We also have pi-hole running that blocks a lot of things, and can turn on and off certain domains (so they can play roblox etc for a short while, then its blocked again) and their devices are pretty locked down
All four of my daughters prohibit my 7 grandchildren from going anywhere near roblox. My grandchildren are currently ages 2-11 but my daughters are so outraged by what happens there that they say their children will never be allowed on roblox until they move out of the house. Apparently it is extremely predatory, lots of bullying, and highly sexualized - and while children are the site's target audience, the site provides no effective oversight.
The key is to be open about it and “more” than reasonable; allow things when requested that aren’t harmful.
If we’re too perfect at protecting them from the world they’ll have no tools to deal with the world, which they will have to do eventually.
Now why they came back, and weren’t working before? The restrictions were so full of holes that they didn’t really work as anything other than a speedbump.
It looks like normal user device enrollment with device management is optional, hence why I think business probably makes sense.
https://support.apple.com/en-sg/guide/apple-business-manager...
The you can force all traffic through a proxy.
https://support.apple.com/en-sg/guide/deployment/dep7ba46fcd...
And since you have root certs on the devices, you can decrypt traffic and uniquely identify devices and block internet from your central management, at any time, regardless if the phone is on your wifi vs a friend's vs mobile data.
I think it should work.