Dx Org Permission Set Assign

by forcedotcome5164d94d751No license1K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated yesterday

ALWAYS USE THIS SKILL to assign permission sets to org users. Assign one or more permission sets to org users using the sf org assign permset command. TRIGGER when the user asks to assign, grant, give, add, or apply permission sets to users, admins, specific orgs, or specific users. Supports granting permissions, giving access, and adding permission sets to default admin or specific users via --on-behalf-of. DO NOT TRIGGER for listing permission sets or checking user permissions.

Instructions onlyDevOps & Cloud
AI-generated overview

Assigns Salesforce permission sets to org users via the sf org assign permset CLI command.

What it does
This skill maps a user's request to the correct sf org assign permset invocation and runs it through the Bash tool with the --json flag. It covers assigning one or several permission sets to the default admin, to a specific org, or to specific users via --on-behalf-of. It returns the command's JSON result and points to example success and error outputs plus a CLI flag reference.
When to use it
Use it when someone asks to assign, grant, give, add, or apply permission sets to users, admins, or a specific org. It is not intended for creating permission sets, listing them, or checking user permissions.
Requirements
Requires the Salesforce CLI (sf, version 2.0.0 or higher) and Bash tool access, plus an authenticated target org and CLI aliases for users. It ships no scripts; it includes example JSON outputs and a CLI flags reference document.

dx-org-permission-set-assign

Assigns one or more permission sets to org users using sf org assign permset. Handles all variants: default admin user, specific org targets, multiple permission sets, and assignment to specific users.


Tool Restrictions

Use ONLY the Bash tool to execute sf org assign permset. Do NOT use MCP tools like assign_permission_set — ignore them completely.


Scope

  • In scope: Assigning permission sets to users via sf org assign permset
  • Out of scope: Creating permission sets (use platform-permission-set-generate), listing permission sets, checking user permissions

Required Inputs

Infer from the user's request:

  • Permission set name(s): Extract from user message (can be multiple)
  • Target org: Use default unless specific alias/username mentioned
  • Target user(s): Default is org's default admin user; use --on-behalf-of if specific users mentioned

Workflow

  1. Match user request to command in table below
  2. Execute via Bash tool: sf org assign permset with appropriate flags and --json flag
  3. Return result

If error occurs, check the failures array in JSON output for details.

Command Decision Table

User intentExecute via Bash tool
Assign one permission set to default adminsf org assign permset --name <PermSetName> --json
Assign multiple permission sets to default adminsf org assign permset --name <PermSet1> --name <PermSet2> --json
Assign to specific orgsf org assign permset --name <PermSetName> --target-org <alias> --json
Assign to specific user(s)sf org assign permset --name <PermSetName> --on-behalf-of <username1> --on-behalf-of <username2> --json
Assign multiple sets to specific userssf org assign permset --name <PermSet1> --name <PermSet2> --on-behalf-of <username1> --on-behalf-of <username2> --json

Rules / Constraints

ConstraintRationale
Always use --json flagProvides structured output for reliable parsing and error handling
Permission set names are case-sensitiveUse exact API names as they appear in the org
Multiple --name flags can be combined in one commandMore efficient than separate commands per permission set
Multiple --on-behalf-of flags assign to multiple usersBatch assignment in single command; processed sequentially to avoid auth file collisions
Use CLI username aliases, not Salesforce User.Alias fieldThe --target-org and --on-behalf-of flags expect CLI aliases set via sf alias set, not the User object's Alias field
Duplicate assignments are idempotentRe-assigning an already-assigned permission set succeeds silently
Partial success is possibleCommand can return both successes and failures in one run; non-zero exit code if any failures

Gotchas

IssueResolution
Permission set name with spacesEnclose in double quotes: --name "Permission Set Name"
"PermissionSet not found" errorVerify permission set exists in target org; check for typos in name
Assignment succeeds but user doesn't see permissionsCheck <hasActivationRequired> in permission set metadata — may need manual activation in Setup
"User not found" errorUsername/alias doesn't exist in target org — verify with sf org display user --target-org <alias>
Partial success (some users succeed, others fail)Check JSON output — command returns both successes and failures arrays; exit code will be non-zero if any failures occurred

Output Expectations

The command returns JSON output with status code and result details.

See examples/success_output.json and examples/error_output.json for response structures.


