Service Itsm Agentic Setup Uel User Create

作者 forcedotcome5164d94d751无许可证1K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库昨天更新

Provision and enable a Unified Employee License (UEL) user in Salesforce with the full entity chain — User, Person Account, PersonContact, and Employee2 — through the Salesforce-hosted headless-360 MCP server. Use when the user asks to create a UEL user, set up a Unified Employee user account, enable an employee under the Unified Employee license, provision an employee with Person Account and Employee2 record, or onboard a new employee onto the Unified Employee profile. Triggers on: create UEL user, set up unified employee, provision unified employee, enable UEL employee, onboard employee user, create person account for employee. DO NOT TRIGGER when: the user asks to create a standard user without UEL, clone an existing user, manage existing user permissions only, assign incident permissions only, reset passwords only, or look up existing users without creation intent.

AI 生成的概览

通过 MCP 在 Salesforce 中开通统一员工许可(UEL)用户,并创建关联的人员账户、PersonContact 和 Employee2 记录。

功能
指导代理在 Salesforce 中创建统一员工许可(UEL)用户:先校验前置条件、解析经理,再在统一员工配置文件下创建用户、分配 Employee Hub 权限集、创建人员账户及其 PersonContact,并创建关联的 Employee2 记录。所有操作均通过 Salesforce 托管的 headless-360 MCP 服务器及其 discover、describe、dispatch、dispatch_readonly 工具执行。最后验证整条实体链,并输出便于阅读的开通结果摘要。
适用场景
适用于用户要求创建 UEL 用户、设置或开通统一员工用户账户、在统一员工许可下启用员工,或为员工创建人员账户与 Employee2 记录并完成入职的场景。不适用于创建非 UEL 的标准用户、克隆现有用户、仅调整权限或重置密码。
运行要求
需要 Salesforce 托管的 headless-360 MCP 服务器及其 discover、describe、dispatch、dispatch_readonly 工具,以及已认证的 MCP 会话(目标组织由 OAuth JWT 决定)。执行操作的管理员需具备管理内部用户、管理配置文件和权限集、自定义应用程序、分配权限集等权限,且组织需具备统一员工许可、配置文件、人员账户记录类型、Employee Hub 权限集和 Employee2 对象。不包含脚本,仅为说明文档,另附 MCP 调用格式的参考文件。

Create and Enable a Unified Employee (UEL) User

Provision an employee under the Unified Employee License (UEL) by creating and linking a User on the Unified Employee license/profile, a Person Account (with an auto-generated Contact), and an Employee2 record, then assigning the required permission sets. Every operation runs through the Salesforce-hosted headless-360 MCP server (server key headless-360) via its four meta-tools (discover, describe, dispatch_readonly, dispatch). The org is derived from the OAuth JWT bound to the current MCP session — the skill never handles an org id, alias, or credentials — so the flow behaves identically against production and sandbox with no per-user MCP install.

Scope

  • In scope: Creating a new UEL User, Person Account, Employee2 record; assigning permission sets; verifying the full chain.
  • Out of scope: Standard user creation (non-UEL); cloning existing users; managing existing user permissions only; deactivating users; license assignment changes.

Routes at a glance

Reads dispatch through mcp__headless-360__dispatch_readonly; writes through mcp__headless-360__dispatch. Both take raw HTTP: {"url": "<path>", "method": "GET|POST", "body"?: {...}, "queryParams"?: {...}}. Full URL paths and request/response bodies for every row live in references/mcp-invocation.md; this table lists only the operation and HTTP method.

ConcernMethod + operationNotes
Unified Employee licenseGET /query (UserLicense)Zero rows → stop
Unified Employee profileGET /query (Profile)Zero rows → stop
Person Account record typeGET /query (RecordType, IsPersonType)Zero rows → stop
Employee Hub perm setGET /query (PermissionSet)Mandatory; zero rows → stop
Employee2 accessibleGET /sobjects/Employee2/describe200 = HR module enabled
Resolve managerGET /query (User by Username/Name)Active users only
Create userPOST /sobjects/UserProfile = Unified Employee
Assign Employee Hub setPOST /sobjects/PermissionSetAssignmentMandatory
Create Person AccountPOST /sobjects/AccountPersonEmail required
Read PersonContactGET /query (Account)Capture PersonContactId
Create Employee2POST /sobjects/Employee2Use UserId/ContactId field names
Verify chainGET /queryUser + Account + Employee2 + perm sets

Response envelope: describe, /query, and /sobjects/… are all standard REST — the dispatch* tool returns the HTTP status plus the parsed body: { "status_code": 200, "body": <REST response> }. Read body. A create returns body.id and body.success == true; a query returns body.records[]. Status codes: 200/201 success; 400 bad body (re-check schema via describe); 401/auth error the MCP session needs re-auth; 404 the endpoint/impl is not present on this org; 500 a downstream dependency issue.


