In the above example, when Alice types `ssh alice.p.hacker@server102` and presses enter, is she now logged in? E.g., does tailscale takes care of having a user on the machine and assigning the known public key through some SAML/LDAP/PAM/sssd-ish magic?
Or does Alice gets 'access denied', then calls the sysadmins who still need to make a user for her on `server102`?
The second option would be understandable, but a bit of a bummer, as in that case the fancy RBAC rules have to be essentially recreated somewhere else for the application layer.