PERMIT
The command that grants or removes a user or group's access to a protected resource.
Also written PE, grant access
PERMIT is the RACF command that changes an access list. It names the profile, the user or group, and the level being granted, or removes an entry entirely.
In practice it is almost always aimed at a group rather than a person. Permitting a group and connecting people to it is the pattern that keeps access manageable; permitting individuals directly produces access lists that nobody can later interpret or safely clean up.
Changes do not always take effect immediately. Profiles that have been loaded into memory for performance need to be refreshed before the system notices, which is a classic cause of "I have been given access but it still will not let me in".
Requests to run it usually go through a process rather than being issued ad hoc, with an approval trail, because it is the point at which someone gains the ability to see or change data.
Alongside it sit the commands to list a profile and see who currently has access, which is what you use to answer why something is or is not permitted.
Related terms
- RACFThe security manager for z/OS, which decides who may sign on, read a dataset, or run a transaction.
- Access levelHow much a user may do to a resource: read it, change it, or control it, with each level including the ones below.
- Dataset profileA security rule describing which datasets it covers and who is allowed to do what to them.
- RACF groupA named collection of users, used to grant access to many people at once rather than one at a time.
- Change controlThe process every change goes through before reaching production: reviewed, approved, scheduled and reversible.