Agent skill

Service Omni Supervisor Permset Assign

by forcedotcom in forcedotcom/sf-skills

A skill your agent uses to assign the Salesforce-shipped standard ContactCenterSupervisor PermissionSet (default) to N existing supervisor users via PermissionSetAssignment DML.

Apache-2.0Auto-check: notesSales & Support

Install Service Omni Supervisor Permset Assign

skills CLI
$ npx skills add forcedotcom/sf-skills --skill service-omni-supervisor-permset-assign -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills service-omni-supervisor-permset-assign --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/service-omni-supervisor-permset-assign .claude/skills/service-omni-supervisor-permset-assign && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
service-omni-supervisor-permset-assign
GitHub stars
1.1k
Token cost
~1.6k tokens
SKILL.md length
638 words
Files
3 (incl. scripts, references)
Skills in repo
252
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses to assign the Salesforce-shipped standard ContactCenterSupervisor PermissionSet (default) to N existing supervisor users via PermissionSetAssignment DML.

  • Works in 7 steps: Compute safe_to_write; derive the 8-char… → Validate every supplied permission-set… → Resolve the… → …
  • Tasks that involve CRM management
  • SKILL.md covers Inputs, Preconditions and safety, Run and Behavior, plus 3 more sections
  • Runs Shell scripts from its folder; calls bash

What it does

Service Omni Supervisor Permset Assign is an agent skill from forcedotcom/sf-skills. Use to assign the Salesforce-shipped standard ContactCenterSupervisor PermissionSet (default) to N existing supervisor users via PermissionSetAssignment DML. Idempotent — SOQL detects existing (user, perm-set) pairs before POST, and DUPLICATEVALUE is treated as reused. The standard set carries its own permission-set license and assigns cleanly on Service-Cloud-enabled orgs; a user whose license lacks the entitlement surfaces FIELDINTEGRITYEXCEPTION so the operator can fix the profile/license. Triggers: assign the…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/api-notes.md` and `scripts/verify-and-assign.sh`).

It sits in Sales & Support, covering CRM management. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve CRM management

Example prompts

  • “/service-omni-supervisor-permset-assign”

Requirements

  • A Bash shell
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Edit, Glob, Grep

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Compute safe_to_write; derive the 8-char org suffix.
  2. Validate every supplied permission-set name as a well-formed DeveloperName (SOQL-injection guard) before any sf call.
  3. Resolve the supervisor{1..N}.@example.com users, filtered to IsActive=true; block if fewer than count are active (an inactive occupant…
  4. Resolve each PermissionSet by name; block naming which is missing.
  5. Query existing PermissionSetAssignment for the (user × set) cross-product; compute the missing pairs.
  6. POST one assignment per missing pair (individual POSTs, no allOrNone); treat DUPLICATE_VALUE as reused.
  7. Re-query to confirm final state and emit the report.

What it can do on your machine

Read from SKILL.md and the folder at commit 4bbae5c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Edit
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Service Omni Supervisor Permset Assign loads about 1.6k tokens when it runs, and up to ~2.6k if it reads all its reference files. Until then it costs about 174 tokens; SKILL.md has 638 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~174
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Edit, Glob, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit 4bbae5c, republished under its Apache-2.0 licence (© forcedotcom). 638 words, ~1,621 tokens.

Download SKILL.mdSave it as .claude/skills/service-omni-supervisor-permset-assign/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
service-omni-supervisor-permset-assign
description
Use to assign the Salesforce-shipped standard ContactCenterSupervisor PermissionSet (default) to N existing supervisor users via PermissionSetAssignment DML. Idempotent — SOQL detects existing (user, perm-set) pairs before POST, and DUPLICATE_VALUE is treated as reused. The standard set carries its own permission-set license and assigns cleanly on Service-Cloud-enabled orgs; a user whose license lacks the entitlement surfaces FIELD_INTEGRITY_EXCEPTION so the operator can fix the profile/license. Triggers: assign the supervisor permset, grant supervisor perms, complete supervisor provisioning. Do not use on production orgs or to assign agent permsets.
allowed-tools
Bash, Read, Write, Edit, Glob, Grep
metadata.version
1.0
metadata.domains
Service
metadata.minApiVersion
66.0
metadata.relatedSkills
service-omni-supervisor-config-deploy

service-omni-supervisor-permset-assign

Assign the Salesforce-shipped standard ContactCenterSupervisor PermissionSet to existing supervisor users via PermissionSetAssignment. The classic Omni-Channel Supervisor UI (Command Center) requires supervisors to hold contact-center supervisor permissions before service-omni-supervisor-config-deploy can bind them. The skill uses detect-before-POST idempotency and treats DUPLICATE_VALUE as an already-satisfied assignment.

