Just going to present several variations on a theme here, tested with a Ubiquiti EdgeRouter 4 in my home lab.
Several resources were consulted in the process of creating these firewall rules, cited below under "Resources".
In these examples, the "default" or "management" VLAN1 is VLAN1, on 192.168.1.0/24. A separate VLAN8 was created for IOT devices on 192.168.8.0/24, along with its own DHCP service on the router.
The minimum requirements here are to have the IOT devices on VLAN8 network get an address from the VLAN8 DHCP server and access the Internet through the VLAN's gateway (192.168.8.1), allow managment network access to the