Agent skill

Platform Dataspace Access Configure

by forcedotcom in forcedotcom/sf-skills

A skill your agent uses to configure or inspect Salesforce Data Cloud DataSpace access for permission sets.

Apache-2.0Auto-check passedSales & Support

Install Platform Dataspace Access Configure

skills CLI
$ npx skills add forcedotcom/sf-skills --skill platform-dataspace-access-configure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills platform-dataspace-access-configure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/platform-dataspace-access-configure .claude/skills/platform-dataspace-access-configure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
platform-dataspace-access-configure
GitHub stars
1.1k
Token cost
~4.7k tokens
SKILL.md length
1,653 words
Files
2 (incl. scripts)
Skills in repo
251
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses to configure or inspect Salesforce Data Cloud DataSpace access for permission sets.

  • Works in 2 steps: DataSpace-level access — grant a… → Object-level access (optional) — grant…
  • Inspect Salesforce Data Cloud DataSpace access for permission sets
  • SKILL.md covers Decide the Case First, When This Skill Owns the Task, Layer 1 — DataSpace-Level… and Read-Only DataSpace Scope…, plus 4 more sections
  • Runs Shell scripts from its folder; calls sf and jq; reaches soap.sforce.com

What it does

Platform Dataspace Access Configure is an agent skill from forcedotcom/sf-skills. Use this skill to configure or inspect Salesforce Data Cloud DataSpace access for permission sets. Grants dataspace-level access via MDAPI PermissionSet XML with dataspaceScopes elements, optionally grants object-level access to DMO, DLO, or CIO objects via the Object Access Grants Connect API, and inspects existing scopes via read-only PermissionSet metadata retrieval. TRIGGER when: user needs to create or update a permission set with DataSpace access, grant access to a specific dataspace, list permission sets…

Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/inspect-dataspace-scopes.sh`).

It sits in Sales & Support, covering CRM management, Authorization and RBAC and Data pipelines and ETL. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • Inspect Salesforce Data Cloud DataSpace access for permission sets
  • : user needs to create
  • Update a permission set with DataSpace access
  • Grant access to a specific dataspace

Example prompts

  • “/platform-dataspace-access-configure”

Requirements

  • A Bash shell

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. DataSpace-level access — grant a PermissionSet access to a DataSpace by embedding a element in the permission set XML and deploying via…
  2. Object-level access (optional) — grant that permission set access to specific DMO / DLO / CIO objects within the DataSpace using the…

What it can do on your machine

Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • sf
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • soap.sforce.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Platform Dataspace Access Configure loads about 4.7k tokens when it runs. Until then it costs about 247 tokens; SKILL.md has 1,653 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~247
When it runs · the whole SKILL.md, loaded when a task matches
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 1,653 words, ~4,719 tokens.

Download SKILL.mdSave it as .claude/skills/platform-dataspace-access-configure/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
platform-dataspace-access-configure
description
Use this skill to configure or inspect Salesforce Data Cloud DataSpace access for permission sets. Grants dataspace-level access via MDAPI PermissionSet XML with dataspaceScopes elements, optionally grants object-level access to DMO, DLO, or CIO objects via the Object Access Grants Connect API, and inspects existing scopes via read-only PermissionSet metadata retrieval. TRIGGER when: user needs to create or update a permission set with DataSpace access, grant access to a specific dataspace, list permission sets with access to a DataSpace, configure dataAccessLevel/objectAccessLevel, add RBAC object access grants, or list/remove object access grants for a permission set + DataSpace pair. DO NOT TRIGGER when: the task is a generic permission set without dataspace access (use platform-permission-set-generate), the request is about data ingestion/streams, or the work involves creating dataspaces themselves rather than granting access to them.
metadata.relatedSkills
platform-permission-set-generate
metadata.version
1.0
metadata.domains
Platform, Data 360
metadata.minApiVersion
67.0

platform-dataspace-access-configure

Configure DataSpace access in Salesforce Data Cloud using a two-layer model:

  1. DataSpace-level access — grant a PermissionSet access to a DataSpace by embedding a <dataspaceScopes> element in the permission set XML and deploying via MDAPI.
  2. Object-level access (optional) — grant that permission set access to specific DMO / DLO / CIO objects within the DataSpace using the Object Access Grants Connect API.

