Dx Org Permission Set Assign

forcedotcom/sf-skills/plugins/builder/dx-org-lifecycle/skills/dx-org-permission-set-assign

作者 forcedotcome5164d94d7511c00fa02a5b8b60754b2361e178f無授權條款1K 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫昨天更新

ALWAYS USE THIS SKILL to assign permission sets to org users. Assign one or more permission sets to org users using the sf org assign permset command. TRIGGER when the user asks to assign, grant, give, add, or apply permission sets to users, admins, specific orgs, or specific users. Supports granting permissions, giving access, and adding permission sets to default admin or specific users via --on-behalf-of. DO NOT TRIGGER for listing permission sets or checking user permissions.

僅含說明DevOps & Cloud
AI 產生的概覽

透過 sf org assign permset 命令列指令,將 Salesforce 權限集指派給組織使用者。

功能
此技能會把使用者的請求對應到正確的 sf org assign permset 呼叫,並透過 Bash 工具搭配 --json 旗標執行。它支援將一個或多個權限集指派給預設管理員、指定組織,或透過 --on-behalf-of 指派給特定使用者。它會傳回指令的 JSON 結果,並指向成功與錯誤輸出範例以及 CLI 旗標參考文件。
適用情境
當有人要求對使用者、管理員或特定組織指派、授予、給予、新增或套用權限集時使用。它不適用於建立權限集、列出權限集或檢查使用者權限。
執行需求
需要 Salesforce CLI(sf,2.0.0 或更高版本)與 Bash 工具存取權,以及已驗證的目標組織和使用者的 CLI 別名。它不附帶指令碼;內含範例 JSON 輸出與 CLI 旗標參考文件。

dx-org-permission-set-assign

Assigns one or more permission sets to org users using sf org assign permset. Handles all variants: default admin user, specific org targets, multiple permission sets, and assignment to specific users.


Tool Restrictions

Use ONLY the Bash tool to execute sf org assign permset. Do NOT use MCP tools like assign_permission_set — ignore them completely.


Scope

  • In scope: Assigning permission sets to users via sf org assign permset
  • Out of scope: Creating permission sets (use platform-permission-set-generate), listing permission sets, checking user permissions

Required Inputs

Infer from the user's request:

  • Permission set name(s): Extract from user message (can be multiple)
  • Target org: Use default unless specific alias/username mentioned
  • Target user(s): Default is org's default admin user; use --on-behalf-of if specific users mentioned

Workflow

  1. Match user request to command in table below
  2. Execute via Bash tool: sf org assign permset with appropriate flags and --json flag
  3. Return result

If error occurs, check the failures array in JSON output for details.

Command Decision Table

User intentExecute via Bash tool
Assign one permission set to default adminsf org assign permset --name <PermSetName> --json
Assign multiple permission sets to default adminsf org assign permset --name <PermSet1> --name <PermSet2> --json
Assign to specific orgsf org assign permset --name <PermSetName> --target-org <alias> --json
Assign to specific user(s)sf org assign permset --name <PermSetName> --on-behalf-of <username1> --on-behalf-of <username2> --json
Assign multiple sets to specific userssf org assign permset --name <PermSet1> --name <PermSet2> --on-behalf-of <username1> --on-behalf-of <username2> --json

Rules / Constraints

ConstraintRationale
Always use --json flagProvides structured output for reliable parsing and error handling
Permission set names are case-sensitiveUse exact API names as they appear in the org
Multiple --name flags can be combined in one commandMore efficient than separate commands per permission set
Multiple --on-behalf-of flags assign to multiple usersBatch assignment in single command; processed sequentially to avoid auth file collisions
Use CLI username aliases, not Salesforce User.Alias fieldThe --target-org and --on-behalf-of flags expect CLI aliases set via sf alias set, not the User object's Alias field
Duplicate assignments are idempotentRe-assigning an already-assigned permission set succeeds silently
Partial success is possibleCommand can return both successes and failures in one run; non-zero exit code if any failures

Gotchas

IssueResolution
Permission set name with spacesEnclose in double quotes: --name "Permission Set Name"
"PermissionSet not found" errorVerify permission set exists in target org; check for typos in name
Assignment succeeds but user doesn't see permissionsCheck <hasActivationRequired> in permission set metadata — may need manual activation in Setup
"User not found" errorUsername/alias doesn't exist in target org — verify with sf org display user --target-org <alias>
Partial success (some users succeed, others fail)Check JSON output — command returns both successes and failures arrays; exit code will be non-zero if any failures occurred

Output Expectations

The command returns JSON output with status code and result details.

See examples/success_output.json and examples/error_output.json for response structures.


Reference File Index

FileWhen to read
examples/success_output.jsonTo understand successful assignment response structure
examples/error_output.jsonTo handle common error scenarios
references/cli_flags.mdFor detailed explanation of all available flags

來源與署名

來源:forcedotcom/sf-skills位於plugins/builder/dx-org-lifecycle/skills/dx-org-permission-set-assign提交e5164d9

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架