classAbilityincludeCanCan::Abilitydefinitialize(user)@user=user||User.new# for guest@user.roles.each{|role|send(role)}if@user.roles.size==0can:read,:all#for guest without rolesendenddefmanagercan:manage,Employeeenddefadminmanagercan:manage,Billendend