You are correct. The approach does not seem to work. It seems that the rule really wants to look for a number mask from the caller ID or once you have implemented the forwarding rules, the exception does not allow the rule to be broken, but rather offers an alternative route that differs from the defined routing for that status.
I am not sure that there is an elegant way of doing what you ask. The exception route seemed promising. I will give it some thought, but the issues I see are:
1. There is no good way to keep the director's extension from becoming known. Presumably calls will be made from that extension and this will show up in the display of the called party (internal anyway).
2. An extension is an extension is an extension and once dialed, it will ring. So, if the director has that extension, it will ring and continue to do so until such time as the PA picks it up. I assume that the PA will either have the Director's extension set as an account or have one of the DSS keys set as BLF.
3. On the PA phone, if set as an account, the phone will ring whenever dialed. If set as a BLF, it will not ring, but an indication of the ring will be visually present. This could be a problem as I assume that no one will be able to maintain a constant vigil.
4. If the PA answers the extension, it will appear as though the call was answered by the director's extension which then brings the conundrum of how one goes about transferring a call while being on the extension of interest to the same extension of interest. You would have to set the extension to be able to handle multiple calls, which can be done, but I am uncertain how it might handle calls to itself.
The main issue is how can one go about "tunneling" through to an extension when that extension has rules in place that serve to preclude the possibility.
Sorry, that I don;t have an answer, but I will poke around a bit.