Has anyone done this ?
For Endevor controlled datasets I mean those libraries updated by Endevor processors at plus the the remote target libraries updated by Endevor shipment.
Yes, dataset security will ensure only Endevor updates these members but looking for belt and braces report of compromises !
PDSMAN can cut SMF updates at member name and report user but may not be useable for PDSE and may not report every kind of access ?
Reporting members without an Endevor footprint could be a check but not tell me the culprit plus valid pre-Endevor modules without footprints would appear as false exceptions ?