Salesforce Policy Guardrails
jeremylongshore/tons-of-skills-marketplace
Gate Salesforce code and configuration for SOQL injection, secret exposure, unsafe API versions, missing access checks, destructive writes, and unreviewed org changes.
Agent skill
Grant a user the runtime permissions an activated ITSM agent's actions need so the actions do not fail on permission errors.
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-agent-runtime-access-assign -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-agent-runtime-access-assign --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/service-itsm-agentic-setup-agent-runtime-access-assign .claude/skills/service-itsm-agentic-setup-agent-runtime-access-assign && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "service-itsm-agentic-setup-agent-runtime-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-agent-runtime-access-assign into .claude/skills/service-itsm-agentic-setup-agent-runtime-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-agent-runtime-access-assign", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-agent-runtime-access-assignType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-agent-runtime-access-assign -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-agent-runtime-access-assign --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/service-itsm-agentic-setup-agent-runtime-access-assign .agents/skills/service-itsm-agentic-setup-agent-runtime-access-assign && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "service-itsm-agentic-setup-agent-runtime-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-agent-runtime-access-assign into .agents/skills/service-itsm-agentic-setup-agent-runtime-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-agent-runtime-access-assign", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-agent-runtime-access-assign -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-agent-runtime-access-assign --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/service-itsm-agentic-setup-agent-runtime-access-assign .cursor/skills/service-itsm-agentic-setup-agent-runtime-access-assign && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "service-itsm-agentic-setup-agent-runtime-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-agent-runtime-access-assign into .cursor/skills/service-itsm-agentic-setup-agent-runtime-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-agent-runtime-access-assign", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/service-itsm-agentic-setup-agent-runtime-access-assign--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-agent-runtime-access-assign -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-agent-runtime-access-assign --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/service-itsm-agentic-setup-agent-runtime-access-assign .gemini/skills/service-itsm-agentic-setup-agent-runtime-access-assign && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "service-itsm-agentic-setup-agent-runtime-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-agent-runtime-access-assign into .gemini/skills/service-itsm-agentic-setup-agent-runtime-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-agent-runtime-access-assign", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-agent-runtime-access-assignInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-agent-runtime-access-assign -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/service-itsm-agentic-setup-agent-runtime-access-assign .github/skills/service-itsm-agentic-setup-agent-runtime-access-assign && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "service-itsm-agentic-setup-agent-runtime-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-agent-runtime-access-assign into .github/skills/service-itsm-agentic-setup-agent-runtime-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-agent-runtime-access-assign", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-agent-runtime-access-assign -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-agent-runtime-access-assign --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/service-itsm-agentic-setup-agent-runtime-access-assign .opencode/skills/service-itsm-agentic-setup-agent-runtime-access-assign && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "service-itsm-agentic-setup-agent-runtime-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-agent-runtime-access-assign into .opencode/skills/service-itsm-agentic-setup-agent-runtime-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-agent-runtime-access-assign", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
service-itsm-agentic-setup-agent-runtime-access-assignGrant a user the runtime permissions an activated ITSM agent's actions need so the actions do not fail on permission errors.
Service Itsm Agentic Setup Agent Runtime Access Assign is an agent skill from forcedotcom/sf-skills. Grant a user the runtime permissions an activated ITSM agent's actions need so the actions do not fail on permission errors. After a Fulfiller or Employee agent is activated, this skill detects which platform feature permission sets are provisioned (Prompt Templates, Data Cloud, Unified Catalog), lets you pick a tier (user/agent vs admin) per feature and which user(s) to assign, then assigns them (license first when license-gated). It also creates a custom "Agent Access" permission set granting the activated…
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `references/cli-invocation.md`, `references/helper-contracts.md` and `references/permset-topology.md`).
It sits in Sales & Support, covering Prompt engineering and CRM management. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadAskUserQuestionFrom allowed-tools in the SKILL.md frontmatter.
