RACF user ID
A person or program's identity on the system. Short, unique, and the basis of every access decision.
Also written user ID, userid, TSO ID
A user ID identifies who is making a request. It is up to eight characters, uppercase, and unique on that system.
Everything a user can do follows from it. When you log on, RACF verifies your password or password phrase and establishes your identity for the session. From then on, every access check is made against that identity and the groups it belongs to.
User IDs are not only for people. Started tasks and batch jobs run under one too, so a service can be given exactly the access it needs and no more, an important control, since a production job with excessive access is a real risk.
Each user has a default group, which affects what happens by default when they create resources, and can be connected to many others.
Some IDs carry special attributes granting broad authority across the system. Those are tightly controlled and audited, because an ID with system-wide authority can bypass ordinary checks entirely. Sites keep the number of them small deliberately.
Related terms
- RACFThe security manager for z/OS, which decides who may sign on, read a dataset, or run a transaction.
- RACF groupA named collection of users, used to grant access to many people at once rather than one at a time.
- LogonSigning on to a mainframe system with a user ID and password to start an interactive session.
- Access levelHow much a user may do to a resource: read it, change it, or control it, with each level including the ones below.
- PERMITThe command that grants or removes a user or group's access to a protected resource.