Dataset profile
A security rule describing which datasets it covers and who is allowed to do what to them.
Also written generic profile, discrete profile, profile
A dataset profile is the record in the security database that protects data. It names a pattern of dataset names, sets a default level of access for everyone, and carries a list of users and groups with specific permissions.
Profiles come in two forms. A discrete profile protects one named dataset exactly. A generic profile uses wildcards to cover a whole family of names at once, which is why naming conventions matter so much. A single profile written against a high-level qualifier and a pattern can protect thousands of datasets, including ones created tomorrow.
When a dataset is accessed, the system finds the most specific profile matching its name and checks that. More specific always wins, so a general rule for an application can be overridden by a tighter one for particular datasets within it.
The universal access setting on the profile is the level granted to anyone not otherwise listed, and setting it to none, meaning no access unless explicitly permitted, is the standard safe default.
Related terms
- RACFThe security manager for z/OS, which decides who may sign on, read a dataset, or run a transaction.
- High-level qualifierThe first part of a dataset name, which usually identifies the owner and drives how security and storage rules apply.
- Access levelHow much a user may do to a resource: read it, change it, or control it, with each level including the ones below.
- PERMITThe command that grants or removes a user or group's access to a protected resource.
- Dataset nameThe full name of a dataset, written as dot-separated qualifiers of up to eight characters each.