From ae4e46d97ffbddb2c003e9fb4d50cb409f66365a Mon Sep 17 00:00:00 2001 From: irisli007 <53790094+irisli007@users.noreply.github.com> Date: Thu, 12 Mar 2026 14:01:32 -0700 Subject: [PATCH] W-21367283: Add skills for metadata permission set generation (#23) * initial skill for perm sets * more edits * changes after testing * more changes * address comments * standard tabs should have prefix * remove apache license --------- Co-authored-by: irisli --- skills/generate-permission-set/SKILL.md | 171 ++++++++++++++++++++++++ 1 file changed, 171 insertions(+) create mode 100644 skills/generate-permission-set/SKILL.md diff --git a/skills/generate-permission-set/SKILL.md b/skills/generate-permission-set/SKILL.md new file mode 100644 index 0000000..791e5e1 --- /dev/null +++ b/skills/generate-permission-set/SKILL.md @@ -0,0 +1,171 @@ +--- +name: generate-permission-set +description: Generates correct, deployable Salesforce permission set metadata (PermissionSet XML) with object, field, user, and app permissions. Use when creating or editing permission set metadata, PermissionSet XML, object permissions, field-level security (FLS), tab visibility, or deploying permission sets. +compatibility: Salesforce Metadata API v60.0+ +metadata: + author: afv-library + version: "1.0" +--- + +## When to Use This Skill + +Use when generating or editing permission set metadata, or when granting object, field, user, and app permissions. + +## Step 1: Define Core Properties + +Start by defining the required permission set properties: + +```xml + + YourPermissionSetName + + Clear description of purpose and intended audience + +``` + +**Naming conventions:** +- Use descriptive API names (e.g., `Sales_Manager_Access`) + +## Step 2: Configure Object Permissions + +Add CRUD permissions for standard and custom objects: + +```xml + + true + true + true + false + false + false + false + Account + +``` + +## Step 3: Set Field-Level Security + +Define field permissions for sensitive or custom fields: + +```xml + + true + true + Account.SSN__c + +``` + +**Important:** +- Required fields must NEVER appear in list of field permissions. Granting field-level security on required fields is not allowed by the platform and will cause deployment failure. +- Before adding any field, confirm from the object metadata that the field exists and is not required +- A field is required when its metadata contains `true`: +```xml + + FieldName__c + true + +``` +- Use format `ObjectName.FieldName` for field references +- Set both readable and editable to true when the user needs edit access; editable implies readable +- If all fields should be visible, can alternatively enable the "viewAllFields" object permission + +## Step 4: Grant User Permissions + +Add system-level permissions for features and capabilities: + +```xml + + true + ApiEnabled + + + true + RunReports + +``` + +**Common permissions:** +- `ApiEnabled`: API access +- `ViewSetup`: View Setup menu +- `ManageUsers`: User management +- `RunReports`: Report execution + +**Security review required for:** +- `ViewAllData`: Read all records +- `ModifyAllData`: Edit all records +- `ManageUsers`: User administration + +## Step 5: Configure App and Tab Visibility + +Make applications and tabs visible to users: + +```xml + + Sales_Console + true + + + CustomTab__c + Visible + +``` + +**Application visibility options:** +- can be true or false + +**Tab visibility options:** +- `Visible`: Always shown +- `Available`: Available but not default +- `Hidden`: Not visible + +**CRITICAL - Tab Naming:** +- Custom object tabs: MUST include the __c suffix (e.g., MyCustomObject__c) +- Standard object tabs: Use the object name with "standard-" prefix (e.g., standard-Account, standard-Contact) +- The tab name matches the object's API name exactly + +## Step 6: Add Apex and Visualforce Access (Optional) + +Grant access to custom code: + +```xml + + CustomController + true + + + CustomPage + true + +``` + +## Step 7: Set License and Record Type Settings (Optional) + +Specify license requirements and record type visibility: + +```xml +Salesforce +false + + Account.Business + true + true + +``` + +## Validation Checklist + +Before deploying, verify: +- [ ] fullName, label, description set +- [ ] Permissions follow least privilege +- [ ] No required fields in `` +- [ ] No duplicate permissions +- [ ] no lengthy comments + +## What Causes Deployment Failure + +- **Field permissions on required fields:** Any required field in `` fails deployment. Required fields cannot have FLS; omit them entirely. Always confirm from object/field metadata that a field exists and is not required—never assume. +- **Incorrect API names:** Using the wrong name or missing suffixes (e.g. missing `__c` for custom objects, fields, tabs) cause failure. + +## Deployment + +Deploy using Salesforce CLI \ No newline at end of file