Ships 7 files in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
sfnodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Service Itsm Agentic Setup Agent Runtime Access Assign loads about 5.4k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 265 tokens; SKILL.md has 2,071 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, AskUserQuestion, Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 2,071 words, ~5,427 tokens.
.claude/skills/service-itsm-agentic-setup-agent-runtime-access-assign/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.An ITSM agent (Fulfiller or Employee) can be created and activated, yet fail the moment it's opened — its actions call platform features the user can't execute. This skill closes that gap after activation via two write-capable steps behind one confirmation:
SetupEntityAccess per agent), then assign it to the same user(s).The verified feature → tier → permset matrix lives in references/permset-topology.md. No org has all three features — assign only what is provisioned and report the rest as unavailable, never failing on an absent feature.
Every read and write runs through the Salesforce CLI (sf) — no metadata XML, no token extraction, no MCP.
Agent_Access permission set; adding a SetupEntityAccess grant per chosen activated agent; assigning Agent_Access to the user(s); verifying assignments by read-back.service-itsm-agentic-setup-agentforce-studio-configure); creating or activating the Employee (service-itsm-agentic-setup-employee-agent-configure) or Fulfiller (service-itsm-agentic-setup-fulfiller-agent-configure) agent; the Fulfiller activation action-surfacing gap (create/activate-time, not this runtime one — service-itsm-agentic-setup-itsm-agentforce-permset-assign); CMDB access (service-itsm-agentic-setup-cmdb-access-assign); generic non-ITSM permission-set assignment; authoring/editing feature permsets.Bash) hold every deterministic decision (A9)Full I/O contracts in references/helper-contracts.md.
scripts/classify-platform-permset-availability.mjs — which features are provisioned, each tier's present + needsPsl, and the org's own display label per tier.scripts/resolve-target-user.mjs — running-user Id from the API-root identity URL (fails closed on a malformed shape).scripts/rank-candidate-users.mjs — up to five real, non-service candidate users to offer, ranked by audience (standard-license first for a Fulfiller agent, Unified Employee first for an Employee agent).scripts/gate-unified-catalog-tiers.mjs — per target user, which Unified Catalog tiers to offer (Community User → Unified Employee; Admin → System Administrator), else omit UC for that user.scripts/classify-activated-agents.mjs — the activated-agent candidate list (BotDefinition InternalCopilot with ≥1 Active BotVersion).scripts/classify-agent-access-state.mjs — whether Agent_Access must be created and which chosen agents still need a grant (idempotency).scripts/classify-assignment-state.mjs — per user+permset idempotency; pass the sentinel NO-PSL when the selected tier's needsPsl:false.sf CLI installed and authenticated to the target org (sf org display -o <alias> shows Connected). All calls use --target-org <alias>; never extract or pass the access token by hand.node ≥ 18 on PATH.If a precondition fails, sf surfaces an auth or 401/403/404; report the raw response verbatim and stop — do not fabricate state.
Ask only what cannot be inferred from conversation:
sf alias. Default to sf config get target-org if unset.AskUserQuestion (see Phase 2); if named, honor it.AskUserQuestion before any write.All calls go through sf; substitute <alias> with the target org. Use the skill's absolute directory for every script path. Exact command shapes: references/cli-invocation.md.
Query the six platform feature permsets, capture to a file, and classify:
sf data query \
-q "SELECT Id, Name, Label, LicenseId FROM PermissionSet WHERE Name IN ('EinsteinGPTPromptTemplateUser','EinsteinGPTPromptTemplateManager','GenieUserEnhancedSecurity','GenieAdmin','UnifiedCatalogCommunityUser','UnifiedCatalogAdmin')" \
--target-org <alias> --json > /tmp/itsm-platform-permsets.json 2>/tmp/itsm-platform-permsets.err || true
node "<skill_dir>/scripts/classify-platform-permset-availability.mjs" /tmp/itsm-platform-permsets.jsonThe classifier returns { features, provisionedFeatures, absentFeatures, verdict }. verdict:"ASSIGNABLE" ⇒ ≥1 feature is provisioned; verdict:"NONE-PROVISIONED" ⇒ no feature permset can be assigned (still continue to the Agent Access concern); verdict:"CANNOT-CONFIRM" ⇒ surface the raw error and stop.
