I think the pattern that needs to be explored is a rails engine that has a web interface to manage permissions for different models. Usually stakeholders want to control the roles and permissions.
We were recently working on designing a moderately complicated permissions system, and my impression is that it's impossible to create such a general-purpose engine and gem that covers enough of the cases that you'll have to manage, without creating something that is incredibly complicated to set up and manage. Except for a few standardized domains, you'll always have rules that are easier to express and maintain with some custom, domain-specific code.
Neat idea, you might be able to quickly throw together a really compelling proof-of-concept by building off of https://github.com/RolifyCommunity/rolify, which seems to strike a nice balance of opinionated, flexible, and doing a fair amount of work for you (IE it gets involved in / takes care of the db data modeling).
Interesting, this is very project specific so might be tough to implement for general user-base.