As they get older I'll remove it in stages: blacklist, logging only, then direct access with no proxy. The opening up will be done when it seems appropriate and in full discussion with them. I don't have a schedule for it.
When they're old enough to have phones I can initially give them managed devices with always-on wireguard and the same transparent proxy. (I've tested this setup and it's not circumventible without wiping the device.)
The claims often made on hn about this stuff, that:
* Kids will resent any attempt to limit their access, and
* Kids are NSA-level hackers who will circumvent any attempt at limiting their access.
are empirically false, at least in my experience so far. I expect they become more true in the teenage years but that's when things can start to open up.
Even if the restrictions have to be entirely dropped or become irrelevant the second they enter senior school, they've already benefited a lot from this over the years.
The other argument, that other kids will have phones etc so there's no point, is just an abdication of responsibility. I feel like I should do my best here, whatever everyone else is doing.
The one thing that is true is that it's quite technically demanding. A managed phone with an always-on wireguard connection to a network with a transparent ssl-bump mitm proxy and a domain-based whitelist with an admin UI to browse logs and block/unblock domains is not an easy thing to set up.
It's possible, though, and it has value. It should be much easier.