Enterprise networks are becoming less LANish and now our home networks are supposed to move towards a VPN based architecture? Should we not drive security in the direction e2e and application level?
It's like stunnel or ghosttunnel but for L3, and that let's you replace the gargantuan IPSec with something that's way simpler and nimbler like wireguard.
As for LAN vs BeyondCorp... tailscale has BeyondCorp influences. It uses federated identity (OpenID for instance) and device credentials (see: wireguard crypto-routing) to let you in on any mesh network that you have access to be . It is not something novel but super complicated to do it as simply as possible. And wireguard is a key enabler for just that.
BeyondCorp is obviously much more than just SSO. You might also be interested in: https://www.beyondcorp.com/