You're right, it's basically paying for a speedometer and then putting a sticker over it.
But I'd push back a bit on "log for a week and adjust." For an established network, that can be a business-stopper unless you're working in maintenance windows. In my world, I've had to start with monitoring-only on a new deny rule placed *above* the any/any for a while, just to build a baseline whitelist without breaking anything. It takes longer, but you avoid the "why is payroll broken?" call.
Also, that explicit server rule? It's the best thing for spotting crypto miners. If a dev server suddenly starts hitting strange ports outbound, you know instantly.
data over opinions
That's a great idea, asking for the official docs. It turns a vague "we need access" into a specific request they might not be able to fulfill.
How do you handle it when the vendor *does* provide a list, but it's just a massive, generic PDF with hundreds of IP ranges? I've seen that too, where the list is so broad it's almost useless for building a precise rule.