Users, groups and profiles
The security manager holds three things: who you are, which groups you belong to, and what rules protect each resource. An access decision is the intersection of those three.
The three building blocks
Profiles: discrete and generic
| Kind | Example | Protects |
|---|---|---|
| Discrete | PROD.PAY.MASTER | Exactly that one dataset |
| Generic | PROD.PAY.* | Everything one level below PROD.PAY |
| Generic | PROD.** | Everything under PROD at any depth |
When several profiles could apply, the most specific match wins. This is why adding a narrow profile can unexpectedly remove access that a broad one was granting — the narrow one now governs, and it has its own access list.
Access levels
| Level | Allows |
|---|---|
| NONE | Nothing |
| EXECUTE | Run a program from a library, without reading it |
| READ | Read |
| UPDATE | Read and write existing data |
| CONTROL | Update plus certain VSAM operations |
| ALTER | Everything, including delete and changing the profile |
Classes: not everything is a dataset
| Class | Protects |
|---|---|
| DATASET | Datasets |
| FACILITY | System functions and product-specific permissions |
| TSOPROC / ACCTNUM | What you may use at TSO logon |
| OPERCMDS | Operator commands |
| SURROGAT | Submitting work as another userid |
| GCICSTRN / TCICSTRN | CICS transactions |
| DSNR | DB2 subsystem access |
| UNIXPRIV / FSACCESS | z/OS Unix privileges and file systems |
Segments on a userid
A userid is not just a name and a password. It carries segments describing what it can do in each environment: a TSO segment with a logon procedure and region size, an OMVS segment with a UID and home directory, a CICS segment with operator details. A missing segment is the cause of many 'I cannot log on to X' problems, and it is a quick fix once identified.
Common mistakes
Individual permits do not survive staff changes and become a compliance problem. Ask to be added to the right group.
The most specific matching profile governs. A new narrow profile can silently override a broad grant.
UACC applies to everyone. Start at NONE and permit deliberately.
What you will see at work
- Access requests go through a process with an approver. Learn it in week one; you will use it constantly.
- Group names usually encode application and function, which makes it possible to guess which group you need — then confirm before requesting.
- Production access is normally read-only for developers, with changes made through a controlled process. That is a feature, not an obstacle.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.