このスキルは、ユーザーが Salesforce の共有ルール(レコード共有に関する設定)のメタデータ(データについての情報)を取得・作成・編集・削除・管理する必要がある場合に使用します。 **以下の場合に使用してください:** - ユーザーが共有ルール、レコード共有、条件ベース共有、役職ベース共有、ゲストユーザーの共有、sharingRules、sharingCriteriaRules、sharingGuestRules、sharingOwnerRules、.sharingRules-meta.xml ファイルについて言及した場合 - 特定の役職やグループとレコードを共有するよう求められた場合 - 組織内の既存の共有ルールを取得・確認したい場合 - 既存の共有ルールを変更・削除したい場合 - 共有ルールの条件やアクセスレベルを更新したい場合 **このスキルを使用しないでください:** - ユーザーが権限セット(アクセス権設定)またはプロファイル(ユーザー権限の集合)が必要な場合は、platform-permission-set-generate を使用してください - オブジェクトレベルセキュリティ(データ全体へのアクセス制御)が必要な場合は、platform-permission-set-generate を使用してください
Use this skill when users need to get, create, edit, delete, or manage Salesforce Sharing Rules metadata. TRIGGER when: users mention sharing rules, record sharing, criteria-based sharing, role-based sharing, guest user sharing, sharingRules, sharingCriteriaRules, sharingGuestRules, sharingOwnerRules, .sharingRules-meta.xml files, or ask to share records with specific roles or groups. Also trigger when users want to retrieve or view existing sharing rules from an org, modify or remove existing sharing rules, or update sharing rule criteria or access levels. DO NOT TRIGGER when user needs permission sets or profiles (use platform-permission-set-generate), or needs object-level security rather than record-level sharing (use platform-permission-set-generate).
Salesforceの共有ルール(アクセス権限)の作成、編集、削除を行い、組織全体の既定設定を超えたレコードレベルのアクセス制御を実現します。条件ベースのルール、ロール/グループベースのオーナールール、Experience Sites向けのゲストユーザールールに対応しています。
対応する機能:
sharingCriteriaRules(条件ベースのルール)、sharingOwnerRules(ロール/グループベースのルール)、sharingGuestRules(ゲストユーザールール)メタデータの作成、編集、削除非対応の機能:
platform-permission-set-generateスキルを使用してください)作業を進める前に、不明な点は以下の内容をユーザーに確認してください。
作業を開始する前に以下の情報を確認または推測してください。
Account、Property__c)sharingCriteriaRules、sharingOwnerRules、sharingGuestRulesのいずれかRead(閲覧のみ)またはEdit(読取/書込)指定がない場合のデフォルト値:
ReadincludeRecordsOwnedByAll: 条件ベースルールの場合はtrueincludeHVUOwnedRecords: ゲストルールの場合はfalseNoneに設定したaccountSettingsを含める各フェーズ内のステップは順序立てて実行します。フェーズ3は操作タイプごとに分岐します。該当する部分だけを実行してください。
SFDXプロジェクトパスの確認 — プロジェクトのsfdx-project.jsonを探し、sharingRules/ディレクトリのパッケージディレクトリを特定してください。
既存共有ルールの確認 — <packageDir>/sharingRules/<ObjectName>.sharingRules-meta.xmlが存在するか確認してください。存在する場合は読み込んで、既存ルールの内容を把握し、重複を避けてください。
ローカルファイルが存在しない場合は、組織から取得してください: sf project retrieve start --metadata "SharingRules:<ObjectName>" --target-org <org>
操作内容の識別 — ユーザーが共有ルールの作成、編集、または削除のどれを望んでいるか判定してください。
ユーザーの意図に基づいてルールタイプを選択してください。各タイプの完全なスキーマと必須要素については、references/rule-types.mdを読んでください。
取引先共有ルールの場合: accountSettings要素が必須です。ユーザーが別の指定をしていない限り、サブアクセスレベルはすべてNoneに設定してください。
ゲストルールの場合: sharedToは、そのサイトのゲストユーザーのコミュニティニックネームを使って<guestUser>を使用する必要があります。ゲストルールに<role>や<group>を使用しないでください。
8a. XMLを構築してください — references/rule-types.mdのスキーマに従います。重要な構造:
