IBM i Security in 2026: User Profiles, Object Authority, Adopted Authority, and Practical Security Patterns
IBM i security is object-based and OS-enforced — bypassing the application does not bypass security. This post covers QSECURITY levels, user profiles and special authorities, object authority and the authority checking sequence, adopted authority for controlled privilege elevation, group profiles, authorisation lists, QAUDJRN audit journalling, Row and Column Access Control (RCAC), and the practical patterns IBM i shops use to maintain least-privilege configurations.