AL permission set design for Business Central. An agent skill from javiarmesto/ALDC-AL-Development-Collection.

MITAuto-check passed

Install Skill Permissions

skills CLI
$ npx skills add javiarmesto/ALDC-AL-Development-Collection --skill skill-permissions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install javiarmesto/ALDC-AL-Development-Collection skill-permissions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/javiarmesto/ALDC-AL-Development-Collection.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skill-permissions .claude/skills/skill-permissions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-permissions
GitHub stars
109
Token cost
~2.5k tokens
SKILL.md length
712 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

AL permission set design for Business Central. An agent skill from javiarmesto/ALDC-AL-Development-Collection.

  • Works in 5 steps: Analyze Required Permissions → HITL Security Gate (MANDATORY) → Generate and Refine → …
  • Creating PermissionSets
  • SKILL.md covers Purpose, When to Load, Core Patterns and Workflow, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Skill Permissions is an agent skill from javiarmesto/ALDC-AL-Development-Collection. AL permission set design for Business Central. Use when creating PermissionSets, implementing least-privilege access, or designing security models for extensions.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: AL development toolkit for Business Central with specialist agents, skills and review workflows for Copilot, Claude Code and Codex. The licence is MIT.

When your agent uses it

  • Creating PermissionSets
  • Implementing least-privilege access
  • Designing security models for extensions

Example prompts

  • “/skill-permissions”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Analyze Required Permissions
  2. HITL Security Gate (MANDATORY)
  3. Generate and Refine
  4. Test with Restrictive Permissions
  5. Document Permission Model

What it can do on your machine

Read from SKILL.md and the folder at commit 4f99d7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are al, xml and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Permissions loads about 2.5k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 712 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from javiarmesto/ALDC-AL-Development-Collection at commit 4f99d7d, republished under its MIT licence (© javiarmesto). 712 words, ~2,539 tokens.

Download SKILL.mdSave it as .claude/skills/skill-permissions/SKILL.md (or your agent's skills folder).
name
skill-permissions
description
AL permission set design for Business Central. Use when creating PermissionSets, implementing least-privilege access, or designing security models for extensions.

Skill: AL Permission Management

Purpose

Generate and manage permission sets for AL Business Central extensions following the principle of least privilege: role-based permission design, AL vs XML formats, permission set extensions, and security validation.

When to Load

This skill should be loaded when:

  • A new extension needs its permission sets generated
  • Permission errors surface at runtime ("You do not have permission to…")
  • Role-based access control is being designed for an extension
  • A security or compliance review requires permission documentation
  • Permission set extensions need to be created for base-app objects

Core Patterns

Pattern 1: AL Permission Set Object (Preferred)

Generate with the VS Code permission-set generation command (not an agent tool), then refine:

al
permissionset 50100 "Contoso Sales"
{
    Assignable = true;
    Caption = 'Contoso Sales Permissions';

    Permissions =
        // Tables — object-level execute
        table "Contoso Sales Setup" = X,
        table "Contoso Discount Rule" = X,
        // Table data — RIMD granularity
        tabledata "Contoso Sales Setup" = R,          // read-only for most users
        tabledata "Contoso Discount Rule" = RIMD,     // full CRUD
        // Executable objects
        codeunit "Contoso Sales Management" = X,
        page "Contoso Sales Setup Card" = X,
        page "Contoso Discount Rules List" = X,
        report "Contoso Sales Summary" = X,
        xmlport "Contoso Sales Import" = X;
}

Permission letters for tabledata:

LetterMeaningGrant when…
RReadUser needs to view data
IInsertUser needs to create records
MModifyUser needs to edit existing records
DDeleteUser needs to remove records (grant sparingly)

For non-tabledata objects (table, codeunit, page, report, xmlport, query):

  • X = Execute / Run
  • 0 = No permission (omit the line instead)
Pattern 2: Role-Based Hierarchy (Least Privilege)

Design a layered permission structure — each role includes only what it needs:

al
// Layer 1: Base — read-only access shared by all roles
permissionset 50100 "Contoso Base"
{
    Assignable = false;                   // not directly assignable to users
    Caption = 'Contoso Base (Read)';

