Create and Enable a Unified Employee (UEL) User
Provision an employee under the Unified Employee License (UEL) by creating and linking a User
on the Unified Employee license/profile, a Person Account (with an auto-generated Contact), and
an Employee2 record, then assigning the required permission sets. Every operation runs through
the Salesforce-hosted headless-360 MCP server (server key headless-360) via its four
meta-tools (discover, describe, dispatch_readonly, dispatch). The org is derived from the
OAuth JWT bound to the current MCP session — the skill never handles an org id, alias, or
credentials — so the flow behaves identically against production and sandbox with no per-user
MCP install.
Scope
- In scope: Creating a new UEL User, Person Account, Employee2 record; assigning permission sets; verifying the full chain.
- Out of scope: Standard user creation (non-UEL); cloning existing users; managing existing user permissions only; deactivating users; license assignment changes.
Routes at a glance
Reads dispatch through mcp__headless-360__dispatch_readonly; writes through
mcp__headless-360__dispatch. Both take raw HTTP:
{"url": "<path>", "method": "GET|POST", "body"?: {...}, "queryParams"?: {...}}. Full URL paths and
request/response bodies for every row live in references/mcp-invocation.md; this table lists only
the operation and HTTP method.
Response envelope: describe, /query, and /sobjects/… are all standard REST — the
dispatch* tool returns the HTTP status plus the parsed body: { "status_code": 200, "body": <REST response> }. Read body. A create returns body.id and body.success == true; a query returns
body.records[]. Status codes: 200/201 success; 400 bad body (re-check schema via describe);
401/auth error the MCP session needs re-auth; 404 the endpoint/impl is not present on this org;
500 a downstream dependency issue.
Required Inputs
Collect from the user (ask only what is not already in conversation context):
Identity (required)
Credentials & Locale (required)
Manager (optional)
HR Attributes for Employee2 (required)
Permission Sets
Employee Hub Unified Employee User (EmployeeHubEmployeeUser) is always assigned — no other
permission sets belong on a UEL user. If the caller asks for extras (Incident Fulfiller, Case
Agent, or any other fulfiller/agent-role set), decline: those are for fulfillers on the Service
Cloud side, not for requesters who log into the Employee Hub. Point the caller at the
appropriate fulfiller user-create flow instead of extending this one.
Workflow
All steps are sequential. Always read before you write. Every call goes through
mcp__headless-360__* tools. Stop and report if any step fails.
Phase 1 — Preflight & discovery
On any 401 / 403 / 404 from a discover / describe / dispatch / dispatch_readonly call below, halt and surface the raw error — the org or client is not configured correctly. 401 → headless-360 MCP client not authenticated to CORE_ORG_ALIAS (session expired). 403 → executing user is missing one of the required perms (ManageUsers, ManageProfilesPermissionsets, CustomizeApplication, AssignPermissionSets) OR the org lacks the Unified Employee License. 404 → the target sObject / route is not available (HR module / UEL not provisioned — surfaces separately as the five prerequisite checks in step 2).
-
Discover the operations —
mcp__headless-360__discover(query="create User Account Employee2 sObject")andmcp__headless-360__describe(id=<operation_id>)for thePOST /sobjects/User,POST /sobjects/Account, andPOST /sobjects/Employee2operations to confirm they are indexed and pull the input schema. Adiscovermiss does not mean the route is absent — the/sobjects/…REST endpoints are core Data API paths and can be invoked directly withdispatch_readonly/dispatchagainst the exact URL (seereferences/mcp-invocation.md). If a directdispatch_readonlyprobe at the documented path also fails (404), direct the user to the Setup UI. -
Verify all five UEL prerequisites (all read-only
/queryor describe). If any fails, stop and report exactly which prerequisite is missing:- Unified Employee license exists → else "Unified Employee license not found in this org."
- Unified Employee profile exists → else "Unified Employee profile not found. Ensure UEL license is provisioned."
- Active Person Account record type exists → else "No active Person Account record type found. Enable Person Accounts in Setup."
- Employee Hub permission set exists → else "Employee Hub Unified Employee User permission set not found. This is required for UEL provisioning."
- Employee2 describe returns 200 → else "Employee2 sObject not accessible. Ensure the HR module is enabled."
Capture:
UnifiedEmployeeProfileId,PersonAccountRecordTypeId,EmployeeHubPermSetId.
Phase 2 — Resolve references
- Resolve the manager — when the user supplied a manager, query by Username or Name (active
users only). On multiple matches, present options and ask the user to disambiguate. Capture
ManagerId. When no manager was supplied, skip this step. - Check username uniqueness — query
UserbyUsername; any record → stop, username taken.
Phase 3 — Confirm & create the chain
- Confirm the plan — present the full configuration (including HR attributes) and wait for explicit confirmation before any mutation.
- Create the User —
POST /sobjects/Userwith identity, locale,ProfileId=UnifiedEmployeeProfileId, andManagerId(omitManagerIdwhen none). CaptureNewUserId. - Assign the Employee Hub permission set (mandatory) —
POST /sobjects/PermissionSetAssignmentwith{AssigneeId: NewUserId, PermissionSetId: EmployeeHubPermSetId}. If this fails, stop and report the exact error — the set exists (verified) but may be incompatible with the license. - Create the Person Account —
POST /sobjects/AccountwithFirstName,LastName,PersonEmail(required), andRecordTypeId=PersonAccountRecordTypeId. CaptureNewAccountId.PersonEmailmust be set: the Employee2 validation hook rejects the record when the linked PersonContact is missingEmailorLastName. - Verify the PersonContact — query the Account for
IsPersonAccountandPersonContactId. ConfirmIsPersonAccount = trueand capturePersonContactId. If it is null, stop and report failure to generate the PersonContact. - Create the Employee2 record —
POST /sobjects/Employee2withUserId=NewUserId,ContactId=PersonContactId, and the HR attributes. Use the foreign-key field namesUserId/ContactId(not the relationship namesUser/Contact). CaptureNewEmployee2Id.
Phase 4 — Verify & present
- Verify the full chain — query the Account (IsPersonAccount, PersonContactId), the User (IsActive, ProfileId, ManagerId), the Employee2 (UserId, ContactId), and confirm the Employee Hub permission set is the only PermissionSetAssignment (beyond the profile).
- Report using the output format below.
Rules / Constraints
Permissions Required
The executing admin user (the identity behind CORE_ORG_ALIAS) must have:
Verification Checklist
- Did
discover+describe(id)(or, on adiscovermiss, a directdispatch_readonlyprobe at the documented/sobjects/…path) confirm the User / Account / Employee2 create operations? - Did all five UEL prerequisites pass (license, profile, Person Account RT, Employee Hub set, Employee2)?
- Did you confirm the username is unique and confirm the plan before any mutation?
- Is
Account.IsPersonAccount = truewith a non-nullPersonContactId? - Is
User.IsActive = trueon the Unified Employee profile (and manager, if provided)? - Does
Employee2linkUserIdandContactIdcorrectly? - Is
Employee Hub Unified Employee Userthe only permission set assigned (no fulfiller-side extras)?
Output Format
On failure, display the error from dispatch* exactly as returned.
On success:
No record IDs in user-facing output — use human-readable names only.
Reference File Index
Related Skills
This skill provisions a Unified Employee License (UEL) user with the full entity chain. Two adjacent flows are out of scope: creating a standard (non-UEL) user, and cloning an existing user's full access configuration. Handle those requests separately — this skill does not cover them.


