Agent skill

Service Omni Permission Set Assign

by forcedotcom in forcedotcom/sf-skills

Assign the required Omni permission sets to provisioned agent users.

Apache-2.0Auto-check: notes

Install Service Omni Permission Set Assign

skills CLI
$ npx skills add forcedotcom/sf-skills --skill service-omni-permission-set-assign -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills service-omni-permission-set-assign --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/service-omni-permission-set-assign .claude/skills/service-omni-permission-set-assign && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
service-omni-permission-set-assign
GitHub stars
1.1k
Token cost
~1.5k tokens
SKILL.md length
657 words
Files
4 (incl. scripts, references, assets)
Skills in repo
252
Repo updated
First seen
Licence
Apache-2.0

At a glance

Assign the required Omni permission sets to provisioned agent users.

  • Works in 6 steps: Compute safe_to_write; derive the 8-char… → Resolve the agent users by the… → Resolve each PermissionSet by name;… → …
  • Users ask to assign Omni permissions to agents
  • SKILL.md covers Inputs, Preconditions and safety, Run and Behavior, plus 3 more sections
  • Runs Shell scripts from its folder; calls bash

What it does

Service Omni Permission Set Assign is an agent skill from forcedotcom/sf-skills. Assign the required Omni permission sets to provisioned agent users. TRIGGER when users ask to assign Omni permissions to agents, grant Omni-Channel access, add OmniAgent permissions, repair missing Omni permission assignments, or prepare agents to use the Omni widget. DO NOT TRIGGER for arbitrary permission-set authoring, agent creation, or queue membership.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts, reference files and assets (for example `references/api-notes.md` and `scripts/verify-and-assign.sh`).

The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • Users ask to assign Omni permissions to agents
  • Grant Omni-Channel access
  • Add OmniAgent permissions
  • Repair missing Omni permission assignments

Example prompts

  • “/service-omni-permission-set-assign”

Requirements

  • A Bash shell
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Edit, Glob, Grep

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Compute safe_to_write; derive the 8-char org suffix.
  2. Resolve the agent users by the agent{1..N}.@example.com pattern; block if any are missing.
  3. Resolve each PermissionSet by name; self-heal Omni_Agent if absent, else block naming which is missing.
  4. Query existing PermissionSetAssignment for the (user × set) cross-product; compute the missing pairs.
  5. POST one assignment per missing pair (individual POSTs, no allOrNone).
  6. Re-query to confirm final state and emit the report.

What it can do on your machine

Read from SKILL.md and the folder at commit 4bbae5c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Edit
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Service Omni Permission Set Assign loads about 1.5k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 99 tokens; SKILL.md has 657 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Edit, Glob, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit 4bbae5c, republished under its Apache-2.0 licence (© forcedotcom). 657 words, ~1,547 tokens.

Download SKILL.mdSave it as .claude/skills/service-omni-permission-set-assign/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
service-omni-permission-set-assign
description
Assign the required Omni permission sets to provisioned agent users. TRIGGER when users ask to assign Omni permissions to agents, grant Omni-Channel access, add Omni_Agent permissions, repair missing Omni permission assignments, or prepare agents to use the Omni widget. DO NOT TRIGGER for arbitrary permission-set authoring, agent creation, or queue membership.
allowed-tools
Bash, Read, Write, Edit, Glob, Grep
metadata.version
1.0
metadata.domains
Service
metadata.minApiVersion
66.0
metadata.relatedSkills
service-omni-agent-users-create, service-omni-presence-status-deploy, service-omni-queue-members-assign

service-omni-permission-set-assign

Assign one or more PermissionSets to N agent users via PermissionSetAssignment Data API POSTs. The default target is Omni_Agent, the permission set granting the OmniChannel widget, presence-status access, and demo-queue visibility — without an assignment row, agents cannot open the widget or receive routed work. Detection is SOQL-based, so the skill only creates the assignments that are missing. Agent users come from service-omni-agent-users-create, and it runs alongside service-omni-presence-status-deploy so assigned agents can both open the widget and select a status.

Inputs

bash
bash scripts/verify-and-assign.sh <org-alias> [count=3] [permission-set-names-csv=Omni_Agent]
  • org-alias (required).
  • count (optional, default 3, range 1..10) — must match the agent user count.
  • permission-set-names-csv (optional, default Omni_Agent) — comma-separated for multiple. Every user gets every listed set (cross-product): count=3 × 2 sets = up to 6 assignments.

