Magic DNS isn't available for testing yet, but coming soon!
Our network diagnostic logs are based on https://apenwarr.ca/log/20190216 and we do intend to surface those eventually to end users or at least network admins. Just need to work out the right API and security model for that.
As for access controls between devices, Tailscale already supports that but our docs are currently too vague. If you're using Tailscale, visit https://login.tailscale.com/admin/acls to explore. Security policies you edit in there are immediately enforced by all nodes right away, so you can give some users access only to central servers, etc.