- オブジェクトごとに1つの.sharingRules-meta.xmlファイル
- 同じオブジェクトのすべてのルールは同じファイルに格納
- 既存ファイルに追加する場合は、既存の<SharingRules>ルート要素内に新しいルール要素を追加してください
8b. ルール名を付けてください — 意図に基づいて<fullName>を導出します(パスカルケース、スペースなし、説明的な名前)。対応する<label>をタイトルケース(単語の最初を大文字)でスペースを含めて生成してください。
8a. 対象ルールを特定してください — 既存の.sharingRules-meta.xmlファイルで<fullName>または<label>によってルールを探します。
8b. 変更内容を判定してください — 変更する要素(例:<accessLevel>、<sharedTo>、<criteriaItems>、<label>)と新しい値を特定してください。この時点では書き込まないでください。すべてのディスク書き込みはフェーズ5でユーザーの確認後に行います。
8a. 対象ルールを特定してください — 既存の.sharingRules-meta.xmlファイルで<fullName>または<label>によってルールを探します。
8b. 残存ルール数を確認してください — grep -c '<sharingCriteriaRules>\|<sharingOwnerRules>\|<sharingGuestRules>' <file>を実行してルール総数を取得します。数が1の場合(削除対象のみ)は、ファイル全体をフェーズ5で削除する必要があります。この時点では書き込まないでください。すべてのディスク書き込みはフェーズ5でユーザーの確認後に行います。
ディスクに書き込む前に、変更内容のサマリーを提示してください。ユーザーの確認を待つために必ず停止してください。サマリーは以下の形式でフォーマットしてください。
操作: 作成 / 編集 / 削除 オブジェクト:
<ObjectName>ルール:<fullName>(<label>) 変更内容: (作成/変更/削除する内容を説明)実行しますか? (yes / no / edit)
ユーザーが明示的に確認するまで、ファイル変更を書き込まないでください。 ユーザーが「no」と言った場合は中止してください。ユーザーが「edit」と言った場合は、フィードバックを反映して再度提示してください。
ユーザーが確認した後にのみ変更を適用してください:
<packageDir>/sharingRules/<ObjectName>.sharingRules-meta.xmlに書き込んでください。<packageDir>/sharingRules/<ObjectName>.sharingRules-meta.xml全体を削除してください。以下の検証チェックリストを実行し、出力を提示する前に、シナリオ別の予期される動作についてサンプルファイル(examples/create-cases.md、examples/edit-cases.md、examples/delete-cases.md)を確認してください。
<SharingRules xmlns="http://soap.sforce.com/2006/04/metadata">ルート要素がありますか?<fullName>がパスカルケースでスペースなしですか?<label>が存在し、人間が読める形式ですか?<accessLevel>がReadまたはEditのいずれかですか?<includeRecordsOwnedByAll>が存在しますか(必須のブール値)?<criteriaItems>に<field>、<operation>、<value>がありますか?<sharedTo>が<guestUser>を使用していますか(<role>や<group>ではなく)?<includeHVUOwnedRecords>が存在しますか(必須のブール値)?<includeRecordsOwnedByAll>が存在していませんか(条件ベースルールのみで、ゲストルールには不要)?<sharedFrom>と<sharedTo>の両要素がありますか?<role>、<roleAndSubordinates>、または<group>ターゲットを使用していますか?<fullName>で一致)が削除されましたか?<SharingRules>ルート要素を持つ整形済み状態ですか?<accountSettings>が3つすべてのサブ要素を含めて存在しますか?<caseAccessLevel>、<contactAccessLevel>、<opportunityAccessLevel>がすべて設定されていますか?| 制約 | 理由 |
|---|---|
オブジェクトごとに1つの.sharingRules-meta.xmlファイル |
プラットフォームの要件 — 複数ファイルはデプロイエラーの原因 |
ゲストルールはsharedToに<guestUser>を使用する必須 |
<role>や<group>を使用すると「Specify a guest user's nickname for the guestUser field」エラーが発生 |
取引先ルールは<accountSettings>を必須とする |
なければ「AccountSettings is required for account sharing rules」エラーが発生 |
includeRecordsOwnedByAllは条件ベースルールで必須 |
なければ「Required field is missing: sharingCriteriaRules」エラーが発生 |
includeHVUOwnedRecordsはゲストルールで必須 |
なければデプロイエラーが発生 |
| 条件フィールド値は組織内のピ |
Get, create, edit, and delete Salesforce Sharing Rules metadata to control record-level access beyond org-wide defaults. Supports criteria-based rules, role/group-based owner rules, and guest user rules for Experience Sites.
