
Generating Permission Set
- 2.5k installs
- 763 repo stars
- Updated July 24, 2026
- forcedotcom/sf-skills
generating-permission-set is a Salesforce skill for deployable PermissionSet XML with object, field, user, and tab permissions.
About
Generating Permission Set guides creation of deployable Salesforce PermissionSet metadata for object CRUD, field-level security, user permissions, and app or tab visibility. Step one defines fullName, label, and description with descriptive API names such as Sales_Manager_Access. Object permissions set allowCreate, allowRead, allowEdit, allowDelete, modifyAllRecords, and viewAllRecords per object. Field permissions require readable and editable flags using ObjectName.FieldName format, with explicit warnings that required fields must never appear in field permissions and formula fields cannot be editable. User permissions grant system capabilities like ApiEnabled and RunReports, with security review flagged for ViewAllData, ModifyAllData, and ManageUsers. Application and tab visibility blocks configure Sales Console visibility and tab settings of Visible, Available, or None, including the rule that custom object tabs must keep the __c suffix. The skill targets Metadata API v60.0 plus deployments and emphasizes verifying field metadata before granting FLS to avoid deployment failures.
- PermissionSet XML steps for objects, fields, users, apps, and tabs.
- Required fields must never appear in fieldPermissions blocks.
- Custom tab names must include the __c suffix for custom objects.
- Security review flags for ViewAllData and ModifyAllData grants.
- Field reference format ObjectName.FieldName with readable and editable pairs.
Generating Permission Set by the numbers
- 2,483 all-time installs (skills.sh)
- +7 installs in the week ending Jul 28, 2026 (Skillselion tracking)
- Ranked #206 of 4,386 Backend & APIs skills by installs in the Skillselion catalog
- Security screen: LOW risk (skills.sh audit)
- Data as of Jul 28, 2026 (Skillselion catalog sync)
generating-permission-set capabilities & compatibility
- Capabilities
- permissionset core property xml templates · object crud permission blocks · field level security with required field guards · user permission grants with security review flag · application and tab visibility configuration
- Works with
- salesforce
- Use cases
- api development · security audit
- Pricing
- Free
What generating-permission-set says it does
Required fields must NEVER appear in list of field permissions.
Custom object tabs: MUST include the __c suffix
Set both readable and editable to true when the user needs edit access
npx skills add https://github.com/forcedotcom/sf-skills --skill generating-permission-setAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 2.5k |
|---|---|
| repo stars | ★ 763 |
| Security audit | 3 / 3 scanners passed |
| Last updated | July 24, 2026 |
| Repository | forcedotcom/sf-skills ↗ |
How do I author correct PermissionSet metadata with FLS and tab visibility that deploys cleanly?
Generate deployable Salesforce PermissionSet XML with object, field, user, app, and tab permissions.
Who is it for?
Salesforce admins and developers creating or editing permission set metadata for deployment.
Skip if: Skip for Apex code generation, LWC components, or Data Cloud SQL query work.
When should I use this skill?
User creates permission sets, field-level security, tab visibility, or deploys PermissionSet XML.
What you get
Valid PermissionSet XML with object CRUD, field security, user permissions, and app or tab visibility.
- PermissionSet XML metadata files
- object and field permission definitions
By the numbers
- Version 1.0 skill targeting Salesforce Metadata API v60.0+
- Covers object permissions, field-level security, tab visibility, and app access controls
Files
data360-query: Data Cloud Retrieve Phase
Use this skill when the user needs query, search, and metadata introspection for Data Cloud: sync SQL, paginated SQL, async query workflows, table describe, vector search, hybrid search, or search index operations.
When This Skill Owns the Task
Use data360-query when the work involves:
sf data360 query *sf data360 search-index *sf data360 metadata *sf data360 profile *orsf data360 insight *inspection- understanding Data Cloud SQL results or query shape
Delegate elsewhere when the user is:
- writing standard CRM SOQL only → platform-soql-query
- designing segment or calculated insight assets → data360-segment
- analyzing STDM/session tracing/parquet telemetry → agentforce-observe
---
Required Context to Gather First
Ask for or infer:
- target org alias
- whether the user needs quick count, medium result set, large export, schema inspection, or semantic search
- table/index name if known
- whether the task is read-only SQL or search-index lifecycle management
---
Core Operating Rules
- Treat Data Cloud SQL as its own query language, not SOQL.
