ROLES Subcommand

The ROLES subcommand lists the active roles a the specified logonid record.
acf2src
The ROLES subcommand lists the active roles a the specified logonid record. The results are based on the active X(ROL) XREF structure in storage. X-ROL records assign users to roles and assign access based on the roles. Use the ROLES subcommand to verify if a logonid has the correct roles assigned.
ROLES *|logonid
You can issue the ROLES subcommand under any setting of the ACF command.
  • ROLES *
    Indicates a list of roles for the last listed, changed, or inserted active logonid. If there is no active logonid, then ROLES * lists your roles. Since X(ROL) records can contain masked logonids, the ROLES subcommand does not check if the logonid you specified actually exists. Therefore, it is possible to list roles for a logonid you have not yet inserted.
  • ROLES logonid
    Lists the active roles for the specified logonid.
Example: Verify assigned roles
As a security administrator, you want to verify what roles are associated with logonid USER01A:
ACF ROLES USER01A
ROLES FOR USER01A
AROLC AROLD AROLE ZROLC ZROLD ZROLE AROLB ZROLB AROLA ZROLA
In this example, ten roles are associated with USER01A logonid.