To prevent clients talking to each other you need the client isolation feature - but this is not supported by the built in AP's. You need a standalone MR.
Yes you could allow clients on different SSID's to talk to each other. The easiest way would be to bridge both SSIDs to the same VLAN.