Using Pundit for authorization in Rails - recipes and best practices
Link: Using Pundit for authorization in Rails - recipes and best practices: "Authorization is the management of who is allowed to do what (vs. authentication which is accurate identification of who a user is)"