sharingCriteriaRules, sharingOwnerRules, and sharingGuestRules metadata; retrieving existing sharing rules from an org using the Metadata API Retrieve pattern; appending new rules to existing files; modifying rule criteria or access levels; removing rules from metadata files; configuring rules for Guest and Portal profiles.platform-permission-set-generate), territory-based sharing rules.Before proceeding, confirm with the user if not already clear:
sharedTo and sharedFrom cannot be edited in place)Gather or infer before proceeding:
Account, Property__c)sharingCriteriaRules, sharingOwnerRules, or sharingGuestRulesRead or Edit (maps to Read-Only or Read/Write)Defaults unless specified:
ReadincludeRecordsOwnedByAll: true for criteria rulesincludeHVUOwnedRecords: false for guest rulesaccountSettings with all sub-access levels set to NoneSteps are sequential within each phase. Phase 3 branches by operation type — execute only the matching branch. Phase 4 applies to create, edit, and delete only (get operations end at Phase 3).
Resolve the SFDX project path — find the project's sfdx-project.json and identify the package directory for sharingRules/.
Always retrieve the latest sharing rules from the org using the Metadata API Retrieve pattern:
sf project retrieve start --metadata "SharingRules:<ObjectName>" --target-org <org>
This ensures the local file reflects the current org state. Never trust a local file that may be stale — edits or deletes against a stale file can recreate rules that were already removed in the org or overwrite changes made by other users.
Read the retrieved file — parse <packageDir>/sharingRules/<ObjectName>.sharingRules-meta.xml to understand existing rules and avoid duplicates.
Identify the operation — determine whether the user wants to get, create, edit, or delete a sharing rule.
Select the rule type based on user intent. Read references/rule-types.md for the complete schema of each type and its required elements.
For Account sharing rules: the accountSettings element is required. Default sub-access levels to None unless the user specifies otherwise.
For Guest rules: the sharedTo must use <guestUser> with the site guest user's community nickname. Never use <role> or <group> for guest rules.
8a. Use the file already retrieved in Phase 1 — the retrieve in step 2 already pulled the latest <ObjectName>.sharingRules-meta.xml from the org. No additional retrieve is needed.
8b. Read and present the retrieved rules — parse the .sharingRules-meta.xml file and present the rules to the user in a readable format showing:
- Rule name (fullName) and label
- Rule type (criteria-based, owner-based, or guest)
- Access level
- Shared-to target
- Criteria (if applicable)
For get operations, skip Phase 4 (no write needed). The retrieve itself writes the metadata file to the local project.
8a. Construct the XML following the schema in references/rule-types.md. Key structure:
- One .sharingRules-meta.xml file per object
- All rules for the same object go in the same file
- If appending to an existing file, add the new rule element inside the existing <SharingRules> root
8b. Name the rule — derive <fullName> from the intent (PascalCase, no spaces, descriptive). Generate a matching <label> in Title Case with spaces.
