@dashrandom For home use, I put the home stuff which is all mobile devices plus stuff like Sonos, Chromecast, etc. devices onto a network designated as "insecure". The work stuff, including the encrypted partition on my NAS containing confidential work files, is on a different network with no WiFi.
I also have a generic "LAB" network for managing any lab VMs, a separate network for CCTV cameras, and a Management network which the BMC and management of the Unifi are done through.