cancancan's way of doing authorization is messy, let's try to figure out a better way The gems that have potential would be: * pundit * action_policy