    Permissions =
        tabledata "Contoso Sales Setup" = R,
        tabledata "Contoso Discount Rule" = R,
        page "Contoso Sales Setup Card" = X,
        page "Contoso Discount Rules List" = X;
}

// Layer 2: User — standard operations (includes Base)
permissionset 50101 "Contoso User"
{
    Assignable = true;
    Caption = 'Contoso User';

    IncludedPermissionSets = "Contoso Base";

    Permissions =
        tabledata "Contoso Discount Rule" = IM,      // create + edit (no delete)
        codeunit "Contoso Sales Management" = X,
        report "Contoso Sales Summary" = X;
}

// Layer 3: Admin — full control (includes User)
permissionset 50102 "Contoso Admin"
{
    Assignable = true;
    Caption = 'Contoso Admin';

    IncludedPermissionSets = "Contoso User";

    Permissions =
        tabledata "Contoso Sales Setup" = RIMD,       // full CRUD on setup
        tabledata "Contoso Discount Rule" = D,         // adds Delete
        xmlport "Contoso Sales Import" = X;            // data import only for admin
}

Design rules:

  • Assignable = false for base/internal layers — only assign leaf-level sets to users
  • IncludedPermissionSets builds hierarchy — no need to repeat parent permissions
  • Separate functional areas into distinct sets when the extension covers multiple domains
Pattern 3: Permission Set Extension

Extend existing BC permission sets to include your extension's objects — so users with standard roles automatically get access:

al
permissionsetextension 50100 "Contoso D365 Sales Ext" extends "D365 SALES"
{
    Permissions =
        tabledata "Contoso Discount Rule" = RIMD,
        codeunit "Contoso Sales Management" = X,
        page "Contoso Discount Rules List" = X;
}

permissionsetextension 50101 "Contoso D365 Read Ext" extends "D365 READ"
{
    Permissions =
        tabledata "Contoso Sales Setup" = R,
        tabledata "Contoso Discount Rule" = R,
        page "Contoso Sales Setup Card" = X;
}

When to use permissionsetextension:

  • Your objects should be accessible to users who already have a standard BC role
  • Avoids requiring admins to manually assign a new permission set to every user
  • Always limit to what that role level logically needs (read-only for D365 READ, full for D365 SALES)
Pattern 4: XML Permission Set (Legacy Format)

Generate the XML format via the VS Code permission-set command (not an agent tool) when:

  • Targeting older BC versions (< BC 20)
  • Import via BC admin UI is required
  • Customer tooling only supports XML format
xml
<?xml version="1.0" encoding="utf-8"?>
<PermissionSets>
  <PermissionSet RoleID="CONTOSO-SALES" RoleName="Contoso Sales Permissions">
    <Permission>
      <ObjectType>0</ObjectType>         <!-- TableData -->
      <ObjectID>50100</ObjectID>
      <ReadPermission>1</ReadPermission>
      <InsertPermission>1</InsertPermission>
      <ModifyPermission>1</ModifyPermission>
      <DeletePermission>0</DeletePermission>
    </Permission>
    <Permission>
      <ObjectType>5</ObjectType>         <!-- Codeunit -->
      <ObjectID>50100</ObjectID>
      <ExecutePermission>1</ExecutePermission>
    </Permission>
  </PermissionSet>
</PermissionSets>

XML ObjectType codes: 0 = TableData, 1 = Table, 3 = Report, 5 = Codeunit, 6 = XMLport, 8 = Page, 9 = Query.

Prefer AL format for new development — it lives in source control, participates in build, and supports IncludedPermissionSets.

