Set up at least one staging server before production environment (recommendation is to have a sandbox/development, QA and Production)
Customization of ruleset is a must to remove false positives and identify risks coming from custom Tcodes. Pre-delivered ruleset acts a good starting point.
Design a simple and easy to manage 2-4 stages workflow for Access Requests. Having a complicated workflow would increase request closure time and add complexity while troubleshooting issues.