跳到主要内容
知仓学习社ZHICANG

dx-org-permission-set-assign

ALWAYS USE THIS SKILL to assign permission sets to org users. Assign one or more permission sets to org users using the sf org assign permset comman…

不碰外部(只输出文字)无严重或高危命中forcedotcom/sf-skills

它会碰到什么

扫了多少4 个文本文件,7 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

dx-org-permission-set-assign

Assigns one or more permission sets to org users using sf org assign permset. Handles all variants: default admin user, specific org targets, multiple permission sets, and assignment to specific users.


Tool Restrictions

Use ONLY the Bash tool to execute sf org assign permset. Do NOT use MCP tools like assign_permission_set — ignore them completely.


Scope

  • In scope: Assigning permission sets to users via sf org assign permset
  • Out of scope: Creating permission sets (use platform-permission-set-generate), listing permission sets, checking user permissions

Required Inputs

Infer from the user's request:

  • Permission set name(s): Extract from user message (can be multiple)
  • Target org: Use default unless specific alias/username mentioned
  • Target user(s): Default is org's default admin user; use --on-behalf-of if specific users mentioned

Workflow

  1. Match user request to command in table below
  2. Execute via Bash tool: sf org assign permset with appropriate flags and --json flag
  3. Return result

If error occurs, check the failures array in JSON output for details.

Command Decision Table

| User intent | Execute via Bash tool |

|-------------|---------|

| Assign one permission set to default admin | sf org assign permset --name <PermSetName> --json |

| Assign multiple permission sets to default admin | sf org assign permset --name <PermSet1> --name <PermSet2> --json |

| Assign to specific org | sf org assign permset --name <PermSetName> --target-org <alias> --json |

| Assign to specific user(s) | sf org assign permset --name <PermSetName> --on-behalf-of <username1> --on-behalf-of <username2> --json |

| Assign multiple sets to specific users | sf org assign permset --name <PermSet1> --name <PermSet2> --on-behalf-of <username1> --on-behalf-of <username2> --json |


Rules / Constraints

| Constraint | Rationale |

|-----------|-----------|

| Always use --json flag | Provides structured output for reliable parsing and error handling |

| Permission set names are case-sensitive | Use exact API names as they appear in the org |

| Multiple --name flags can be combined in one command | More efficient than separate commands per permission set |

| Multiple --on-behalf-of flags assign to multiple users | Batch assignment in single command; processed sequentially to avoid auth file collisions |

| Use CLI username aliases, not Salesforce User.Alias field | The --target-org and --on-behalf-of flags expect CLI aliases set via sf alias set, not the User object's Alias field |

| Duplicate assignments are idempotent | Re-assigning an already-assigned permission set succeeds silently |

| Partial success is possible | Command can return both successes and failures in one run; non-zero exit code if any failures |


Gotchas

| Issue | Resolution |

|-------|------------|

| Permission set name with spaces | Enclose in double quotes: --name "Permission Set Name" |

| "PermissionSet not found" error | Verify permission set exists in target org; check for typos in name |

| Assignment succeeds but user doesn't see permissions | Check <hasActivationRequired> in permission set metadata — may need manual activation in Setup |

| "User not found" error | Username/alias doesn't exist in target org — verify with sf org display user --target-org <alias> |

| Partial success (some users succeed, others fail) | Check JSON output — command returns both successes and failures arrays; exit code will be non-zero if any failures occurred |


Output Expectations

The command returns JSON output with status code and result details.

See examples/success_output.json and examples/error_output.json for response structures.


Reference File Index

| File | When to read |

|------|-------------|

| examples/success_output.json | To understand successful assignment response structure |

| examples/error_output.json | To handle common error scenarios |

| references/cli_flags.md | For detailed explanation of all available flags |

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

同名技能的其他版本

有 2 个不同仓库或目录里都有叫 dx-org-permission-set-assign 的技能。它们内容并不相同,别混用:

  • forcedotcom/sf-skills — ALWAYS USE THIS SKILL to assign permission sets to org users. Assign one or more permissio