Pattern 5: Indirect Permissions and TestPermissions

Some objects are accessed indirectly (via codeunit calls) and need indirect permission:

al
// In the codeunit that accesses data on behalf of the user
codeunit 50100 "Contoso Sales Management"
{
    Permissions =
        tabledata "Contoso Internal Log" = RIMD;   // indirect — user doesn't access directly
}

For test codeunits, set the permission level to validate security:

al
codeunit 50200 "Contoso Sales Test"
{
    Subtype = Test;
    TestPermissions = Restrictive;   // NonRestrictive | Restrictive | Disabled

    [Test]
    procedure TestUserCanCreateDiscount()
    var
        PermissionsMock: Codeunit "Library - Lower Permissions";
    begin
        // Simulate a user with only "Contoso User" permissions
        PermissionsMock.SetOutsidePermissionSet("Contoso User");

        // Test that user CAN create discount rule
        // ...
    end;
}

Workflow

Step 1: Analyze Required Permissions
  1. List all custom objects in the extension (tables, pages, codeunits, reports, xmlports)
  2. For each object, determine the minimum access level needed per role
  3. Identify base-app objects accessed indirectly (need Permissions property on codeunit)
  4. Map roles to permission layers: Base (read) → User (operate) → Admin (configure + delete)
Show full SKILL.md (261 more words)Show less
Step 2: HITL Security Gate (MANDATORY)

STOP — present the permission matrix to the user before generating:

markdown
| Object | Type | Base (R) | User | Admin |
|---|---|---|---|---|
| Contoso Sales Setup | tabledata | R | R | RIMD |
| Contoso Discount Rule | tabledata | R | RIM | RIMD |
| Contoso Sales Mgmt | codeunit | — | X | X |
| Contoso Sales Import | xmlport | — | — | X |

Justify each permission and confirm the principle of least privilege is respected. Wait for explicit approval before generating permission sets.

Step 3: Generate and Refine
  1. Generate the initial full set via the VS Code permission-set command (not an agent tool)
  2. Split into role-based layers (Pattern 2)
  3. Create permissionsetextension for standard BC roles if needed (Pattern 3)
  4. Add indirect permissions to codeunits (Pattern 5)
  5. Build: al_build — verify no errors
Step 4: Test with Restrictive Permissions
  1. Set TestPermissions = Restrictive on test codeunits
  2. Run tests simulating each role
  3. Verify: users with "Base" CANNOT create/modify/delete
  4. Verify: users with "User" CAN operate but NOT delete setup data
  5. Verify: users with "Admin" have full access
  6. Document any runtime permission errors and adjust sets
Step 5: Document Permission Model

Include in the extension's documentation or architecture file:

  • Role matrix (object × role × RIMD)
  • Rationale for elevated permissions (Delete, setup tables)
  • Permission set extension mappings to standard BC roles
  • Indirect permissions declared on codeunits

References

Constraints

  • NEVER generate permission sets without HITL security gate approval (Step 2)
  • NEVER grant D (Delete) on setup/configuration tables unless explicitly justified
  • NEVER grant permissions on system tables — use appropriate APIs instead
  • NEVER set Assignable = true on intermediate/base layers (only leaf-level sets)
  • Permission errors at runtime → load skill-debug.md for investigation
  • Data sensitivity classification and GDPR → outside this skill scope

© javiarmesto, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/skill-permissions of javiarmesto/ALDC-AL-Development-Collection.

Open the folder on GitHubat commit 4f99d7d

Compare with similar skills

Skill Permissions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Permissions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Permissions this skilljaviarmesto/ALDC-AL-Development-Collection109—~2.5kAutomated safety check: PassMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
SageMaker IAM Role Preflighthuggingface/skills11k1 repos~1.8kAutomated safety check: PassApache-2.0
K8s Security PoliciesCybereason-Public/owLSM28012 repos~2kAutomated safety check: PassGPL-2.0
Ccfddl X Postsccfddl/ccf-deadlines9.4k—~5.6kAutomated safety check: PassMIT
Payloadpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Official

    Finds or validates a usable SageMaker execution role before deploying or training, so scripts do not try to create IAM roles they lack permission to create.

    11k GitHub starsUsed in 1 repo~1.8k tokens
    DevOps & CloudAuto-check passed
  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 12 repos~2k tokens
    Backend & APIsAuto-check passed
  • Ccfddl X Posts

    ccfddl/ccf-deadlines

    Prepare and, with a verified authenticated publishing route and authorization, publish daily conference-deadline countdown posts for @ccfddl on X/Twitter.

