At a previous job, we seemed to have had a "don't ask, don't tell" policy when it came to remote workers logging in from outside of their home country. Then we had a member of the infosec team start logging in from a war zone and the policy suddenly because crystal clear that logins would only be accepted from the employee's home country unless permission was granted ahead of time and programmed into the VPN.