The MDAPI layer is required to establish the PermissionSet → DataSpace linkage. The Connect API layer is optional and only needed when access should be scoped to specific objects rather than governed entirely by data governance policies.


Decide the Case First

Pick exactly one case from the table below before writing any files. Each case has a different output shape.

CaseUser intentPermission set stateFiles to emit
A. Create new permset with DS access"create a permission set called X with dataspace scope Y"does NOT exist yetpermissionsets/<Name>.permissionset-meta.xml and package.xml
B. Add DS access to existing permset"grant existing permission set X access to dataspace Y"already deployed (may contain other permissions)patched permissionsets/<Name>.permissionset-meta.xml and package.xml — see Case B workflow below
C. Object-level grant only"grant permset X access to object Z (in dataspace Y)" — permset + scope already configuredalready deployed with dataspaceScopesapi-request.json (Connect API body). NO permission set XML, NO package.xml
D. Inspect existing DS access"which permission sets have access to dataspace Y?"anychat/report only. NO deployable files, NO runtime API mutation

Only emit the files listed for the case you picked. Emitting Case A/B files for a Case C prompt (or vice versa) is a correctness failure — extra files change the deployment shape.

Case B — critical: PermissionSet MDAPI deploy is a full metadata replace. Every <objectPermissions>, <fieldPermissions>, <userPermissions>, <tabSettings>, <applicationVisibilities>, <recordTypeVisibilities>, <customPermissions>, <pageAccesses>, <classAccesses>, <customMetadataTypeAccesses>, <customSettingAccesses>, <externalDataSourceAccesses> element you omit from the redeploy is deleted from the org. Before adding <dataspaceScopes> to an existing permset, retrieve the current XML and patch it — do not hand-author from scratch.

Case B workflow
  1. Retrieve the existing permission set:
    bash
    sf project retrieve start --metadata PermissionSet:<Name> --target-org <alias>
  2. Open the retrieved permissionsets/<Name>.permissionset-meta.xml. Keep every element already there.
  3. Insert the <dataspaceScopes> block for the target DataSpace (element order in the file does not matter for MDAPI). If the file already has a <dataspaceScopes> block for this same DataSpace, replace only that block. Leave every <dataspaceScopes> block for other DataSpaces untouched — one block per DataSpace. For a requested scope removal, remove only the matching block and deploy; omitting the block revokes that DataSpace grant. Verify by retrieving the PermissionSet and confirming the matching <dataspaceScopes> block is absent.
  4. Write package.xml listing the permset in <members>.
  5. Redeploy with sf project deploy start.

When This Skill Owns the Task

Trigger this skill when the user wants to:

  • Create a permission set that grants access to a Data Cloud DataSpace
  • Add or modify dataspaceScopes on an existing permission set
  • Grant a permission set access to specific DMO / DLO / CIO objects in a DataSpace
  • List which permission sets have a DataSpace scope and inspect its access levels
  • Configure dataAccessLevel and objectAccessLevel for a DataSpace scope
  • List or remove object access grants for a permission set + DataSpace pair

Delegate elsewhere when:

  • The permission set has no DataSpace access at all → platform-permission-set-generate

Layer 1 — DataSpace-Level Access (MDAPI)

Embed a <dataspaceScopes> element inside the PermissionSet XML. Deploy with MDAPI.