Required Inputs

Collect from the user (ask only what is not already in conversation context):

Identity (required)

FieldDescription
FirstNameEmployee first name
LastNameEmployee last name
EmailEmployee email address

Credentials & Locale (required)

FieldDescriptionExample
UsernameEmail-formatted, globally unique[email protected]
AliasMax 8 charsjdoe
TimeZoneSidKeyTimezoneAmerica/Los_Angeles
LocaleSidKeyLocaleen_US
LanguageLocaleKeyLanguageen_US
EmailEncodingKeyEmail encodingUTF-8

Manager (optional)

FieldDescription
ManagerName or ManagerUsernameResolve to ManagerId via SOQL

HR Attributes for Employee2 (required)

FieldDescription
DepartmentEmployee department
LocationEmployee location
EmployeeNumberHR employee number
TitleJob title
HireDateDate format: YYYY-MM-DD

Permission Sets

Employee Hub Unified Employee User (EmployeeHubEmployeeUser) is always assigned — no other permission sets belong on a UEL user. If the caller asks for extras (Incident Fulfiller, Case Agent, or any other fulfiller/agent-role set), decline: those are for fulfillers on the Service Cloud side, not for requesters who log into the Employee Hub. Point the caller at the appropriate fulfiller user-create flow instead of extending this one.


Workflow

All steps are sequential. Always read before you write. Every call goes through mcp__headless-360__* tools. Stop and report if any step fails.

Phase 1 — Preflight & discovery

On any 401 / 403 / 404 from a discover / describe / dispatch / dispatch_readonly call below, halt and surface the raw error — the org or client is not configured correctly. 401 → headless-360 MCP client not authenticated to CORE_ORG_ALIAS (session expired). 403 → executing user is missing one of the required perms (ManageUsers, ManageProfilesPermissionsets, CustomizeApplication, AssignPermissionSets) OR the org lacks the Unified Employee License. 404 → the target sObject / route is not available (HR module / UEL not provisioned — surfaces separately as the five prerequisite checks in step 2).

  1. Discover the operations — mcp__headless-360__discover(query="create User Account Employee2 sObject") and mcp__headless-360__describe(id=<operation_id>) for the POST /sobjects/User, POST /sobjects/Account, and POST /sobjects/Employee2 operations to confirm they are indexed and pull the input schema. A discover miss does not mean the route is absent — the /sobjects/… REST endpoints are core Data API paths and can be invoked directly with dispatch_readonly / dispatch against the exact URL (see references/mcp-invocation.md). If a direct dispatch_readonly probe at the documented path also fails (404), direct the user to the Setup UI.

  2. Verify all five UEL prerequisites (all read-only /query or describe). If any fails, stop and report exactly which prerequisite is missing:

    • Unified Employee license exists → else "Unified Employee license not found in this org."
    • Unified Employee profile exists → else "Unified Employee profile not found. Ensure UEL license is provisioned."
    • Active Person Account record type exists → else "No active Person Account record type found. Enable Person Accounts in Setup."
    • Employee Hub permission set exists → else "Employee Hub Unified Employee User permission set not found. This is required for UEL provisioning."
    • Employee2 describe returns 200 → else "Employee2 sObject not accessible. Ensure the HR module is enabled."

    Capture: UnifiedEmployeeProfileId, PersonAccountRecordTypeId, EmployeeHubPermSetId.

Phase 2 — Resolve references

  1. Resolve the manager — when the user supplied a manager, query by Username or Name (active users only). On multiple matches, present options and ask the user to disambiguate. Capture ManagerId. When no manager was supplied, skip this step.
  2. Check username uniqueness — query User by Username; any record → stop, username taken.

