PluginBench
Skill
Pass
Audit score 90

platform-sharing-owd-configure

forcedotcom/sf-skills

Retrieve and update Organization-Wide Default (OWD) sharing settings for Salesforce objects.

What is platform-sharing-owd-configure?

Manage baseline access levels (Private, Public Read Only, Public Read/Write, Controlled by Parent) for standard and custom objects in Salesforce. Use this skill when you need to check or change who can see records by default, configure internal and external sharing models, or update sharingModel in object metadata files.

  • Query current OWD settings for any standard or custom object using the Tooling API
  • Update internal and external access levels via metadata deployment
  • Validate access level changes against platform constraints and immutable object rules
  • Handle Master-Detail relationships requiring ControlledByParent
  • Verify external access is not more permissive than internal access
  • Detect and explain platform-fixed OWD values that cannot be changed

How to install platform-sharing-owd-configure

npx skills add https://github.com/forcedotcom/sf-skills --skill platform-sharing-owd-configure
Prerequisites
  • Salesforce CLI (sf) version 2.0.0 or later
  • Connected org with authentication (default org or specified alias)
  • Manage Sharing permission or System Administrator profile to update OWD settings
  • Tooling API and Metadata API enabled in target org
Claude Code
Cursor
Windsurf
Cline

How to use platform-sharing-owd-configure

  1. 1.Identify the object(s) and desired access level (Private, Public Read Only, Public Read/Write, or Controlled by Parent)
  2. 2.Run a query to retrieve current OWD settings using the Tooling API
  3. 3.Review the current internal and external sharing models
  4. 4.Confirm the requested access level is valid for the object (check immutable/fixed objects list)
  5. 5.Retrieve the object metadata file (.object-meta.xml)
  6. 6.Update sharingModel and/or externalSharingModel in the metadata
  7. 7.Verify external access is not more permissive than internal access
  8. 8.Deploy the updated metadata to the org

Use cases

Good for
  • Check current sharing defaults for a custom object before making changes
  • Change Account OWD from Public Read/Write to Private to restrict baseline access
  • Configure external sharing model for a custom object when external org-wide defaults are enabled
  • Verify Price Book OWD is correctly set to the platform-enforced value
  • Update multiple objects' sharing models as part of org security hardening
Who it's for
  • Salesforce administrators managing org-wide security policies
  • Developers configuring sharing models for custom objects
  • Security teams implementing least-privilege access controls
  • Org architects planning data governance and record visibility

platform-sharing-owd-configure FAQ

What is the difference between internal and external access levels?

Internal access defines the baseline sharing model for users within your org; external access defines it for external users (partner portal, customer portal). External access cannot be more permissive than internal access.

Can I change OWD for objects with Master-Detail relationships?

Yes, but only to ControlledByParent. Objects with Master-Detail relationships must use this value — attempting other values will fail during deployment.

Why does the skill refuse to deploy a change to Price Book OWD?

Price Book external OWD is platform-fixed at None and internal OWD only accepts Use or No Access. Standard access levels (Private/Read/ReadWrite) are invalid. The skill detects this upfront to avoid failed deployments.

What happens if I change OWD to a more restrictive level?

Salesforce triggers a sharing recalculation, which can take significant time on large orgs. The skill warns you before deployment so you can plan for this.

What permission do I need to update OWD settings?

You must have the Manage Sharing permission or System Administrator profile. Without it, queries and deployments will fail with INSUFFICIENT_ACCESS errors.

Full instructions (SKILL.md)

Source of truth, from forcedotcom/sf-skills.


name: platform-sharing-owd-configure description: "Use when the user wants to retrieve or update Organization-Wide Default (OWD) sharing settings for Salesforce objects. TRIGGER on org-wide defaults, checking/viewing sharing defaults, changing default access levels (Private, Public Read Only, Public Read/Write, Controlled by Parent), internal/external access for standard or custom objects, making records private, or sharingModel in .object-meta.xml files. DO NOT TRIGGER for sharing rules, criteria-based sharing, role hierarchy, or manual sharing — delegate to platform-sharing-rules-generate." metadata: relatedSkills: - "platform-metadata-deploy" - "platform-sharing-rules-generate" version: "1.2" domains: ["Platform"] cliTools: - tool: ["sf"] semver: ">=2.0.0"

Managing Org-Wide Defaults

Retrieve and update Organization-Wide Default (OWD) sharing settings for standard and custom objects in a Salesforce org. OWDs define the baseline level of access users have to records they do not own.

Scope

  • In scope: Retrieving current OWD settings, updating internal/external access levels for standard and custom objects
  • Out of scope: Sharing rules, role hierarchy configuration, manual sharing, permission sets, criteria-based sharing — delegate to appropriate skills

Clarifying Questions

Before proceeding, confirm with the user if not already clear:

  • Which object(s) do you want to get or update OWD settings for?
  • What access level do you want to set? (Private, Public Read Only, Public Read/Write, Controlled by Parent)
  • Do you need to change both internal and external access, or just one?

Required Inputs

Gather or infer before proceeding:

  • Target org: The org alias or username to query/update (use default org if not specified)
  • Object name(s): Standard object API name (e.g., Account, Contact) or custom object API name (e.g., Invoice__c)
  • Operation: Get (retrieve current settings) or Update (change access levels)
  • Access levels (for update): Internal access and/or external access values

Defaults unless specified:

  • Use the default connected org
  • If only one access level is provided, assume it applies to internal access

Workflow

All steps are sequential. Do not skip or reorder.

