Clarification on service security policies


taken from this page:

Could someone please clarify, I presume that the note means the tag access section of the policy is meaningless if running on a single gateway (edge in this instance).

  1. Does this mean if there is a remote gateway on the network that access to tags can be controlled through the policy when connected to the local gateway?
  2. Is there any way to control access to prevent a certain zone from being able to edit tags if using only a single gateway?