8a. Locate the target rule — find the rule by <fullName> or <label> in the existing .sharingRules-meta.xml file.
8b. Gate unsupported edits — the platform does NOT support in-place modification of <sharedTo> or <sharedFrom> elements. If the user requests a change to the sharing target or source, refuse the edit and instruct them to delete the existing rule and create a new one with the desired target. This is the same pattern used for rule-type changes (see TC-16).
8c. Determine modifications based on rule type:
- Owner-based rules (sharingOwnerRules): only <accessLevel> can be edited. The platform does not support modifying any other element (sharedTo, sharedFrom, label) on owner rules. If the user requests changes beyond access level, refuse and instruct them to delete + create.
- Criteria-based rules (sharingCriteriaRules): supported editable elements are <accessLevel>, <criteriaItems>, <label>, and <booleanFilter>.
- Guest rules (sharingGuestRules): supported editable elements are <accessLevel>, <criteriaItems>, <label>, and <includeHVUOwnedRecords>.
8a. Locate the target rule — find the rule by <fullName> or <label> in the existing .sharingRules-meta.xml file.
8b. Count remaining rules — run scripts/count-remaining-rules.sh <file> to get the total rule count. If the count is 1 (only the rule being deleted), the file must be removed entirely in Phase 4.
8c. Delegate destructive deployment to platform-destructive-deploy — a normal sf project deploy start is additive and will NOT remove a rule from the org. Delegate to the platform-destructive-deploy skill with the following context:
- Metadata type: SharingCriteriaRule, SharingOwnerRule, or SharingGuestRule (depending on the rule type)
- Member: <ObjectName>.<RuleFullName>
- Target org: the user's specified org
Apply the change:
<packageDir>/sharingRules/<ObjectName>.sharingRules-meta.xml.<packageDir>/sharingRules/<ObjectName>.sharingRules-meta.xml entirely.Run the verification checklist below and consult the examples files (examples/create-cases.md, examples/edit-cases.md, examples/delete-cases.md) for scenario-specific expected behaviors before presenting output.
<SharingRules xmlns="http://soap.sforce.com/2006/04/metadata"> root?<fullName> use PascalCase with no spaces?<label> present and human-readable?<accessLevel> one of Read or Edit?<includeRecordsOwnedByAll> present (required boolean)?<criteriaItems> have <field>, <operation>, and <value>?<sharedTo> use <guestUser> (NOT <role> or <group>)?<includeHVUOwnedRecords> present (required boolean)?<includeRecordsOwnedByAll> ABSENT (only for criteria rules, not guest rules)?<sharedFrom> and <sharedTo> elements?<role>, <roleAndSubordinates>, or <group> targets?accessLevelaccessLevel, criteriaItems, label, booleanFilteraccessLevel, criteriaItems, label, includeHVUOwnedRecordssharedTo/sharedFrom left unchanged? (if user requested that change, refuse and advise delete + create)<fullName>)?<SharingRules> root?platform-destructive-deploy delegated to with the correct metadata type (SharingCriteriaRule, SharingOwnerRule, or SharingGuestRule)?<accountSettings> present with all three sub-elements?<caseAccessLevel>, <contactAccessLevel>, <opportunityAccessLevel> all set?| Constraint | Rationale |
|---|---|
One .sharingRules-meta.xml file per object |
Platform requirement — multiple files cause deployment errors |
Guest rules must use <guestUser> in sharedTo |
Using <role> or <group> causes: "Specify a guest user's nickname for the guestUser field" |
Account rules require <accountSettings> |
Without it: "AccountSettings is required for account sharing rules" |
includeRecordsOwnedByAll is required on criteria rules |
Missing it causes: "Required field is missing: sharingCriteriaRules" |
includeHVUOwnedRecords is required on guest rules |
Missing it causes deployment failure |
| Criteria field values must exist as picklist values on the org | Invalid values cause: "Picklist value does not exist" |
Never hardcode file paths — resolve from sfdx-project.json |