xml
<?xml version="1.0" encoding="UTF-8"?>
<PermissionSet xmlns="http://soap.sforce.com/2006/04/metadata">
    <label>Data Cloud Analyst</label>
    <description>Data cloud analyst access to the default dataspace</description>
    <hasActivationRequired>false</hasActivationRequired>
    <dataspaceScopes>
        <dataspaceScope>default</dataspaceScope>
        <dataAccessLevel>ALL</dataAccessLevel>
        <objectAccessLevel>BY_POLICY</objectAccessLevel>
    </dataspaceScopes>
</PermissionSet>
Element Rules
ElementRequiredValid ValuesPurpose
<dataspaceScopes>yesparent element (plural)Container for a single dataspace scope grant
<dataspaceScope>yesDataSpace API name (e.g. default)Which DataSpace this grant is for
<dataAccessLevel>yesNONE, CONTROLLED_BY_PARENT, ALLRow-level data access within the DataSpace
<objectAccessLevel>yesBY_POLICY, ALL_IN_DATASPACEObject-level access. BY_POLICY defers to data governance policies. ALL_IN_DATASPACE is only allowed when dataAccessLevel is CONTROLLED_BY_PARENT
Common Mistakes
  • Wrong parent name — using <dataspaceScopeAccess> instead of <dataspaceScopes>. Deployment fails silently or with cryptic errors.
  • Wrong child name — using <dataspaceScopeName> instead of <dataspaceScope>.
  • Wrong enum values — ViewAllRows / Read / OWNER / EDIT are not valid. Use NONE, CONTROLLED_BY_PARENT, or ALL for dataAccessLevel; use BY_POLICY or ALL_IN_DATASPACE for objectAccessLevel. See Element Rules table for allowed combinations. Deployment error -379999659 means invalid enum.
  • Multiple scopes in one element — <dataspaceScopes> grants access to exactly one DataSpace. To grant access to multiple, add multiple <dataspaceScopes> blocks.
Package Layout (Case A and Case B)

A deployable bundle for Layer 1 always contains both files:

text
<output-root>/
  package.xml
  permissionsets/<Name>.permissionset-meta.xml

package.xml (required — list every permission set being deployed in <members>):

xml
<?xml version="1.0" encoding="UTF-8"?>
<Package xmlns="http://soap.sforce.com/2006/04/metadata">
    <types>
        <members>Data_Cloud_Analyst</members>
        <name>PermissionSet</name>
    </types>
    <version>67.0</version>
</Package>

Deploy:

bash
sf project deploy start --source-dir force-app/main/default/permissionsets/ --target-org <alias>

Read-Only DataSpace Scope Inspection — Case D

Use Case D when the user asks which permission sets have access to a DataSpace, or asks to inspect dataAccessLevel and objectAccessLevel without making a change.

Never query DataspaceScope or DataspaceScopeAccess with SOQL. Those objects are not a supported query surface for this relationship. Do not try SOQL as discovery, fallback, or troubleshooting.

  1. Retrieve PermissionSet metadata into an isolated temporary local project and output directory. Do not retrieve into the user's existing metadata tree. Save the skill repository path first (as an absolute path if possible):
    bash
    REPO_ROOT="<absolute/path/to/sf-skills-internal>"  # or $(pwd) if you're in the repo root
    WORK_DIR=$(mktemp -d)
    sf project generate --name dataspace-scope-inspection --output-dir "$WORK_DIR"
    cd "$WORK_DIR/dataspace-scope-inspection"
     sf project retrieve start --json \
       --metadata "PermissionSet:*" --target-org <alias> \
       --output-dir "$WORK_DIR/retrieved"
    Inspect the JSON result before continuing. A nonzero command status, a failed result.status, warnings, or an unexpectedly low result.fileProperties count means the retrieve may be incomplete. Report that limitation rather than treating the result as empty, and do not fall back to SOQL.
  2. Run the inspection script from the skill directory (do not rely on relative paths after cd changed the working directory). Supply the retrieved directory and optional DataSpace name:
    bash
    "$REPO_ROOT/skills/platform-dataspace-access-configure/scripts/inspect-dataspace-scopes.sh" \
      "$WORK_DIR/retrieved" "<DataSpace API name, if given>"
    Report the output to the user, one result per line.

Case D is read-only with respect to the org. Do not deploy metadata, assign a permission set, execute Apex, perform record DML, or make a POST, PUT, PATCH, or DELETE request. Do not generate package.xml, PermissionSet XML, or api-request.json in the user's workspace as part of inspection. Remove the temporary work directory after reporting: rm -rf "$WORK_DIR". The scope-level objectAccessLevel is not an inventory of explicit object grants; inspect those separately with the read-only object-access-grants endpoint only when requested.


Layer 2 — Object-Level Access (Connect API) — Case C

Only needed when objectAccessLevel is not BY_POLICY, or when governance policies do not cover the target objects. Grants are runtime — no MDAPI deploy, no package.xml, no permission set XML. The only artifact for a Case C task is a single api-request.json describing the Connect API call.

