make:policy writes a class to app/Policies. With --model it adds the seven resource methods, typed for the model, and each returns false, so nothing is allowed until you write the rule:
php artisan make:policy ReviewPolicy --model=Review
grep -o 'function [a-zA-Z]*' app/Policies/ReviewPolicy.php | cut -c10- | paste -sd ' 'Output
INFO Policy [app/Policies/ReviewPolicy.php] created successfully. viewAny view create update delete restore forceDelete
You never register it: the gate maps App\Models\Review to App\Policies\ReviewPolicy (or App\Models\Policies\ReviewPolicy). In tinker, Gate::getPolicyFor(Review::class) returned a ReviewPolicy and User's returned null. Otherwise put #[UsePolicy(OrderPolicy::class)] on the model, call Gate::policy(Order::class, OrderPolicy::class) in boot(), or override Gate::guessPolicyNamesUsing(). The container builds policies, so constructors may type-hint dependencies.