Tom,
I don't think that this could be achieved in an orthodox way, usually Per-App VPNs are based o App signatures and a MDM to make the tunneling decision and the automatic VPN.
Personally I request my customers to define what is Per-App VPN for them, there are many definitions and mis-definitions for it.
Having said that, a "similar" solution would be to create access rules for your remote access users based on identity where you allow them to only access certain applications. I know that it's not technical the same but maybe it works for you.
____
____________
https://www.linkedin.com/in/federicomeiners/