Yes, every action is actually verified before moving to the next action, even after a heal has happened. Users can configure exactly how they want to verify an action, they can make it custom or leave the default verification that comes with every node.
For instance, if a fill node gets a selector healing for an input and types into it, a verification happens before moving to the next node. It will check if what is supposed to be typed into that input was actually typed and is actually right there.
For your example of a button click (submit or cancel), you can configure the node to verify the actual outcome of the click, like waiting for a specific URL change, a success toast, or a new element to appear on the page.
If that outcome isn't verified, Selonate doesn't just blindly guess or crash. It will try to self-heal, and if it exhausts all options without verifying the right outcome, it simply pauses and escalates to the user for manual intervention before continuing. The automation never breaks, but it also won't force its way through an irreversible action if it isn't 100% confident. And exactly as you mentioned, for highly sensitive or irreversible actions, users always have the option to keep auto-healing off entirely and handle it deterministically.
OnlineProxy
a hybrid setup like this is a common approach so the idea makes sense. i'd want to know what happens when a heal is wrong, like clicking cancel instead of submit. do you verify outcomes such as a record actually being created, or does it stop at the click? for anything irreversible I'd skip auto healing completely, since confidence scores can be off and make a weak gate there