Churn Risk
indranilbanerjee/digital-marketing-pro
Score customer segments for churn risk from behavioral signals — email engagement decline, purchase recency, usage drops, support sentiment — producing a 0-100 risk scorecard with four tiers…
Grant a specific user access to CMDB (Configuration Management Database) data in Service Cloud ITSM against a production or sandbox org by assigning the license-backed CMDB permission sets…
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-cmdb-access-assign -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-cmdb-access-assign --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/service-itsm-agentic-setup-cmdb-access-assign .claude/skills/service-itsm-agentic-setup-cmdb-access-assign && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "service-itsm-agentic-setup-cmdb-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-cmdb-access-assign into .claude/skills/service-itsm-agentic-setup-cmdb-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-cmdb-access-assign", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-cmdb-access-assignType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-cmdb-access-assign -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-cmdb-access-assign --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/service-itsm-agentic-setup-cmdb-access-assign .agents/skills/service-itsm-agentic-setup-cmdb-access-assign && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "service-itsm-agentic-setup-cmdb-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-cmdb-access-assign into .agents/skills/service-itsm-agentic-setup-cmdb-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-cmdb-access-assign", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-cmdb-access-assign -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-cmdb-access-assign --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/service-itsm-agentic-setup-cmdb-access-assign .cursor/skills/service-itsm-agentic-setup-cmdb-access-assign && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "service-itsm-agentic-setup-cmdb-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-cmdb-access-assign into .cursor/skills/service-itsm-agentic-setup-cmdb-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-cmdb-access-assign", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/service-itsm-agentic-setup-cmdb-access-assign--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-cmdb-access-assign -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-cmdb-access-assign --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/service-itsm-agentic-setup-cmdb-access-assign .gemini/skills/service-itsm-agentic-setup-cmdb-access-assign && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "service-itsm-agentic-setup-cmdb-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-cmdb-access-assign into .gemini/skills/service-itsm-agentic-setup-cmdb-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-cmdb-access-assign", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-cmdb-access-assignInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-cmdb-access-assign -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/service-itsm-agentic-setup-cmdb-access-assign .github/skills/service-itsm-agentic-setup-cmdb-access-assign && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "service-itsm-agentic-setup-cmdb-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-cmdb-access-assign into .github/skills/service-itsm-agentic-setup-cmdb-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-cmdb-access-assign", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-cmdb-access-assign -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-cmdb-access-assign --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/service-itsm-agentic-setup-cmdb-access-assign .opencode/skills/service-itsm-agentic-setup-cmdb-access-assign && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "service-itsm-agentic-setup-cmdb-access-assign" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-itsm-agentic-setup-cmdb-access-assign into .opencode/skills/service-itsm-agentic-setup-cmdb-access-assign/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-itsm-agentic-setup-cmdb-access-assign", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
service-itsm-agentic-setup-cmdb-access-assignGrant a specific user access to CMDB (Configuration Management Database) data in Service Cloud ITSM against a production or sandbox org by assigning the license-backed CMDB permission sets…
Service Itsm Agentic Setup Cmdb Access Assign is an agent skill from forcedotcom/sf-skills. Grant a specific user access to CMDB (Configuration Management Database) data in Service Cloud ITSM against a production or sandbox org by assigning the license-backed CMDB permission sets (Configuration Item Reader, Owner, Type Reader, Type Manager) and their permission-set licenses. Use when the user asks to give someone CMDB access, assign CMDB permission sets, grant a user the Configuration Item Reader/Owner role, or fix a CMDB 403 FUNCTIONALITYNOTENABLED that a user still hits after the CMDB feature is…
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/mcp-invocation.md`).
It sits in Sales & Support. It works with Salesforce and Model Context Protocol. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadAskUserQuestionmcp__headless-360__discovermcp__headless-360__describemcp__headless-360__dispatchmcp__headless-360__dispatch_readonlyFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Service Itsm Agentic Setup Cmdb Access Assign loads about 4.8k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 262 tokens; SKILL.md has 2,134 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 2,134 words, ~4,812 tokens.
.claude/skills/service-itsm-agentic-setup-cmdb-access-assign/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Grants a specific user the ability to read and work with CMDB (Configuration Management Database)
data by assigning the license-backed CMDB permission sets and their permission-set licenses. Every
call runs through the Salesforce-hosted Headless-360 MCP server (server key headless-360) via its
four meta-tools (discover, describe, dispatch_readonly, dispatch). The org is derived from the
OAuth JWT bound to the current MCP session — the skill never handles an org id, alias, or credentials —
so this works identically against production and sandbox with no per-user MCP install.
