master
if user # Anyone can read their own account. can(:read, Account) { |account| user.account == account } # redundant with one above?