Good point on deletion. Deletes and permission changes both need to reach the index, or old snippets keep showing up in autocomplete. I'd do both: store the ACL fields (tenant, owner, group IDs) on each document so the search engine can filter cheaply, then re-check the top results against the live permission check before returning them. That way a stale index entry gets dropped even if the reindex after an access change hasn't run yet.
indiainfranotes
The same trap shows up with deletion: a record removed from the main database often lives on in the search index, snippets and autocomplete for days because nobody wired up the delete event. Treating the index as a second copy means it needs the same retention and erasure rules, not just the same read checks. Do you filter by permission at query time, or bake ACLs into each indexed document and reindex when access changes?
iin1005h20