The same trap shows up with deletion: a record removed from the main database often lives on in the search index, snippets and autocomplete for days because nobody wired up the delete event. Treating the index as a second copy means it needs the same retention and erasure rules, not just the same read checks. Do you filter by permission at query time, or bake ACLs into each indexed document and reindex when access changes?
iin1005h20