Agent skill

Platform Sharing Owd Configure

by forcedotcom in forcedotcom/sf-skills

A skill your agent uses when the user wants to retrieve or update Organization-Wide Default (OWD) sharing settings for Salesforce objects.

Apache-2.0Auto-check passedSales & Support

Install Platform Sharing Owd Configure

skills CLI
$ npx skills add forcedotcom/sf-skills --skill platform-sharing-owd-configure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills platform-sharing-owd-configure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/platform-sharing-owd-configure .claude/skills/platform-sharing-owd-configure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
platform-sharing-owd-configure
GitHub stars
1.1k
Token cost
~2.2k tokens
SKILL.md length
1,027 words
Files
5 (incl. references)
Skills in repo
251
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user wants to retrieve or update Organization-Wide Default (OWD) sharing settings for Salesforce objects.

  • Works in 2 steps: Retrieve Current Settings → Update Settings (if requested)
  • The user wants to retrieve
  • SKILL.md covers Scope, Clarifying Questions, Required Inputs and Workflow, plus 5 more sections
  • Calls sf

What it does

Platform Sharing Owd Configure is an agent skill from forcedotcom/sf-skills. Use when the user wants to retrieve or update Organization-Wide Default (OWD) sharing settings for Salesforce objects. TRIGGER on org-wide defaults, checking/viewing sharing defaults, changing default access levels (Private, Public Read Only, Public Read/Write, Controlled by Parent), internal/external access for standard or custom objects, making records private, or sharingModel in .object-meta.xml files. DO NOT TRIGGER for sharing rules, criteria-based sharing, role hierarchy, or manual sharing — delegate to…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `examples/get_owd_output.md`, `examples/update_owd_output.md` and `references/access_levels.md`).

It sits in Sales & Support, covering CRM management. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • The user wants to retrieve
  • Update Organization-Wide Default (OWD) sharing settings for Salesforce objects
  • Org-wide defaults
  • Checking/viewing sharing defaults

Example prompts

  • “/platform-sharing-owd-configure”

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Retrieve Current Settings
  2. Update Settings (if requested)

What it can do on your machine

Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • sf

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Platform Sharing Owd Configure loads about 2.2k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 145 tokens; SKILL.md has 1,027 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~145
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 1,027 words, ~2,241 tokens.

Download SKILL.mdSave it as .claude/skills/platform-sharing-owd-configure/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
platform-sharing-owd-configure
description
Use when the user wants to retrieve or update Organization-Wide Default (OWD) sharing settings for Salesforce objects. TRIGGER on org-wide defaults, checking/viewing sharing defaults, changing default access levels (Private, Public Read Only, Public Read/Write, Controlled by Parent), internal/external access for standard or custom objects, making records private, or sharingModel in .object-meta.xml files. DO NOT TRIGGER for sharing rules, criteria-based sharing, role hierarchy, or manual sharing — delegate to platform-sharing-rules-generate.
metadata.relatedSkills
platform-metadata-deploy, platform-sharing-rules-generate
metadata.version
1.2
metadata.domains
Platform

Managing Org-Wide Defaults

Retrieve and update Organization-Wide Default (OWD) sharing settings for standard and custom objects in a Salesforce org. OWDs define the baseline level of access users have to records they do not own.

Scope

  • In scope: Retrieving current OWD settings, updating internal/external access levels for standard and custom objects
  • Out of scope: Sharing rules, role hierarchy configuration, manual sharing, permission sets, criteria-based sharing — delegate to appropriate skills

Clarifying Questions

Before proceeding, confirm with the user if not already clear:

  • Which object(s) do you want to get or update OWD settings for?
  • What access level do you want to set? (Private, Public Read Only, Public Read/Write, Controlled by Parent)
  • Do you need to change both internal and external access, or just one?

Required Inputs

Gather or infer before proceeding:

  • Target org: The org alias or username to query/update (use default org if not specified)
  • Object name(s): Standard object API name (e.g., Account, Contact) or custom object API name (e.g., Invoice__c)
  • Operation: Get (retrieve current settings) or Update (change access levels)
  • Access levels (for update): Internal access and/or external access values

Defaults unless specified:

  • Use the default connected org
  • If only one access level is provided, assume it applies to internal access

Workflow

All steps are sequential. Do not skip or reorder.

Phase 1 — Retrieve Current Settings
  1. Query current OWD settings using the Salesforce CLI Tooling API: sf data query --query "SELECT QualifiedApiName, InternalSharingModel, ExternalSharingModel FROM EntityDefinition WHERE QualifiedApiName = '<ObjectName>'" --use-tooling-api --target-org <org>

  2. For retrieving all OWD settings at once: sf data query --query "SELECT QualifiedApiName, InternalSharingModel, ExternalSharingModel FROM EntityDefinition WHERE IsCustomizable = true ORDER BY QualifiedApiName" --use-tooling-api --target-org <org>

  3. Present results clearly — read references/access_levels.md for valid values and display a formatted table to the user.

