A single account-level timestamp checked at every dispatch entry point. Until it is set, the dispatcher logs and sends nothing. A failed read counts as not enabled.
Also called: opt in to notifications · stop all emails · notifications are off by default
- 1orgNotificationsEnabled reads organizations.notifications_enabled_at and fails closed on any error.
- 2It is checked once per dispatch rather than inside the per-recipient path, so it does not become one query per person notified.
- 3Once on, an event with no preference row falls back to the registry defaults, which the account can then dial back per event.
Migration 149 quotes the owner directly (2026-): “we want to make sure that the users don't get notifications from our system until they've said and enabled the notifications for themselves… If they enable them, then they will own the responsibility for receiving them.” The failure it replaced is spelled out: absence of configuration meant NOTIFY, not silence, and because the preferences table was unwritable until migration 134, 'every tenant has always been on "admin gets everything by email" without anyone choosing it. A new sub-account therefore started emailing its owner and its homeowners from the first completed stage. That is how a sending domain earns a junk-folder reputation before anyone has decided the product is useful.' Fail-closed is deliberate: 'missing one notification is recoverable, and mailing a tenant's customers during a database blip is not.'
- Default-on notification behaviour nobody chose
- Outbound mail to homeowners from a brand-new account
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →