The operation being authorized. Borrows so Custom carries a handler’s
&str name without allocating; it’s Copy, and the lifetime elides to
Action<'_> at every call site.
A pluggable authorization policy. can is synchronous and called several
times per request, so an implementation must not perform I/O here — a
DB-backed one reads a pre-loaded in-memory cache.