Generate Salesforce PermissionSet XML: object, field, user and app permissions
Generate deployable Salesforce permission set metadata — CRUD object permissions, field-level security, user permissions, app/tab visibility, Apex/Visualforce access, Agentforce agent access — with least-privilege validation rules
- What
- Generate deployable Salesforce permission set metadata — CRUD object permissions, field-level security, user permissions, app/tab visibility, Apex/Visualforce access, Agentforce agent access — with least-privilege validation rules
- Cost
- Free
- Needs
- Salesforce org access (a free Developer Edition org works) and the Salesforce CLI for deployment — the skill is guidance the agent follows, not software to install
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @forcedotcom's skill for generating correct, deployable Salesforce PermissionSet XML: an 8-step workflow — core properties (descriptive API names like `Sales_Manager_Access`, fullName/label/description); CRUD object permissions (`allowCreate/Read/Edit/Delete`, `modifyAllRecords`, `viewAllRecords`, `viewAllFields`); field-level security with the hard rule that required fields must NEVER appear in `<fieldPermissions>` (deployment fails — confirm from object metadata first; formula fields can't be editable); user permissions (`ApiEnabled`, `ViewSetup`, `ManageUsers`, `RunReports`) with a security-review flag on `ViewAllData`, `ModifyAllData` and `ManageUsers`; app and tab visibility (tab naming: `__c` for custom tabs, `standard-` prefix for standard tabs); optional Apex class and Visualforce page access; license and record-type settings; Agentforce employee-agent access. Honest caveats: permission sets GRANT ACCESS — follow least privilege, never deploy an unreviewed permission set to production, and test in a sandbox first; you deploy with the Salesforce CLI against your own org. Apache-2.0 licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: Salesforce org access (a free Developer Edition org works) and the Salesforce CLI for deployment — the skill is guidance the agent follows, not software to install Install "Generate Salesforce PermissionSet XML: object, field, user and app permissions" for me. It teaches my agent @forcedotcom's permission-set workflow: core properties with descriptive API names; CRUD object permissions; field-level security (required fields NEVER in fieldPermissions — confirm from object metadata; formula fields not editable); user permissions with the security-review flag on ViewAllData/ModifyAllData/ManageUsers; app/tab visibility with exact tab naming; optional Apex/Visualforce access, license and record-type settings, and Agentforce agent access. IMPORTANT: permission sets GRANT ACCESS — always review before deploying and test in a sandbox first; follow least privilege. Apache-2.0 licensed. Repository: https://github.com/forcedotcom/sf-skills/blob/main/plugins/builder/salesforce-development/skills/platform-permission-set-generate/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "platform-permission-set-generate". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. hand the agent the access requirements for the permission set; review the generated XML, deploy with the Salesforce CLI to a sandbox first, and verify least privilege before any production deployment). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.