Licensing. The supervisor system permissions (IsContactCenterSupervisor, OmniSupervisorManageQueue, ViewOmnichnlAnlytDshbrd) are gated by a permission-set license. The standard ContactCenterSupervisor set carries its own license linkage and assigns cleanly on a Service-Cloud-enabled org, so it is the default and supported path — a hand-rolled custom set that re-declares these permissions fails with FIELD_INTEGRITY_EXCEPTION. If a specific user's license lacks the underlying entitlement, the assignment surfaces that same exception so the operator can move the user to a profile/license that carries it.

That custom-permission-set warning does not mean assigning the existing Salesforce-shipped ContactCenterSupervisor set removes access or rewrites the set. This skill only creates a missing PermissionSetAssignment; it never creates, edits, or replaces the permission set itself.

Inputs

bash
bash scripts/verify-and-assign.sh <org-alias> [count=1] [permission-set-names-csv=ContactCenterSupervisor]
  • org-alias (required).
  • count (optional, default 1, range 1..5) — must match the supervisor user count.
  • permission-set-names-csv (optional, default ContactCenterSupervisor) — comma-separated for multiple. Every supervisor gets every listed set (cross-product).

Preconditions and safety

  • Target org authenticated via sf CLI, Service Cloud license, sf CLI ≥ 2.139.6.
  • The supervisor users exist and are active; fewer than count active users blocks with a remediation message.
  • The ContactCenterSupervisor set is Salesforce-shipped and present on any Service-Cloud-enabled org; a custom name that is missing blocks with a Setup click-path.
  • The executing user has PermissionsAssignPermissionSets (standard on System Administrator) — required even for org admins.
  • The three-way safe_to_write production guard applies — assigning permission sets on a production org can escalate a real user's privileges, so it blocks with no override.

Run

verify-and-assign.sh performs the whole cycle:

  1. Compute safe_to_write; derive the 8-char org suffix.
  2. Validate every supplied permission-set name as a well-formed DeveloperName (SOQL-injection guard) before any sf call.
  3. Resolve the supervisor{1..N}.<suffix>@example.com users, filtered to IsActive=true; block if fewer than count are active (an inactive occupant does not satisfy the count).
  4. Resolve each PermissionSet by name; block naming which is missing.
  5. Query existing PermissionSetAssignment for the (user × set) cross-product; compute the missing pairs.
  6. POST one assignment per missing pair (individual POSTs, no allOrNone); treat DUPLICATE_VALUE as reused.
  7. Re-query to confirm final state and emit the report.
Show full SKILL.md (258 more words)Show less

Behavior

Cross-product. Every supervisor gets every listed set; a partial assignment is a failure, not a feature.

Idempotency. PermissionSetAssignment has a uniqueness constraint on (AssigneeId, PermissionSetId), so a re-POST raises DUPLICATE_VALUE; the skill detects existing pairs first and treats that as reused for concurrent-run safety. POSTs are individual so one error never rolls back its siblings, and it re-queries after all POSTs — a 201 only means the write was accepted; a SOQL confirms it is active.

Non-destructive. Create-only; it never deletes existing assignments (supervisors may hold out-of-band permissions) and derives users from the supervisor pattern rather than an explicit id list.

Output contract

A single JSON object with status ∈ assigned | reused | partial | blocked, the resolved permission_sets, org_suffix, requested_count, expected_assignment_count (= requested_count × len(permission_sets)), a before snapshot, assigned_this_run/assigned_count, reused_count, an after snapshot, manual_actions, and blocking_issue.

  • assigned — at least one new assignment created; all expected pairs exist after.
  • reused — all expected pairs already existed; nothing POSTed.
  • partial — some POSTs failed; final count is below expected.
  • blocked — precondition failed (production org, missing set, missing/inactive users, or a license that does not allow the permission).

assigned_count + reused_count == expected_assignment_count unless partial; blocking_issue is non-null only for blocked/partial.

Limitations

  • Provisioning the user license that the supervisor permset requires is the users-create skill's responsibility, not this one.
  • Assigns individual PermissionSets only — a PermissionSetGroup is a different sObject and is out of scope.
  • Create-only; it does not remove assignments.

References

FileWhen to read
references/api-notes.mdBefore the POST loop — PermissionSetAssignment schema, DUPLICATE_VALUE semantics, and why users are derived from the supervisor pattern rather than an explicit id list

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in skills/service-omni-supervisor-permset-assign of forcedotcom/sf-skills.

