Authority
The Authority field specifies the public authority to the user profile.
- Add User prompt:
- Not shown
- CL parameter:
- AUT
The authority to a profile controls many functions associated
with the profile, such as:
- Changing the profile
- Displaying the profile
- Deleting the profile
- Submitting a job using the profile
- Specifying the profile in a job description
- Transferring object ownership to the profile
- Adding members, if the profile is a group profile
*EXCLUDE | The public is specifically denied access to the user profile. |
*ALL | The public is given all management and data authorities to the user profile. |
*CHANGE | The public is given the authority to change the user profile. |
*USE | The public is given authority to view the user profile. |
See Defining how information can be accessed for a complete explanation of the authorities that can be granted.
Recommendations: To prevent misuse of user profiles that have authority to critical objects, make sure the public authority to the profiles is *EXCLUDE. Possible misuses of a profile include submitting a job that runs under that user profile or changing a program to adopt the authority of that user profile.