salesforce-enterprise-rbac
Installation
SKILL.md
Salesforce Enterprise Access and Sharing Governance
Overview
Build least privilege from job and workload needs through app authorization, org permissions, object and field access, record sharing, and periodic review.
Prerequisites
- Personas and integration workloads, business functions, data classes, orgs, environments, and owners
- Current profiles, permission sets and groups, licenses, roles, sharing defaults and rules, field access, queues, and app policies
- Identity lifecycle, SSO and MFA, privileged access, break-glass, segregation, recertification, and audit requirements
Tool Discipline
Use Read, Glob, and Grep to inspect approved repository and evidence files, WebFetch to re-check current first-party Salesforce documentation, and Write or Edit only for secretless plans, fixtures, configuration, and redacted receipts.
Current Contract
Salesforce authorization is layered: identity and app policy, license and profile baseline, permission sets or groups, object CRUD, field access, record sharing, and contextual controls. Effective access must be measured in the target org and user context.