Fair, a single global guard shouldn't carry one blanket failure policy, defaulting open, with fail-closed reserved for the specific routes where sensitive operations are carried out. Login endpoint will also fail open. Good callout on webhook retries too, I hadn't separated that from general traffic. A flat limit treating a legitimate retry storm the same as abuse, exactly when you'd want the opposite, is a real gap. Worth handling on its own rather than folding it into the same limit. Fixing both. Thank you for your input.