Hello,
Are the IOS switches configured for "command authorization"?
aaa authorization commands 0 default group tacacs+ local
aaa authorization commands 1 default group tacacs+ local
aaa authorization commands 15 default group tacacs+ local
Also, is the appropriate rule being matched on the ACS Access Policies?
Regards.