- Run the shared readiness classifier before relying on query/search surfaces:
node ../data360-orchestrate/scripts/diagnose-org.mjs -o <org> --phase retrieve --json. - Use describe before guessing columns.
- Prefer
sqlv2or async query flows for larger result sets. - Use vector search or hybrid search only when the search index lifecycle is healthy.
- Keep STDM/parquet/session-tracing workflows out of this skill family.
---
Recommended Workflow
1. Classify readiness for retrieve work
node ../data360-orchestrate/scripts/diagnose-org.mjs -o <org> --phase retrieve --json
# optional query-plane probe, only with a real table name
node ../data360-orchestrate/scripts/diagnose-org.mjs -o <org> --phase retrieve --describe-table MyDMO__dlm --json2. Choose the smallest correct query shape
sf data360 query sql -o <org> --sql 'SELECT COUNT(*) FROM "ssot__Individual__dlm"' 2>/dev/null
sf data360 query sqlv2 -o <org> --sql 'SELECT * FROM "ssot__Individual__dlm"' 2>/dev/null
sf data360 query async-create -o <org> --sql 'SELECT * FROM "ssot__Individual__dlm"' 2>/dev/null3. Use describe before guessing fields
sf data360 query describe -o <org> --table ssot__Individual__dlm 2>/dev/null4. Use vector or hybrid search only when an index exists
sf data360 search-index list -o <org> 2>/dev/null
sf data360 query vector -o <org> --index Knowledge_Index --query "reset password" --limit 5 2>/dev/null
sf data360 query hybrid -o <org> --index Knowledge_Index --query "reset password" --limit 5 2>/dev/null
sf data360 query hybrid -o <org> --index Insurance_Index --query "weather damage coverage" --prefilter "Type_of_Insurance__c='Home'" --limit 10 2>/dev/null5. Reuse curated search-index examples when creating indexes
Use the phase-owned examples instead of inventing JSON from scratch:
examples/search-indexes/vector-knowledge.jsonexamples/search-indexes/hybrid-structured.json
---
High-Signal Gotchas
- Data Cloud SQL is not SOQL.
- Table names should be double-quoted in SQL.
sqlv2is better than ad hoc OFFSET paging for medium result sets.- async query is preferable for large results.
- search-index operations and vector/hybrid queries depend on the index lifecycle being healthy.
- Hybrid search can use
--prefilter, but only on fields configured as prefilter-capable when the search index was created. - HNSW index parameters are typically read-only on create; leave
userValues: []unless the platform explicitly documents otherwise. query describeis not a universal tenant probe; only run it with a known DMO or DLO table after broader readiness has been confirmed.
---
Output Format
Retrieve task: <sql / sqlv2 / async / describe / vector / search-index>
Target org: <alias>
Target object: <table or index>
Commands: <key commands run>
Verification: <query rows / schema / status>
Next step: <segment / harmonize / follow-up>---
References
- README.md
- examples/search-indexes/vector-knowledge.json
- examples/search-indexes/hybrid-structured.json
- ../data360-orchestrate/assets/definitions/search-index.template.json
- ../data360-orchestrate/references/plugin-setup.md
- ../data360-orchestrate/references/feature-readiness.md
Credits & Acknowledgments
Primary contributor: Gnanasekaran Thoppae
This skill is part of the *-datacloud family. Shared attribution, upstream source mapping, and maintenance notes live in:
- ../data360-orchestrate/CREDITS.md
- ../data360-orchestrate/UPSTREAM.md
{
"label": "<INDEX_NAME>",
"developerName": "<INDEX_NAME>",
"description": "Hybrid search index on a structured Data Cloud DMO",
"sourceDmoDeveloperName": "<SOURCE_DMO>__dlm",
"chunkDmoName": "<INDEX_NAME> chunk",
"chunkDmoDeveloperName": "<INDEX_NAME>_chunk",
"vectorDmoName": "<INDEX_NAME> index",