This is Layer 3 of CMDB setup. It assumes the org-level CMDB gate is already lifted (the feature
is ENABLED) — that is a separate skill (service-itsm-agentic-setup-cmdb-configure, Layers 0–2).
This skill grants a user access; it does not enable the feature for the org.
Enabling the CMDB feature lifts the org-level gate, but some CMDB reads (e.g. bundleListView)
also enforce user-level access. A user with no CMDB permission sets still gets
403 FUNCTIONALITY_NOT_ENABLED ("not enabled for this user") even when the feature is correctly
ENABLED for the org. This skill assigns that user the CMDB permission sets so those reads succeed.
This skill is a no-op if the org feature is not enabled. User-level access has no effect until the org-level CMDB feature is ENABLED. If you find the org gate is still closed, stop and tell the user the CMDB feature must be turned on for the org first — see the cross-skill note at the end.
Each is a license-backed Standard permission set; assigning it also requires (and this skill assigns) its permission-set license (PSL).
| Role | Permission set (Name) | Backing PSL (DeveloperName) | Grants |
|---|---|---|---|
| Reader | ItSrvcCnfgItmReadPermissionSet | ItSrvcCnfgItmReadPsl | Read CMDB configuration items |
| Owner | ItSrvcCnfgItmOwnerPermissionSet | ItSrvcCnfgItmOwnerPsl | Own / edit configuration items |
| Type Reader | ItSrvcCnfgItmTypReadPermissionSet | ItSrvcCnfgItmTypReadPsl | Read configuration-item types |
| Type Manager | ItSrvcCnfgItmTypManagerPermissionSet | ItSrvcCnfgItmTypMgrPsl | Manage configuration-item types |
For read-only CMDB access, Reader (+ Type Reader) is the minimal set. For users who edit CMDB records, add Owner; for those who manage the type catalog, add Type Manager. If the user does not specify a role, ask (see Clarifying questions) — default to Reader + Type Reader for a viewer.
Bundle management needs Type Manager. If the user's goal is to install or manage CMDB content bundles (or they hit a
403on a bundle-management read such asGET /connect/cmdb/bundles/details), the role that clears it is Type Manager — a user holding only Reader / Owner / Type Reader still gets403 FUNCTIONALITY_NOT_ENABLEDon bundle operations. Assign Type Manager (with its own backing PSL,ItSrvcCnfgItmTypMgrPsl) for anyone who deploys or manages bundles.
service-itsm-agentic-setup-cmdb-configure), installing content bundles, CMDB record CRUD,
creating custom permission sets, or org-permission/edition changes.All operations dispatch through headless-360 MCP tools. Reads go through
mcp__headless-360__dispatch_readonly, writes through mcp__headless-360__dispatch — both take raw
HTTP: {"url": "<path>", "method": "GET|POST", "body"?: {...}, "queryParams"?: {...}} — not
{operation_id, arguments}. See references/mcp-invocation.md for the exact url / method / body
of every call. The four tools:
mcp__headless-360__discover — semantic search over the indexed operation catalog. The standard
/query and /sobjects/... REST routes this skill uses are not always indexed, so a miss does
not mean the route is absent — dispatch the exact path directly (see references/mcp-invocation.md).mcp__headless-360__describe — pull the full input schema and canonical route before any POST.mcp__headless-360__dispatch_readonly — the dispatcher for every read (GET).mcp__headless-360__dispatch — the dispatcher for every write (POST/PATCH).The skill never handles credentials — the org is bound to the current OAuth session. If a dispatch*
call returns an auth error, tell the user to re-authenticate the headless-360 MCP connection (and
confirm the session points at the intended org), then stop.
Ask only what you cannot infer from conversation:
Do not re-ask for anything the user already provided; pre-populate and note "(from conversation)".
Always read before you write: run the read-only checks before any assignment. All assignments are per-user and idempotent — a duplicate assignment must be treated as already-done, not an error.
