What Happened
A SaaS product sent a “New sign-in detected” email on every login from an unrecognised device. That included the customer’s own new devices, so the alert fired for normal behaviour as well as potential risk.
The email opened with two paragraphs about the company’s security practices. Only after that explanation did it name the device and location. Customers either ignored the message after enough false alarms or, in one flagged case, missed a genuine unauthorised sign-in because it looked identical to the earlier self-triggered alerts.
The Pattern
This is Consequence-After-Caveat, also called Caveat Before Consequence, applied to the one category where the consequence is genuinely severe. The message reassures and explains before showing the detail the reader needs to check.
Consequence-After-Caveat appears in 74% of audited emails. In a security alert, repetition makes the problem worse: when every instance looks the same, readers cannot distinguish a routine alert from a real account threat. The alert system spends trust before it needs to use it.
The Rebuild
Move the specific, checkable detail to the first line: which account, which device, which location, and when. Cut the security-practices paragraph from the transactional alert entirely. The reader is not evaluating the company’s security philosophy in that moment; they are checking whether the sign-in was theirs.
Replace a multi-click “Review account activity” link with two binary actions: “This was me” and “This wasn’t me”. The response should match the decision the reader is actually making.
Composite audit case. This is illustrative, not a named real client or a claim about a specific company.
Put the detail the reader can check before the explanation they can skip.
Name the account, device, location, and time first, then give one binary action. For a security alert, clarity is the safety feature.
Questions people ask
Why do users ignore security alerts?
Identical-looking alerts, regardless of real risk level, train readers to stop reading closely. A routine self-triggered alert and a genuine unauthorised sign-in become indistinguishable.
What is Consequence-After-Caveat?
Consequence-After-Caveat places background, reassurance, or organisational explanation before the outcome the reader needs to understand. It delays the reason to act until attention has already been spent.
What is the highest-leverage fix for a security alert email?
Move the specific detail to the first line: the account, device, location, and time. Then reduce the response to one binary action, such as “This was me” or “This wasn’t me”.
Related reading
Transactional messages work when the consequence is visible before the caveat.
SaaS Password Reset Emails Get the Structure Right by Accident. Marketing Emails Could Copy Them.
Field Note: The Renewal Reminder That Users Read as a Threat