Skip to main content
Glama
advancedcommunities

Salesforce MCP Server

assign_permission_set

Destructive

Assign one or more Salesforce permission sets to org users or admins using CLI aliases, enabling bulk access management across target orgs.

Instructions

Assign a permission set to one or more org users. To specify an alias for the --target-org or --on-behalf-of flags, use the CLI username alias, such as the one you set with the 'alias set' command. Don't use the value of the Alias field of the User Salesforce object for the org user. To assign multiple permission sets, specify multiple names in the permissionSetNames array. Enclose names that contain spaces in the array elements. The same syntax applies to onBehalfOf array for specifying multiple users.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
inputYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.7.0

TDQS

C2.9/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare destructiveHint=true, idempotentHint=false, openWorldHint=true, so the safety profile is covered by structured data. The description adds useful domain context about CLI username aliases vs the User Alias field, which is not in annotations. However, it doesn't state that the operation requires specific permissions, nor mention the destructive/non-idempotent nature explicitly.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The core assignment sentence is front-loaded, which is good, but the remaining sentences are dense and somewhat repetitive about alias vs Alias field and array syntax, adding length without proportionate clarity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a destructive, non-idempotent mutation tool with no output schema and 0% schema coverage, the description omits prerequisites (permissions needed, org authentication), irreversibility, and what happens on partial failure. The alias-domain detail is present, but the risk-relevant information is not.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0%, so the description must compensate. It does explain that permissionSetNames accepts multiple names and that onBehalfOf accepts multiple users with the same syntax, plus alias-vs-Alias-field guidance. But it does not explain targetOrg semantics beyond the schema's own description, and the array element syntax guidance is partial – much of the parameter meaning still rests on the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a clear verb+resource: 'Assign a permission set to one or more org users.' The sibling assign_permission_set_license is not mentioned, so it lacks explicit differentiation, but the purpose itself is unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance on when to use this tool versus assign_permission_set_license or other permission-related siblings. The description explains CLI alias syntax mechanics but never says when this tool is the right choice.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.