Customer projects use custom package directories |
For managed package custom objects, use the full API name including namespace prefix (e.g., ns__Object__c) |
Namespace-prefixed objects store sharing rules under the prefixed name |
sharedTo and sharedFrom cannot be edited in place |
Platform does not support modifying sharing targets — deploy will fail. Delete the rule and create a new one instead |
Owner-based rules only support editing accessLevel |
No other field (label, sharedTo, sharedFrom) can be modified on owner rules — delete and recreate instead |
| Always retrieve from the org before edit or delete | Local files may be stale; editing a stale file can recreate deleted rules or overwrite concurrent changes |
| Deleting a rule requires a destructive deployment | A normal deploy is additive — it will not remove rules from the org. Delegate to platform-destructive-deploy |
| Edit must preserve unmodified elements | Changing only accessLevel must not alter criteriaItems or other fields |
| Delete must remove the entire rule block | Partial deletion leaves invalid XML and causes deployment failures |
| Delete last rule removes the file | An empty <SharingRules> root with no children is invalid metadata |
| Issue | Resolution |
|---|---|
Guest rule uses <role> instead of <guestUser> |
Replace with <guestUser>CommunityNickname</guestUser> |
Account rule missing accountSettings |
Add <accountSettings> with all three access level sub-elements set to None |
Criteria rule missing includeRecordsOwnedByAll |
Add <includeRecordsOwnedByAll>true</includeRecordsOwnedByAll> |
| Picklist value mismatch | Query the org for valid values before generating criteria |
| Appending duplicates existing rule name | Check existing <fullName> values before writing |
| Guest user nickname not found | Query: SELECT CommunityNickname FROM User WHERE UserType='Guest' AND IsActive=true |
User requests edit to sharedTo or sharedFrom |
Not supported — refuse the edit and instruct user to delete + create a new rule |
User requests edit to owner rule beyond accessLevel |
Not supported — owner rules only allow accessLevel edits. Refuse and instruct user to delete + create |
| Editing changes rule type (e.g., criteria → owner) | Not supported — delete the old rule and create a new one instead |
| Local file is stale (rule deleted/changed in org) | Always retrieve fresh from org before edit or delete to avoid recreating removed rules |
| Delete deployed with normal deploy (no destructive manifest) | Rule remains in the org — delegate to platform-destructive-deploy for proper removal |
| Deleting a rule referenced by other automation | Warn the user about potential downstream impact |
| Delete leaves malformed XML | Ensure proper XML structure after removal; validate the file is well-formed |
Deliverables:
<packageDir>/sharingRules/<ObjectName>.sharingRules-meta.xml — retrieved sharing rules file from the org, plus a formatted summary of all rules found<packageDir>/sharingRules/<ObjectName>.sharingRules-meta.xml — complete sharing rules file for the target object| Need | Delegate to |
|---|---|
| Permission set configuration | platform-permission-set-generate skill |
| Custom object creation (if target object doesn't exist) | platform-custom-object-generate skill |
| Destructive deployment (rule deletion from org) | platform-destructive-deploy skill |
| File | When to read |
|---|---|
references/rule-types.md |
Phase 2 — before generating any rule, to get the complete XML schema for each rule type |
scripts/count-remaining-rules.sh |
Phase 3, step 8b (Delete) — count sharing rule elements to determine if file should be removed |
examples/create-cases.md |
Phase 4, step 10 — expected behavior for create and append scenarios |
examples/edit-cases.md |
Phase 4, step 10 — expected behavior for edit scenarios |
examples/delete-cases.md |
Phase 4, step 10 — expected behavior for delete scenarios |
原文・著作権は Anthropic および各プラグイン作者に帰属します。日本語訳は Claude API による自動翻訳です。