Zero Trust profile always includes routes in Default

I’m testing Zero Trust. I have network detection set up, and according to warp-cli get-alternate-network, the Warp / Zero Trust agent is correctly detecting that it is on my office network.

I have a default profile that includes 3 routes. I have a profile for the office network that includes two routes (ommitting the one for the office). But for some reason, even though the client detects that it is on the office network, it still gets a route from the default profile.

I’m using splut tunnels with the “include IPs and domains” option.

Does anyone know how to make this work?