Earlier quoted context omitted.
Yes, you are exactly right. Wireguard is a typical example of a thing I'd call myopic-cryptographer-protocol. Solve one problem in the minimal fashion that can be called proof-of-concept, do it in a maybe-more-secure way and call it done. Everything else, like proper key distribution and user management, which you need for a real-world deployment that isn't just a personal toy, is left as an exercise to the reader. A…
If people want Wireguard to be a complete multiplatform audited free enterprise VPN solution they need to donate more. A lot more.
What we do need is a proper replacement for roughly the things OpenVPN plus PAM can do. A VPN plus some user and key management.