Agent skill

Service Omni Supervisor Users Create

by forcedotcom in forcedotcom/sf-skills

A skill your agent uses to create N Omni-Channel supervisor users on a Salesforce org via Anonymous Apex, using the supervisor{i}.<suffix@example.com pattern with SOQL-based idempotency (re-runs…

Apache-2.0Auto-check: notesSales & Support

Install Service Omni Supervisor Users Create

skills CLI
$ npx skills add forcedotcom/sf-skills --skill service-omni-supervisor-users-create -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills service-omni-supervisor-users-create --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/service-omni-supervisor-users-create .claude/skills/service-omni-supervisor-users-create && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
service-omni-supervisor-users-create
GitHub stars
1.1k
Token cost
~2.1k tokens
SKILL.md length
829 words
Files
7 (incl. scripts, references, assets)
Skills in repo
251
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses to create N Omni-Channel supervisor users on a Salesforce org via Anonymous Apex, using the supervisor{i}.<suffix@example.com pattern with SOQL-based idempotency (re-runs…

  • Create N Omni-Channel supervisor users on a Salesforce org via Anonymous Apex
  • SKILL.md covers Inputs, Preconditions and safety, Run and Behavior, plus 3 more sections
  • Runs Shell scripts from its folder; calls bash and sf
  • Using the supervisor{i}.<suffix@example.com pattern with SOQL-based idempotency (re-runs skip existing usernames)

What it does

Service Omni Supervisor Users Create is an agent skill from forcedotcom/sf-skills. Use to create N Omni-Channel supervisor users on a Salesforce org via Anonymous Apex, using the supervisor{i}.<suffix@example.com pattern with SOQL-based idempotency (re-runs skip existing usernames). Passwords are set via System.setPassword and handled fail-closed: the wrapper proves no active debug TraceFlag before setting a password, and otherwise leaves the user ACTIVE and resetrequired. Triggers: create supervisor users, provision supervisor accounts, scaffold supervisor personas. Do not use on production…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts, reference files and assets (for example `references/apex-patterns.md`, `references/apex-template-notes.md` and `scripts/detect-and-create.sh`).

It sits in Sales & Support, covering CRM management. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • Create N Omni-Channel supervisor users on a Salesforce org via Anonymous Apex
  • Using the supervisor{i}.<suffix@example.com pattern with SOQL-based idempotency (re-runs skip existing usernames)

Example prompts

  • “/service-omni-supervisor-users-create”

Requirements

  • A Bash shell
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Edit, Glob, Grep

What it can do on your machine

Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Edit
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • sf

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Service Omni Supervisor Users Create loads about 2.1k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 197 tokens; SKILL.md has 829 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~197
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Edit, Glob, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 829 words, ~2,101 tokens.

Download SKILL.mdSave it as .claude/skills/service-omni-supervisor-users-create/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
service-omni-supervisor-users-create
description
Use to create N Omni-Channel supervisor users on a Salesforce org via Anonymous Apex, using the supervisor{i}.<suffix>@example.com pattern with SOQL-based idempotency (re-runs skip existing usernames). Passwords are set via System.setPassword and handled fail-closed: the wrapper proves no active debug TraceFlag before setting a password, and otherwise leaves the user ACTIVE and reset_required. Triggers: create supervisor users, provision supervisor accounts, scaffold supervisor personas. Do not use on production customer orgs (blocked by the safe_to_write guard), to bind supervisors to OmniSupervisorConfig (service-omni-supervisor-config-deploy), or to assign the ContactCenterSupervisor permission set (service-omni-supervisor-permset-assign).
allowed-tools
Bash, Read, Write, Edit, Glob, Grep
metadata.version
1.0
metadata.domains
Service
metadata.minApiVersion
66.0
metadata.relatedSkills
service-omni-agent-users-create, service-omni-supervisor-config-deploy, service-omni-supervisor-permset-assign

service-omni-supervisor-users-create

Create N supervisor users on a Salesforce org for the classic Omni-Channel Supervisor Configuration (OmniSupervisorConfig), which binds named user records via OmniSupervisorConfigUser. Users follow a deterministic supervisor{i}.<suffix>@example.com pattern so the coordinator can rediscover them across runs. It is the supervisor counterpart to service-omni-agent-users-create and shares its detection, password, and idempotency model; the only differences are the username/alias prefixes and the debug-log marker. Binding these users into a config (service-omni-supervisor-config-deploy) and granting them supervisor access (service-omni-supervisor-permset-assign) are separate leaves.

Inputs

Confirm once, up front:

  • org-alias (required, no default) — must resolve via sf org display.
  • Supervisor count (optional, default 1, range 1..5; the coordinator typically requests 1).
  • Profile name (optional, default Standard User). The coordinator overrides this to a Service Cloud profile so supervisors consume Service Cloud licenses; supervisor access itself comes from the standard ContactCenterSupervisor permission set assigned later.

Usernames and passwords are never accepted from the operator — both are generated (usernames from the org suffix, passwords via Anonymous Apex).