User access is meaningless until the org gate is lifted. Read the feature status:
dispatch_readonly({ "url": "/services/data/v67.0/connect/setup/discovery/feature/service-cloud-itsm-cmdb-integration/status", "method": "GET" })status == ENABLED → proceed.status != ENABLED (or the call returns 403 FUNCTIONALITY_NOT_ENABLED) → STOP. Tell the user, in
plain language, that CMDB has to be turned on for the org before a user can be given access, and
point them to the CMDB feature-enable skill (see the cross-skill note). Do not assign anything.For "the current user" / "me" / "my own user" (do NOT use USER_ID() — it is Apex-only and is
rejected by the REST query API; do NOT rely on /chatter/users/me or /connect/user-profiles/me —
they return 403 FUNCTIONALITY_NOT_ENABLED when Chatter/Communities are off). Instead read the API
root and parse the identity URL:
dispatch_readonly({ "url": "/services/data/v67.0/", "method": "GET" })The response identity field is a URL ending in /<orgId>/<userId> (the user Id is the last path
segment and starts with 005). Use that Id directly as the target user, or confirm it:
dispatch_readonly({ "url": "/services/data/v67.0/query", "method": "GET", "queryParams": { "q": "SELECT Id, Username, Name, IsActive FROM User WHERE Id = '<userId>'" } })For a named user (username / email supplied):
dispatch_readonly({ "url": "/services/data/v67.0/query", "method": "GET", "queryParams": { "q": "SELECT Id, Username, Name, IsActive FROM User WHERE Username = '<username>'" } })Id.For each requested role, resolve the permission set and its backing license:
dispatch_readonly({ "url": "/services/data/v67.0/query", "method": "GET", "queryParams": { "q": "SELECT Id, Name, LicenseId FROM PermissionSet WHERE Name = '<psName>'" } })Use the Name values from the table above. Capture each Id (the permission set) and LicenseId
(the PSL to assign). If a permission set is not found, the org likely is not CMDB-licensed — stop and
report that CMDB does not appear to be set up on this org.
A role can be granted two ways, and this check must accept both — or it falsely reports an already-granted role as missing and wrongly asks to assign it:
PermissionSetAssignment whose PermissionSetId is the role's own permission set.PermissionSetAssignment row carries a PermissionSetGroupId and
its PermissionSetId is the group's internal aggregate set — not the member permission set —
so a query filtering on PermissionSetId = '<psId>' returns zero even though the user
effectively holds the role.Run both permission-set reads per role; the permission set is present if either returns
totalSize >= 1 (the second is a top-level semi-join — nesting it inside an OR throws MALFORMED_QUERY):
dispatch_readonly({ "url": "/services/data/v67.0/query", "method": "GET", "queryParams": { "q": "SELECT Id FROM PermissionSetAssignment WHERE AssigneeId = '<userId>' AND PermissionSetId = '<psId>'" } })
dispatch_readonly({ "url": "/services/data/v67.0/query", "method": "GET", "queryParams": { "q": "SELECT Id FROM PermissionSetAssignment WHERE AssigneeId = '<userId>' AND PermissionSetGroupId IN (SELECT PermissionSetGroupId FROM PermissionSetGroupComponent WHERE PermissionSetId = '<psId>')" } })Then check the backing license (a PSG that includes the role also assigns its backing PSL directly, so this single read already covers the PSG case):
dispatch_readonly({ "url": "/services/data/v67.0/query", "method": "GET", "queryParams": { "q": "SELECT Id FROM PermissionSetLicenseAssign WHERE AssigneeId = '<userId>' AND PermissionSetLicenseId = '<pslId>'" } })If the permission set is present by either path and the license read returns totalSize >= 1,
that role is already assigned — skip its writes and record it as already-done. Only assign what is
genuinely missing, and do not re-assign the member permission set directly when the user already
holds it through a PSG.
Confirm the target user, org, and role(s) with the user, then for each missing role assign the PSL first, then the permission set:
dispatch({ "url": "/services/data/v67.0/sobjects/PermissionSetLicenseAssign", "method": "POST", "body": { "AssigneeId": "<userId>", "PermissionSetLicenseId": "<pslId>" } })
dispatch({ "url": "/services/data/v67.0/sobjects/PermissionSetAssignment", "method": "POST", "body": { "AssigneeId": "<userId>", "PermissionSetId": "<psId>" } })201 → assigned.400 DUPLICATE_VALUE → the user already had it; treat as success (idempotent), not a failure.INSUFFICIENT_ACCESS / no seats) → STOP for that role; tell the user
the CMDB license has no available seats and how many are in use (see references/mcp-invocation.md
for the seat query). Do not retry.Re-run the Step 4 reads — both the direct and the via-PSG permission-set checks, plus the license check. A role counts as done only when its permission set is present by either path and its backing license reads back. Report per-role: assigned / already had it. Only roles confirmed present in this read count as done.
