Data Cloud policy rule authoring
Author PolicyRuleDefinition and PolicyRuleDefinitionSet metadata for Salesforce Data Cloud governance — ACCESS, GOVERNANCE, RECORD and TRANSFORM variants
- What
- Author PolicyRuleDefinition and PolicyRuleDefinitionSet metadata for Salesforce Data Cloud governance — ACCESS, GOVERNANCE, RECORD and TRANSFORM variants
- Cost
- Free
- Needs
- a Salesforce org with the EnforceOMatic and PolicyRuleMDAPI org permissions (Data Cloud governance); the sf CLI (>=2.0.0) authenticated against the org; target org on API v64.0+ (v66.0+ for PolicyJsonExpression conditions)
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @forcedotcom's authoring guide for Salesforce Data Cloud governance policies on disk: the deployable package layout (`policyRuleDefinitions/`, `policyRuleDefinitionSets/`, `package.xml`), the full `PolicyRuleDefinition` schema, a category decision tree (category names the enforcement domain — ACCESS, GOVERNANCE, RECORD, TRANSFORM — effect names the action — Permit, Forbid, Transform — independent except for the bidirectional Transform coupling), the scope×category compatibility matrix that throws `INVALIDFORCATEGORY` when violated, ten validation guardrails, and a Data Governance Policy Builder UI-compatibility checklist (bare conjunction indices and OR-of-ENTITYTYPE clauses crash the builder on load — the skill shows the UI-safe rewrites). Ships copy-paste templates for all four variants and a three-layer correctness check: runtime enforcement, MDAPI deploy validity, UI editability. By @forcedotcom, listed here with credit to its creator. Honest caveats: gated on the `EnforceOMatic` and `PolicyRuleMDAPI` org permissions, min API v64.0 (66.0 for `PolicyJsonExpression` conditions); some shapes are not authorable via MDAPI at all (identified-guest record access, `SCALAR`/`PLURAL_ATTRIBUTE` paths need a runtime RuleProvider); the agent's user-facing text must never name internal engines or implementation internals (the skill's output-hygiene rules). Apache-2.0 licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a Salesforce org with the EnforceOMatic and PolicyRuleMDAPI org permissions (Data Cloud governance); the sf CLI (>=2.0.0) authenticated against the org; target org on API v64.0+ (v66.0+ for PolicyJsonExpression conditions) Install "Data Cloud policy rule authoring" for me. It teaches the agent @forcedotcom's authoring workflow for PolicyRuleDefinition/PolicyRuleDefinitionSet metadata XML: pick the category first with the decision tree (ACCESS/GOVERNANCE/RECORD/TRANSFORM), lay out the bare rule from the closest copy-paste template, add WHEN/UNLESS conditions one at a time with all four anchors (clause, operator, path element, value), keep the scope×category matrix in bounds, run the UI-compatibility check (wrapping bare conjunction indices, adding the OR-of-ENTITYTYPE clause), update package.xml, and validate with a dry-run before any real deploy. Repository: https://github.com/forcedotcom/sf-skills/blob/main/skills/platform-policy-rule-generate/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "platform-policy-rule-generate". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. confirm the org has the required permissions and tell the agent which policy variant I want to author — ACCESS, GOVERNANCE, RECORD or TRANSFORM). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.