites a defence.
Because learning a structure is exactly what destroys your ability to evaluate it. Staff and regular users have memorised the map, so the cost of a bad one falls almost entirely on newcomers — who do not file complaints, they leave. This produces a specific trap: the longer a team has owned a structure, the more confident and the less reliable its judgement about that structure becomes. It is also why every method in this series takes its evidence from outside the team, and why an afternoon with five strangers beats a month of internal debate.
Every number quoted above, with where it comes from and why it is here.
The reference shelf for all four parts, not only this one. Grouped rather than alphabetised, because the groups tell you what kind of thing you are about to read — a book that will change how you think, a study with a number in it, a standard you may be held to, or an argument still going on.
Books are listed without links where no stable public copy exists — a citation you can search beats a URL that rots. Everything with a link was read while writing this series.
Four parts, one argument — and four methods, each costing about an afternoon.
Pick the cheapest of the four — a first-click test on your current menu with three real tasks and five people who do not work with you. It takes an afternoon and it will change what the next meeting is about.