Skip to content
Security

RACF group

A named collection of users, used to grant access to many people at once rather than one at a time.

Also written group, connect

Groups are how mainframe security stays manageable. Rather than listing every individual against every resource, access is granted to a group, and users are connected to the group.

The practical effect is that access follows roles. There might be a group for the payments development team, another for its testers, another for production support. Each is permitted to the datasets and transactions that role needs. Joining the team means being connected to the group; leaving means being removed, and the access disappears in one action.

Groups are arranged in a hierarchy, with authority able to be delegated downwards. That allows a team leader to be made responsible for managing membership of their own group without being given authority over the whole system, which is how large organisations distribute administration safely.

Groups can also own resources, so a dataset can belong to a team rather than a person and survive that person leaving.

When you cannot access something you expect to, the usual answer is that you are not connected to the right group.

Browse all 115 terms

Learn this properly.

Use RACF group for real in Mainframe101, in your browser, with Zed beside you. Join the waitlist.

Early access and updates. No spam, unsubscribe any time.