Phase 1 — Retrieve Current Settings

  1. Query current OWD settings using the Salesforce CLI Tooling API: sf data query --query "SELECT QualifiedApiName, InternalSharingModel, ExternalSharingModel FROM EntityDefinition WHERE QualifiedApiName = '<ObjectName>'" --use-tooling-api --target-org <org>

  2. For retrieving all OWD settings at once: sf data query --query "SELECT QualifiedApiName, InternalSharingModel, ExternalSharingModel FROM EntityDefinition WHERE IsCustomizable = true ORDER BY QualifiedApiName" --use-tooling-api --target-org <org>

  3. Present results clearly — read references/access_levels.md for valid values and display a formatted table to the user.

Phase 2 — Update Settings (if requested)

  1. Check for immutable/fixed OWD — read references/access_levels.md "Immutable / Fixed OWD Objects" section. If the requested change targets a fixed value (e.g., Price Book external OWD), stop immediately and explain to the user that this value is platform-fixed and cannot be changed by any means. Do not attempt a deploy.

  2. Validate the requested access level — read references/access_levels.md to confirm the value is valid for the target object. If the value is not in the allowed set for that object, explain what values are valid and ask the user to choose one. Do not guess alternative values.

  3. Retrieve the object metadata using the Metadata API (same command for both standard and custom objects): sf project retrieve start --metadata CustomObject:<ObjectName> --target-org <org>. This retrieves <ObjectName>.object-meta.xml containing <sharingModel> and <externalSharingModel>. See references/metadata_api_approach.md for the full procedure.

  4. Modify the sharing settings — update the <sharingModel> (internal access) and/or <externalSharingModel> (external access) in the object's .object-meta.xml. Read references/metadata_api_approach.md for details.

  5. Pre-deploy verification — before deploying, confirm:

    • External access is not more permissive than internal access
    • Objects with Master-Detail relationships use ControlledByParent
    • The requested access level is valid for the target object (see references/access_levels.md)
    • Cross-object constraints are satisfied (see "Cross-Object Constraints" in references/access_levels.md)
    • The target field is not listed as immutable/fixed in references/access_levels.md
  6. Deploy the updated settings: sf project deploy start --metadata CustomObject:<ObjectName> --target-org <org>.

  7. Handle deploy failure (max 2 attempts): If the deploy fails:

    • Read the error message and identify the root cause.
    • If the error indicates the value is invalid or unsupported for the object, stop — report the failure to the user with the exact error message and explain what is and isn't possible. Do not try alternative values unless the user explicitly requests a different valid value.
    • If the error is transient (network timeout, auth expired), retry once.
    • Never attempt more than 2 total deploys for the same change. After 2 failures, report the error, discard local edits (sf project retrieve start --metadata CustomObject:<ObjectName> --target-org <org>), and ask the user how to proceed.
  8. Verify the change by re-running the query from Phase 1, Step 1.


Rules / Constraints

ConstraintRationale
Objects with Master-Detail relationships must use ControlledByParentPlatform enforces this — attempting other values fails
External access cannot be more permissive than internal accessSalesforce rejects configurations where external > internal
Some objects have immutable/fixed OWD (e.g., Price Book external, User, Activity external)These are platform-enforced — explain impossibility upfront, never attempt a deploy
Price Book only accepts Use (ReadSelect) or No Access (None) for internal OWD; external is always NoneStandard access levels (Private/Read/ReadWrite) are invalid for Price Book
Changing OWD to more restrictive triggers sharing recalculationThis can take significant time on large orgs — warn the user
Custom objects default to Public Read/Write when createdUsers may not realize the default is permissive
For managed package custom objects, use the full API name including namespace prefix (e.g., ns__Object__c)Namespace-prefixed objects require the prefix in both queries and metadata retrieval
Always verify the org connection before queryingPrevents confusing error messages
Maximum 2 deploy attempts per changePrevents unbounded retry loops — after 2 failures, stop and report to the user

Gotchas

IssueResolution
INSUFFICIENT_ACCESS error when updatingUser needs Manage Sharing permission or System Administrator profile
OWD change appears stuckSharing recalculation is running — check Setup > Sharing Settings for progress
Custom object not found in queryUse the full API name including __c suffix
ControlledByParent not availableObject has no Master-Detail relationship — use Private, Public Read Only, or Public Read/Write
External access field not showingExternal sharing model only appears when external org-wide defaults are enabled
Query returns no resultsObject may not be customizable or API name may be incorrect — verify spelling
Deploy fails with invalid value for Price BookPrice Book only accepts Use/None (internal) and external is fixed at None — do not retry with other values, explain to user

Output Expectations

Deliverables:

  • For get operations: Formatted table showing object name, internal access level, and external access level
  • For update operations: Confirmation of the change with before/after comparison

Cross-Skill Integration

NeedDelegate to
Creating sharing rules after restricting OWDplatform-sharing-rules-generate skill
Deploying metadata changes to another orgplatform-metadata-deploy skill

Reference File Index

FileWhen to read
references/access_levels.mdWhen validating or explaining OWD access level values
references/metadata_api_approach.mdWhen using Metadata API to update OWD instead of Tooling API
examples/get_owd_output.mdTo verify formatted output matches expected structure
examples/update_owd_output.mdTo verify update confirmation matches expected structure