Right, that's what I thought. This implies that you'd either need to recreate the access rules somewhere else for the application layer and use something like Teleport or some PAM server on top of Tailscale, or use some proverbial 'admin/pass123', if the Tailscale access guarantees feel strong enough.
Thanks!