TSRACCESS=RO

An LDS-backed VTS may also be configured with TSRACCESS=RO to support VTSManager alias switching. The same foundational RACF setup applies: a profile must be defined, CONTROL-level access is required to start the VTS or obtain full access, and consistent RACF definitions are needed for both true and alias names. VTSManager command boundaries and tableBASE privilege enforcement apply identically to this configuration as they do under TSRACCESS=RF.

Behaviorally, a VTS under TSRACCESS=RO is fully read-only. Any update
commands such as IK or RK will fail with error 13-6, even when the issuing user holds RACF
WRITE privileges.