SAF
The interface z/OS and its subsystems use to ask the security manager whether something is allowed.
Also written System Authorization Facility
SAF, the System Authorization Facility, is the standard interface through which security questions are asked on z/OS. When a component needs to know whether a request is permitted, it calls SAF, and SAF passes the question to whichever security manager is installed.
That indirection is why the platform can support RACF, ACF2 and Top Secret interchangeably. Applications and subsystems are written against SAF, not against a particular product, so a site can run any of them and everything above continues to work.
It also means security is centralised in one place. z/OS itself, CICS, DB2, the job entry subsystem, file transfer services and site-written applications all ask the same question through the same interface and get an answer from the same database. There is one place where the rules live, and one place to audit.
Application programs can call it too, which is how a site-written system checks whether a user is allowed to perform a business function using the same identity and rules as everything else, rather than inventing its own permissions.
Related terms
- RACFThe security manager for z/OS, which decides who may sign on, read a dataset, or run a transaction.
- Access levelHow much a user may do to a resource: read it, change it, or control it, with each level including the ones below.
- SubsystemA major piece of software running under z/OS that provides a service to applications, such as a database or a transaction manager.
- z/OSThe main operating system that runs on IBM mainframes, in the same way Windows or Linux runs on a laptop or server.
- Dataset profileA security rule describing which datasets it covers and who is allowed to do what to them.