Query the activated agents (BotDefinition + active-version child subquery), capture, and classify:
sf data query \
-q "SELECT Id, DeveloperName, MasterLabel, (SELECT Status FROM BotVersions WHERE Status='Active') FROM BotDefinition WHERE Type='InternalCopilot'" \
--target-org <alias> --json > /tmp/itsm-agents.json 2>/tmp/itsm-agents.err || true
node "<skill_dir>/scripts/classify-activated-agents.mjs" /tmp/itsm-agents.jsonverdict:"AGENTS-FOUND" ⇒ present activatedAgents[] for the multi-select; verdict:"NONE-ACTIVE" ⇒ there is nothing for Agent_Access to grant (report it; if NONE-PROVISIONED also holds there is no work — stop).
Resolve the running user (to offer as a labelled option) and query active org users so a helper can rank real, non-service candidates to offer as ready picks — never proceed with an unstated default:
sf api request rest "/services/data/v67.0/" --method GET --target-org <alias> > /tmp/api-root.json 2>/tmp/api-root.err || true
node "<skill_dir>/scripts/resolve-target-user.mjs" /tmp/api-root.json
sf data query -q "SELECT Name, Profile.Name, Profile.UserLicense.Name FROM User WHERE Id='<userId>'" --target-org <alias> --json > /tmp/itsm-running-user.json 2>/dev/null || true
sf data query -q "SELECT Id, Name, Username, Profile.Name, Profile.UserLicense.Name FROM User WHERE IsActive = true ORDER BY LastLoginDate DESC NULLS LAST LIMIT 25" --target-org <alias> --json > /tmp/itsm-candidate-users.json 2>/dev/null || true
node "<skill_dir>/scripts/rank-candidate-users.mjs" /tmp/itsm-candidate-users.json <audience> <userId>On verdict:"RESOLVED" keep userId; take its Name from /tmp/itsm-running-user.json for the label; on CANNOT-CONFIRM surface the reasons and stop. If the prompt already named the target user(s) ("grant me" / a username), honor it without asking. Otherwise set <audience> from the agent this grant is for — fulfiller (prefer standard-license users) or employee (prefer Unified Employee users), else any — inferring it from the agent named in the request/handoff or the Phase-1 activated set; rank-candidate-users.mjs returns up to five real, non-service candidates ranked for that audience. Present an AskUserQuestion (multi-select) with those users as direct selectable options — never a plain-prose username request: the running user (labelled "Me — <name>", or just "Me"; recommended) plus the top candidates. The picker allows four options, so offer "Me" + the top three ranked candidates; its built-in "Other" takes any username(s) not listed. Resolve each chosen/typed user by Username (query shape in references/cli-invocation.md, capturing each to its own file); skip inactive/unknown with a note. The confirmed user Ids drive every assignment below.
AskUserQuestion and record the selected tier's { name, Id, LicenseId, needsPsl }; report each absent feature as "not provisioned on this org — skipped". Unified Catalog is license-shape gated per selected user — run scripts/gate-unified-catalog-tiers.mjs once per user against that user's own capture and offer only its offer[] tiers: Community User only to a Unified Employee user, Admin only to a System Administrator; on omit, skip Unified Catalog for that user as "not applicable for this user's license/profile — skipped" — never offered, never a failed write.Agent_Access via AskUserQuestion (multi-select). Record their BotDefinition Ids as a comma-separated list.Agent Access state. Query the Agent_Access permset and (only if it exists) its existing BotDefinition grants — capture to /tmp/agent-access.json and /tmp/sea.json (query shapes in references/cli-invocation.md → Phase 4) — then classify against the chosen agent Ids:
node "<skill_dir>/scripts/classify-agent-access-state.mjs" /tmp/agent-access.json <sea.json|NO-PERMSET> "<chosenAgentIds-csv>"Pass NO-PERMSET for the second arg when Agent_Access does not exist yet. The classifier returns { permsetExists, permsetId, missingAgentIds, needsCreate, needsGrants, verdict }.