| Constraint | Rationale |
|---|---|
| Confirm the org feature is ENABLED before assigning | User access has no effect until the org-level CMDB gate is lifted; assigning first would be a misleading no-op |
| Resolve the user to exactly one record before writing | Assigning to the wrong (or an ambiguous) user is hard to reverse and a security concern |
| Read existing assignments before every assign | Assignment is per-user; re-assigning throws DUPLICATE_VALUE — skip what already exists |
| Assign the PSL before the permission set | The permission set is license-backed; the license seat must be held for the assignment to stick |
Treat DUPLICATE_VALUE as success | It means the user already has that access — idempotent, not an error |
| Never create or edit permission sets | This skill only assigns the standard CMDB permission sets; authoring perm sets is out of scope |
| Confirm the target org, user, and each write with the user | These are real changes granting a user data access on a live org |
| Never expose internal jargon to the user | Keep record IDs, HTTP status codes (403/400/…), API error codes (FUNCTIONALITY_NOT_ENABLED, DUPLICATE_VALUE), object names (PermissionSetLicenseAssign), developer names (ItSrvcCnfgItmReadPsl), and tooling internals (dispatch, headless-360) out of user-facing output. Use human-readable role names and plain language |
ENABLED before any assignment?CMDB Access Assignment — Complete (via service-itsm-agentic-setup-cmdb-access-assign)
Target org: <org>
User: <name> (<username>)
Configuration Item Reader ......... Assigned
Configuration Item Type Reader .... Already had access
This user can now read CMDB data in this org. If they still can't, confirm the org's
CMDB feature is turned on (that's a separate setup step).Keep internal jargon out of user-facing output (no record IDs, HTTP status codes, error codes, object
or developer names). If any step fails, stop and tell the user — in plain language — which part didn't
succeed and what it means for them. Translate any raw error (e.g. a 403 or FUNCTIONALITY_NOT_ENABLED)
into what it means ("CMDB isn't turned on for this org yet"), rather than echoing the code.
| Symptom | Likely cause | What to tell the user |
|---|---|---|
Feature status not ENABLED (or 403 on the status read) | Org-level CMDB gate not lifted | CMDB must be turned on for the org first; this is a separate setup step — point to the feature-enable skill |
| Permission set not found | Org is not CMDB-licensed / not set up | CMDB does not appear to be available on this org; confirm it is licensed and enabled |
403 FUNCTIONALITY_NOT_ENABLED on a bundle-management read (e.g. bundles/details, bundleListView) after assignment, feature ENABLED | The user holds Reader/Owner/Type Reader but not Type Manager — bundle operations require it | Assign Type Manager — this role is required for CMDB bundle management; the other CMDB roles do not cover bundle operations |
| Skill says a CMDB role is missing and asks to assign it, but the user already has it (e.g. through a permission set group) | Idempotency check saw only directly assigned permission sets and was blind to group-delivered grants — fixed in Step 4, which now also checks group membership | The user already has that access through a permission set group; treat the role as already granted — no new assignment is needed |
400 DUPLICATE_VALUE on assign | User already has that access | Not an error — report the role as already assigned |
| License-limit / no-seats error on assign | CMDB permission-set license seats exhausted | Report seats in use vs available; a seat must free up (or more licenses added) before assigning |
dispatch* auth error | headless-360 MCP session not authenticated / token expired | Re-authenticate the headless-360 MCP connection and confirm the session points at the intended org |
| When | Skill |
|---|---|
| The org CMDB feature is not enabled yet (org gate still closed) | service-itsm-agentic-setup-cmdb-configure (Layers 0–2 — enable the feature first, then return here) |
| The user needs the CMDB base content bundle installed | service-itsm-agentic-setup-cmdb-bundle-deploy (Layer 4 — content, separate from user access). That skill's bundle-management reads require the user hold Type Manager, so assign it here first |
| File | When to read |
|---|---|
references/mcp-invocation.md | Exact dispatch* url/method/body for every read and write, response envelopes, the license-seat query, and the error table |
© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/service-itsm-agentic-setup-cmdb-access-assign of forcedotcom/sf-skills.
