SSHSSH,
Attack Signatures is not the only use for staging, your assumption surrounding tightening in correct for file types, but also applies to URLs and parameters. Staging can also be used within File Types and Parameter as well, you can place individual file types into staging mode in order to learn lengths and the same is true for parameters to learn their values. So basically you can have your policy in blocking mode and still turn on staging for a particular file type or parameter thus allowing you to keep as much security as possible in place.
Mike