Per user + permset. For each target user × (each selected feature tier and Agent_Access), read existing assignments (PermissionSetAssignment, plus PermissionSetLicenseAssign only when needsPsl:true; shapes in references/cli-invocation.md) and classify. Agent_Access is standalone (needsPsl:false → NO-PSL); a feature tier uses needsPsl from its own row. If step 6 flagged Agent_Access absent (needsCreate:true), skip its keyed PermissionSetAssignment read — no permset ⇒ verdict NEEDS-WRITE; Phase 6 creates it, then assigns by name. Run the keyed read for Agent_Access only when step 6 returned an existing permsetId:
node "<skill_dir>/scripts/classify-assignment-state.mjs" /tmp/psa.json </tmp/psla.json|NO-PSL>Agent_Access will be created and which agents it will grant, and every permset assignment — and require an explicit "yes" via AskUserQuestion. On "no", stop and report the planned state with no writes. Assigning a license-gated tier consumes a license seat and takes effect for a live session.Agent Access permset (once): if needsCreate, POST to /sobjects/PermissionSet {"Name":"Agent_Access","Label":"Agent Access"} and capture the new id. Then for each Id in missingAgentIds, POST to /sobjects/SetupEntityAccess {"ParentId":"<permsetId>","SetupEntityId":"<agentId>"} — do not send SetupEntityType (it is not createable; it is derived from the 0Xx key prefix). DUPLICATE_VALUE on a grant ⇒ already granted, treat as success.
Feature tiers, per user, for each tier whose Phase 4 verdict was NEEDS-WRITE, ordered by needsPsl:
needsPsl:true — POST the PSL to /sobjects/PermissionSetLicenseAssign (using the tier's own LicenseId) FIRST, then sf org assign permset --name <tierName> (running user: omit --on-behalf-of; named user: --on-behalf-of "<username>").needsPsl:false — skip the PSL POST; run sf org assign permset only.Agent Access assignment, per user: sf org assign permset --name Agent_Access (running user: omit --on-behalf-of; named user: --on-behalf-of "<username>") when its Phase 4 verdict was NEEDS-WRITE. --on-behalf-of resolves by Username, never a 005 Id or a $USERNAME shell var (see references/cli-invocation.md).
Response handling (all writes): success ⇒ done; DUPLICATE_VALUE/already has ⇒ idempotent success; INSUFFICIENT_ACCESS/seat-exhaustion on a PSL POST ⇒ STOP and tell the user no seats are available; any other error ⇒ surface verbatim, mark FAILED. (Full taxonomy in references/cli-invocation.md.)
