
Post-Install Configuration
OfficialFreeAutomate configuration for Salesforce managed packages.
Free · Opens the source repo
What Post-Install Configuration does
The Post-Install Configuration skill is designed to streamline the process of setting up Salesforce managed packages after installation. This skill is package-agnostic, meaning it can work with any managed package, including popular options like LMA, FMA, and work.com. When triggered, it automates the necessary post-install configuration steps, which can include setting up permission sets, object and field permissions, page layouts, Visualforce page access, and tab settings. This automation helps reduce manual errors and saves time during the setup process.
To use this skill, you will need to provide the name of the managed package you are configuring. Optionally, you can supply a path to the post-install documentation, which the skill will read to extract the required configuration steps. If no documentation is provided, the skill will prompt you to supply it. The workflow is methodical, ensuring that each phase is completed successfully before moving on to the next, which helps maintain the integrity of the configuration process.
The skill operates in several phases, starting with discovering available execution methods based on the Salesforce org's setup. It checks for the availability of org-native platform MCP servers and falls back to the Salesforce CLI if necessary. After verifying authentication and ensuring the package is installed, the skill reads and parses the post-install document to classify the steps as either automated or manual. This classification allows for an interactive review, where users can approve all steps, choose specific ones, or ask questions before proceeding.
In summary, the Post-Install Configuration skill is a valuable tool for Salesforce developers and administrators looking to automate and streamline the often tedious process of configuring managed packages post-installation. By leveraging this skill, users can ensure that their configurations are accurate and efficient, ultimately leading to a smoother deployment process.
When to use it
Use this skill when you need to automate the post-install configuration of any Salesforce managed package.
When not to use it
This skill is not suitable for standalone permission set assignments or generating permission set metadata XML.
What you can build with it
Automating LMA Setup
After installing the LMA package, use this skill to automate the necessary configuration steps.
Configuring FMA Permissions
When setting up FMA, this skill can streamline the configuration of permission sets and access.
Post-Install for work.com
Utilize this skill to efficiently configure settings for the work.com managed package after installation.
How to install Post-Install Configuration
View source1. Install with the skills CLI
npx skills add forcedotcom/sf-skills/dx-pkg-post-install-configure --agent claude-code2. Or install it manually
Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.
Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs
Inside SKILL.md
Written by forcedotcomWhen to Use This Skill
Use when automating post-install configuration for any Salesforce managed package. This skill reads the package's post-install documentation, discovers available execution methods, and automates the configuration steps — including permission sets, object/field permissions, page layouts, Visualforce page access, and tab settings.
Input
- Required: Package name (e.g.,
LMA,FMA,work.com) - Optional: Path to post-install doc (PDF, markdown, URL)
If no doc is provided, ask the user to supply it.
Workflow
Execute phases in order. Each phase must pass before proceeding.
Phase 1: Discover Available Execution Methods
Priority order:
- Org-native platform MCP servers (highest — direct org access via Headless 360)
- Claude Code external MCP servers (sf-sobject-all, sf-sobject-all-sb, etc.)
- sf CLI fallback (always available if authenticated)
Step 1A: Resolve org API version
Discover the org's current API version dynamically — never hardcode a version number:
sf org display --target-org <alias> --json
From the JSON response, read result.apiVersion (e.g., "67.0"). Store this value and use it as v<apiVersion> in all subsequent REST paths. If the command fails, fall back to the minApiVersion declared in this skill's metadata (67.0).
Step 1B: Check for org-native platform MCP servers
Query the Tooling API for MCP server availability:
sf api request rest "/services/data/v<apiVersion>/tooling/query?q=SELECT+Id,DeveloperName,MasterLabel+FROM+McpServerAccess" --target-org <alias>
Step 1C: Determine execution method
Check which Claude Code MCP tools are available and authenticated.
MCP tool prefixes by org type:
| Org Type | Tool Prefix |
|---|---|
| Production | mcp__sf-sobject-all__ |
| Sandbox | mcp__sf-sobject-all-sb__ |
| Falcon Test (pc-rnd) | mcp__sf-sobject-all-falcon__ |
If MCP needs auth, call the authenticate tool. If auth fails, fall back to sf CLI.