Show full SKILL.md (695 more words)Show less
Resolve the API version first

Every Connect API endpoint in this layer contains an /services/data/v<apiVersion>/… segment. Do not hardcode v67.0. Resolve the target org's actual API version before writing the envelope so the request matches the org's supported surface:

bash
sf org display --target-org <alias> --json | jq -r '.result.apiVersion'
  • Substitute the returned value (e.g. 67.0, 68.0) into the endpoint as v<apiVersion>.
  • If the org can't be queried (offline authoring, no alias yet), fall back to the minApiVersion from this skill's frontmatter (67.0) — the endpoint was introduced there and any newer version accepts the same body.
  • If the user explicitly specifies a version in the prompt, use that verbatim.

In the templates below, {apiVersion} is a placeholder. Replace it with the resolved API version (e.g., 67.0, 68.0) before emitting api-request.json.

api-request.json — canonical shape

Emit the request as a self-describing envelope with method, endpoint, headers, body, and expectedResponse. Do NOT emit only the body — reviewers and downstream tooling read the envelope.

json
{
  "method": "POST",
  "endpoint": "/services/data/v{apiVersion}/ssot/data-governance/object-access-grants",
  "headers": {
    "Content-Type": "application/json"
  },
  "body": {
    "permissionSetName": "Data_Cloud_Analyst",
    "dataSpaceName": "default",
    "objectApiName": "Account__dlm"
  },
  "expectedResponse": {
    "status": 201,
    "body": {
      "permissionSetName": "Data_Cloud_Analyst",
      "dataSpaceName": "default",
      "objectApiName": "Account__dlm"
    }
  }
}
Bulk Grant

Same api-request.json envelope shape. endpoint gains the /actions/bulk-create suffix, body.objectApiName is replaced by the list-valued body.objectApiNames, and expectedResponse omits the body field because bulk responses return per-object status entries rather than the flat request payload (see Gotchas below).

json
{
  "method": "POST",
  "endpoint": "/services/data/v{apiVersion}/ssot/data-governance/object-access-grants/actions/bulk-create",
  "headers": {
    "Content-Type": "application/json"
  },
  "body": {
    "permissionSetName": "Data_Cloud_Analyst",
    "dataSpaceName": "default",
    "objectApiNames": ["Account__dlm", "Contact__dlm", "Opportunity__dlm"]
  },
  "expectedResponse": {
    "status": 201
  }
}
List Grants

Same envelope shape with method: "GET", query parameters on the endpoint, and no body.

json
{
  "method": "GET",
  "endpoint": "/services/data/v{apiVersion}/ssot/data-governance/object-access-grants?permissionSetName=Data_Cloud_Analyst&dataSpaceName=default",
  "headers": {
    "Accept": "application/json"
  },
  "expectedResponse": {
    "status": 200
  }
}
Revoke Grant

Same envelope shape with method: "DELETE", the object API name as a path segment, and expectedResponse.status: 204 (No Content).

json
{
  "method": "DELETE",
  "endpoint": "/services/data/v{apiVersion}/ssot/data-governance/object-access-grants/Account__dlm?permissionSetName=Data_Cloud_Analyst&dataSpaceName=default",
  "headers": {
    "Accept": "application/json"
  },
  "expectedResponse": {
    "status": 204
  }
}
Object Types
  • DMO (Data Model Object) — unified profile objects, suffix __dlm
  • DLO (Data Lake Object) — raw ingested data, suffix __dll
  • CIO (Calculated Insight Object) — computed metrics, suffix __cio

Combined Setup — Case A + Case C from a Cold Start

Use this section ONLY when the user is starting from nothing and asks for both the permset+scope AND per-object grants in a single request. If the user's prompt is only about the Connect API grant (Case C) — for example "grant Account__dlm access; the permset and dataspace scope already exist" — SKIP this section entirely and emit only api-request.json from Layer 2.

The commands below are operator-facing sf CLI invocations (a runnable cold-start walkthrough), NOT the artifact you emit. For a normal Case C task the artifact is a single api-request.json envelope as documented in Layer 2 above.

Goal: Grant Data_Cloud_Analyst permission set access to Account__dlm and Contact__dlm in the default DataSpace.

