Context
A lean technical team was spending too much attention on suspicious traffic patterns and application pressure.
Challenge
The goal was to reduce obvious bad traffic while keeping rules understandable and reversible.
Approach
Reviewed logs and request patterns before writing rules.
Introduced scoped managed rules, rate limits, and allow-list logic where appropriate.
Documented rule intent so future teams could adjust safely.
Outcome
Created a more maintainable WAF posture.
Improved signal for future incident analysis.
Avoided claiming perfect bot elimination, because that is not how real web traffic works.
