I have a similar problem in a bit more complex network where I have different brand routers and devices, not only MikroTik and I'm overboard with manually modifying the ACLs. Besides the time and the energy spent on that routine, the job is also extremely error prone and human-factor dependent, which makes me verify the configuration every time I update it.
Now I'm also looking for a automated tool which can handle my situation but my case is way more complex. I have many cascaded routers and situations, when I have to let one router pass the traffic from a specific IP and the other router block it, thus allow the IP access some part of the network while deny the remaining. Will look into the startup you mentioned, not sure if it will work for me, however, this is better than nothing. May be I can achieve the result with some customizations!
Have a great day!