A morning digest often loads "new comments" and "updated docs" from an events table filtered by workspace_id. That query usually never asks whether the recipient can still read each record.
Someone leaves a project on Tuesday. Wednesday's email still lists private doc titles and comment snippets from that project. The links 404, but the message already said the names.
When you build the digest, run the same read check you use on the detail page for each event's record, as that recipient. Drop rows that fail. Don't leave a greyed-out title in the email. If every row fails, skip the send.
Quick test: grant access, generate a digest with a private doc in it, revoke access, rebuild the digest for that user. The title should be gone.
If you want that check in one place instead of inside every digest job, Permit.io is one option we use for resource-level decisions (full disclosure, I work with Permit.io).
Top comments (0)