The thing I'd flag from running Redis-backed throttling in production: what happens when Redis itself blips matters as much as the ttl/limit numbers. A global APP_GUARD throttle that fails closed on a Redis hiccup turns a two-second cache blip into "nobody can log in," which is a worse outage than the abuse it's meant to stop. Fail-open at the global layer and reserve fail-closed for the specific routes where you'd rather reject than risk letting something through unmetered. The other one worth rehearsing on Titan specifically: legitimate retries from an upstream payment webhook don't back off politely on a 429 the way a browser does, so the exact moment you're mid-incident and getting hammered by real retries is also the moment a flat global limit is most likely to start eating legitimate traffic.