"vectorDmoDeveloperName": "<INDEX_NAME>_index",
"searchType": "HYBRID",
"vectorEmbedding": {
"vectorEmbeddingRelatedFields": []
},
"rankingConfigurations": [],
"chunkingConfiguration": {
"fieldLevelConfigurations": [
{
"sourceDmoDeveloperName": "<SOURCE_DMO>__dlm",
"sourceDmoFieldDeveloperName": "<TEXT_FIELD>__c",
"config": {
"id": "passage_extraction",
"userValues": [
{ "id": "max_tokens", "value": "512" },
{ "id": "strip_html", "value": "true" }
]
}
}
]
},
"vectorEmbeddingConfiguration": {
"embeddingModel": {
"id": "e5_large_v2",
"userValues": [
{ "id": "dimension", "value": "1024" },
{ "id": "max_token_limit", "value": "512" }
]
},
"index": {
"id": "HNSW",
"userValues": []
},
"similarityMetric": "COSINE"
}
}
{
"label": "My_kav",
"developerName": "My_kav",
"sourceDmoDeveloperName": "ssot__KnowledgeArticleVersion__dlm",
"chunkDmoName": "My_kav chunk",
"chunkDmoDeveloperName": "My_kav_chunk",
"vectorDmoName": "My_kav index",
"vectorDmoDeveloperName": "My_kav_index",
"searchType": "VECTOR",
"vectorEmbedding": {
"vectorEmbeddingRelatedFields": []
},
"chunkingConfiguration": {
"fieldLevelConfigurations": [
{
"sourceDmoDeveloperName": "ssot__KnowledgeArticleVersion__dlm",
"sourceDmoFieldDeveloperName": "ssot__Name__c",
"config": {
"id": "passage_extraction",
"userValues": [
{ "id": "strip_html", "value": "true" },
{ "id": "max_tokens", "value": "512" }
]
}
}
]
},
"vectorEmbeddingConfiguration": {
"embeddingModel": {
"id": "e5_large_v2",
"userValues": [
{ "id": "dimension", "value": "1024" },
{ "id": "max_token_limit", "value": "512" }
]
},
"index": {
"id": "HNSW",
"userValues": []
},
"similarityMetric": "COSINE"
},
"rankingConfigurations": []
}
data360-query
Query and search workflows for Salesforce Data Cloud.
Use this skill for
- quick SQL counts
- paginated SQL (
sqlv2) - async query lifecycles
- table describe
- vector search
- hybrid search with optional prefilter
- search index inspection and lifecycle work
Example requests
"Run a Data Cloud SQL query against unified profiles"
"Describe this Data Cloud table before I write SQL"
"Help me troubleshoot vector search in Data Cloud"
"Run a hybrid search with a prefilter in Data Cloud"
"Create and inspect a search index"Common commands
sf data360 query sql -o myorg --sql 'SELECT COUNT(*) FROM "ssot__Individual__dlm"' 2>/dev/null
sf data360 query describe -o myorg --table ssot__Individual__dlm 2>/dev/null
sf data360 search-index list -o myorg 2>/dev/null
sf data360 query vector -o myorg --index Knowledge_Index --query "reset password" --limit 5 2>/dev/null
sf data360 query hybrid -o myorg --index Knowledge_Index --query "reset password" --limit 5 2>/dev/nullExample payloads
- examples/search-indexes/vector-knowledge.json
- examples/search-indexes/hybrid-structured.json
References
- SKILL.md
- ../data360-orchestrate/assets/definitions/search-index.template.json
- CREDITS.md
Related skills
Forks & variants (1)
Generating Permission Set has 1 known copy in the catalog totaling 1.6k installs. They canonicalize to this original listing.
- forcedotcom - 1.6k installs
How it compares
Pick generating-permission-set when you need deployable PermissionSet XML metadata rather than manual Setup UI clicks or generic Salesforce coding patterns.
FAQ
Can required fields go in fieldPermissions?
No. Required fields must never appear; granting FLS on them causes deployment failure.
How name custom object tabs?
Custom object tabs must include the __c suffix, for example MyCustomObject__c.
When is ViewAllData risky?
It grants read access to all records and needs explicit security review before enabling.
Is Generating Permission Set safe to install?
skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.