Phase 2 — Update Settings (if requested)
  1. Check for immutable/fixed OWD — read references/access_levels.md "Immutable / Fixed OWD Objects" section. If the requested change targets a fixed value (e.g., Price Book external OWD), stop immediately and explain to the user that this value is platform-fixed and cannot be changed by any means. Do not attempt a deploy.

  2. Validate the requested access level — read references/access_levels.md to confirm the value is valid for the target object. If the value is not in the allowed set for that object, explain what values are valid and ask the user to choose one. Do not guess alternative values.

  3. Retrieve the object metadata using the Metadata API (same command for both standard and custom objects): sf project retrieve start --metadata CustomObject:<ObjectName> --target-org <org>. This retrieves <ObjectName>.object-meta.xml containing <sharingModel> and <externalSharingModel>. See references/metadata_api_approach.md for the full procedure.

  4. Modify the sharing settings — update the <sharingModel> (internal access) and/or <externalSharingModel> (external access) in the object's .object-meta.xml. Read references/metadata_api_approach.md for details.

  5. Pre-deploy verification — before deploying, confirm:

    • External access is not more permissive than internal access
    • Objects with Master-Detail relationships use ControlledByParent
    • The requested access level is valid for the target object (see references/access_levels.md)
    • Cross-object constraints are satisfied (see "Cross-Object Constraints" in references/access_levels.md)
    • The target field is not listed as immutable/fixed in references/access_levels.md
  6. Deploy the updated settings: sf project deploy start --metadata CustomObject:<ObjectName> --target-org <org>.

  7. Handle deploy failure (max 2 attempts): If the deploy fails:

    • Read the error message and identify the root cause.
    • If the error indicates the value is invalid or unsupported for the object, stop — report the failure to the user with the exact error message and explain what is and isn't possible. Do not try alternative values unless the user explicitly requests a different valid value.
    • If the error is transient (network timeout, auth expired), retry once.
    • Never attempt more than 2 total deploys for the same change. After 2 failures, report the error, discard local edits (sf project retrieve start --metadata CustomObject:<ObjectName> --target-org <org>), and ask the user how to proceed.
  8. Verify the change by re-running the query from Phase 1, Step 1.


Show full SKILL.md (387 more words)Show less

Rules / Constraints

ConstraintRationale
Objects with Master-Detail relationships must use ControlledByParentPlatform enforces this — attempting other values fails
External access cannot be more permissive than internal accessSalesforce rejects configurations where external > internal
Some objects have immutable/fixed OWD (e.g., Price Book external, User, Activity external)These are platform-enforced — explain impossibility upfront, never attempt a deploy
Price Book only accepts Use (ReadSelect) or No Access (None) for internal OWD; external is always NoneStandard access levels (Private/Read/ReadWrite) are invalid for Price Book
Changing OWD to more restrictive triggers sharing recalculationThis can take significant time on large orgs — warn the user
Custom objects default to Public Read/Write when createdUsers may not realize the default is permissive
For managed package custom objects, use the full API name including namespace prefix (e.g., ns__Object__c)Namespace-prefixed objects require the prefix in both queries and metadata retrieval
Always verify the org connection before queryingPrevents confusing error messages
Maximum 2 deploy attempts per changePrevents unbounded retry loops — after 2 failures, stop and report to the user

Gotchas

IssueResolution
INSUFFICIENT_ACCESS error when updatingUser needs Manage Sharing permission or System Administrator profile
OWD change appears stuckSharing recalculation is running — check Setup > Sharing Settings for progress
Custom object not found in queryUse the full API name including __c suffix
ControlledByParent not availableObject has no Master-Detail relationship — use Private, Public Read Only, or Public Read/Write
External access field not showingExternal sharing model only appears when external org-wide defaults are enabled
Query returns no resultsObject may not be customizable or API name may be incorrect — verify spelling
Deploy fails with invalid value for Price BookPrice Book only accepts Use/None (internal) and external is fixed at None — do not retry with other values, explain to user

Output Expectations

Deliverables:

  • For get operations: Formatted table showing object name, internal access level, and external access level
  • For update operations: Confirmation of the change with before/after comparison

Cross-Skill Integration

NeedDelegate to
Creating sharing rules after restricting OWDplatform-sharing-rules-generate skill
Deploying metadata changes to another orgplatform-metadata-deploy skill

Reference File Index

FileWhen to read
references/access_levels.mdWhen validating or explaining OWD access level values
references/metadata_api_approach.mdWhen using Metadata API to update OWD instead of Tooling API
examples/get_owd_output.mdTo verify formatted output matches expected structure
examples/update_owd_output.mdTo verify update confirmation matches expected structure

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/platform-sharing-owd-configure of forcedotcom/sf-skills.

