United We Transform | Facilitator run sheet

Do, Redo & Undo

Teams stress-test a proposed process, feature, or plan by brainstorming potential errors and failure states. They then categorize remedies into redesigning to avoid the error (Do), allowing in-flight corrections (Redo), or fully reverting to a prior state (Undo).

60 minutes | 4 to 24 people

Choose this exercise

Purpose: Identify failure modes in a workflow or system design and map concrete prevention, correction, and recovery mechanisms for each one.

Use it when: Use when a team has an initial concept, workflow draft, or product feature spec and needs to account for edge cases, mistakes, and rollbacks before implementation.

Skip it when: Skip during early divergent ideation when no baseline concept exists yet, or when evaluating fixed regulatory rules that cannot be redesigned.

Group arrangement: Subgroups of 3 to 5 participants working in parallel on dedicated templates.

Timing: Based on the source indication of 1 hour or more depending on system complexity.

Materials and tools

Before participants arrive

  1. Write or print the baseline scenario, user flow, or feature spec where everyone can see it.
  2. Draw or post the 4-column template (Failure Scenario | Do | Redo | Undo) on a wall or table for each subgroup.
  3. Distribute sticky notes and markers to each subgroup workspace.

Say this to open

Most plans assume smooth execution, but real systems need ways to handle mistakes, changes of mind, and interruptions. Today we are examining our baseline draft through three lenses: Do, which means redesigning to avoid the mistake entirely; Redo, which means course-correcting midstream; and Undo, which means completely rolling back to a safe prior state. Your subgroup will first brainstorm everything that could go wrong, and then design specific remedies across these three categories.

How to run it

  1. Review baseline concept 10 minutes

    Facilitator introduces the session purpose and reviews the baseline concept, process map, or feature draft. Subgroups spend 5 minutes reading through the flow, clarifying ambiguities, and confirming where user or operator actions occur.

  2. Brainstorm failure scenarios 15 minutes

    Working individually for 5 minutes, participants write potential mistakes, missteps, or interruptions on yellow sticky notes (one idea per note), prompted by questions like 'What happens if someone pulls the plug?' or 'What if an untrained person tries to use this?' Subgroups then spend 10 minutes posting notes in their Failure Scenario column, clustering duplicates, and selecting their top 3 to 5 highest-risk scenarios to address.

  3. Map Do, Redo, and Undo remedies 20 minutes

    Subgroups address their selected scenarios using the hierarchy of solutions. On green notes, write remedies across the three categories: Do (change the design to eliminate the risk), Redo (provide a mid-action adjustment or buffer), or Undo (revert completely to a clean prior state). Subgroups place their remedy notes in the corresponding column next to each failure scenario.

  4. Cross-group walk and debrief 15 minutes

    Give subgroups 5 minutes to read other groups' templates. Reconvene the full room for a 10-minute debrief. Hear brief examples from 2 or 3 subgroups on which Do redesigns eliminated a problem entirely, and how recovery paths were defined.

Debrief questions

Finished output: A populated 4-column matrix mapping prioritized failure scenarios to concrete Do, Redo, or Undo system changes, ready to incorporate into the revised plan.

Remote

Set up a shared digital whiteboard with duplicate frames for each subgroup. Each frame contains the baseline workflow summary and four columns: Failure Scenario, Do, Redo, Undo. Break participants into breakout rooms of 3 to 5 people. Run the timer centrally and broadcast step transitions via room announcements.

Hybrid

Form distinct remote-only and in-person-only breakout groups. In-person groups use physical wall templates while remote groups work on the digital board. During the cross-group review, screenshare digital boards in the physical room and assign an in-person representative to photograph and paste physical boards into the shared virtual canvas.

Access and participation choices

If the session gets stuck

Groups focus entirely on edge-case recovery (Undo) without considering design fixes (Do).
Remind participants of the preference order: ask 'Can we change the initial step so this user mistake is physically impossible, eliminating the need to undo it?'
Subgroups get stuck generating dozens of trivial mistakes and run out of time for solutions.
Enforce the 15-minute cap on failure brainstorming. Direct groups to vote or pick their top 3 to 5 most severe risks immediately and move to solution columns.

Terms used here

Do, Redo & Undo Subgroup Matrix

Template Structure: Column 1: Failure Scenario (What error, disruption, or mistake occurs?)Example: User submits incorrect shipping address during checkout. Column 2: Do (Design out the risk)Example: Auto-fill address via verified postal database lookup so manual typos are impossible. Column 3: Redo (Course-correct in flight)Example: Show an inline validation prompt highlighting invalid postal formats before final submission. Column 4: Undo (Revert to previous state)Example: Allow a 30-minute self-service order cancellation window that restores the shopping cart.

Sources and adaptation

Observed in Gamestorming (gamestorming.com/do-redo-undo), which attributes the game to James Macanufo.

Retained the core mechanic from the Gamestorming source: brainstorming failure states (with prompts like pulling the plug) and categorizing responses into Do (prevent via design), Redo (course-correct), and Undo (revert). Added structured subgroup timing, concrete templates, neutral e-commerce address validation example, and clear hybrid facilitation mechanics.

See our editorial policy for AI use, sourcing and corrections.