Preconditions and safety

  • Target org authenticated via sf CLI (My Domain URL, not .lightning.force.com), Service Cloud license present, sf CLI ≥ 2.139.6.
  • The executing user has PermissionsModifyAllData and PermissionsManagePasswordPolicies (standard on System Administrator).
  • Production guardrail: the detect script computes safe_to_write as IsSandbox OR TrialExpirationDate != null OR OrganizationType in {Developer Edition, Base Edition}, and the skill blocks with no override when it is false. CDOs, scratch orgs, and dev orgs are permitted.

Password handling (fail-closed). Passwords are set by Anonymous Apex System.setPassword (sf user password generate cannot target Apex-inserted users). The literal appears in the inline executeAnonymous debug log and, only when a debug-log TraceFlag is active for the running user, in a queryable ApexLog. The wrapper therefore fails closed before the first System.setPassword: it proves via a SOQL-filtered Tooling API query (ExpirationDate > now) that no active TraceFlag exists. If safety cannot be positively proven, it sets no password at all; the user is left ACTIVE, flagged password_status:"reset_required", and a security_warning explains why. It never deletes logs. A user whose password could not be set is kept ACTIVE and flagged for reset — never deactivated.

Run

bash
# read-only preview (never writes)
bash scripts/detect-and-create.sh plan <org-alias> [count] [profile-name]
# detect, enforce safe_to_write, then insert only the missing supervisors
bash scripts/detect-and-create.sh run  <org-alias> [count=1] [profile-name="Standard User"]

detect-and-create.sh is the canonical entry point: it re-runs detection, enforces the production guard, and only then inserts. Do not call scripts/run-create.sh directly — it is internal and does not enforce the guard.

Behavior

Detection. The detector derives an 8-char suffix from Organization.Id, resolves the profile by name, and queries User for supervisor{i}.<suffix>@example.com, splitting occupied slots into active existing_users and inactive_users.

Insertion. The Apex loads assets/create-supervisors.apex.template, substitutes __COUNT__/__PROFILE_ID__/__SUFFIX__, and inserts only the missing indexes, re-checking inside the transaction to prevent a single run from double-inserting; across concurrent runs this check is not a guarantee (both can pass their pre-query before either commits), so duplicate protection there relies on the global username-uniqueness constraint plus the DUPLICATE_USERNAME retry (see references/apex-template-notes.md). Created users get the Service Cloud feature (UserPermissionsSupportUser=true); if the profile's license does not allow it, the Apex strips the flag and retries (the permset assign will then block until the user is on a suitable license). Each created user is reported via SUPERVISOR_CREATED|<id>|<username>|<email> (no password in the marker — it is set by the separate System.setPassword submission).

Inactive occupants. An inactive user occupying a supervisor slot is not a reusable supervisor and cannot be recreated (usernames are globally unique). It is surfaced as a required manual reactivation and never counted toward the requested slots — counting it would under-provision the config.

Verification. After insertion the detector re-runs and must show missing_count == 0.

Show full SKILL.md (259 more words)Show less

Output contract

detect-and-create.sh emits a single JSON object with status ∈ created | partial | reused | action_needed | blocked, plus detect, create (null when nothing was created), created_count, reused_count, total_present_after, users_needing_password_reset, action_required, and safe_to_write.

  • created — every missing index landed with a working password.
  • partial — some landed but not all, any System.setPassword failed (kept ACTIVE, listed in users_needing_password_reset), or a slot is occupied by an inactive user needing reactivation.
  • reused — all requested slots already existed; no DML.
  • action_needed — plan mode only.
  • blocked — precondition failed.

create.created_users[].password is populated only for users created this run whose System.setPassword succeeded. create.rolled_back_users is always empty (this skill never deactivates a user). Generated passwords are a secret: the returned JSON is the only place they appear; a caller that persists stdout must write it only to a restricted CREDENTIALS.json (mode 0600), redact it elsewhere, and delete it after distribution — the coordinator does this automatically.

Limitations

  • Username pattern and org suffix are fixed and never operator-configurable — that determinism is what enables idempotent re-runs.
  • Creates only supervisor users; it never deletes or deactivates users, including orphaned supervisors from prior runs.
  • Common User errors (DUPLICATE_USERNAME, INVALID_EMAIL, LICENSE_LIMIT_EXCEEDED) are translated into operator-friendly messages rather than surfaced raw.

References

FileWhen to read
references/apex-patterns.mdBefore running the Apex — Apex structure, User field defaults, password policy, and the profile-localization risk
references/apex-template-notes.mdWhen creation returns a duplicate, license, password, or trace-safety error
assets/create-supervisors.apex.templateLoaded by scripts/run-create.sh when missing supervisor users must be inserted
scripts/detect-existing.shLoaded by scripts/detect-and-create.sh for the read-only org, profile, safety, and existing-user checks
scripts/run-create.shInternal writer loaded by scripts/detect-and-create.sh only after guard checks pass

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references, assets) in skills/service-omni-supervisor-users-create of forcedotcom/sf-skills.

