Interesting discussion…and scary! Your sprinkler needs Internet access? I get it...but wow!
How about this for an approach:
I would look at grouping devices by trust and damage that can be done if they are hacked. i.e. if your sprinkler is hacked you get a wet lawn vs your cameras hacked and they can look inside your house and put your family online!
Maybe put your cameras on their own VLAN with very restrictive rules, specific alias IPs, limited ports, snort IPS, etc...
Sprinkler, thermostat, TVs, A/C Reciever, wireless printer(No internet access), wireless light switches on thier own.
I have a printer which I don't trust as far as I can spit...so I don't give it any internet access. I group it in my IOT VLAN and access it thru polcy rules from other VLANs,
Email/banking devices give their own VLAN.
Alexa maybe its own VLAN...thats another scary device.
I think the balance you will need to look at is manageability, security, usability and privacy. Keep it simple...
Follow up questions would be:
Do you have cable running thru the house or is wireless your only option? That would drive the number of SSID vs using a switch and hardwire.
How big is your house i.e. do you need a big range?
Do some of these devices need to be on the same segment to control?
Open to feedback...