This is going to be a tall order but I might as well ask...
Modsec does a superb job at filtering but it can be a frustrating experience for clients and their clients when they hit a false positive. It only gets more frustrating for myself as an admin to then track it down because they don't always tell me immediately (especially if it's a client of a client) so I can't just hop into the web interface and report it (often the report comes in as "Oh, yeah, Bob said he got blocked a couple of times last week. Can you look into that?"). What would be nice is some sort of scoring mechanism (not dissimilar to how spamassassin works) where, if an odd block happens, you can be proactively notified as an admin. Maybe options for either an instant notice or a rollup report. Options to pick what rules you ignore, what rules always alert you (if you're having problems with a certain rule), track domains where you're having problems (this would be huge for me), etc. This strikes me as more of a paradigm change so I don't expect it by tomorrow (I'll give you til at least next week

) but as part of the next iteration of ASL it would certainly make a big difference in not only how admins use it, but how readily we can get the false positive data to you guys.