Adding a rule for a service should allow multiple source/destination pairs for each rule, so that I could have a single rule for things like Zoom, with multiple source/destination entries.
There is a “grouped networks” feature that allows you to group and name a range of IP addresses, which can then be used as a source or destination in outbound policies and firewall rules.
On the local web admin console you can find it in Advanced > Misc. Settings > Grouped Networks.
In InControl you can find it under Group settings > Network Settings > Grouped Networks.