System, Jobs, and Messages
Read bounded system values, inspect scoped jobs and logs, and work with assigned message queues using typed operations.

Managed browser access for IBM i applications
Scoped operations beside the terminal
PristineScreen400 provides a fixed catalog of typed IBM i capabilities. Administrators assign panels, operations, approvals, risk ceilings, and resource scopes to an exact application user and IBM i identity grant.
Direct answer
The browser cannot call JTOpen directly or submit an arbitrary command or SQL string. It invokes only compiled capability identifiers through a workspace owned by the authenticated user. The server rechecks the grant, capability assignment, risk policy, resource scope, approval, and current workspace state.
Capability surfaces
Availability depends on deployment ceilings and exact grant assignments. A panel label does not imply unrestricted system authority.
Read bounded system values, inspect scoped jobs and logs, and work with assigned message queues using typed operations.
List, preview, download, hold, release, move, or delete output only within assigned owner and output-queue scope.
Use closed read or approved mutation contracts with path, schema, table, queue, row, byte, and timeout limits.
Inspect scoped objects and run only application-registered command, program, SQL, or service-program workflows.
Expose approved security reads and changes under explicit risk and approval policy rather than raw system access.
Keep terminal and operation activity tied to the current owner, grant, workspace, revision, and sanitized outcome.
Effective assignment
Frequently asked questions
No. Only registered, typed application capabilities are available. Caller-supplied command strings, arbitrary SQL, connector objects, and target controls are not browser contracts.
Yes. Assignment policy can require approval, and the server checks that policy again when the operation is invoked.
No. The deployment has a compiled capability allow-list and maximum risk ceiling, then each grant receives explicit assignments and scopes.
Start with required operations
A capability review maps required reads and changes to risk, approval, and resource scope before access is assigned.
Review capability fit