Using the firewall ip rules with exceptions to certain devices from WARP?

Hello, I am using Cloudflare to run a tunnel to 2 different sites. We currently have three firewalls rules on the tunnel, one of which is an ip rule requiring the users ip to be one of four accepted ones. We are now trying to role these sites out to more people without requiring their ip’s, but we do not want to open the site to everybody. Is there a way to block traffic both through ip’s and some sort of device list like what WARP gives you. We are also open to other ideas outside of WARP.

Mainly we want people to be able to access the sites on their phones on both celluar or wifi

