I have something very similar to this in my environment. I use a subgroup in the System Tree which is dedicated to "Special Case" servers. If the group is named something to make sure it is above the rest of the subgroups (Eg. #Special Cases) and configured to have the sorting criteria bases on tags it should ensure that the system sorts in to that group before it matches any other criteria.
Once you have your separate subgroup autopopulating; you can use the subgroup to break inheritance and assign your policy with the exclusions.
Hope this makes sense.
Excellent . It works. Thanks Katalyst.