Preconditions and safety

  • Target org authenticated via sf CLI, Service Cloud license, sf CLI ≥ 2.139.6.
  • The agent users exist (service-omni-agent-users-create); a count mismatch blocks with a pointer back to that skill.
  • The executing user has PermissionsAssignPermissionSets (standard on System Administrator) — required even for org admins; ModifyAllData alone is insufficient.
  • At least one Omni presence status exists before Omni_Agent self-heals — the bundled set grants agent capability via servicePresenceStatusAccesses for whichever curated statuses exist (e.g. Available_Case/Available_Voice + Busy), generated at deploy time. Run service-omni-presence-status-deploy first; the coordinator sequences presence before permset for this reason.
  • The three-way safe_to_write guard applies — assigning permission sets on a production org can escalate a real user's privileges, so it blocks with no override.

Self-heal (run mode only). When the default Omni_Agent set is absent, the skill deploys the bundled Omni_Agent metadata once, then assigns. In --plan mode it never deploys — it reports action_needed and exits read-only. This covers only the bundled Omni_Agent asset; any other permission set must already exist or the run blocks with a click-path.

Run

verify-and-assign.sh performs the whole cycle:

  1. Compute safe_to_write; derive the 8-char org suffix.
  2. Resolve the agent users by the agent{1..N}.<suffix>@example.com pattern; block if any are missing.
  3. Resolve each PermissionSet by name; self-heal Omni_Agent if absent, else block naming which is missing.
  4. Query existing PermissionSetAssignment for the (user × set) cross-product; compute the missing pairs.
  5. POST one assignment per missing pair (individual POSTs, no allOrNone).
  6. Re-query to confirm final state and emit the report.
Show full SKILL.md (294 more words)Show less

Behavior

Cross-product. Every user gets every listed set; a partial assignment is a failure, not a feature.

Idempotency. PermissionSetAssignment has a database uniqueness constraint on (AssigneeId, PermissionSetId), so a re-POST raises DUPLICATE_VALUE; the skill detects existing pairs first and treats DUPLICATE_VALUE as a safety net for concurrent races. It POSTs individually so one duplicate or error never rolls back its successful siblings, and it re-queries after all POSTs — a 201 only means Salesforce accepted the write; a subsequent SOQL confirms the assignment is active.

Non-destructive. The skill is create-only; it never deletes existing assignments (users may hold out-of-band permissions from other admins) and derives users from the agent pattern rather than accepting an explicit user-id list, so it never assigns demo permissions to real named users.

Output contract

A single JSON object with status ∈ assigned | reused | partial | blocked, the resolved permission_sets, org_suffix, requested_count, expected_assignment_count (= requested_count × len(permission_sets)), a before snapshot, assigned_this_run/assigned_count, reused_count, an after snapshot, manual_actions, and blocking_issue.

  • assigned — at least one new assignment created; all expected pairs exist after.
  • reused — all expected pairs already existed; nothing POSTed.
  • partial — some POSTs failed; final count is below expected.
  • blocked — precondition failed (production org, missing set, missing users, missing permissions).

assigned_count + reused_count == expected_assignment_count unless partial; blocking_issue is non-null only for blocked/partial.

Limitations

  • Assigns individual PermissionSets only — a PermissionSetGroup is a different sObject and is out of scope.
  • Self-heal covers only the bundled Omni_Agent; it is not a general-purpose permission-set authoring surface.
  • Create-only; it does not remove assignments.

References

FileWhen to read
assets/package.xmlLoad when the default Omni_Agent permission set is missing and the run-mode self-heal path must deploy the bundled metadata
references/api-notes.mdBefore the POST loop — PermissionSetAssignment schema, its DUPLICATE_VALUE semantics, and why users are derived from the agent pattern rather than an explicit id list

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references, assets) in skills/service-omni-permission-set-assign of forcedotcom/sf-skills.