Phase 3 — Confirm & create the chain

  1. Confirm the plan — present the full configuration (including HR attributes) and wait for explicit confirmation before any mutation.
  2. Create the User — POST /sobjects/User with identity, locale, ProfileId = UnifiedEmployeeProfileId, and ManagerId (omit ManagerId when none). Capture NewUserId.
  3. Assign the Employee Hub permission set (mandatory) — POST /sobjects/PermissionSetAssignment with {AssigneeId: NewUserId, PermissionSetId: EmployeeHubPermSetId}. If this fails, stop and report the exact error — the set exists (verified) but may be incompatible with the license.
  4. Create the Person Account — POST /sobjects/Account with FirstName, LastName, PersonEmail (required), and RecordTypeId = PersonAccountRecordTypeId. Capture NewAccountId. PersonEmail must be set: the Employee2 validation hook rejects the record when the linked PersonContact is missing Email or LastName.
  5. Verify the PersonContact — query the Account for IsPersonAccount and PersonContactId. Confirm IsPersonAccount = true and capture PersonContactId. If it is null, stop and report failure to generate the PersonContact.
  6. Create the Employee2 record — POST /sobjects/Employee2 with UserId = NewUserId, ContactId = PersonContactId, and the HR attributes. Use the foreign-key field names UserId/ContactId (not the relationship names User/Contact). Capture NewEmployee2Id.

Phase 4 — Verify & present

  1. Verify the full chain — query the Account (IsPersonAccount, PersonContactId), the User (IsActive, ProfileId, ManagerId), the Employee2 (UserId, ContactId), and confirm the Employee Hub permission set is the only PermissionSetAssignment (beyond the profile).
  2. Report using the output format below.

Rules / Constraints

ConstraintRationale
Verify all five prerequisites before any mutationPrevents partial state when the org is not configured for UEL
Always describe before a POSTYou need the exact input schema for each sObject
Confirm the plan with the user before creating recordsPrevents unintended record creation
PersonEmail is required on Person Account createThe Employee2 validation hook rejects a PersonContact with no Email
Use UserId/ContactId field names on Employee2The API rejects bare IDs under the relationship names
Employee Hub Unified Employee User is the ONLY permset assignedUEL users are Employee Hub requesters, not fulfillers/agents — no other permsets are compatible
Omit null/empty foreign keys from create bodiesThe API rejects an explicit empty ManagerId
Display the exact error from dispatch* on failureHelps diagnose issues
Never show Salesforce record IDs to the userUse human-readable names only

Permissions Required

The executing admin user (the identity behind CORE_ORG_ALIAS) must have:

PermissionPurpose
Manage Internal UsersCreate User records
Manage Profiles and Permission SetsAssign permission sets
Customize ApplicationCreate Employee2 and Person Account records
Assign Permission SetsCreate PermissionSetAssignment records

Verification Checklist

  • Did discover + describe(id) (or, on a discover miss, a direct dispatch_readonly probe at the documented /sobjects/… path) confirm the User / Account / Employee2 create operations?
  • Did all five UEL prerequisites pass (license, profile, Person Account RT, Employee Hub set, Employee2)?
  • Did you confirm the username is unique and confirm the plan before any mutation?
  • Is Account.IsPersonAccount = true with a non-null PersonContactId?
  • Is User.IsActive = true on the Unified Employee profile (and manager, if provided)?
  • Does Employee2 link UserId and ContactId correctly?
  • Is Employee Hub Unified Employee User the only permission set assigned (no fulfiller-side extras)?

Output Format

On failure, display the error from dispatch* exactly as returned.

On success:

text
UEL User Provisioning Complete (via service-itsm-agentic-setup-uel-user-create)
User:  Name:     <FirstName> <LastName>  Username: <Username>  Email:    <Email>  Profile:  Unified Employee  Manager:  <ManagerName> (or "not set")  Status:   Active
Person Account:  Account Name: <FirstName> <LastName>  Person Contact: linked
Employee Record:  Department:    <Department>  Title:         <Title>  Location:      <Location>  Employee No:   <EmployeeNumber>  Hire Date:     <HireDate>
Permission Set Assigned:  - Employee Hub Unified Employee User
Chain: User > Person Account > PersonContact > Employee2 > Employee Hub permset

No record IDs in user-facing output — use human-readable names only.


Reference File Index

FileWhen to read
references/mcp-invocation.mdEvery phase — exact mcp__headless-360__* call shapes, the five prerequisite queries, the create bodies for the full chain, response envelope, discovery, and gotchas

Related Skills

This skill provisions a Unified Employee License (UEL) user with the full entity chain. Two adjacent flows are out of scope: creating a standard (non-UEL) user, and cloning an existing user's full access configuration. Handle those requests separately — this skill does not cover them.