PermissionSetAssignment / PermissionSetLicenseAssign for the target user(s); SetupEntityAccess for Agent_Access) and confirm each intended row is present. Then report one aggregate verdict:| Constraint | Rationale |
|---|---|
| Detect provisioned features before assigning; report absent features as "not provisioned", never fail on them | No org has all three; an absent permset errors and masks real state |
| Ask the tier (user/agent vs admin) per provisioned feature — never auto-select | The lighter tier suffices to use the feature; admin over-grants |
| Offer standard-license users for a Fulfiller agent, Unified Employee for an Employee agent; the ranker drops service/bot accounts | The wrong cohort offers users who can't run that agent |
Offer a Unified Catalog tier only to a user who can hold it (Community User → Unified Employee; Admin → System Administrator), else omit for that user — via scripts/gate-unified-catalog-tiers.mjs | UC PSLs are license-shape gated; an ineligible tier is a hard write-time failure, not a seat shortage |
| All availability / idempotency / activation decisions are made by helper scripts, never by prose | They gate writes/success; scripts are deterministic, prose is not (A9) |
needsPsl is read PER ROW from the selected tier's own LicenseId; the PSL POST uses that LicenseId — never a hard-coded PSL name | Different orgs carry different license shapes; a wrong PermissionSetLicenseId POSTs the wrong seat |
Assign the PSL before the permission set when needsPsl:true | The permset is license-backed; hold the seat first |
Agent_Access grants access to activated agents ONLY, via SetupEntityAccess rows whose SetupEntityId is the BotDefinition Id | Access is granted like Apex-class access — one grant row per agent |
POST SetupEntityAccess with ParentId + SetupEntityId ONLY — never SetupEntityType | Not createable — derived from the SetupEntityId key prefix; sending it errors |
Create Agent_Access via the standard data API POST to /sobjects/PermissionSet — never Tooling/Metadata XML | Createable over the data API with just Name+Label; no deploy needed |
| One consolidated confirm-to-write before ANY write | The full plan (seats consumed, live-session effect) must be approved once |
Treat DUPLICATE_VALUE / already has as idempotent success on every write | Re-running must be safe; a duplicate means the state already holds |
| Verify by read-back before reporting ASSIGNED | A POST return code alone doesn't prove the row is present |
| Never extract the access token; never use an MCP dispatcher | Extracting a token leaks a bearer credential |
| Report exact error text from the CLI response | Enables support to diagnose failures |
scripts/classify-platform-permset-availability.mjs; absent reported "not provisioned", not failed.scripts/gate-unified-catalog-tiers.mjs.scripts/classify-activated-agents.mjs; only active-version agents were offered.AskUserQuestion (running user + audience-ranked users from scripts/rank-candidate-users.mjs + "Other"), never silent. Running user via scripts/resolve-target-user.mjs; named by Username.Agent_Access create/grant decided by scripts/classify-agent-access-state.mjs; SetupEntityAccess POSTs sent ParentId+SetupEntityId only.scripts/classify-assignment-state.mjs before any write.LicenseId drove the PSL POST when needsPsl:true, POSTed before the permset.DUPLICATE_VALUE / already has treated as success; other errors surfaced verbatim.ITSM Agent Runtime-Access Assignment (via service-itsm-agentic-setup-agent-runtime-access-assign)
Org: <org-alias> (API v67.0)
Target user(s): <username> (<userId>)[, ...]
Runtime action permissions:
Prompt Templates ...... <tier chosen: User | Manager | skipped | not provisioned> -> <assigned | already-had | FAILED>
Data Cloud ............ <tier chosen | skipped | not provisioned> -> <assigned | already-had | FAILED>
Unified Catalog ....... <tier chosen | skipped | not provisioned> -> <assigned | already-had | FAILED>
Agent Access permission set:
Permission set ........ <created | already existed>
Agents granted ........ <comma-separated agent names, or none>
Assigned to user(s) ... <assigned | already-had | FAILED>
Verdict: ASSIGNED | ALREADY-ASSIGNED | PARTIAL | NONE-PROVISIONED | FAILED
Reason: <plain-language explanation, or empty on success>
Next steps:
- <If ASSIGNED / ALREADY-ASSIGNED: "The user can now open and exercise the agent(s) in Agentforce Studio — action calls should no longer fail on missing permissions.">
- <If PARTIAL: list which assignments succeeded and which failed, verbatim.>
- <If NONE-PROVISIONED: nothing to assign — create/activate an agent and enable its features first.>
- <If FAILED: list the observed error(s) verbatim + remediation.>Keep internal jargon (record Ids, HTTP codes, DUPLICATE_VALUE, object/dev names) out of user-facing output.
| File | When to read |
|---|---|
references/permset-topology.md | Any change to the feature/tier matrix — the six platform permsets, their tiers, PSLs, and the Agent_Access / SetupEntityAccess agent-access mechanism |
references/cli-invocation.md | Every phase — exact sf data query / sf api request rest POST / sf org assign permset call shapes, the --json rule, the never-extract-token rule, response envelopes, and the error taxonomy |
references/helper-contracts.md | The input/output shapes of all seven helper scripts and how to interpret each verdict |
© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 10 other files (scripts, references) in skills/service-itsm-agentic-setup-agent-runtime-access-assign of forcedotcom/sf-skills.