  • SKILL.md
  • assets/create-supervisors.apex.template
  • references/apex-patterns.md
  • references/apex-template-notes.md
  • scripts/detect-and-create.sh
  • scripts/detect-existing.sh
  • scripts/run-create.sh

Open the folder on GitHubat commit e5164d9

Compare with similar skills

Service Omni Supervisor Users Create next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Service Omni Supervisor Users Create compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Service Omni Supervisor Users Create this skillforcedotcom/sf-skills1.1k—~2.1kAutomated safety check: NotesApache-2.0
Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib154—~4.3kAutomated safety check: PassMIT
Sf DatacloudJaganpro/sf-skills424—~2.7kAutomated safety check: PassMIT
Soql Lib Selectorbeyond-the-cloud-dev/soql-lib154—~2kAutomated safety check: PassMIT
Dev SetupPortwood-Global-Solutions/Portwood126—~1.1kAutomated safety check: PassApache-2.0
Sf FlowJaganpro/sf-skills424—~1.8kAutomated safety check: PassMIT

Similar skills

  • Soql Lib Query Builder

    beyond-the-cloud-dev/soql-lib

    Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).

    154 GitHub stars~4.3k tokensUpdated 6 days ago
    Sales & SupportAuto-check passed
  • Sf Datacloud

    Jaganpro/sf-skills

    Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.

    424 GitHub stars~2.7k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Soql Lib Selector

    beyond-the-cloud-dev/soql-lib

    Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.

    154 GitHub stars~2k tokensUpdated 6 days ago
    Sales & SupportAuto-check passed
  • Dev Setup

    Portwood-Global-Solutions/Portwood

    Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.

    126 GitHub stars~1.1k tokensUpdated today
    Sales & SupportAuto-check passed
  • Sf Flow

    Jaganpro/sf-skills

    Creates and validates Salesforce Flows with 110-point scoring.

    424 GitHub stars~1.8k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Google Maps Export

    gmapsscraper/google-maps-agent-skills

    Export Google Maps business data to CSV, JSON, or CRM format (HubSpot, Pipedrive, Salesforce).

    132 GitHub stars~1.2k tokensUpdated 4 mo ago
    Sales & SupportAuto-check passed

More from forcedotcom/sf-skills

All 251 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated 2 days ago
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated 2 days ago
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated 2 days ago
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated 2 days ago
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Service Omni Supervisor Users Create

What does Service Omni Supervisor Users Create do?

A skill your agent uses to create N Omni-Channel supervisor users on a Salesforce org via Anonymous Apex, using the supervisor{i}.<suffix@example.com pattern with SOQL-based idempotency (re-runs…. Service Omni Supervisor Users Create is an agent skill from forcedotcom/sf-skills.com pattern with SOQL-based idempotency (re-runs skip existing usernames).

When should I use Service Omni Supervisor Users Create?

Service Omni Supervisor Users Create fits situations like: create N Omni-Channel supervisor users on a Salesforce org via Anonymous Apex; using the supervisor{i}.<suffix@example.com pattern with SOQL-based idempotency (re-runs skip existing usernames).

How do I install Service Omni Supervisor Users Create in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill service-omni-supervisor-users-create -a claude-code`. Or copy the skill folder (skills/service-omni-supervisor-users-create in forcedotcom/sf-skills) into .claude/skills/service-omni-supervisor-users-create in your project. Claude Code loads it when a task matches its description.

How do I install Service Omni Supervisor Users Create in Codex?

Run `npx skills add forcedotcom/sf-skills --skill service-omni-supervisor-users-create -a codex`. Or copy the skill folder (skills/service-omni-supervisor-users-create in forcedotcom/sf-skills) into .agents/skills/service-omni-supervisor-users-create in your project. Codex loads it when a task matches its description.

Can I use Service Omni Supervisor Users Create in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill service-omni-supervisor-users-create -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/service-omni-supervisor-users-create, .gemini/skills/service-omni-supervisor-users-create, .github/skills/service-omni-supervisor-users-create and .opencode/skills/service-omni-supervisor-users-create in your project.

What does Service Omni Supervisor Users Create need to run?

Going by SKILL.md and its folder, Service Omni Supervisor Users Create needs a shell for the scripts in its folder and the command-line tools its instructions call (bash and sf). Our summary lists: A Bash shell. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep.

Does Service Omni Supervisor Users Create access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Service Omni Supervisor Users Create safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Service Omni Supervisor Users Create use?

Service Omni Supervisor Users Create is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Service Omni Supervisor Users Create use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Service Omni Supervisor Users Create?

Skills that share tags, products or a category with Service Omni Supervisor Users Create: Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars), Sf Datacloud (Jaganpro/sf-skills, 424 stars), Soql Lib Selector (beyond-the-cloud-dev/soql-lib, 154 stars) and Dev Setup (Portwood-Global-Solutions/Portwood, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Service Omni Supervisor Users Create?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,065 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.