Step 1 — Deploy PermissionSet with DataSpace scope (MDAPI):

xml
<PermissionSet xmlns="http://soap.sforce.com/2006/04/metadata">
    <label>Data Cloud Analyst</label>
    <description>Data cloud analyst access to the default dataspace</description>
    <hasActivationRequired>false</hasActivationRequired>
    <dataspaceScopes>
        <dataspaceScope>default</dataspaceScope>
        <dataAccessLevel>ALL</dataAccessLevel>
        <objectAccessLevel>BY_POLICY</objectAccessLevel>
    </dataspaceScopes>
</PermissionSet>
bash
sf project deploy start --source-dir permissionsets/ --target-org <alias>

Step 2 — Grant object access (Connect API): (Required here because the default DataSpace has no governance policies covering Account__dlm and Contact__dlm. Skip Step 2 when BY_POLICY policies already govern the target objects — Layer 1 alone is sufficient.)

Resolve the org's API version first (see Resolve the API version first above), then substitute it into the --path value:

bash
API_VERSION=$(sf org display --target-org <alias> --json | jq -r '.result.apiVersion')

sf org api rest --target-org <alias> \
  --method POST \
  --path "/services/data/v${API_VERSION}/ssot/data-governance/object-access-grants/actions/bulk-create" \
  --body '{
    "permissionSetName": "Data_Cloud_Analyst",
    "dataSpaceName": "default",
    "objectApiNames": ["Account__dlm", "Contact__dlm"]
  }'

Step 3 — Verify:

bash
sf org api rest --target-org <alias> \
  --path "/services/data/v${API_VERSION}/ssot/data-governance/object-access-grants?permissionSetName=Data_Cloud_Analyst&dataSpaceName=default"

Rules and Constraints

RuleReason
Use <dataspaceScopes> (plural) as parent, <dataspaceScope> (singular) as childXML schema requirement; other names deploy-fail
dataAccessLevel values: NONE, CONTROLLED_BY_PARENT, ALL onlyOther values (e.g. OWNER, ViewAllRows) are rejected
objectAccessLevel values: BY_POLICY, ALL_IN_DATASPACE onlyOther values (e.g. READ, EDIT, Read) are rejected. ALL_IN_DATASPACE requires dataAccessLevel=CONTROLLED_BY_PARENT
Prefer BY_POLICY when data governance policies existDelegates row/column filtering to central policy — no per-object grants needed
One <dataspaceScopes> block per DataSpaceRepeat the block for multiple DataSpaces on the same permission set
Org must have Data Cloud provisioned to deploy <dataspaceScopes>On non-Data-Cloud orgs, the element is ignored or rejected
Do not query DataspaceScope / DataspaceScopeAccess via SOQLNot queryable; use Case D PermissionSet Metadata API retrieval to inspect existing scopes. Never use SOQL as a fallback.

Gotchas

IssueResolution
Deployment fails with error -379999659Check enum values — dataAccessLevel must be NONE/CONTROLLED_BY_PARENT/ALL; objectAccessLevel must be BY_POLICY/ALL_IN_DATASPACE
Permission set deploys but users still can't query DataSpace dataLayer 2 not applied — objects need explicit grants if objectAccessLevel != BY_POLICY
Bulk-create returns AlreadyExists for some objectsIdempotent — safe to retry; response shows per-object status
Connect API returns 404 for object grants endpointOrg lacks Data Cloud provisioning, or the resolved API version is below the minimum. The endpoint was introduced in v67.0 — re-run sf org display --json to confirm the org's apiVersion field is 67.0 or later, and substitute that value into the endpoint path
Retrieved PermissionSet XML shows different element names than deployedMetadata API sometimes echoes legacy names on retrieve — always author with current names

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills/platform-dataspace-access-configure of forcedotcom/sf-skills.