    9.4k GitHub stars~5.6k tokensUpdated today
    Media & CreativeAuto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from javiarmesto/ALDC-AL-Development-Collection

All 14 skills in this repo
  • Skill Agent Instructions

    javiarmesto/ALDC-AL-Development-Collection

    Generate, review, and optimize natural language instructions for Business Central agents (Designer or SDK).

    109 GitHub stars~2.8k tokensUpdated 3 days ago
    Auto-check passed
  • Skill API

    javiarmesto/ALDC-AL-Development-Collection

    AL API development patterns for Business Central. An agent skill from javiarmesto/ALDC-AL-Development-Collection.

    109 GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed
  • Skill Copilot

    javiarmesto/ALDC-AL-Development-Collection

    AL Copilot capability development for Business Central. An agent skill from javiarmesto/ALDC-AL-Development-Collection.

    109 GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed
  • Skill Migrate

    javiarmesto/ALDC-AL-Development-Collection

    AL version migration for Business Central. An agent skill from javiarmesto/ALDC-AL-Development-Collection.

    109 GitHub stars~3k tokensUpdated 3 days ago
    Auto-check passed
  • Skill Agent Task Patterns

    javiarmesto/ALDC-AL-Development-Collection

    Agent SDK task integration patterns for Business Central. An agent skill from javiarmesto/ALDC-AL-Development-Collection.

    109 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • Skill Agent Toolkit

    javiarmesto/ALDC-AL-Development-Collection

    Build, configure, and integrate Business Central agents using the AI Development Toolkit and Agent SDK.

    109 GitHub stars~4.4k tokensUpdated 3 days ago
    Auto-check passed

Questions about Skill Permissions

What does Skill Permissions do?

AL permission set design for Business Central. An agent skill from javiarmesto/ALDC-AL-Development-Collection. Skill Permissions is an agent skill from javiarmesto/ALDC-AL-Development-Collection. AL permission set design for Business Central.

When should I use Skill Permissions?

Skill Permissions fits situations like: creating PermissionSets; implementing least-privilege access; designing security models for extensions.

How do I install Skill Permissions in Claude Code?

Run `npx skills add javiarmesto/ALDC-AL-Development-Collection --skill skill-permissions -a claude-code`. Or copy the skill folder (skills/skill-permissions in javiarmesto/ALDC-AL-Development-Collection) into .claude/skills/skill-permissions in your project. Claude Code loads it when a task matches its description.

How do I install Skill Permissions in Codex?

Run `npx skills add javiarmesto/ALDC-AL-Development-Collection --skill skill-permissions -a codex`. Or copy the skill folder (skills/skill-permissions in javiarmesto/ALDC-AL-Development-Collection) into .agents/skills/skill-permissions in your project. Codex loads it when a task matches its description.

Can I use Skill Permissions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add javiarmesto/ALDC-AL-Development-Collection --skill skill-permissions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-permissions, .gemini/skills/skill-permissions, .github/skills/skill-permissions and .opencode/skills/skill-permissions in your project.

What does Skill Permissions need to run?

SKILL.md names no scripts, command-line tools or credentials: Skill Permissions is instructions for the agent only.

Does Skill Permissions access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Skill Permissions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skill Permissions use?

Skill Permissions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Permissions use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skill Permissions?

Skills that share tags, products or a category with Skill Permissions: Configuring Horizon (coollabsio/coolify, 63k stars), SageMaker IAM Role Preflight (huggingface/skills, 11k stars), K8s Security Policies (Cybereason-Public/owLSM, 280 stars) and Ccfddl X Posts (ccfddl/ccf-deadlines, 9.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Permissions?

javiarmesto (a GitHub user) maintains it in javiarmesto/ALDC-AL-Development-Collection, which has 109 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 7, 2026.

Source: javiarmesto/ALDC-AL-Development-Collection on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.