extract policy helper to turn signed_in? && (question.user == current_user || current_user.admin?) into can_modify?(question)