Phase 2: Verify Authentication & Org Identity
- Run a lightweight test query (
SELECT Id, Name, IsSandbox FROM Organization) - If MCP auth fails, automatically fall back to sf CLI
- Display org info and ask user to confirm before proceeding
Phase 3: Verify Package Installation
- Determine the package namespace (ask user if unknown)
- Check via Tooling API (
InstalledSubscriberPackage) — do NOT usePackageLicense - If package not found, stop and inform user
Phase 4: Read and Parse Post-Install Document
Read the provided document and extract discrete configuration steps.
Supported formats: PDF, markdown, URL (via WebFetch), pasted text.
Parsing approach:
- Extract each numbered/bulleted step from the document
- Present the extracted steps to the user for validation before proceeding
Phase 5: Classify Steps & Interactive Plan Review
For each step extracted from the doc, classify as Automated or Manual.
Automation capabilities reference
Via MCP (sobject-all) or sf CLI CRUD:
- Record CRUD on any standard or custom object (PermissionSet, ObjectPermissions, FieldPermissions, SetupEntityAccess, PermissionSetTabSetting, PermissionSetAssignment, etc.)
Via Metadata API retrieve/deploy (sf CLI):
- Page layout modifications (add related lists, fields, sections)
- Profile settings
- Custom metadata type records
Via sf CLI Tooling API:
- Tooling queries (InstalledSubscriberPackage, ApexPage, ApexClass, etc.)
- Any REST-accessible Tooling operation
Manual (no API path — requires Setup UI):
- System permissions not exposed via REST
- Connected app OAuth configuration
- Environment Hub linkage
Interactive approval
Present the classified plan and let the user choose:
- "Approve all" — Execute all steps as planned
- "Let me choose" — Select which steps to approve/skip
- "I have questions" — Discuss specific steps before deciding
Phase 6: Execute Approved Steps
For each approved step, use the resolved execution method.
Execution method reference
| Operation | Via MCP | Via sf CLI |
|---|---|---|
| SOQL query | soqlQuery tool | sf data query --query "<SOQL>" --target-org <alias> --json |
| Create record | createSobjectRecord tool | sf data create record --sobject <Object> --values "..." --target-org <alias> --json |
| Update record | updateSobjectRecord tool | sf data update record --sobject <Object> --record-id <id> --values "..." --target-org <alias> --json |
| Describe object | getObjectSchema tool | sf api request rest "/services/data/v<apiVersion>/sobjects/<Object>/describe" --target-org <alias> |
| Page layout | N/A | Metadata API retrieve/deploy |
Page layout modifications via Metadata API
Use sf project retrieve start → edit the layout XML → sf project deploy start.
Execution rules
- Idempotency: Before creating any record, query to check if it already exists. Skip if so.
- Report after each step: Show success count, skipped items, and reasons.
- Automatic fallback: If MCP fails mid-execution, retry via sf CLI.
- On failure: Report error, ask user to retry/skip/stop.
Phase 7: Guide Manual Steps (if any)
If any steps could not be automated, present each with Setup navigation instructions. Wait for user confirmation before proceeding to the next.
Phase 8: Summary
Display final summary with step-by-step status, method used, and any skipped items.
Error Handling
- Auth failure mid-execution: Stop, ask user to re-auth, offer to resume
- Duplicate record errors: Treat as "already configured", skip and continue
- Permission errors: Report which permission is missing, suggest resolution
- Unknown step type: Ask user to clarify, offer to mark as manual
Notes
- Priority: org-native MCP > Claude Code MCP > sf CLI > manual
- sf CLI is always a valid fallback for all CRUD and Tooling API operations
- Page layout modifications are automated via Metadata API retrieve/deploy
- Always verify org identity before making changes
- All actions respect the authenticated user's permissions
Frequently asked questions about Post-Install Configuration
Similar skills
Spring Boot Testing
Master testing techniques for Spring Boot 4 applications.
GitHub Issues
Manage GitHub issues efficiently with MCP tools.
Geofeed Tuner
Optimize your IP geolocation feeds in CSV format.
Batch Files
Master Windows batch scripting for automation and task management.
Adobe Illustrator Scripting
Automate your Illustrator workflows with ExtendScript.
Plugin Structure
Create and organize Claude Code plugins effectively.
