Skip to content
Security

SAF

The interface z/OS and its subsystems use to ask the security manager whether something is allowed.

Also written System Authorization Facility

SAF, the System Authorization Facility, is the standard interface through which security questions are asked on z/OS. When a component needs to know whether a request is permitted, it calls SAF, and SAF passes the question to whichever security manager is installed.

That indirection is why the platform can support RACF, ACF2 and Top Secret interchangeably. Applications and subsystems are written against SAF, not against a particular product, so a site can run any of them and everything above continues to work.

It also means security is centralised in one place. z/OS itself, CICS, DB2, the job entry subsystem, file transfer services and site-written applications all ask the same question through the same interface and get an answer from the same database. There is one place where the rules live, and one place to audit.

Application programs can call it too, which is how a site-written system checks whether a user is allowed to perform a business function using the same identity and rules as everything else, rather than inventing its own permissions.

Browse all 115 terms

Learn this properly.

Use SAF for real in Mainframe101, in your browser, with Zed beside you. Join the waitlist.

Early access and updates. No spam, unsubscribe any time.