Open the folder on GitHubat commit e5164d9
Service Itsm Agentic Setup Cmdb Access Assign next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Service Itsm Agentic Setup Cmdb Access Assign this skillforcedotcom/sf-skills | 1.1k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| Churn Riskindranilbanerjee/digital-marketing-pro | 859 | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Lead Importindranilbanerjee/digital-marketing-pro | 859 | 1 repos | ~3.3k | Automated safety check: Pass | MIT | |
| Pipeline Updateindranilbanerjee/digital-marketing-pro | 859 | 1 repos | ~3.3k | Automated safety check: Pass | MIT | |
| Zsxqunnoo/zsxq-skill | 304 | — | ~3.8k | Automated safety check: Pass | MIT | |
| Agentforce GenerateSalesforceAIResearch/agentforce-adlc | 114 | 1 repos | ~7.4k | Automated safety check: Pass | Custom licence |
indranilbanerjee/digital-marketing-pro
Score customer segments for churn risk from behavioral signals — email engagement decline, purchase recency, usage drops, support sentiment — producing a 0-100 risk scorecard with four tiers…
indranilbanerjee/digital-marketing-pro
Import leads into Salesforce, HubSpot, Zoho, or Pipedrive with validation, deduplication against existing CRM records, lead scoring, consent and compliance checks, and source attribution — then push…
indranilbanerjee/digital-marketing-pro
Update CRM deals — move stages, change values and close dates, attach notes and activities, create follow-up tasks — with validation against pipeline rules, a before-and-after comparison, and…
unnoo/zsxq-skill
知识星球 CLI(zsxq-cli)与底层接口完整操作指南,涵盖星球和内容管理、Skill Pay 微信支付场景。当用户提到知识星球、zsxq、小密圈、星球、登录/认证、发帖、评论、回答、编辑、删除主题、定时发布/定时任务/定时回答、投票、问答主题、markdown 正文、AI…
SalesforceAIResearch/agentforce-adlc
Build, modify, audit, repair, optimize, debug, and deploy agents with Agentforce Agent Script.
romangojiberryAI/gojiberryai-sales-os
A complete outbound sales department in one skill. An agent skill from romangojiberryAI/gojiberryai-sales-os.
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Works with
Categories
Grant a specific user access to CMDB (Configuration Management Database) data in Service Cloud ITSM against a production or sandbox org by assigning the license-backed CMDB permission sets…. Service Itsm Agentic Setup Cmdb Access Assign is an agent skill from forcedotcom/sf-skills. Grant a specific user access to CMDB (Configuration Management Database) data in Service Cloud ITSM against a production or sandbox org by assigning the license-backed CMDB permission sets (Configuration Item Reader, Owner, Type Reader, Type Manager) and their permission-set licenses.
Service Itsm Agentic Setup Cmdb Access Assign fits situations like: the user asks to give someone CMDB access; assign CMDB permission sets; grant a user the Configuration Item Reader/Owner role; fix a CMDB 403 FUNCTIONALITYNOTENABLED that a user still hits after the CMDB feature is already enabled.
Run `npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-cmdb-access-assign -a claude-code`. Or copy the skill folder (skills/service-itsm-agentic-setup-cmdb-access-assign in forcedotcom/sf-skills) into .claude/skills/service-itsm-agentic-setup-cmdb-access-assign in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-cmdb-access-assign -a codex`. Or copy the skill folder (skills/service-itsm-agentic-setup-cmdb-access-assign in forcedotcom/sf-skills) into .agents/skills/service-itsm-agentic-setup-cmdb-access-assign in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-cmdb-access-assign -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/service-itsm-agentic-setup-cmdb-access-assign, .gemini/skills/service-itsm-agentic-setup-cmdb-access-assign, .github/skills/service-itsm-agentic-setup-cmdb-access-assign and .opencode/skills/service-itsm-agentic-setup-cmdb-access-assign in your project.
SKILL.md names no scripts, command-line tools or credentials: Service Itsm Agentic Setup Cmdb Access Assign is instructions for the agent only. Its frontmatter pre-approves these tools: Read, AskUserQuestion, mcp__headless-360__discover, mcp__headless-360__describe, mcp__headless-360__dispatch, mcp__headless-360__dispatch_readonly.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Service Itsm Agentic Setup Cmdb Access Assign is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Service Itsm Agentic Setup Cmdb Access Assign: Churn Risk (indranilbanerjee/digital-marketing-pro, 859 stars), Lead Import (indranilbanerjee/digital-marketing-pro, 859 stars), Pipeline Update (indranilbanerjee/digital-marketing-pro, 859 stars) and Zsxq (unnoo/zsxq-skill, 304 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,065 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.