Yes, I think we are on the same page.
I was trying to explain that having a separate monitoring infra and network group wouldn't work as a replacement for unidirectional network setup, because you sill need to open network access between critical infra and the monitoring system in your design, which will expose it to the internet.
So like you said, you still need to have an unidirectional network in place.