Dx Org Permission Set Assign

forcedotcom/sf-skills/plugins/builder/dx-org-lifecycle/skills/dx-org-permission-set-assign

作者 forcedotcome5164d94d7511c00fa02a5b8b60754b2361e178f无许可证1K 个星标收录于 2026年10月9日更新于 2026年10月9日仓库昨天更新

ALWAYS USE THIS SKILL to assign permission sets to org users. Assign one or more permission sets to org users using the sf org assign permset command. TRIGGER when the user asks to assign, grant, give, add, or apply permission sets to users, admins, specific orgs, or specific users. Supports granting permissions, giving access, and adding permission sets to default admin or specific users via --on-behalf-of. DO NOT TRIGGER for listing permission sets or checking user permissions.

仅含说明DevOps & Cloud
AI 生成的概览

通过 sf org assign permset 命令行命令,将 Salesforce 权限集分配给组织用户。

功能
该技能把用户的请求对应到正确的 sf org assign permset 调用,并通过 Bash 工具带 --json 标志执行。它支持将一个或多个权限集分配给默认管理员、指定组织,或通过 --on-behalf-of 分配给特定用户。它返回命令的 JSON 结果,并指向成功与错误输出示例以及 CLI 标志参考文档。
适用场景
当有人要求向用户、管理员或特定组织分配、授予、给予、添加或应用权限集时使用。它不适用于创建权限集、列出权限集或检查用户权限。
运行要求
需要 Salesforce CLI(sf,2.0.0 或更高版本)和 Bash 工具访问权限,以及已认证的目标组织和用户的 CLI 别名。它不附带脚本;包含示例 JSON 输出和 CLI 标志参考文档。

dx-org-permission-set-assign

Assigns one or more permission sets to org users using sf org assign permset. Handles all variants: default admin user, specific org targets, multiple permission sets, and assignment to specific users.


Tool Restrictions

Use ONLY the Bash tool to execute sf org assign permset. Do NOT use MCP tools like assign_permission_set — ignore them completely.


Scope

  • In scope: Assigning permission sets to users via sf org assign permset
  • Out of scope: Creating permission sets (use platform-permission-set-generate), listing permission sets, checking user permissions

Required Inputs

Infer from the user's request:

  • Permission set name(s): Extract from user message (can be multiple)
  • Target org: Use default unless specific alias/username mentioned
  • Target user(s): Default is org's default admin user; use --on-behalf-of if specific users mentioned

Workflow

  1. Match user request to command in table below
  2. Execute via Bash tool: sf org assign permset with appropriate flags and --json flag
  3. Return result

If error occurs, check the failures array in JSON output for details.

Command Decision Table

User intentExecute via Bash tool
Assign one permission set to default adminsf org assign permset --name <PermSetName> --json
Assign multiple permission sets to default adminsf org assign permset --name <PermSet1> --name <PermSet2> --json
Assign to specific orgsf org assign permset --name <PermSetName> --target-org <alias> --json
Assign to specific user(s)sf org assign permset --name <PermSetName> --on-behalf-of <username1> --on-behalf-of <username2> --json
Assign multiple sets to specific userssf org assign permset --name <PermSet1> --name <PermSet2> --on-behalf-of <username1> --on-behalf-of <username2> --json

Rules / Constraints

ConstraintRationale
Always use --json flagProvides structured output for reliable parsing and error handling
Permission set names are case-sensitiveUse exact API names as they appear in the org
Multiple --name flags can be combined in one commandMore efficient than separate commands per permission set
Multiple --on-behalf-of flags assign to multiple usersBatch assignment in single command; processed sequentially to avoid auth file collisions
Use CLI username aliases, not Salesforce User.Alias fieldThe --target-org and --on-behalf-of flags expect CLI aliases set via sf alias set, not the User object's Alias field
Duplicate assignments are idempotentRe-assigning an already-assigned permission set succeeds silently
Partial success is possibleCommand can return both successes and failures in one run; non-zero exit code if any failures

Gotchas

IssueResolution
Permission set name with spacesEnclose in double quotes: --name "Permission Set Name"
"PermissionSet not found" errorVerify permission set exists in target org; check for typos in name
Assignment succeeds but user doesn't see permissionsCheck <hasActivationRequired> in permission set metadata — may need manual activation in Setup
"User not found" errorUsername/alias doesn't exist in target org — verify with sf org display user --target-org <alias>
Partial success (some users succeed, others fail)Check JSON output — command returns both successes and failures arrays; exit code will be non-zero if any failures occurred

Output Expectations

The command returns JSON output with status code and result details.

See examples/success_output.json and examples/error_output.json for response structures.


Reference File Index

FileWhen to read
examples/success_output.jsonTo understand successful assignment response structure
examples/error_output.jsonTo handle common error scenarios
references/cli_flags.mdFor detailed explanation of all available flags

来源与署名

来源:forcedotcom/sf-skills位于plugins/builder/dx-org-lifecycle/skills/dx-org-permission-set-assign提交e5164d9

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架