New to Claude Skills? Learn how to install them →

forcedotcom on GitHub

Org Permission Set Assign

OfficialFree

Easily assign permission sets to users in your org.

Get this skill

Free · Opens the source repo

What Org Permission Set Assign does

The Org Permission Set Assign skill streamlines the process of assigning permission sets to users within a Salesforce org. By leveraging the sf org assign permset command, this skill allows users to assign one or multiple permission sets to the default admin or specific users efficiently. The skill is particularly useful for administrators who need to manage user permissions quickly and effectively, especially in environments with multiple users or complex permission requirements.

When a user prompts to assign permission sets, the skill intelligently infers the necessary parameters, including the permission set names, target org, and target users. It supports batch assignments, allowing multiple permission sets to be assigned in a single command, which enhances productivity and reduces the time spent on repetitive tasks. The skill ensures that all assignments are executed with structured JSON output, making it easier to parse and handle any errors that may arise during the process.

This skill is designed specifically for Salesforce administrators and developers who need to manage user permissions without delving into the Salesforce UI. By automating the assignment process, users can focus on more critical tasks while ensuring that permissions are correctly assigned according to organizational needs. The skill's constraints and guidelines help prevent common pitfalls, such as typos in permission set names or issues with user aliases, providing a reliable tool for permission management.

When to use it

Use this skill when you need to assign permission sets to users, whether it's a single user or multiple users at once.

When not to use it

This skill is not suitable for creating permission sets or for listing existing permission sets; use other tools for those tasks.

What you can build with it

Assigning to Default Admin

Quickly assign a permission set to the default admin user without specifying any additional parameters.

Batch Assignments

Assign multiple permission sets to several users in one command, improving efficiency in user management.

Targeting Specific Users

Assign permission sets to specific users by leveraging the `--on-behalf-of` flag, ensuring tailored access.

How to install Org Permission Set Assign

View source

1. Install with the skills CLI

npx skills add forcedotcom/sf-skills/dx-org-permission-set-assign --agent claude-code

2. Or install it manually

Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.

Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs

Inside SKILL.md

Written by forcedotcom

dx-org-permission-set-assign

Assigns one or more permission sets to org users using sf org assign permset. Handles all variants: default admin user, specific org targets, multiple permission sets, and assignment to specific users.


Tool Restrictions

Use ONLY the Bash tool to execute sf org assign permset. Do NOT use MCP tools like assign_permission_set — ignore them completely.


Scope

  • In scope: Assigning permission sets to users via sf org assign permset
  • Out of scope: Creating permission sets (use platform-permission-set-generate), listing permission sets, checking user permissions

Required Inputs

Infer from the user's request:

  • Permission set name(s): Extract from user message (can be multiple)
  • Target org: Use default unless specific alias/username mentioned
  • Target user(s): Default is org's default admin user; use --on-behalf-of if specific users mentioned

Workflow

  1. Match user request to command in table below
  2. Execute via Bash tool: sf org assign permset with appropriate flags and --json flag
  3. Return result

If error occurs, check the failures array in JSON output for details.

Command Decision Table

User intentExecute via Bash tool
Assign one permission set to default adminsf org assign permset --name <PermSetName> --json
Assign multiple permission sets to default adminsf org assign permset --name <PermSet1> --name <PermSet2> --json
Assign to specific orgsf org assign permset --name <PermSetName> --target-org <alias> --json
Assign to specific user(s)sf org assign permset --name <PermSetName> --on-behalf-of <username1> --on-behalf-of <username2> --json
Assign multiple sets to specific userssf org assign permset --name <PermSet1> --name <PermSet2> --on-behalf-of <username1> --on-behalf-of <username2> --json

Rules / Constraints

ConstraintRationale
Always use --json flagProvides structured output for reliable parsing and error handling
Permission set names are case-sensitiveUse exact API names as they appear in the org
Multiple --name flags can be combined in one commandMore efficient than separate commands per permission set
Multiple --on-behalf-of flags assign to multiple usersBatch assignment in single command; processed sequentially to avoid auth file collisions
Use CLI username aliases, not Salesforce User.Alias fieldThe --target-org and --on-behalf-of flags expect CLI aliases set via sf alias set, not the User object's Alias field
Duplicate assignments are idempotentRe-assigning an already-assigned permission set succeeds silently
Partial success is possibleCommand can return both successes and failures in one run; non-zero exit code if any failures

Gotchas

IssueResolution
Permission set name with spacesEnclose in double quotes: --name "Permission Set Name"
"PermissionSet not found" errorVerify permission set exists in target org; check for typos in name
Assignment succeeds but user doesn't see permissionsCheck <hasActivationRequired> in permission set metadata — may need manual activation in Setup
"User not found" errorUsername/alias doesn't exist in target org — verify with sf org display user --target-org <alias>
Partial success (some users succeed, others fail)Check JSON output — command returns both successes and failures arrays; exit code will be non-zero if any failures occurred

Output Expectations

The command returns JSON output with status code and result details.

See examples/success_output.json and examples/error_output.json for response structures.


Reference File Index

FileWhen to read
examples/success_output.jsonTo understand successful assignment response structure
examples/error_output.jsonTo handle common error scenarios
references/cli_flags.mdFor detailed explanation of all available flags

Frequently asked questions about Org Permission Set Assign

Similar skills