the access and write list cant be the same.
give access to the /24, and single IPs to the write list.
all others will have read only at that point.