The deficit in Tailscale ACLs (as I found while evaluating) is they can't make use of groups from your SSO supplier so you have to explicitly list users in there.
I landed on Perimeter 81 as a useful alternative that does what we needed
Interesting... this is also a defect in ZeroTier but thanks for the idea. :)
Hey thanks, this might be exactly what we are looking for. Somehow they never hit my radar when I was looking! User identity focused etc.