on a separate note -
I would like to re-iterate the (simple) desired behavior :
when traveling, we usually carry our “work tools” (laptop, phone) and our “entertainment tools”.
the idea is to have some devices to go thru vpn and the others directly to wan.

I have tried almost every conceivable combination (with or without using guest wifi) and it seems like the VPN policies simply don’t make any difference with that.
it might be that vpn policies work fine for dealing with destinations, but it does nothing to dealing with policing the clients/origins.
it is important to note that vpn policies for my use-case become useless if they only offer the ability to police destinations. trying to keep track of which addresses/urls are used by streaming services etc is not simple and time consuming.

all we need is a SIMPLE way to set a “policy” that can decide if a certain internal subnet/ip/mac can exit to vpn and default all others to wan, OR vice versa - default is vpn and specified is to wan.

either what exists now is really really broken, OR works but in an improperly documented and/or counter-intuitive.

I am willing to put time and effort in helping test it but I want to first understand if what I am trying to do is in fact included in the designs.