  • SKILL.md
  • references/api-notes.md
  • scripts/verify-and-assign.sh

Open the folder on GitHubat commit 4bbae5c

Compare with similar skills

Service Omni Supervisor Permset Assign next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Service Omni Supervisor Permset Assign compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Service Omni Supervisor Permset Assign this skillforcedotcom/sf-skills1.1k—~1.6kAutomated safety check: NotesApache-2.0
Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib154—~4.3kAutomated safety check: PassMIT
Sf DatacloudJaganpro/sf-skills424—~2.7kAutomated safety check: PassMIT
Soql Lib Selectorbeyond-the-cloud-dev/soql-lib154—~2kAutomated safety check: PassMIT
Dev SetupPortwood-Global-Solutions/Portwood126—~1.1kAutomated safety check: PassApache-2.0
Sf FlowJaganpro/sf-skills424—~1.8kAutomated safety check: PassMIT

Similar skills

  • Soql Lib Query Builder

    beyond-the-cloud-dev/soql-lib

    Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).

    154 GitHub stars~4.3k tokensUpdated 8 days ago
    Sales & SupportAuto-check passed
  • Sf Datacloud

    Jaganpro/sf-skills

    Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.

    424 GitHub stars~2.7k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Soql Lib Selector

    beyond-the-cloud-dev/soql-lib

    Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.

    154 GitHub stars~2k tokensUpdated 8 days ago
    Sales & SupportAuto-check passed
  • Dev Setup

    Portwood-Global-Solutions/Portwood

    Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.

    126 GitHub stars~1.1k tokensUpdated yesterday
    Sales & SupportAuto-check passed
  • Sf Flow

    Jaganpro/sf-skills

    Creates and validates Salesforce Flows with 110-point scoring.

    424 GitHub stars~1.8k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Google Maps Export

    gmapsscraper/google-maps-agent-skills

    Export Google Maps business data to CSV, JSON, or CRM format (HubSpot, Pipedrive, Salesforce).

    132 GitHub stars~1.2k tokensUpdated 4 mo ago
    Sales & SupportAuto-check passed

More from forcedotcom/sf-skills

All 252 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated yesterday
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Service Omni Supervisor Permset Assign

What does Service Omni Supervisor Permset Assign do?

A skill your agent uses to assign the Salesforce-shipped standard ContactCenterSupervisor PermissionSet (default) to N existing supervisor users via PermissionSetAssignment DML. Service Omni Supervisor Permset Assign is an agent skill from forcedotcom/sf-skills. Use to assign the Salesforce-shipped standard ContactCenterSupervisor PermissionSet (default) to N existing supervisor users via PermissionSetAssignment DML.

When should I use Service Omni Supervisor Permset Assign?

Service Omni Supervisor Permset Assign fits situations like: tasks that involve CRM management.

How do I install Service Omni Supervisor Permset Assign in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill service-omni-supervisor-permset-assign -a claude-code`. Or copy the skill folder (skills/service-omni-supervisor-permset-assign in forcedotcom/sf-skills) into .claude/skills/service-omni-supervisor-permset-assign in your project. Claude Code loads it when a task matches its description.

How do I install Service Omni Supervisor Permset Assign in Codex?

Run `npx skills add forcedotcom/sf-skills --skill service-omni-supervisor-permset-assign -a codex`. Or copy the skill folder (skills/service-omni-supervisor-permset-assign in forcedotcom/sf-skills) into .agents/skills/service-omni-supervisor-permset-assign in your project. Codex loads it when a task matches its description.

Can I use Service Omni Supervisor Permset Assign in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill service-omni-supervisor-permset-assign -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/service-omni-supervisor-permset-assign, .gemini/skills/service-omni-supervisor-permset-assign, .github/skills/service-omni-supervisor-permset-assign and .opencode/skills/service-omni-supervisor-permset-assign in your project.

What does Service Omni Supervisor Permset Assign need to run?

Going by SKILL.md and its folder, Service Omni Supervisor Permset Assign needs a shell for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: A Bash shell. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep.

Does Service Omni Supervisor Permset Assign access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Service Omni Supervisor Permset Assign safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Service Omni Supervisor Permset Assign use?

Service Omni Supervisor Permset Assign is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Service Omni Supervisor Permset Assign use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 989 tokens, read only when the agent opens those files.

What are the alternatives to Service Omni Supervisor Permset Assign?

Skills that share tags, products or a category with Service Omni Supervisor Permset Assign: Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars), Sf Datacloud (Jaganpro/sf-skills, 424 stars), Soql Lib Selector (beyond-the-cloud-dev/soql-lib, 154 stars) and Dev Setup (Portwood-Global-Solutions/Portwood, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Service Omni Supervisor Permset Assign?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,067 GitHub stars. The repository holds 252 skills in this directory. The repository was last updated on October 9, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.