A mountable Rails engine for authorization: permissions auto-derived from controller actions, roles as editable data, per-record scoped roles, a separation-of-duties veto, and an ambient authorization context that makes allowed_to? work identically in controllers, views, and components. BETA (pre-1.0): the core is built and security-hardened; general availability is gated on one real-world enforce bake. Adopt it, run report mode, and send feedback. See the README and the issue tracker (#116).
Required Ruby Version
>= 3.2
Authors
David Teren