Maintain exceptions separately
Keep it Smart: If there are exceptions (i.e., a "blacklist") of devices to allow into a smart group, maintain a separate DG-blacklist containing these devices rather than abandoning the rules and manually removing the devices from the group, for example when troubleshooting or as bad actors emerge in the network. For example: DG-new = + DG-a + [ various criteria ] – DG-blacklist.