Not rooted.
That is the opposite of how I read the wireguard docs. I thought it should be that allowed IPs are destination ranges that must pass through the VPN. So the global default *should* do the trick.
Guide you recommend for this one? The mixed meanings of the word profile in the context is making search hard.