将类别设为私有并添加用户至特定访问组

That’s usually my preferred solution. But it probably makes more sense to pull a page from the bulk operations examples and apply the where clause on the User object in rails. (Having a test environment for a time like this helps!)