Discovery & Extraction • REXX collectors for TSS LIST / WHOOWNS / ACID extract ACIDs, DEPT/ZONE, resource rules (DATASET, FACILITY, LPA, APPL, DB2, CICS, TCP), ownership, and expiry details • Outputs TSS data (LIST/WHOOWNS/ACID) to a flat file Normalization & Mapping • Rule engine maps TSS to RACF: o ACID → USER/GROUP (DEPT/ZONE → RACF group hierarchy) o TSS PERMIT → RACF PERMIT (translates access levels; handles FORCE/INHIBIT) o FACILITY/RESOURCE → RACF CLASS (e.g., FACILITY(TSSCMD) → CLASS(FACILITY) PROFILE(TSSCMD)) Transformation Phase (TSS ➜ RACF) • Map zones/divisions/departments to RACF groups • Convert users and access levels to RACF USER/GROUP relationships • Map Control IDs to RACF attributes (SPECIAL, OPERATIONS) • Convert TSS resource rules to RACF classes/profiles with correct UACC and masking Command Generation & Load (TEST ➜ PROD) • Generates audited RACF commands (ADDUSER, RDEFINE, PERMIT, SETROPTS) with dry-run diffs Validation & Reports • Synthetic access tests simulate ACID access on mapped RACF profiles • Parity diff reports highlight missing profiles, UACC mismatches, excessive permits, and orphan users • Validates access and parity integrity ________________________________________ Benefits (with Metrics) • 85–95% faster migration (e.g., 20,000 permits in 3–5 days vs 4–6 weeks) • ≥99.9% rule parity with 0 Sev-1 authorization failures at cutover (SLO) • 50–70% reduction in over-permissive grants (tightened UACC, improved SoD compliance) • 30–45% reduction in effort/cost (minimal manual work, fewer dual-skilled SMEs) • Fully audit-ready: signed CSVs, command logs, parity and rollback packs