Double encryption should help as long as the Tailscale client installed on your own machines is safe. Without double encryption for SSH, Tailscale and your SSO provider can theoretically run
commands on your machines without involving malicious client software. But that's not possible if you encrypt your SSH connection with your own keys.
Also for Linux, the Tailscale client is fully open source and I obtain the binary from the distro. I find that a bit reassuring.