Each OAuth client ID maps to a specific RACF user ID. Most granular but most administrative overhead. - **Role-based mapping** — OAuth token claims include a role (e.g., `read-only`, `read-write`, `admin`). Each role maps to a RACF user ID with appropriate permissions. - **Client certificate mapping