Reference File Index

FileWhen to read
examples/success_output.jsonTo understand successful assignment response structure
examples/error_output.jsonTo handle common error scenarios
references/cli_flags.mdFor detailed explanation of all available flags

Source and attribution

Source:forcedotcom/sf-skillsinskills/dx-org-permission-set-assignat commite5164d9

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from forcedotcom/sf-skills

Service Itsm Teams Itservice Configure

forcedotcom

Configure the "Set Up Salesforce IT Service" checklist for Microsoft Teams Employee Service (ITSM) — the employee side, covering app enablement, marketplace install guidance, user access assignment, and Digital Experience Site selection. Use this for: 'turn on Salesforce IT Service', 'set up IT Service on Teams', 'assign Teams for Employee permission set', 'give employees access to Teams for Employee Service', 'manage user access for Teams ITSM', 'grant users the permission sets needed for Teams Employee Service', 'select a digital experience site for Teams', 'install Salesforce IT Service app on Teams', or any request to complete the IT Service half of the Teams ITSM Go page checklist (including the Manage User Access step). DO NOT TRIGGER for the base Teams Salesforce Go page toggle or Azure/Entra app setup (service-itsm-teams-configure) or for the IT Desk/fulfiller half of the checklist (service-itsm-teams-itdesk-configure).

Awaiting classification1Kupdated yesterday

Service Itsm Teams Coordinate

forcedotcom

End-to-end autopilot orchestrator for setting up Microsoft Teams integration in Salesforce Service Cloud ITSM — runs the whole flow (enable the Teams for Employee Service Go feature, register the Microsoft Entra app, populate Named Credentials, configure the IT Desk and IT Service checklists, turn on Swarming, and optionally embed the Agentforce agent) in one continuous pass, stopping only at the points a human must act. Use when the user asks to set up Microsoft Teams for ITSM end to end, 'set up teams for it service', 'do the whole teams itsm setup', 'configure microsoft teams for employee service', or wants a guided Teams ITSM walkthrough. Delegates each stage to a specialized child skill while driving the sequence itself. DO NOT TRIGGER when the user asks to enable Teams alone, configure just the IT Desk or IT Service checklist alone, or enable Swarming alone — delegate directly to the specific child skill in those cases.

Awaiting classification1Kupdated yesterday

Service Itsm Teams Itdesk Configure

forcedotcom

Configure the "Set Up Salesforce IT Desk" checklist for Microsoft Teams Employee Service (ITSM) — the fulfiller/agent side, covering app enablement, marketplace install guidance, user access assignment, and Swarming collaboration-tool setup. Use this for: 'turn on Salesforce IT Desk', 'set up IT Desk on Teams', 'assign Teams for IT Desk permission set', 'set Teams as collaboration tool for swarming', 'install Salesforce IT Desk app on Teams', or any request to complete the IT Desk half of the Teams ITSM Go page checklist. DO NOT TRIGGER for the base Teams Salesforce Go page toggle or Azure/Entra app setup (service-itsm-teams-configure) or for the IT Service/employee half of the checklist (service-itsm-teams-itservice-configure).

Awaiting classification1Kupdated yesterday

Service Itsm Teams Debug

forcedotcom

Diagnoses failing Microsoft Teams for Employee Service (ITSM) setups by running pass/fail configuration checklists against a Salesforce org.

DevOps & Cloud1Kupdated yesterday

Service Itsm Teams Employee Agent Configure

forcedotcom

Configure the embedded Agentforce Employee Agent so it replies inside the Microsoft Teams ITSM custom client ('Salesforce Employee Assist' / 'Ask AI Agent'). Use this for: 'set up employee agent in Teams', 'embed Agentforce agent in Teams', 'make the IT Service Employee Agent reply in Teams', 'Teams Ask AI Agent not responding', 'agent joins then leaves without replying', 'configure MIAW deployment for Teams employee agent', 'Teams embedded messaging agent setup'. Builds the whole stack headlessly (zero Setup-UI clicks): the Web messaging channel with User Verification ON, the Enhanced Chat User Verification Key Set (JWKS_URL) it requires, the Teams_AgentForce custom-client deployment, the routing flow to the agent, and the Agent Access permission set that lets the portal user reach the agent. DO NOT TRIGGER for enabling the Teams feature Salesforce Go page toggle (service-itsm-teams-configure) or for configuring notification preferences.

Awaiting classification1Kupdated yesterday

Service Itsm Swarming Configure

forcedotcom

Enables the Salesforce Swarming ITSM feature and sets the collaboration tool to Teams via Connect API calls.

DevOps & Cloud1Kupdated yesterday
Dx Org Permission Set Assign Agent Skill | SourceWeft