Hey Bastian,
I should have shared more infos, the thing is that there is more then one branch and they all will us the same topology = breackout with the same VLAN ID on the controller.
So I don't think that I'd control it on the device (switch/router) that connects the controller = I can't limit it per branch as they use all the same topology/subnet.
BR,
Ron