All means all
I built filters for a crowded email account. Family, medical, entertainment, a few more, so I could look at one slice at a time instead of the whole pile. Alongside the filters, I had it build a delete-all action, meant to work on whatever the current filter was showing.
One day I had a filter applied and reached for delete-all. It did not delete what the filter was showing. It deleted everything in the account. Not the visible slice. Every message.
I remember the moment exactly, opening the inbox afterward and finding nothing there. No warning, no confirmation, no undo. Just an empty account that had been full a minute before.
I got lucky. The account mattered to me, but what was actually in it did not, fortunately, or I probably would not be telling you this so plainly. It was a humbling few minutes, and not one I want anywhere near repeating.
What got built had done exactly what it was told, delete everything, and never checked whether a filter was supposed to narrow that down first. It ran cleanly and removed messages, which is exactly the kind of wrong that is easy to miss, because nothing about running it looked like a failure.
Afterward I told it plainly what must never happen again, and had it add one thing: a count, shown before the action fires, of exactly how many messages a delete is about to touch. Not a dialog to click through without reading. A number, in front of me, before anything happens.
I want to be honest about what that fix actually was. It was not a new philosophy about verifying destructive actions. It has not come up again, on this tool or any other, since. It was a narrow patch for one specific way a filter and a delete-all button had stopped agreeing with each other. Some lessons generalize into a habit you carry everywhere. This one did not need to. It needed to not happen a second time, in that one place, and it hasn't.
Not every fix has to become a rule. Some of them just have to work.
Be Better - all means all, so check what you are actually about to delete.