Skip to content
Security

Access level

How much a user may do to a resource: read it, change it, or control it, with each level including the ones below.

Also written UACC, universal access, READ UPDATE ALTER

Access is granted in levels, and they are cumulative: each includes everything the ones beneath it allow.

NONE means no access at all, and is the right default for anything sensitive. READ allows the data to be read but not changed. UPDATE allows records to be read and written, which is what an application needs to maintain a file. CONTROL grants more, needed for certain utility operations. ALTER is full control, including the ability to delete the dataset and change its security profile.

Choosing the right level is the everyday work of access management, and the principle is to grant the minimum that lets the job be done. A reporting job needs READ. Giving it UPDATE means a bug can corrupt production data. Giving it ALTER means a bug can delete it.

ALTER in particular is worth treating carefully, because it includes authority over the profile itself. Someone with it can change who else has access.

The same levels appear for other resource types, so the vocabulary carries across.

Browse all 115 terms

Learn this properly.

Use Access level for real in Mainframe101, in your browser, with Zed beside you. Join the waitlist.

Early access and updates. No spam, unsubscribe any time.