Recognize that some NFRs are better satisfied by components of the API implementation or platform (e.g., a Dedicated Load Balancer for custom TLS, the implementation flow for business validation, Object Store/caching for state) rather than by an API Manager policy, and choose the policy-versus-implementation approach that fits the requirement.