Open the folder on GitHubat commit e5164d9
Service Itsm Agentic Setup Agent Runtime Access Assign next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Service Itsm Agentic Setup Agent Runtime Access Assign this skillforcedotcom/sf-skills | 1.1k | — | ~5.4k | Automated safety check: Notes | Apache-2.0 | |
| Salesforce Policy Guardrailsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Agentforce GenerateSalesforceAIResearch/agentforce-adlc | 114 | 1 repos | ~7.4k | Automated safety check: Pass | Custom licence | |
| Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib | 154 | — | ~4.3k | Automated safety check: Pass | MIT | |
| Sf DatacloudJaganpro/sf-skills | 424 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Soql Lib Selectorbeyond-the-cloud-dev/soql-lib | 154 | — | ~2k | Automated safety check: Pass | MIT |
jeremylongshore/tons-of-skills-marketplace
Gate Salesforce code and configuration for SOQL injection, secret exposure, unsafe API versions, missing access checks, destructive writes, and unreviewed org changes.
SalesforceAIResearch/agentforce-adlc
Build, modify, audit, repair, optimize, debug, and deploy agents with Agentforce Agent Script.
beyond-the-cloud-dev/soql-lib
Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).
Jaganpro/sf-skills
Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.
beyond-the-cloud-dev/soql-lib
Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.
Portwood-Global-Solutions/Portwood
Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Works with
Categories
Grant a user the runtime permissions an activated ITSM agent's actions need so the actions do not fail on permission errors. Service Itsm Agentic Setup Agent Runtime Access Assign is an agent skill from forcedotcom/sf-skills. Grant a user the runtime permissions an activated ITSM agent's actions need so the actions do not fail on permission errors.
Service Itsm Agentic Setup Agent Runtime Access Assign fits situations like: grant a user access to an activated agent; assign prompt-template; unified-catalog access; create an Agent Access permission set.
Run `npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-agent-runtime-access-assign -a claude-code`. Or copy the skill folder (skills/service-itsm-agentic-setup-agent-runtime-access-assign in forcedotcom/sf-skills) into .claude/skills/service-itsm-agentic-setup-agent-runtime-access-assign in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-agent-runtime-access-assign -a codex`. Or copy the skill folder (skills/service-itsm-agentic-setup-agent-runtime-access-assign in forcedotcom/sf-skills) into .agents/skills/service-itsm-agentic-setup-agent-runtime-access-assign in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-agent-runtime-access-assign -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/service-itsm-agentic-setup-agent-runtime-access-assign, .gemini/skills/service-itsm-agentic-setup-agent-runtime-access-assign, .github/skills/service-itsm-agentic-setup-agent-runtime-access-assign and .opencode/skills/service-itsm-agentic-setup-agent-runtime-access-assign in your project.
Going by SKILL.md and its folder, Service Itsm Agentic Setup Agent Runtime Access Assign needs JavaScript for the scripts in its folder and the command-line tools its instructions call (sf and node). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash, Read, AskUserQuestion.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Service Itsm Agentic Setup Agent Runtime Access Assign is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Service Itsm Agentic Setup Agent Runtime Access Assign: Salesforce Policy Guardrails (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Agentforce Generate (SalesforceAIResearch/agentforce-adlc, 114 stars), Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars) and Sf Datacloud (Jaganpro/sf-skills, 424 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.