RACF authority needed to perform DFSMShsm functions

DFSMShsm bypasses any security checking during automatic volume space management, automatic secondary space management, and availability management.

Undirected automatic recall is caused by reference from JCL, or under TSO, to a cataloged data set that is, in fact, migrated. In such a reference, the target volume is not specified. Once recall has occurred, standard RACF® protection applies through OPEN. Table 1 shows the authority needed by TSO users to issue DFSMShsm commands.

Table 1. RACF Authorization Required for DFSMShsm Functions
  DFSMShsm Function RACF Resource Access Authority Required
Migrate a data set UPDATE
Recall a data set EXECUTE
Delete a migrated data set ALTER
Back up a data set UPDATE
Recover a backup version without specifying NEWNAME ALTER
Recover a backup version and specify NEWNAME READ to original data set; ALTER on the NEWNAME
Delete a backup version ALTER
Change backup characteristics ALTER
Aggregate backup READ
Special considerations apply to the TSO user commands HBDELETE (to delete backup versions) and HALTERDS (to modify backup characteristics):