ZeroTier has a rules engine with tags and capabilities, but currently editing it requires some low-level knowledge of TCP/IP and manual management of tags and what they mean. It needs a higher level editor.
There's also some things you can do here for security that are unique, like sending copies of select traffic to security monitoring nodes or transparently redirecting traffic.