Each public method is an ability of the same name: can('update', $review) calls update(), and a hyphenated ability such as force-delete becomes forceDelete(). The method receives the user, then the model, and returns a bool or a Response. Only its author may edit a review, and delete() is the same test returning a bool:
public function update(User $user, Review $review): Response
{
return $user->id === $review->user_id
? Response::allow()
: Response::deny('You can only edit your own reviews.');
}Ben's PUT /reviews/1 on Ann's review got 403 {"message":"You can only edit your own reviews."}; Ann's got 200. $review->user()->is($user) also compares table and connection. @can in a loop over 50 reviews calls the method 50 times, so eager-load what a rule reads (Eager Loading).