  • SKILL.md
  • scripts/inspect-dataspace-scopes.sh

Open the folder on GitHubat commit e5164d9

Compare with similar skills

Platform Dataspace Access Configure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Platform Dataspace Access Configure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Platform Dataspace Access Configure this skillforcedotcom/sf-skills1.1k—~4.7kAutomated safety check: PassApache-2.0
Salesforce Enterprise Rbacjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
SalesforceCraftOS-dev/CraftBot392—~2.9kAutomated safety check: PassMIT
Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib154—~4.3kAutomated safety check: PassMIT
Sf DatacloudJaganpro/sf-skills424—~2.7kAutomated safety check: PassMIT
Soql Lib Selectorbeyond-the-cloud-dev/soql-lib154—~2kAutomated safety check: PassMIT

Similar skills

  • Salesforce Enterprise Rbac

    jeremylongshore/tons-of-skills-marketplace

    Review and govern Salesforce enterprise access across profiles, permission sets and groups, sharing, field access, OAuth apps, SSO, and privileged roles.

    2.8k GitHub stars~1.1k tokensUpdated today
    Sales & SupportAuto-check passed
  • Salesforce

    CraftOS-dev/CraftBot

    Salesforce CRM API integration with managed OAuth. An agent skill from CraftOS-dev/CraftBot.

    392 GitHub stars~2.9k tokensUpdated yesterday
    Sales & SupportAuto-check passed
  • Soql Lib Query Builder

    beyond-the-cloud-dev/soql-lib

    Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).

    154 GitHub stars~4.3k tokensUpdated 5 days ago
    Sales & SupportAuto-check passed
  • Sf Datacloud

    Jaganpro/sf-skills

    Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.

    424 GitHub stars~2.7k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Soql Lib Selector

    beyond-the-cloud-dev/soql-lib

    Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.

    154 GitHub stars~2k tokensUpdated 5 days ago
    Sales & SupportAuto-check passed
  • Dev Setup

    Portwood-Global-Solutions/Portwood

    Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.

    125 GitHub stars~1.1k tokensUpdated today
    Sales & SupportAuto-check passed

More from forcedotcom/sf-skills

All 251 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated yesterday
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Platform Dataspace Access Configure

What does Platform Dataspace Access Configure do?

A skill your agent uses to configure or inspect Salesforce Data Cloud DataSpace access for permission sets. Platform Dataspace Access Configure is an agent skill from forcedotcom/sf-skills. Use this skill to configure or inspect Salesforce Data Cloud DataSpace access for permission sets.

When should I use Platform Dataspace Access Configure?

Platform Dataspace Access Configure fits situations like: inspect Salesforce Data Cloud DataSpace access for permission sets; : user needs to create; update a permission set with DataSpace access; grant access to a specific dataspace.

How do I install Platform Dataspace Access Configure in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill platform-dataspace-access-configure -a claude-code`. Or copy the skill folder (skills/platform-dataspace-access-configure in forcedotcom/sf-skills) into .claude/skills/platform-dataspace-access-configure in your project. Claude Code loads it when a task matches its description.

How do I install Platform Dataspace Access Configure in Codex?

Run `npx skills add forcedotcom/sf-skills --skill platform-dataspace-access-configure -a codex`. Or copy the skill folder (skills/platform-dataspace-access-configure in forcedotcom/sf-skills) into .agents/skills/platform-dataspace-access-configure in your project. Codex loads it when a task matches its description.

Can I use Platform Dataspace Access Configure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill platform-dataspace-access-configure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/platform-dataspace-access-configure, .gemini/skills/platform-dataspace-access-configure, .github/skills/platform-dataspace-access-configure and .opencode/skills/platform-dataspace-access-configure in your project.

What does Platform Dataspace Access Configure need to run?

Going by SKILL.md and its folder, Platform Dataspace Access Configure needs a shell for the scripts in its folder and the command-line tools its instructions call (sf and jq). Our summary lists: A Bash shell.

Does Platform Dataspace Access Configure access the network?

SKILL.md names 1 domain. In commands or code: soap.sforce.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Platform Dataspace Access Configure safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Platform Dataspace Access Configure use?

Platform Dataspace Access Configure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Platform Dataspace Access Configure use?

About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Platform Dataspace Access Configure?

Skills that share tags, products or a category with Platform Dataspace Access Configure: Salesforce Enterprise Rbac (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Salesforce (CraftOS-dev/CraftBot, 392 stars), Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars) and Sf Datacloud (Jaganpro/sf-skills, 424 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Platform Dataspace Access Configure?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.