  • SKILL.md
  • assets/package.xml
  • references/api-notes.md
  • scripts/verify-and-assign.sh

Open the folder on GitHubat commit 4bbae5c

Compare with similar skills

Service Omni Permission Set Assign next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Service Omni Permission Set Assign compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Service Omni Permission Set Assign this skillforcedotcom/sf-skills1.1k—~1.5kAutomated safety check: NotesApache-2.0
Manage Settingsasgeirtj/system_prompts_leaks69k—~3.1kAutomated safety check: PassCC0-1.0
OmniRoute Settings APIdiegosouzapw/OmniRoute75k—~3.6kAutomated safety check: PassMIT
ESP32 CSI Node Provisioningruvnet/RuView97k—~579Automated safety check: PassMIT
Gemini Omnicalesthio/OpenMontage66k—~2.1kAutomated safety check: NotesAGPL-3.0
Requirementsrizsotto/Bear6.5k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • Manage Settings

    asgeirtj/system_prompts_leaks

    Any explicit Muse Code setting question or change (model, reasoning effort, /settings) requires a silent readskill call for bundled:manage-settings as FIRST ACTION—no assistant text or other tool…

    69k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • OmniRoute Settings API

    diegosouzapw/OmniRoute

    Read and update global application settings: system prompts, thinking budget, IP filters, payload rules, combo defaults, and require-login configuration.

    75k GitHub stars~3.6k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Builds, flashes and provisions an ESP32-S3 or C6 CSI node for RuView, with checksum-verified flashing, WiFi settings and boot-log evidence that CSI is flowing.

    97k GitHub stars~579 tokensUpdated today
    DevelopmentAuto-check passed
  • Gemini Omni

    calesthio/OpenMontage

    Generate and conversationally edit short videos with Google Gemini Omni Flash (gemini-omni-flash-preview).

    66k GitHub stars~2.1k tokensUpdated 7 days ago
    Media & CreativeAuto-check: notes
  • Requirements

    rizsotto/Bear

    Write, modify, or review a requirement file under docs/requirements -- pick the single owning file, keep the text contract-only, name IDs so they need no explanation, and verify cross-references and…

    6.5k GitHub stars~2k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Argent Settings Permissions

    bbplayer-app/BBPlayer

    Grant, deny, or reset an app's runtime permissions (camera, microphone, photos, contacts, notifications, calendar, location, location-always, media-library, motion, reminders) on an iOS simulator or…

    1.2k GitHub stars~3.8k tokensUpdated 3 days ago
    MobileAuto-check passed

More from forcedotcom/sf-skills

All 252 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated yesterday
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Questions about Service Omni Permission Set Assign

What does Service Omni Permission Set Assign do?

Assign the required Omni permission sets to provisioned agent users. Service Omni Permission Set Assign is an agent skill from forcedotcom/sf-skills. Assign the required Omni permission sets to provisioned agent users.

When should I use Service Omni Permission Set Assign?

Service Omni Permission Set Assign fits situations like: users ask to assign Omni permissions to agents; grant Omni-Channel access; add OmniAgent permissions; repair missing Omni permission assignments.

How do I install Service Omni Permission Set Assign in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill service-omni-permission-set-assign -a claude-code`. Or copy the skill folder (skills/service-omni-permission-set-assign in forcedotcom/sf-skills) into .claude/skills/service-omni-permission-set-assign in your project. Claude Code loads it when a task matches its description.

How do I install Service Omni Permission Set Assign in Codex?

Run `npx skills add forcedotcom/sf-skills --skill service-omni-permission-set-assign -a codex`. Or copy the skill folder (skills/service-omni-permission-set-assign in forcedotcom/sf-skills) into .agents/skills/service-omni-permission-set-assign in your project. Codex loads it when a task matches its description.

Can I use Service Omni Permission Set Assign in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill service-omni-permission-set-assign -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/service-omni-permission-set-assign, .gemini/skills/service-omni-permission-set-assign, .github/skills/service-omni-permission-set-assign and .opencode/skills/service-omni-permission-set-assign in your project.

What does Service Omni Permission Set Assign need to run?

Going by SKILL.md and its folder, Service Omni Permission Set Assign needs a shell for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: A Bash shell. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep.

Does Service Omni Permission Set Assign access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Service Omni Permission Set Assign safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Service Omni Permission Set Assign use?

Service Omni Permission Set Assign is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Service Omni Permission Set Assign use?

About 1.5k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to Service Omni Permission Set Assign?

Skills that share tags, products or a category with Service Omni Permission Set Assign: Manage Settings (asgeirtj/system_prompts_leaks, 69k stars), OmniRoute Settings API (diegosouzapw/OmniRoute, 75k stars), ESP32 CSI Node Provisioning (ruvnet/RuView, 97k stars) and Gemini Omni (calesthio/OpenMontage, 66k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Service Omni Permission Set Assign?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,067 GitHub stars. The repository holds 252 skills in this directory. The repository was last updated on October 9, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.