Mainframe Path Start learning free
Core7 min readLesson 1 of 3

Users, groups and profiles

The security manager holds three things: who you are, which groups you belong to, and what rules protect each resource. An access decision is the intersection of those three.

The three building blocks

How an access decision is assembled
UserA userid, with segments describing what it can do (TSO, OMVS, CICS)
GroupsCollections of users; access is nearly always granted to groups
ProfileA rule protecting a resource, with an access list and a default

Profiles: discrete and generic

KindExampleProtects
DiscretePROD.PAY.MASTERExactly that one dataset
GenericPROD.PAY.*Everything one level below PROD.PAY
GenericPROD.**Everything under PROD at any depth

When several profiles could apply, the most specific match wins. This is why adding a narrow profile can unexpectedly remove access that a broad one was granting — the narrow one now governs, and it has its own access list.

Access levels

LevelAllows
NONENothing
EXECUTERun a program from a library, without reading it
READRead
UPDATERead and write existing data
CONTROLUpdate plus certain VSAM operations
ALTEREverything, including delete and changing the profile

Classes: not everything is a dataset

ClassProtects
DATASETDatasets
FACILITYSystem functions and product-specific permissions
TSOPROC / ACCTNUMWhat you may use at TSO logon
OPERCMDSOperator commands
SURROGATSubmitting work as another userid
GCICSTRN / TCICSTRNCICS transactions
DSNRDB2 subsystem access
UNIXPRIV / FSACCESSz/OS Unix privileges and file systems

Segments on a userid

A userid is not just a name and a password. It carries segments describing what it can do in each environment: a TSO segment with a logon procedure and region size, an OMVS segment with a UID and home directory, a CICS segment with operator details. A missing segment is the cause of many 'I cannot log on to X' problems, and it is a quick fix once identified.

Common mistakes

Requesting access for a userid instead of a group

Individual permits do not survive staff changes and become a compliance problem. Ask to be added to the right group.

Assuming a broad profile always applies

The most specific matching profile governs. A new narrow profile can silently override a broad grant.

Creating a profile with a permissive UACC

UACC applies to everyone. Start at NONE and permit deliberately.

What you will see at work

Key terms

Check your understanding.
Take this lesson's quiz and save your progress. Free.

Take the lesson quiz
Reading a violation and asking for the right thing →