We are an MSSP and I'm sure these are the ones we spend a high proportion of our time on to fine-tune, but we have to make them work across 100s of customers, which may differ for your scenario.
I'd just say that you will probably need a watchlist for exclusions or have a playbook to handle exclusions, depending where you choose to do the optimization. We don't have a single strategy (apart from using a watchlist) as many needed bespoke work to fine-tune.