> For example, you identified an end point that should have a rate limit and didn't; you fixed it, it was a potential security issue
That sounds careless. Any such change would need to have a impact analysis (which should be part of the team/org/company's SDLC). In this case, communication should be sent out to the clients of that endpoint, with a reasonable deadline, before enforcing any rate-limit.