  • SKILL.md
  • examples/get_owd_output.md
  • examples/update_owd_output.md
  • references/access_levels.md
  • references/metadata_api_approach.md

Open the folder on GitHubat commit e5164d9

Compare with similar skills

Platform Sharing Owd Configure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Platform Sharing Owd Configure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Platform Sharing Owd Configure this skillforcedotcom/sf-skills1.1k—~2.2kAutomated safety check: PassApache-2.0
Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib154—~4.3kAutomated safety check: PassMIT
Sf DatacloudJaganpro/sf-skills424—~2.7kAutomated safety check: PassMIT
Soql Lib Selectorbeyond-the-cloud-dev/soql-lib154—~2kAutomated safety check: PassMIT
Dev SetupPortwood-Global-Solutions/Portwood125—~1.1kAutomated safety check: PassApache-2.0
Sf FlowJaganpro/sf-skills424—~1.8kAutomated safety check: PassMIT

Similar skills

  • Soql Lib Query Builder

    beyond-the-cloud-dev/soql-lib

    Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).

    154 GitHub stars~4.3k tokensUpdated 5 days ago
    Sales & SupportAuto-check passed
  • Sf Datacloud

    Jaganpro/sf-skills

    Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.

    424 GitHub stars~2.7k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Soql Lib Selector

    beyond-the-cloud-dev/soql-lib

    Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.

    154 GitHub stars~2k tokensUpdated 5 days ago
    Sales & SupportAuto-check passed
  • Dev Setup

    Portwood-Global-Solutions/Portwood

    Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.

    125 GitHub stars~1.1k tokensUpdated today
    Sales & SupportAuto-check passed
  • Sf Flow

    Jaganpro/sf-skills

    Creates and validates Salesforce Flows with 110-point scoring.

    424 GitHub stars~1.8k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Google Maps Export

    gmapsscraper/google-maps-agent-skills

    Export Google Maps business data to CSV, JSON, or CRM format (HubSpot, Pipedrive, Salesforce).

    132 GitHub stars~1.2k tokensUpdated 4 mo ago
    Sales & SupportAuto-check passed

More from forcedotcom/sf-skills

All 251 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated yesterday
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Platform Sharing Owd Configure

What does Platform Sharing Owd Configure do?

A skill your agent uses when the user wants to retrieve or update Organization-Wide Default (OWD) sharing settings for Salesforce objects. Platform Sharing Owd Configure is an agent skill from forcedotcom/sf-skills. Use when the user wants to retrieve or update Organization-Wide Default (OWD) sharing settings for Salesforce objects.

When should I use Platform Sharing Owd Configure?

Platform Sharing Owd Configure fits situations like: the user wants to retrieve; update Organization-Wide Default (OWD) sharing settings for Salesforce objects; org-wide defaults; checking/viewing sharing defaults.

How do I install Platform Sharing Owd Configure in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill platform-sharing-owd-configure -a claude-code`. Or copy the skill folder (skills/platform-sharing-owd-configure in forcedotcom/sf-skills) into .claude/skills/platform-sharing-owd-configure in your project. Claude Code loads it when a task matches its description.

How do I install Platform Sharing Owd Configure in Codex?

Run `npx skills add forcedotcom/sf-skills --skill platform-sharing-owd-configure -a codex`. Or copy the skill folder (skills/platform-sharing-owd-configure in forcedotcom/sf-skills) into .agents/skills/platform-sharing-owd-configure in your project. Codex loads it when a task matches its description.

Can I use Platform Sharing Owd Configure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill platform-sharing-owd-configure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/platform-sharing-owd-configure, .gemini/skills/platform-sharing-owd-configure, .github/skills/platform-sharing-owd-configure and .opencode/skills/platform-sharing-owd-configure in your project.

What does Platform Sharing Owd Configure need to run?

Going by SKILL.md and its folder, Platform Sharing Owd Configure needs the command-line tools its instructions call (sf).

Does Platform Sharing Owd Configure access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Platform Sharing Owd Configure safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Platform Sharing Owd Configure use?

Platform Sharing Owd Configure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Platform Sharing Owd Configure use?

About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Platform Sharing Owd Configure?

Skills that share tags, products or a category with Platform Sharing Owd Configure: Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars), Sf Datacloud (Jaganpro/sf-skills, 424 stars), Soql Lib Selector (beyond-the-cloud-dev/soql-lib, 154 stars) and Dev Setup (Portwood-Global-Solutions/Portwood, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Platform Sharing Owd Configure?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.