来源与署名

来源:forcedotcom/sf-skills位于skills/service-itsm-agentic-setup-uel-user-create提交e5164d9

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 forcedotcom/sf-skills 的技能

Service Itsm Teams Itservice Configure

forcedotcom

Configure the "Set Up Salesforce IT Service" checklist for Microsoft Teams Employee Service (ITSM) — the employee side, covering app enablement, marketplace install guidance, user access assignment, and Digital Experience Site selection. Use this for: 'turn on Salesforce IT Service', 'set up IT Service on Teams', 'assign Teams for Employee permission set', 'give employees access to Teams for Employee Service', 'manage user access for Teams ITSM', 'grant users the permission sets needed for Teams Employee Service', 'select a digital experience site for Teams', 'install Salesforce IT Service app on Teams', or any request to complete the IT Service half of the Teams ITSM Go page checklist (including the Manage User Access step). DO NOT TRIGGER for the base Teams Salesforce Go page toggle or Azure/Entra app setup (service-itsm-teams-configure) or for the IT Desk/fulfiller half of the checklist (service-itsm-teams-itdesk-configure).

待分类1K昨天更新

Service Itsm Teams Coordinate

forcedotcom

End-to-end autopilot orchestrator for setting up Microsoft Teams integration in Salesforce Service Cloud ITSM — runs the whole flow (enable the Teams for Employee Service Go feature, register the Microsoft Entra app, populate Named Credentials, configure the IT Desk and IT Service checklists, turn on Swarming, and optionally embed the Agentforce agent) in one continuous pass, stopping only at the points a human must act. Use when the user asks to set up Microsoft Teams for ITSM end to end, 'set up teams for it service', 'do the whole teams itsm setup', 'configure microsoft teams for employee service', or wants a guided Teams ITSM walkthrough. Delegates each stage to a specialized child skill while driving the sequence itself. DO NOT TRIGGER when the user asks to enable Teams alone, configure just the IT Desk or IT Service checklist alone, or enable Swarming alone — delegate directly to the specific child skill in those cases.

待分类1K昨天更新

Service Itsm Teams Itdesk Configure

forcedotcom

Configure the "Set Up Salesforce IT Desk" checklist for Microsoft Teams Employee Service (ITSM) — the fulfiller/agent side, covering app enablement, marketplace install guidance, user access assignment, and Swarming collaboration-tool setup. Use this for: 'turn on Salesforce IT Desk', 'set up IT Desk on Teams', 'assign Teams for IT Desk permission set', 'set Teams as collaboration tool for swarming', 'install Salesforce IT Desk app on Teams', or any request to complete the IT Desk half of the Teams ITSM Go page checklist. DO NOT TRIGGER for the base Teams Salesforce Go page toggle or Azure/Entra app setup (service-itsm-teams-configure) or for the IT Service/employee half of the checklist (service-itsm-teams-itservice-configure).

待分类1K昨天更新

Service Itsm Teams Debug

forcedotcom

通过针对 Salesforce 组织运行通过/失败配置检查清单,诊断 Microsoft Teams 员工服务(ITSM)配置故障。

DevOps & Cloud1K昨天更新

Service Itsm Teams Employee Agent Configure

forcedotcom

Configure the embedded Agentforce Employee Agent so it replies inside the Microsoft Teams ITSM custom client ('Salesforce Employee Assist' / 'Ask AI Agent'). Use this for: 'set up employee agent in Teams', 'embed Agentforce agent in Teams', 'make the IT Service Employee Agent reply in Teams', 'Teams Ask AI Agent not responding', 'agent joins then leaves without replying', 'configure MIAW deployment for Teams employee agent', 'Teams embedded messaging agent setup'. Builds the whole stack headlessly (zero Setup-UI clicks): the Web messaging channel with User Verification ON, the Enhanced Chat User Verification Key Set (JWKS_URL) it requires, the Teams_AgentForce custom-client deployment, the routing flow to the agent, and the Agent Access permission set that lets the portal user reach the agent. DO NOT TRIGGER for enabling the Teams feature Salesforce Go page toggle (service-itsm-teams-configure) or for configuring notification preferences.

待分类1K昨天更新

Service Itsm Swarming Configure

forcedotcom

通过 Connect API 调用启用 Salesforce Swarming ITSM 功能,并将协作工具设为 Teams。

DevOps & Cloud1K昨天更新