Lesson: silence and failure must look different
Two months in, the paid data source fell into an unpaid invoice and returned errors for nine days. The bot honestly reported «no new reviews», which was true of its database, not of the listings. The outage was indistinguishable from silence.
Fixed in code: if a whole polling round fails, an alert goes to the administrator, and the client digest gets a health block with the date of the last successful poll, without technical detail. The backlog was loaded in one pass: four hundred reviews over three weeks, seven negatives delivered personally, the rest as a single summary so the chat would not turn into four hundred cards.
The rule we took into every loop: any poller of a paid API must be able to announce its own death. «No data» and «source unavailable» must look different in a client report.