Firewall rules, per gateway and per user
Access control decides what gets in. Firewall rules decide what it is allowed to reach once it is in, and they are written two ways. A rule set attached to a gateway covers what that gateway serves, which is the right shape when the rule is about a site or a branch. A rule set attached to a user profile follows the person instead of the place, so they connect from a hotel on Tuesday and from the office on Thursday and the rule does not change because the postcode did.
They are applied to the gateways in real time, so a change does not wait for a maintenance window. They are also reapplied when a device reconnects, and that second part is the one worth reading twice: the laptop that spent the month you were tightening everything up sitting in a bag at the back of a car comes back on the current rules, not the ones it left with. Anything that only enforces at the moment you change it has a hole shaped exactly like that laptop.